Day 1 Flashcards

(30 cards)

1
Q

What does the ‘L’ in LG-SQ (Audit Objectives) stand for?

A

Legal and regulatory compliance – Ensuring systems comply with applicable laws, regulations, and contracts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the ‘G’ in LG-SQ stand for?

A

Governance – Ensuring compliance with internal policies, standards, and governance frameworks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does the ‘S’ in LG-SQ stand for?

A

Security – Ensuring confidentiality, integrity, and availability (CIA) of information systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the ‘Q’ in LG-SQ stand for?

A

Quality – Ensuring that IT systems are efficient and meet business needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can an auditor deviate from ISACA Standards?

A

Only if justifiably beneficial to the organization, and must be documented with reasoning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the role of ISACA Guidelines?

A

Provide guidance and commentary on how to apply the standards; not mandatory.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the role of ISACA Tools & Techniques?

A

Offer practical examples and aids to support implementation; discretionary use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three main phases of an audit?

A
  1. Planning
  2. Fieldwork & Documentation
  3. Reporting & Follow-up
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 4 main stages in the risk lifecycle?

A
  1. Risk Identification
  2. Risk Assessment
  3. Risk Treatment
  4. Risk Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the IS Audit Objectives

A

Legal, Governance, Security, Quality (LGSQ)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 5C of Audit Report

A

Criteria
Condition
Cause
Consequence
Corrective Action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the three levels of ISACA’s audit guidance?

A
  1. Standards (mandatory)
  2. Guidelines (recommended, use professional judgment)
  3. Tools and Techniques (optional support)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the role of ISACA Guidelines?

A

Provide guidance and commentary on how to apply the standards; not mandatory.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the role of ISACA Tools & Techniques?

A

Offer practical examples and aids to support implementation; discretionary use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the three main phases of an audit?

A
  1. Planning
  2. Fieldwork & Documentation
  3. Reporting & Follow-up
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the objective of the Planning Phase?

A

Define scope, objectives, and prepare audit strategy based on risk.

17
Q

What happens during Fieldwork & Documentation?

A

Perform testing, collect evidence, and document findings.

18
Q

What is included in Reporting & Follow-up?

A

Communicate findings, recommend corrective actions, and verify implementation.

19
Q

What is Inherent Risk?

A

The level of risk before any controls are applied.

20
Q

What is Residual Risk?

A

The risk that remains after controls are implemented.

21
Q

What is Risk Appetite?

A

The level of risk an organization is willing to accept.

22
Q

Name 4 common risk treatment strategies.

A
  1. Reduce (Mitigate)
  2. Transfer (e.g., insurance)
  3. Accept
  4. Avoid
23
Q

What audit framework does ISACA follow?

A

ISACA follows the IPPF (International Professional Practices Framework), based on the COSO framework.

24
Q

What is ITAF in ISACA guidance?

A

ITAF stands for Information Technology Assurance Framework, providing standards, guidelines, tools, and techniques for IT auditors.

25
What is the first step in the audit planning process?
Gain an understanding of the business, including its mission, vision, objectives, and processes.
26
Why should prior audit work papers be reviewed?
To understand past audit issues, trends, and assess control maturity, aiding in planning the depth of current audit checks.
27
Can auditors perform control self-assessments?
No, auditors should not perform CSAs but can guide, support, and facilitate them.
28
What role do auditors play in control self-assessment?
Auditors act as facilitators by helping to develop checklists and train the business units without directly executing the CSA.
29
What are some common types of IT audits?
Operational, integrated, administrative, specialized (e.g., pen testing), and functional audits for readiness assessment.
30
What is an integrated audit?
An audit combining IT, financial, and operational components into one review, often resulting in a consolidated report.