Day 1 Flashcards
(30 cards)
What does the ‘L’ in LG-SQ (Audit Objectives) stand for?
Legal and regulatory compliance – Ensuring systems comply with applicable laws, regulations, and contracts.
What does the ‘G’ in LG-SQ stand for?
Governance – Ensuring compliance with internal policies, standards, and governance frameworks.
What does the ‘S’ in LG-SQ stand for?
Security – Ensuring confidentiality, integrity, and availability (CIA) of information systems.
What does the ‘Q’ in LG-SQ stand for?
Quality – Ensuring that IT systems are efficient and meet business needs.
Can an auditor deviate from ISACA Standards?
Only if justifiably beneficial to the organization, and must be documented with reasoning.
What is the role of ISACA Guidelines?
Provide guidance and commentary on how to apply the standards; not mandatory.
What is the role of ISACA Tools & Techniques?
Offer practical examples and aids to support implementation; discretionary use.
What are the three main phases of an audit?
- Planning
- Fieldwork & Documentation
- Reporting & Follow-up
What are the 4 main stages in the risk lifecycle?
- Risk Identification
- Risk Assessment
- Risk Treatment
- Risk Monitoring
What are the IS Audit Objectives
Legal, Governance, Security, Quality (LGSQ)
What are the 5C of Audit Report
Criteria
Condition
Cause
Consequence
Corrective Action
What are the three levels of ISACA’s audit guidance?
- Standards (mandatory)
- Guidelines (recommended, use professional judgment)
- Tools and Techniques (optional support)
What is the role of ISACA Guidelines?
Provide guidance and commentary on how to apply the standards; not mandatory.
What is the role of ISACA Tools & Techniques?
Offer practical examples and aids to support implementation; discretionary use.
What are the three main phases of an audit?
- Planning
- Fieldwork & Documentation
- Reporting & Follow-up
What is the objective of the Planning Phase?
Define scope, objectives, and prepare audit strategy based on risk.
What happens during Fieldwork & Documentation?
Perform testing, collect evidence, and document findings.
What is included in Reporting & Follow-up?
Communicate findings, recommend corrective actions, and verify implementation.
What is Inherent Risk?
The level of risk before any controls are applied.
What is Residual Risk?
The risk that remains after controls are implemented.
What is Risk Appetite?
The level of risk an organization is willing to accept.
Name 4 common risk treatment strategies.
- Reduce (Mitigate)
- Transfer (e.g., insurance)
- Accept
- Avoid
What audit framework does ISACA follow?
ISACA follows the IPPF (International Professional Practices Framework), based on the COSO framework.
What is ITAF in ISACA guidance?
ITAF stands for Information Technology Assurance Framework, providing standards, guidelines, tools, and techniques for IT auditors.