← All CISA Flashcard Decks

IT Audit Standards and Frameworks Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IT Audit Standards and Frameworks flashcards as text
  1. What does the acronym COBIT stand for?

    Answer: Control Objectives for Business and Related Technology

    COBIT stands for Control Objectives for Business and Related Technology, the IT governance and management framework developed by ISACA.

  2. ISO 27001 is an international standard that primarily addresses which of the following?

    Answer: Information security management systems (ISMS)

    ISO 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

  3. The COSO Internal Control — Integrated Framework is primarily designed to help organizations with which concern?

    Answer: Internal control and enterprise risk management

    COSO is a widely adopted framework for designing, implementing, and evaluating internal control and enterprise risk management across an organization.

  4. Which framework is specifically designed for IT service management best practices?

    Answer: ITIL

    ITIL (Information Technology Infrastructure Library) is the globally recognized framework of best practices for IT service management.

  5. COBIT 2019 organizes governance and management objectives into how many domains?

    Answer: 5

    COBIT 2019 defines five domains: EDM (governance) and APO, BAI, DSS, MEA (management), for a total of five domains.

  6. Which ISO standard specifically addresses IT governance for organizations?

    Answer: ISO 38500

    ISO 38500 provides principles for the governance of IT, guiding board members and senior managers in evaluating, directing, and monitoring IT use.

  7. ISACA's IS Audit and Assurance Standards are organized into which three primary categories?

    Answer: Standards, Guidelines, and Tools and Techniques

    ISACA organizes its IS audit and assurance publications into Standards (mandatory), Guidelines (guidance), and Tools and Techniques (practical assistance).