Career Employer

Your FREE CISA Flashcards 2026 – 250+ Cards

Realistic, CISA exam-style flashcards across all 5 ISACA domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CISA”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CISA cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official ISACA domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

CISA Flashcard Study Modes

Four modes run off the same 283 cards. Flip is for first passes and review. Match times you on pairing terms with definitions. Type shows the definition and asks you to produce the term, so a card like RPO has to come back cold. Quiz turns the fronts into multiple choice for a quick check. Rotate them rather than repeating one.

Free CISA flashcards from Career Employer — active recall for the Certified Information Systems Auditor exam

Why Flashcards Work for the CISA

IS Operations & Business Resilience holds 55 cards and shares the top 26% weighting. The cards drill recovery and availability measures such as RTO, RPO and MTD, along with reliability terms like MTBF and MTTR, and the infrastructure vocabulary behind continuity planning, including RAID, Hot site and Warm site.

Protection of Information Assets is the largest block at 66 cards and also carries 26%. Expect network and cryptography terms: DMZ, VPN and TLS for perimeter and transport, IPsec and Hashing for data in transit and at rest, and identity and monitoring cards such as SAML, OAuth and SIEM.

Information Systems Auditing Process, 58 cards weighted 18%, covers the vocabulary of the engagement itself through fronts like IS audit, Control and Fieldwork, plus the standards and techniques an auditor leans on, including ITAF, CAATs and Test data, and risk concepts such as Collusion and the CIA triad.

Governance & Management of IT, 54 cards and also 18%, works through frameworks and regulations such as COBIT, COSO and SOX, compliance drivers including GDPR and PCI DSS, and the document hierarchy you are expected to keep straight — Policy, Standard and Baseline.

IS Acquisition, Development & Implementation, 50 cards at 12%, is the lightest domain but still asks you to separate delivery approaches like Waterfall, Agile and DevOps, project artifacts such as Test plan and Gantt chart, and structures including PMO, SDLC and ERP system.

The CISA is dense with terminology — audit standards, control types, governance frameworks, recovery objectives, and security concepts.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

CISA Flashcards by Domain

The cards are organized by the five official ISACA domains. Lead with the two largest — Operations & Business Resilience and Protection of Information Assets (26% each) — but cover all five:[1]

CISA flashcards by domain and weight
DomainExam weight
IS Operations & Business Resilience26%
Protection of Information Assets26%
Information Systems Auditing Process18%
Governance & Management of IT18%
IS Acquisition, Development & Implementation12%

How to Get the Most Out of These Flashcards

  • Start with the 26% domains. IS Operations & Business Resilience and Protection of Information Assets carry the heaviest weighting, so work those 55 and 66 cards before you touch anything else.
  • Type-drill the acronyms. Fronts like RTO and SAML are easy to recognize and hard to reproduce, so stay in Type until the definition alone pulls the exact term back.
  • Match the look-alikes. Match is strongest on sets that blur together, such as Hot site against Warm site, or Policy against Standard and Baseline, where speed exposes the pairs you only half know.
  • Move to the practice test when recall holds. Once Quiz runs clean across Information Systems Auditing Process and Governance & Management of IT, shift to the practice test for scenario wording and use the study guide for gaps.
  • Keep sessions narrow. With 283 cards, take one domain per sitting, close with a mixed Quiz, and revisit the 50 cards in IS Acquisition, Development & Implementation often so the 12% domain does not fade.

CISA Flashcards FAQ

Hundreds of free CISA flashcards, organized across all five ISACA domains — Information Systems Auditing Process, Governance & Management of IT, IS Acquisition, Development & Implementation, IS Operations & Business Resilience, and Protection of Information Assets. They're free with no account required.

CISA flashcard bank

All 283 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Information Systems Auditing Process (58)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security and assurance.

IS audit
Show answer

An independent, systematic examination of information systems and controls to provide assurance over CIA and compliance.

ITAF
Show answer

ISACA's Information Technology Assurance Framework — the standards, guidelines, and tools for IS audit and assurance work.

IS audit standards
Show answer

Mandatory requirements in ITAF that every IS auditor must follow (vs. guidelines, which are recommended).

IS audit guidelines
Show answer

Recommended best-practice guidance in ITAF — helpful but not mandatory, unlike standards.

Risk-based audit planning
Show answer

Allocating limited audit resources to the areas of greatest risk and business impact to the organization.

Audit universe
Show answer

The complete inventory of auditable areas/entities from which the risk-based audit plan is built.

Audit charter
Show answer

A document, approved by senior management/the board, that defines the audit function's authority, scope, and responsibility.

Audit independence
Show answer

Freedom from conditions that threaten objectivity; the auditor must be impartial in fact and appearance.

Objectivity
Show answer

An unbiased mental attitude that lets the auditor perform work and form conclusions without compromise.

Due professional care
Show answer

Applying the diligence and skill a prudent, competent auditor would exercise in the same situation.

Materiality
Show answer

The threshold at which a finding is significant enough to influence decisions or require reporting.

Audit risk
Show answer

The risk an auditor reaches a wrong conclusion; a function of inherent, control, and detection risk.

Inherent risk
Show answer

The risk that exists before any controls are considered, due to the nature of the activity.

Control risk
Show answer

The risk that a material error is not prevented or detected by the internal control system.

Detection risk
Show answer

The risk that the auditor's procedures fail to detect a material error; the part the auditor controls.

Control
Show answer

A policy, procedure, or mechanism that reduces risk by preventing, detecting, or correcting an event.

Preventive control
Show answer

A control that stops an incident before it occurs (e.g., access controls, segregation of duties, firewalls).

Detective control
Show answer

A control that identifies an incident after it occurs (e.g., audit logs, monitoring, reconciliations).

Corrective control
Show answer

A control that restores systems and fixes the cause after an incident (e.g., backups, incident response).

Compensating control
Show answer

An alternative control used when the ideal (primary) control cannot feasibly be implemented.

Deterrent control
Show answer

A control that discourages a threat actor from acting (e.g., warning banners, visible cameras).

Compliance testing
Show answer

Testing whether a control is operating as designed (e.g., are change requests approved before deployment?).

Substantive testing
Show answer

Testing the integrity of data or results themselves (e.g., recomputing values, confirming balances).

Audit evidence
Show answer

Sufficient, reliable, and relevant information that supports the auditor's findings and conclusions.

CAATs
Show answer

Computer-Assisted Audit Techniques — software/analytics used to test large data populations directly.

Generalized audit software
Show answer

CAAT tools that read, extract, sort, and analyze data files independent of the audited application.

Integrated test facility (ITF)
Show answer

A CAAT that processes fictitious test transactions through the live system to verify processing controls.

Test data
Show answer

A CAAT technique that runs known input through a program to confirm it produces the expected output.

Continuous auditing
Show answer

Performing audit procedures automatically and frequently, often in near real time, on transactions.

Continuous monitoring
Show answer

Management's ongoing, automated oversight of controls and performance (a management activity, not audit).

Statistical sampling
Show answer

Selecting a sample using probability so results can be projected to the population with measurable confidence.

Non-statistical sampling
Show answer

Sample selection based on auditor judgment; results cannot be statistically projected to the population.

Attribute sampling
Show answer

Sampling that estimates the rate of occurrence of a condition (e.g., % of items missing approval).

Variable sampling
Show answer

Sampling that estimates a numeric value or total (e.g., the dollar value of an account).

Sampling risk
Show answer

The risk that the sample is not representative and leads the auditor to a wrong conclusion.

Control self-assessment (CSA)
Show answer

Process owners assess the adequacy of their own controls; supplements, never replaces, independent audit.

Audit finding
Show answer

A documented condition where a control is missing, inadequate, or not operating, with its risk and cause.

Audit follow-up
Show answer

Confirming that management acted on agreed recommendations and that the risk was actually reduced.

Audit report
Show answer

The auditor's objective communication of scope, findings, risk, and recommendations to management/the committee.

Irregularity vs. illegal act
Show answer

An irregularity is intentional deception (fraud); an illegal act violates laws/regulations — both must be reported.

Reasonable assurance
Show answer

A high but not absolute level of assurance — controls reduce risk to an acceptable level, not to zero.

Engagement letter
Show answer

An agreement defining the objectives, scope, responsibilities, and deliverables of a specific audit engagement.

Audit committee
Show answer

A board subcommittee that oversees the audit function, financial reporting, and internal controls.

Three lines model
Show answer

Management owns/controls risk (1st line); risk & compliance oversee (2nd); internal audit assures (3rd).

Stop-or-go sampling
Show answer

A sampling approach that lets the auditor stop early once enough evidence supports a low error rate.

Re-performance
Show answer

An auditor independently executing a control or calculation to verify it produces the correct result.

Walk-through
Show answer

Tracing a transaction end to end through a process to confirm the auditor understands the controls.

Inherent limitations of controls
Show answer

Controls can't give absolute assurance due to human error, collusion, and management override.

Collusion
Show answer

Two or more people cooperating to bypass segregation of duties and conceal fraud.

Management override
Show answer

Senior management bypassing controls — a key reason controls give only reasonable, not absolute, assurance.

Audit trail
Show answer

A chronological record of system activity that lets an auditor reconstruct and verify events.

Embedded audit module
Show answer

Code built into an application that continuously captures audit data on selected transactions.

Snapshot technique
Show answer

A CAAT that captures the state of data before and after processing to verify a transaction's path.

Risk assessment
Show answer

Identifying and analyzing risks to determine likelihood and impact, prioritizing audit and control effort.

Audit scope
Show answer

The boundaries of an engagement — what systems, processes, and time period the audit will cover.

Professional skepticism
Show answer

A questioning mindset that critically assesses evidence rather than assuming management's honesty.

Fieldwork
Show answer

The evidence-gathering phase of an audit, where tests of controls and substantive tests are performed.

Governance & Management of IT (54)

COBIT
Show answer

ISACA's framework for the governance and management of enterprise IT, separating governance from management.

IT governance
Show answer

The board/senior management's responsibility to set IT direction, define risk appetite, and monitor value.

IT management
Show answer

Planning, building, running, and monitoring IT day to day — execution, distinct from governance.

EDM (COBIT)
Show answer

COBIT governance objectives: Evaluate, Direct, and Monitor — the board's governance role.

IT strategy
Show answer

The plan that aligns IT investments and capabilities with the organization's business objectives.

IT steering committee
Show answer

A senior cross-functional group that prioritizes IT investments and aligns IT with business needs.

Enterprise architecture
Show answer

A blueprint of business processes, data, applications, and technology and how they fit together.

Policy
Show answer

A high-level statement of management intent and goals; mandatory direction for the organization.

Standard
Show answer

A specific, mandatory requirement that supports a policy (e.g., 'use AES-256 for data at rest').

Procedure
Show answer

Detailed, step-by-step instructions for performing a task in line with policy and standards.

Guideline
Show answer

Recommended, discretionary best practice — the only document type that is not mandatory.

Baseline
Show answer

A defined minimum level of security or configuration that systems must meet.

Segregation of duties (SoD)
Show answer

Splitting a sensitive task so no one person can both perform and conceal an error or fraud.

RACI chart
Show answer

A responsibility matrix: who is Responsible, Accountable, Consulted, and Informed for each activity.

Accountable vs. responsible
Show answer

Accountable = ultimately answerable (one person); responsible = does the work (one or more people).

Enterprise risk management (ERM)
Show answer

The organization-wide process to identify, assess, treat, and monitor risk against the risk appetite.

Risk appetite
Show answer

The amount and type of risk an organization is willing to accept in pursuit of its objectives.

Risk tolerance
Show answer

The acceptable variation around the risk appetite for a specific objective or activity.

Residual risk
Show answer

The risk that remains after controls are applied; senior management formally accepts it.

Risk mitigation
Show answer

Reducing risk to an acceptable level by implementing controls.

Risk transfer
Show answer

Shifting the financial impact of a risk to a third party, such as via insurance.

Risk avoidance
Show answer

Eliminating a risk by ceasing the activity that creates it.

Risk acceptance
Show answer

A documented, management-approved decision to tolerate a risk and its potential impact.

Maturity model
Show answer

A scale (e.g., 0–5) used to assess and improve how capable and consistent a process is.

Key performance indicator (KPI)
Show answer

A metric that measures how well an activity achieves its objective (e.g., uptime, project on-time rate).

Key risk indicator (KRI)
Show answer

A metric that signals rising exposure to a risk before it materializes.

Balanced scorecard
Show answer

A performance tool linking objectives across financial, customer, internal, and learning perspectives.

IT portfolio management
Show answer

Managing the set of IT investments to maximize value and align with strategy.

Benefits realization
Show answer

Confirming that an IT investment actually delivered the value promised in its business case.

Outsourcing
Show answer

Contracting a third party to perform an IT function; the organization retains accountability for risk.

Service provider governance
Show answer

Overseeing outsourced/cloud providers via contracts, SLAs, right-to-audit clauses, and monitoring.

Right-to-audit clause
Show answer

A contract term allowing the customer (or its auditors) to audit a service provider's controls.

Data governance
Show answer

The framework of roles, policies, and standards ensuring data is accurate, available, and controlled.

Data owner
Show answer

The senior business manager accountable for data who sets its classification and protection requirements.

Data custodian
Show answer

The party (usually IT) responsible for implementing and maintaining controls protecting data day to day.

Privacy by design
Show answer

Embedding privacy protections into systems and processes from the outset, not as an add-on.

Regulatory compliance
Show answer

Adhering to applicable laws, regulations, and industry standards (e.g., GDPR, SOX, PCI DSS).

PCI DSS
Show answer

The Payment Card Industry Data Security Standard governing the handling of cardholder data.

Conflict of interest
Show answer

A situation where a person's private interest could improperly influence their professional duties.

Quality management system (QMS)
Show answer

A documented set of processes ensuring IT services and products consistently meet requirements.

Capacity planning (governance)
Show answer

Aligning IT resource investment with forecast business demand to deliver value efficiently.

Strategic alignment
Show answer

Ensuring IT plans, investments, and operations directly support business goals.

Tone at the top
Show answer

The ethical climate set by leadership, which strongly shapes the organization's control environment.

Control environment
Show answer

The overall attitude, awareness, and actions regarding controls — the foundation of internal control.

COSO
Show answer

A framework defining internal control over five components, widely used for governance and SOX compliance.

SOX
Show answer

The Sarbanes-Oxley Act — U.S. law requiring management/auditors to assess internal control over financial reporting.

GDPR
Show answer

The EU General Data Protection Regulation governing the processing and protection of personal data.

Data controller
Show answer

Under privacy law, the entity that decides why and how personal data is processed.

Data processor
Show answer

A party that processes personal data on behalf of, and on the instructions of, the controller.

Vendor risk management
Show answer

Assessing and monitoring the risk introduced by third-party suppliers and service providers.

Cloud governance
Show answer

Overseeing cloud services for security, compliance, cost, and the shared-responsibility model.

Shared responsibility model
Show answer

Cloud security split between provider (of the cloud) and customer (in the cloud).

Key goal indicator (KGI)
Show answer

A metric that shows whether an IT process achieved its business goal (outcome-focused).

IT balanced scorecard
Show answer

Aligning IT performance to business value across multiple perspectives, not just cost.

IS Acquisition, Development & Implementation (50)

SDLC
Show answer

System Development Lifecycle — feasibility, requirements, design, build, test, implement, and review.

Feasibility study
Show answer

An early analysis of whether a proposed system is technically, operationally, and economically viable.

Business case
Show answer

The justification for a project — costs, benefits, risks, and alignment with strategy.

Requirements definition
Show answer

Capturing what the system must do (functional) and how well (non-functional) before design.

Waterfall
Show answer

A sequential SDLC where each phase completes before the next; suits stable, well-understood requirements.

Agile
Show answer

An iterative SDLC delivering working software in short sprints; suits changing requirements and fast feedback.

Prototyping
Show answer

Building an early working model to refine unclear requirements before full development.

DevOps
Show answer

Integrating development and operations to deliver and run software faster and more reliably.

Function point analysis
Show answer

A method to estimate software size/effort from the functionality delivered to the user.

Project management
Show answer

Planning, executing, and controlling a project's scope, schedule, cost, quality, and risk.

PMO
Show answer

Project Management Office — the function that governs and supports project delivery and standards.

Critical path method
Show answer

Scheduling technique identifying the longest sequence of dependent tasks that sets the minimum duration.

Gantt chart
Show answer

A bar chart showing project tasks against a timeline, used to plan and track schedule.

Scope creep
Show answer

Uncontrolled growth of project scope without corresponding adjustments to time, cost, or resources.

Unit testing
Show answer

Testing individual components or modules in isolation to confirm each works correctly.

Integration testing
Show answer

Testing that combined components work together as expected.

System testing
Show answer

Testing the complete, integrated system against its requirements.

User acceptance testing (UAT)
Show answer

Testing by end users to confirm the system meets business requirements before go-live.

Regression testing
Show answer

Re-testing after a change to confirm existing functionality still works.

Parallel changeover
Show answer

Running old and new systems together until the new one is proven — safest, but most costly.

Phased changeover
Show answer

Rolling out a new system in stages (by module, site, or function) to limit risk.

Pilot changeover
Show answer

Deploying a new system to one group/location first before a wider rollout.

Direct changeover
Show answer

Switching the old system off and the new one on at once (big-bang) — cheapest but riskiest.

Data conversion
Show answer

Migrating data from the old system to the new one — must be complete, accurate, and reconciled.

Post-implementation review
Show answer

An after-stabilization evaluation of whether a system met its objectives, benefits, and controls.

Configuration management (dev)
Show answer

Controlling and tracking versions of code, documents, and components throughout development.

Change control (dev)
Show answer

Managing approved changes to requirements, design, or code during a project.

Source code escrow
Show answer

Depositing source code with a third party so the customer can access it if the vendor fails.

Quality assurance (QA)
Show answer

Process-focused activities that build quality into development (vs. QC, which inspects the product).

Quality control (QC)
Show answer

Product-focused inspection and testing to detect defects in the deliverable.

System interface
Show answer

A connection allowing two systems to exchange data; a key control and audit point during integration.

Decision support system (DSS)
Show answer

A system that helps managers analyze data and make semi-structured decisions.

ERP system
Show answer

Enterprise Resource Planning — an integrated suite managing core business processes on shared data.

Cutover plan
Show answer

The detailed plan and checklist for switching from the old system to the new one, including fallback.

Fallback / rollback plan
Show answer

A documented way to revert to the prior system or state if an implementation fails.

Application controls
Show answer

Controls within an application over input, processing, and output of transactions.

Input controls
Show answer

Application controls ensuring data entered is accurate, complete, and authorized (e.g., edit checks).

Edit check / validation
Show answer

An input control that verifies data meets defined rules (range, format, completeness) before processing.

Output controls
Show answer

Controls ensuring processed results are accurate, complete, and distributed only to authorized recipients.

Sign-off (go-live)
Show answer

Formal management/user approval that a system is ready to move into production.

Object-oriented design
Show answer

Designing software around reusable objects that bundle data and behavior.

Rapid application development (RAD)
Show answer

A fast, iterative methodology using prototyping and user feedback to speed delivery.

Spiral model
Show answer

An iterative SDLC that performs heavy risk analysis at each cycle before proceeding.

Requirements traceability
Show answer

Linking each requirement to its design, build, and test so nothing is missed or unverified.

Test plan
Show answer

A document defining test scope, approach, cases, data, and pass/fail criteria.

Black-box testing
Show answer

Testing functionality against requirements without knowledge of internal code.

White-box testing
Show answer

Testing based on knowledge of internal code structure and logic.

Code review
Show answer

Examining source code to find defects and security flaws (static analysis or peer review).

Library control software
Show answer

Tools that control and track access to and movement of program source and object code.

Acceptance criteria
Show answer

The conditions a deliverable must meet for users to accept it as complete and correct.

IS Operations & Business Resilience (55)

RTO
Show answer

Recovery Time Objective — the target time to restore a system after disruption; must be less than the MTD.

RPO
Show answer

Recovery Point Objective — the maximum acceptable data loss measured backward in time; drives backup frequency.

MTD
Show answer

Maximum Tolerable Downtime — the longest a process can be unavailable before unacceptable harm.

Business Impact Analysis (BIA)
Show answer

Identifies critical processes and sets recovery objectives (MTD, RTO, RPO); the heart of resilience planning.

Business continuity plan (BCP)
Show answer

A plan to keep critical business functions operating during and after a disruption.

Disaster recovery plan (DRP)
Show answer

The IT-focused plan to restore systems, data, and infrastructure; it supports the broader BCP.

Hot site
Show answer

A fully equipped recovery site with near-real-time data, ready for near-immediate failover (costliest).

Warm site
Show answer

A recovery site with hardware and connectivity but needing data restored and configuration (moderate).

Cold site
Show answer

A recovery site with power and cooling only (empty space) — cheapest, slowest to bring online.

Reciprocal agreement
Show answer

A mutual-aid arrangement where two organizations agree to host each other in a disaster (rarely reliable).

Mirror site
Show answer

A fully redundant site kept in sync with production for the fastest possible failover.

Full backup
Show answer

A backup of all selected data — fastest to restore (one set), slowest/largest to create.

Incremental backup
Show answer

Backs up data changed since the last backup of any type — fast backup, slow restore (full + all increments).

Differential backup
Show answer

Backs up data changed since the last full backup — slower backup, faster restore (full + one differential).

Grandfather-father-son
Show answer

A backup rotation scheme keeping daily (son), weekly (father), and monthly (grandfather) copies.

Electronic vaulting
Show answer

Transmitting backup data to an offsite location to reduce data loss and speed recovery.

Change management
Show answer

The controlled process to request, approve, test, document, and deploy changes to production.

Emergency change
Show answer

An urgent change that follows an expedited path but still requires after-the-fact review and documentation.

Configuration management
Show answer

Maintaining an accurate baseline of what hardware and software is in production and controlling changes.

Configuration item (CI)
Show answer

A discrete, tracked component (hardware, software, service) recorded in the configuration baseline.

Patch management
Show answer

Acquiring, testing, and applying software updates that fix vulnerabilities and defects.

Release management
Show answer

Planning, scheduling, and controlling the build, test, and deployment of releases into production.

Incident management
Show answer

Detecting, responding to, recovering from, and learning from disruptions and service incidents.

Problem management
Show answer

Finding and eliminating the root cause of recurring incidents to prevent recurrence.

Service level agreement (SLA)
Show answer

A documented agreement defining service targets (e.g., uptime) and how they are measured.

Operating level agreement (OLA)
Show answer

An internal agreement between IT teams that supports delivery of an external-facing SLA.

Capacity management
Show answer

Ensuring IT resources meet current and forecast demand, using trend analysis.

Availability management
Show answer

Ensuring services meet agreed availability targets, measured by metrics like MTBF and MTTR.

MTBF
Show answer

Mean Time Between Failures — the average operating time between failures; higher is more reliable.

MTTR
Show answer

Mean Time To Repair — the average time to restore a failed component; lower is better.

Job scheduling
Show answer

Automating and sequencing batch jobs so they run, complete, and are monitored for failure.

End-user computing (EUC)
Show answer

User-built tools (spreadsheets, small apps) — a common, under-controlled operational risk.

Help desk / service desk
Show answer

The single point of contact that logs, triages, and routes user incidents and requests.

Database management system (DBMS)
Show answer

Software that stores, retrieves, and controls access to data with integrity and concurrency controls.

Database normalization
Show answer

Organizing data to reduce redundancy and improve integrity by structuring tables and relationships.

Referential integrity
Show answer

A database control ensuring relationships between tables stay valid (no orphaned foreign keys).

RAID
Show answer

Redundant Array of Independent Disks — combines drives for fault tolerance and/or performance.

Fault tolerance
Show answer

A system's ability to keep operating despite the failure of a component (e.g., redundancy).

High availability
Show answer

Designing systems to minimize downtime, often via clustering, redundancy, and failover.

Plan testing (BCP)
Show answer

Validating a plan: checklist, structured walk-through (tabletop), simulation, parallel, full interruption.

Tabletop exercise
Show answer

A discussion-based test where the team walks through the plan against a scenario, no systems affected.

Parallel test (BCP)
Show answer

Bringing up recovery systems alongside production to verify they work, without stopping production.

Full interruption test
Show answer

Shutting down production and running on recovery systems — the most realistic and riskiest test.

Recovery strategy
Show answer

The chosen approach (sites, backups, redundancy) that meets the RTO and RPO set by the BIA.

Single point of failure
Show answer

A component whose failure would stop the whole system; eliminated through redundancy.

Hash total
Show answer

A control total computed over a field to detect data loss or alteration in processing or transfer.

Checkpoint / restart
Show answer

A recovery feature that saves processing state so a long job can resume after failure.

Storage area network (SAN)
Show answer

A high-speed network providing block-level shared storage to servers.

Network-attached storage (NAS)
Show answer

File-level shared storage attached to a network for multiple clients.

Cloud backup
Show answer

Offsite backup to a cloud provider, improving resilience and offsite copy management.

Crisis management team
Show answer

The group that leads response and decision-making during a major disruption.

Call tree
Show answer

A pre-defined contact chain for rapidly notifying staff during an incident or disaster.

Service continuity
Show answer

Ensuring IT services can be restored within agreed timeframes after a disruption.

Patch testing
Show answer

Validating patches in a non-production environment before deploying to production.

Capacity threshold
Show answer

A defined utilization level that triggers action before performance degrades.

Protection of Information Assets (66)

Least privilege
Show answer

Granting users and processes only the minimum access needed to do their job, and nothing more.

Authentication
Show answer

Proving a claimed identity with a credential — something you know, have, or are.

Authorization
Show answer

Determining what an authenticated identity is permitted to access and do.

Identification
Show answer

A subject claiming an identity (e.g., a username) — the first step of access control.

Accountability
Show answer

Tying actions back to a specific identity through logging and monitoring.

Multi-factor authentication (MFA)
Show answer

Using two or more factors from different categories — something you know, have, and are.

Something you know
Show answer

An authentication factor based on knowledge — password, PIN, or passphrase.

Something you have
Show answer

An authentication factor based on possession — token, smart card, or phone.

Something you are
Show answer

An authentication factor based on a biometric — fingerprint, iris, or face.

Need-to-know
Show answer

Restricting access to the specific information required to perform a task, even within a clearance level.

Access recertification
Show answer

Periodic review of user access rights to catch privilege creep and remove unneeded access.

Discretionary access control (DAC)
Show answer

Access decided by the data owner (e.g., file permissions, access control lists).

Mandatory access control (MAC)
Show answer

Access enforced by the system from labels and clearances; rigid and high-security.

Role-based access control (RBAC)
Show answer

Access granted by job role rather than the individual; scales well in enterprises.

Attribute-based access control (ABAC)
Show answer

Access decided by attributes and policy (user, resource, time, location); the most granular.

Single sign-on (SSO)
Show answer

One authentication that grants access to multiple systems (e.g., via Kerberos or SAML).

Privileged access management (PAM)
Show answer

Controls that secure, monitor, and limit the use of high-privilege accounts.

Symmetric encryption
Show answer

Encryption using one shared secret key for both encryption and decryption (e.g., AES); fast.

Asymmetric encryption
Show answer

Encryption using a public/private key pair (e.g., RSA, ECC); solves key exchange and enables signatures.

Hashing
Show answer

A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256); not reversible.

Digital signature
Show answer

A hash of a message encrypted with the sender's private key — integrity, authenticity, non-repudiation.

Public Key Infrastructure (PKI)
Show answer

The certificate authorities, certificates, and policies that manage public keys and trust.

Certificate authority (CA)
Show answer

A trusted entity that issues and signs digital certificates binding identities to public keys.

Non-repudiation
Show answer

Assurance that a party cannot deny having performed an action, via digital signatures and logging.

Encrypt for confidentiality
Show answer

Encrypt with the RECIPIENT's public key — only their private key can decrypt.

Sign for authenticity
Show answer

Sign with YOUR private key — anyone can verify with your public key.

Defense in depth
Show answer

Layering multiple, overlapping controls so that if one fails, others still protect the asset.

Firewall
Show answer

A network control that permits or blocks traffic between networks based on a defined ruleset.

Intrusion detection system (IDS)
Show answer

A control that detects and alerts on malicious or anomalous network/host activity.

Intrusion prevention system (IPS)
Show answer

A control that detects and actively blocks malicious traffic in line.

Network segmentation
Show answer

Dividing a network into zones (VLANs/subnets) to limit the spread of an attack.

DMZ
Show answer

A buffer network segment between the internet and the internal network that hosts public-facing services.

VPN
Show answer

A Virtual Private Network — an encrypted tunnel that protects data in transit over an untrusted network.

TLS
Show answer

Transport Layer Security — encrypts application traffic in transit (e.g., HTTPS).

IPsec
Show answer

A protocol suite that secures IP traffic at the network layer, commonly used for VPN tunnels.

Data classification
Show answer

Labeling data by sensitivity so the right level of protection is applied throughout its lifecycle.

Data loss prevention (DLP)
Show answer

Controls that detect and block unauthorized movement or exfiltration of sensitive data.

Data at rest
Show answer

Stored data — protected with full-disk or database encryption.

Data in transit
Show answer

Moving data — protected with TLS, IPsec, or VPNs.

Data remanence
Show answer

Residual data left on media after deletion or formatting that may still be recoverable.

Media sanitization
Show answer

Removing data via clearing, purging, or destruction so it cannot be recovered (NIST SP 800-88).

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs for detection and analysis.

Vulnerability scan
Show answer

An automated check that identifies known weaknesses without exploiting them.

Penetration test
Show answer

An authorized, simulated attack that actively exploits weaknesses to demonstrate real impact.

Social engineering
Show answer

Manipulating people into revealing information or granting access (e.g., phishing, pretexting).

Phishing
Show answer

A social-engineering attack using fraudulent messages to steal credentials or deliver malware.

Malware
Show answer

Malicious software (viruses, worms, ransomware, trojans) designed to harm or exploit systems.

Chain of custody
Show answer

Documentation showing who handled evidence and when, preserving its integrity for legal use.

Incident response lifecycle
Show answer

Prepare, detect & analyze, contain, eradicate, recover, and conduct post-incident review.

Containment
Show answer

Limiting the spread and damage of a security incident before eradication and recovery.

Physical access control
Show answer

Controls protecting facilities and equipment (badges, locks, mantraps, guards, cameras).

Environmental control
Show answer

Protection against environmental threats — HVAC, fire suppression, UPS, and water detection.

Security awareness training
Show answer

Educating users to recognize and resist threats — a key administrative control.

Honeypot
Show answer

A decoy system that lures attackers to detect, study, and divert malicious activity.

Kerberos
Show answer

A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).

SAML
Show answer

An XML standard for exchanging authentication and authorization data for web SSO and federation.

OAuth
Show answer

An authorization framework that lets apps access resources on a user's behalf without sharing credentials.

Biometric false acceptance rate
Show answer

FAR — the rate at which a biometric system wrongly accepts an unauthorized user.

Biometric false rejection rate
Show answer

FRR — the rate at which a biometric system wrongly rejects an authorized user.

Crossover error rate (CER)
Show answer

The point where a biometric's FAR equals its FRR; lower CER means a more accurate system.

Mantrap
Show answer

A physical access control with two interlocking doors that allows one person through at a time.

Zero trust
Show answer

A security model that trusts no user or device by default and verifies every access request.

Tokenization
Show answer

Replacing sensitive data with a non-sensitive token, keeping the real data in a secure vault.

Endpoint protection
Show answer

Controls (anti-malware, EDR, hardening) that secure end-user devices and servers.

Security incident
Show answer

An event that actually or potentially compromises the confidentiality, integrity, or availability of an asset.

Forensic analysis
Show answer

The disciplined collection and examination of digital evidence to investigate an incident.

References

  1. 1.ISACA. “CISA Exam Content Outline (effective 1 August 2024).” isaca.org. ↑
  2. 2.ISACA. “CISA — Certified Information Systems Auditor.” isaca.org. ↑
  3. 3.ISACA. “COBIT — Framework for Governance & Management of Enterprise IT.” isaca.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.