← All CISA Flashcard Decks

IS Audit Planning Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IS Audit Planning flashcards as text
  1. An IS auditor is planning an audit of a cloud-hosted ERP system. Which consideration is UNIQUE to cloud environments compared to on-premises systems?

    Answer: Reliance on third-party audits such as SOC 2 reports to assess provider controls

    In cloud environments, the auditor typically cannot directly test provider infrastructure controls and must rely on third-party assurance reports like SOC 2 Type II to evaluate those controls.

  2. During IS audit planning, the concept of 'audit universe' refers to:

    Answer: The complete inventory of auditable entities from which the audit plan is derived

    The audit universe is the comprehensive inventory of all auditable entities — systems, processes, departments — that forms the basis for developing a risk-based audit plan.

  3. When should IS audit planning ideally begin relative to the audit fieldwork?

    Answer: Well in advance to allow adequate preparation, risk assessment, and resource allocation

    Planning should begin well in advance of fieldwork to allow time for risk assessment, scoping, resource scheduling, and coordination with auditees.

  4. Which factor would MOST likely cause an IS auditor to increase the sample size during audit planning?

    Answer: High control risk

    High control risk means existing controls may not be effective, so the auditor needs a larger sample to gain sufficient confidence in the audit conclusions.

  5. An IS auditor planning an audit of the software development lifecycle (SDLC) should PRIMARILY focus on which phase for the highest control risk?

    Answer: Production deployment phase

    Production deployment is the highest-risk SDLC phase because unauthorized or untested code moving to production can directly impact business operations and data integrity.

  6. In the context of IS audit planning, 'scope creep' refers to:

    Answer: Gradual expansion of audit scope beyond what was originally agreed, without corresponding adjustment of resources or timelines

    Scope creep occurs when the audit scope expands incrementally beyond original boundaries without formal approval, potentially compromising audit quality and resource management.

  7. Which of the following BEST describes a risk-based audit approach in IS audit planning?

    Answer: Allocating audit resources to areas with the highest risk to achieve audit objectives efficiently

    A risk-based approach directs audit resources toward the areas posing the greatest risk, ensuring that audit effort is proportionate to the likelihood and impact of potential issues.

IS Audit Planning Flashcards — CISA Study Cards with Answers