Free CISA Exam Flashcards

Memorize 50 essential terms and definitions for the ISACA Certified Information Systems Auditor (CISA). See the term, recall the definition, then flip to check yourself.

50 Flashcards
10 Topics
100% Free
TermClick to flip

Risk-Based Audit Planning

Tap to reveal definition
Card 1 of 50Audit Process

Filter by Topic

Jump to Card

About These CISA Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the ISACA Certified Information Systems Auditor (CISA). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Audit Process6 cards
Governance and IT Management6 cards
Risk and Controls6 cards
Evidence and Sampling6 cards
Reporting and Follow-Up5 cards
Systems Acquisition5 cards
Development and Change4 cards
Operations and Service Management5 cards
Business Resilience4 cards
Protection of Information Assets3 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

Risk-Based Audit Planning

An approach that directs audit resources toward areas with the greatest business impact and likelihood of control failure. Scope, timing, and testing depth should follow assessed risk rather than auditor preference or system visibility.

Audit Charter

A formal document that defines the audit function's purpose, authority, independence, and reporting line. It helps auditors obtain records and perform work without inappropriate management interference.

Audit Objective

The specific question the audit is designed to answer, such as whether access controls restrict privileged activity. Clear objectives keep procedures aligned with assurance needs and prevent unfocused testing.

Audit Scope

The boundaries of audit work, including systems, locations, processes, periods, and exclusions. Scope should be documented so stakeholders understand what assurance the audit does and does not provide.

Independence in IS Auditing

The auditor must be free from conflicts that could impair judgment or appear to impair judgment. Independence is especially important when reviewing systems, controls, or processes the auditor helped design.

Professional Skepticism

A questioning mindset that accepts neither management assertions nor system outputs without appropriate support. It requires corroborating claims with evidence while staying fair and objective.

IT Governance

The leadership and oversight structure that ensures technology supports business objectives, delivers value, and manages risk. Auditors evaluate whether decision rights, accountability, and measurement are clear.

Board Oversight of IT

The board or executive leadership sets direction, risk appetite, and accountability for major technology decisions. Day-to-day configuration and troubleshooting belong to management, not governance bodies.

IT Strategy Alignment

The condition where IT priorities, investments, and services support business goals. Misalignment can cause technically successful projects to fail because they do not deliver needed business value.

Policy Review

A governance control that keeps policies current with business changes, technology, threats, and legal obligations. Stale policies may describe controls that no longer exist or omit risks that now matter.

IT Steering Committee

A cross-functional group that helps prioritize technology initiatives, resolve resource conflicts, and keep projects aligned with business needs. Effective committees include business representation, not only IT staff.

Third-Party Governance

Oversight of vendors through due diligence, contracts, service expectations, security requirements, and monitoring. The organization can outsource work, but it retains accountability for related risks.

Inherent Risk

The level of risk that exists before considering controls. Complex processes, high transaction value, sensitive data, or rapid change can raise inherent risk even before control design is reviewed.

Residual Risk

The risk remaining after controls are designed and operating. Management may reduce, transfer, avoid, or accept residual risk, but acceptance should be informed and consistent with risk appetite.

Risk Appetite

The amount and type of risk leadership is willing to accept in pursuit of objectives. Controls and monitoring should be evaluated against this business-level tolerance, not against a zero-risk ideal.

Preventive Control

A control designed to stop an unwanted event before it occurs. Examples include access approvals, input validation, segregation of duties, and configuration settings that block unauthorized actions.

Detective Control

A control designed to identify errors, exceptions, or unauthorized activity after they occur. Log reviews, reconciliations, exception reports, and monitoring alerts support timely investigation.

Compensating Control

An alternate control that reduces risk when the preferred control is absent or impractical. Auditors should verify that the compensating control actually addresses the same risk and operates reliably.

Sufficient Evidence

Evidence is sufficient when there is enough support to justify the audit conclusion. Higher-risk findings usually require more corroboration than low-risk observations.

Appropriate Evidence

Evidence is appropriate when it is relevant, reliable, and directly tied to the audit objective. A system screenshot may show a setting, but logs or approvals may be needed to prove operation over time.

Population in Audit Sampling

The complete set of items from which a sample is selected. If the population is incomplete or incorrectly defined, sample results may not support the intended conclusion.

Sampling Risk

The risk that a sample leads to a conclusion different from testing the full population. Auditors manage it through sample design, confidence expectations, and careful interpretation of exceptions.

CAATs

Computer-assisted audit techniques use technology to analyze data, test controls, identify anomalies, or select samples. They improve coverage but still require auditor judgment about criteria and conclusions.

Audit Trail

A record of events that allows activity to be traced from initiation through processing and approval. A reliable audit trail supports accountability, investigation, and reconstruction of transactions.

Audit Finding

A documented condition that explains what was observed, the expected criterion, the cause, the risk or effect, and the recommended action. Strong findings are evidence-based and actionable.

Criteria in an Audit Report

The standard, policy, control objective, law, contract, or procedure used to judge the observed condition. Without criteria, a finding may read like preference instead of a defensible audit conclusion.

Management Response

Management's documented agreement, disagreement, action plan, owner, and target timing for an audit issue. The response helps convert findings into accountable remediation work.

Follow-Up Audit Work

Procedures performed to verify whether agreed corrective actions were completed and effective. Closure should be based on evidence, not only on management's statement that remediation is finished.

Materiality in IS Audit

The significance of an issue based on business impact, risk, compliance effect, or decision relevance. Materiality helps determine how prominently a matter should be reported.

Requirements Traceability

A method for linking business requirements to design, build, testing, and acceptance evidence. It helps auditors determine whether the delivered system addresses approved needs.

Business Case

The documented rationale for a technology investment, including expected benefits, costs, risks, and alternatives. Auditors review whether approval was based on business value rather than technical enthusiasm alone.

User Acceptance Testing

Testing by business users to confirm the system supports intended workflows and requirements. It is not a substitute for technical testing; it validates business readiness.

Data Migration Reconciliation

Controls that compare source and target data for completeness and accuracy after conversion. Record counts, control totals, exception review, and sign-off help prove migration integrity.

Post-Implementation Review

A review after go-live that evaluates whether objectives were met, benefits are being realized, controls are working, and lessons should inform future projects.

Change Advisory Board

A group that reviews proposed changes for risk, readiness, timing, approvals, and business impact. Its value comes from disciplined review, not from rubber-stamping every request.

Emergency Change

A change made quickly to restore service or address urgent risk. It should still be logged, authorized under emergency procedures, tested when practical, and reviewed after implementation.

Segregation of Development and Production

Developers should not have uncontrolled ability to modify production systems. Separating duties reduces the risk of unauthorized code, untested changes, and concealed errors.

Version Control

A control for tracking code, configuration, and document changes over time. It supports accountability, rollback, peer review, and evidence that approved versions reached production.

Service Level Agreement

A documented commitment between a service provider and customer that defines expected service performance, responsibilities, reporting, and remedies. Auditors compare measured performance to agreed service targets.

Incident Management

The process for restoring normal service after disruption while recording impact, actions, and resolution. Good incident records support trend analysis and later problem management.

Problem Management

The process for identifying and addressing root causes of recurring or significant incidents. Its goal is to reduce future disruption rather than simply close individual tickets faster.

Capacity Management

Planning and monitoring resources so systems can meet current and future demand. Auditors look for forecasts tied to business growth, thresholds, and timely scaling decisions.

Job Scheduling Controls

Controls over automated processing that ensure jobs run completely, in the correct order, and with exception alerts. Failures should be detected by operations, not first discovered by users.

Business Impact Analysis

A process that identifies critical business functions, dependencies, disruption impacts, and recovery priorities. It provides the business basis for continuity and recovery requirements.

RTO and RPO

Recovery time objective is the target time to restore a service; recovery point objective is the acceptable amount of data loss measured by time. Both should be driven by business impact.

Backup Restoration Testing

A control that proves backups can actually be restored and used. Successful backup jobs alone do not provide assurance if restoration procedures, media, permissions, or data integrity fail.

Continuity Plan Exercise

A planned test of roles, procedures, communication, and recovery capability. Exercises should produce lessons learned and updates to plans, contact lists, and dependencies.

Least Privilege

Users, services, and administrators receive only the access needed for their duties. Access should be approved, periodically reviewed, and removed when duties change.

Data Classification

A scheme that labels information by sensitivity, value, and handling requirements. Classification helps determine access, encryption, retention, sharing, and disposal controls.

Centralized Security Logging

Sending logs to a protected location improves monitoring and preserves evidence if a source system is compromised. Access, retention, time synchronization, and alerting all affect log usefulness.

Frequently Asked Questions

What does the CISA exam cover?

CISA covers five ISACA domains: the information systems auditing process, governance and management of IT, systems acquisition and implementation, operations and business resilience, and protection of information assets.

How should I use these CISA flashcards?

Use the cards for active recall, then apply the terms in audit scenarios. For each missed card, identify the related control objective, likely evidence, business risk, and defensible auditor action.

What is the CISA retake timing?

Candidates typically face a 30-day wait before the second attempt and 90-day waits before later attempts within the allowed attempt cycle.

Same family resources

Explore More ISACA Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.