← All CISA Flashcard Decks

IT Audit Standards and Frameworks Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IT Audit Standards and Frameworks flashcards as text
  1. In IS auditing, 'audit risk' is composed of which three components?

    Answer: Inherent risk, control risk, and detection risk

    Audit risk is the product of inherent risk (risk without controls), control risk (risk that controls fail), and detection risk (risk auditors miss a material issue).

  2. Within ISACA's framework, which component provides IS auditors with specific step-by-step procedures for conducting an audit?

    Answer: Tools and Techniques

    Tools and Techniques are practical resources that provide IS auditors with specific procedures, checklists, and methods to apply the Standards and Guidelines.

  3. According to the COSO framework, internal control is best described as:

    Answer: A process effected by an entity's board, management, and other personnel

    COSO defines internal control as a process effected by people at all levels of the organization — the board, management, and staff — not just a set of policies.

  4. The COBIT 2019 management domain APO primarily deals with which activities?

    Answer: Aligning IT strategy with business goals, planning IT resources, and organizing IT functions

    APO (Align, Plan and Organize) covers strategic alignment, IT resource planning, portfolio management, risk management, and organizational structures.

  5. ISACA's CRISC certification complements CISA by focusing on which specialized area?

    Answer: IT risk identification and information systems control

    CRISC (Certified in Risk and Information Systems Control) focuses on IT risk identification, assessment, response, and the design of IS controls — a natural complement to CISA.

  6. What is the primary purpose of IT governance frameworks such as COBIT for an organization?

    Answer: To provide a common language and framework for aligning IT with business objectives

    IT governance frameworks like COBIT provide a structured approach and common language to ensure IT activities align with and deliver value to business objectives.

  7. When ISO 27001 is implemented, the Plan-Do-Check-Act (PDCA) cycle is applied to:

    Answer: Manage and continually improve the information security management system

    ISO 27001 applies the PDCA cycle to the ISMS lifecycle: Plan (establish), Do (implement), Check (monitor and review), Act (improve and correct).