Click Study Flashcards above to open the flashcard hub — hundreds of CISA cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official ISACA domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CISA Flashcard Study Modes
Four modes run off the same 283 cards. Flip is for first passes and review. Match times you on pairing terms with definitions. Type shows the definition and asks you to produce the term, so a card like RPO has to come back cold. Quiz turns the fronts into multiple choice for a quick check. Rotate them rather than repeating one.

Why Flashcards Work for the CISA
IS Operations & Business Resilience holds 55 cards and shares the top 26% weighting. The cards drill recovery and availability measures such as RTO, RPO and MTD, along with reliability terms like MTBF and MTTR, and the infrastructure vocabulary behind continuity planning, including RAID, Hot site and Warm site.
Protection of Information Assets is the largest block at 66 cards and also carries 26%. Expect network and cryptography terms: DMZ, VPN and TLS for perimeter and transport, IPsec and Hashing for data in transit and at rest, and identity and monitoring cards such as SAML, OAuth and SIEM.
Information Systems Auditing Process, 58 cards weighted 18%, covers the vocabulary of the engagement itself through fronts like IS audit, Control and Fieldwork, plus the standards and techniques an auditor leans on, including ITAF, CAATs and Test data, and risk concepts such as Collusion and the CIA triad.
Governance & Management of IT, 54 cards and also 18%, works through frameworks and regulations such as COBIT, COSO and SOX, compliance drivers including GDPR and PCI DSS, and the document hierarchy you are expected to keep straight — Policy, Standard and Baseline.
IS Acquisition, Development & Implementation, 50 cards at 12%, is the lightest domain but still asks you to separate delivery approaches like Waterfall, Agile and DevOps, project artifacts such as Test plan and Gantt chart, and structures including PMO, SDLC and ERP system.
The CISA is dense with terminology — audit standards, control types, governance frameworks, recovery objectives, and security concepts.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CISA Flashcards by Domain
The cards are organized by the five official ISACA domains. Lead with the two largest — Operations & Business Resilience and Protection of Information Assets (26% each) — but cover all five:[1]
| Domain | Exam weight |
|---|---|
| IS Operations & Business Resilience | 26% |
| Protection of Information Assets | 26% |
| Information Systems Auditing Process | 18% |
| Governance & Management of IT | 18% |
| IS Acquisition, Development & Implementation | 12% |
How to Get the Most Out of These Flashcards
- Start with the 26% domains. IS Operations & Business Resilience and Protection of Information Assets carry the heaviest weighting, so work those 55 and 66 cards before you touch anything else.
- Type-drill the acronyms. Fronts like RTO and SAML are easy to recognize and hard to reproduce, so stay in Type until the definition alone pulls the exact term back.
- Match the look-alikes. Match is strongest on sets that blur together, such as Hot site against Warm site, or Policy against Standard and Baseline, where speed exposes the pairs you only half know.
- Move to the practice test when recall holds. Once Quiz runs clean across Information Systems Auditing Process and Governance & Management of IT, shift to the practice test for scenario wording and use the study guide for gaps.
- Keep sessions narrow. With 283 cards, take one domain per sitting, close with a mixed Quiz, and revisit the 50 cards in IS Acquisition, Development & Implementation often so the 12% domain does not fade.
CISA Flashcards FAQ
Hundreds of free CISA flashcards, organized across all five ISACA domains — Information Systems Auditing Process, Governance & Management of IT, IS Acquisition, Development & Implementation, IS Operations & Business Resilience, and Protection of Information Assets. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the CISA's heavy terminology across audit, governance, resilience, and security.
All five ISACA domains: the IS Auditing Process (standards, risk-based planning, controls, evidence), Governance & Management of IT (COBIT, segregation of duties), IS Acquisition, Development & Implementation (SDLC, changeover), IS Operations & Business Resilience (change management, BCP/DR), and Protection of Information Assets (access control, cryptography).
Lead with the two largest domains — IS Operations & Business Resilience (26%) and Protection of Information Assets (26%), which together are 52% of the exam — but cover all five. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to ISACA's current exam content outline effective 1 August 2024, covering all five domains in their official proportions.
CISA flashcard bank
All 283 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Information Systems Auditing Process (58)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security and assurance.
- IS audit
Show answerHide answer
An independent, systematic examination of information systems and controls to provide assurance over CIA and compliance.
- ITAF
Show answerHide answer
ISACA's Information Technology Assurance Framework — the standards, guidelines, and tools for IS audit and assurance work.
- IS audit standards
Show answerHide answer
Mandatory requirements in ITAF that every IS auditor must follow (vs. guidelines, which are recommended).
- IS audit guidelines
Show answerHide answer
Recommended best-practice guidance in ITAF — helpful but not mandatory, unlike standards.
- Risk-based audit planning
Show answerHide answer
Allocating limited audit resources to the areas of greatest risk and business impact to the organization.
- Audit universe
Show answerHide answer
The complete inventory of auditable areas/entities from which the risk-based audit plan is built.
- Audit charter
Show answerHide answer
A document, approved by senior management/the board, that defines the audit function's authority, scope, and responsibility.
- Audit independence
Show answerHide answer
Freedom from conditions that threaten objectivity; the auditor must be impartial in fact and appearance.
- Objectivity
Show answerHide answer
An unbiased mental attitude that lets the auditor perform work and form conclusions without compromise.
- Due professional care
Show answerHide answer
Applying the diligence and skill a prudent, competent auditor would exercise in the same situation.
- Materiality
Show answerHide answer
The threshold at which a finding is significant enough to influence decisions or require reporting.
- Audit risk
Show answerHide answer
The risk an auditor reaches a wrong conclusion; a function of inherent, control, and detection risk.
- Inherent risk
Show answerHide answer
The risk that exists before any controls are considered, due to the nature of the activity.
- Control risk
Show answerHide answer
The risk that a material error is not prevented or detected by the internal control system.
- Detection risk
Show answerHide answer
The risk that the auditor's procedures fail to detect a material error; the part the auditor controls.
- Control
Show answerHide answer
A policy, procedure, or mechanism that reduces risk by preventing, detecting, or correcting an event.
- Preventive control
Show answerHide answer
A control that stops an incident before it occurs (e.g., access controls, segregation of duties, firewalls).
- Detective control
Show answerHide answer
A control that identifies an incident after it occurs (e.g., audit logs, monitoring, reconciliations).
- Corrective control
Show answerHide answer
A control that restores systems and fixes the cause after an incident (e.g., backups, incident response).
- Compensating control
Show answerHide answer
An alternative control used when the ideal (primary) control cannot feasibly be implemented.
- Deterrent control
Show answerHide answer
A control that discourages a threat actor from acting (e.g., warning banners, visible cameras).
- Compliance testing
Show answerHide answer
Testing whether a control is operating as designed (e.g., are change requests approved before deployment?).
- Substantive testing
Show answerHide answer
Testing the integrity of data or results themselves (e.g., recomputing values, confirming balances).
- Audit evidence
Show answerHide answer
Sufficient, reliable, and relevant information that supports the auditor's findings and conclusions.
- CAATs
Show answerHide answer
Computer-Assisted Audit Techniques — software/analytics used to test large data populations directly.
- Generalized audit software
Show answerHide answer
CAAT tools that read, extract, sort, and analyze data files independent of the audited application.
- Integrated test facility (ITF)
Show answerHide answer
A CAAT that processes fictitious test transactions through the live system to verify processing controls.
- Test data
Show answerHide answer
A CAAT technique that runs known input through a program to confirm it produces the expected output.
- Continuous auditing
Show answerHide answer
Performing audit procedures automatically and frequently, often in near real time, on transactions.
- Continuous monitoring
Show answerHide answer
Management's ongoing, automated oversight of controls and performance (a management activity, not audit).
- Statistical sampling
Show answerHide answer
Selecting a sample using probability so results can be projected to the population with measurable confidence.
- Non-statistical sampling
Show answerHide answer
Sample selection based on auditor judgment; results cannot be statistically projected to the population.
- Attribute sampling
Show answerHide answer
Sampling that estimates the rate of occurrence of a condition (e.g., % of items missing approval).
- Variable sampling
Show answerHide answer
Sampling that estimates a numeric value or total (e.g., the dollar value of an account).
- Sampling risk
Show answerHide answer
The risk that the sample is not representative and leads the auditor to a wrong conclusion.
- Control self-assessment (CSA)
Show answerHide answer
Process owners assess the adequacy of their own controls; supplements, never replaces, independent audit.
- Audit finding
Show answerHide answer
A documented condition where a control is missing, inadequate, or not operating, with its risk and cause.
- Audit follow-up
Show answerHide answer
Confirming that management acted on agreed recommendations and that the risk was actually reduced.
- Audit report
Show answerHide answer
The auditor's objective communication of scope, findings, risk, and recommendations to management/the committee.
- Irregularity vs. illegal act
Show answerHide answer
An irregularity is intentional deception (fraud); an illegal act violates laws/regulations — both must be reported.
- Reasonable assurance
Show answerHide answer
A high but not absolute level of assurance — controls reduce risk to an acceptable level, not to zero.
- Engagement letter
Show answerHide answer
An agreement defining the objectives, scope, responsibilities, and deliverables of a specific audit engagement.
- Audit committee
Show answerHide answer
A board subcommittee that oversees the audit function, financial reporting, and internal controls.
- Three lines model
Show answerHide answer
Management owns/controls risk (1st line); risk & compliance oversee (2nd); internal audit assures (3rd).
- Stop-or-go sampling
Show answerHide answer
A sampling approach that lets the auditor stop early once enough evidence supports a low error rate.
- Re-performance
Show answerHide answer
An auditor independently executing a control or calculation to verify it produces the correct result.
- Walk-through
Show answerHide answer
Tracing a transaction end to end through a process to confirm the auditor understands the controls.
- Inherent limitations of controls
Show answerHide answer
Controls can't give absolute assurance due to human error, collusion, and management override.
- Collusion
Show answerHide answer
Two or more people cooperating to bypass segregation of duties and conceal fraud.
- Management override
Show answerHide answer
Senior management bypassing controls — a key reason controls give only reasonable, not absolute, assurance.
- Audit trail
Show answerHide answer
A chronological record of system activity that lets an auditor reconstruct and verify events.
- Embedded audit module
Show answerHide answer
Code built into an application that continuously captures audit data on selected transactions.
- Snapshot technique
Show answerHide answer
A CAAT that captures the state of data before and after processing to verify a transaction's path.
- Risk assessment
Show answerHide answer
Identifying and analyzing risks to determine likelihood and impact, prioritizing audit and control effort.
- Audit scope
Show answerHide answer
The boundaries of an engagement — what systems, processes, and time period the audit will cover.
- Professional skepticism
Show answerHide answer
A questioning mindset that critically assesses evidence rather than assuming management's honesty.
- Fieldwork
Show answerHide answer
The evidence-gathering phase of an audit, where tests of controls and substantive tests are performed.
Governance & Management of IT (54)
- COBIT
Show answerHide answer
ISACA's framework for the governance and management of enterprise IT, separating governance from management.
- IT governance
Show answerHide answer
The board/senior management's responsibility to set IT direction, define risk appetite, and monitor value.
- IT management
Show answerHide answer
Planning, building, running, and monitoring IT day to day — execution, distinct from governance.
- EDM (COBIT)
Show answerHide answer
COBIT governance objectives: Evaluate, Direct, and Monitor — the board's governance role.
- IT strategy
Show answerHide answer
The plan that aligns IT investments and capabilities with the organization's business objectives.
- IT steering committee
Show answerHide answer
A senior cross-functional group that prioritizes IT investments and aligns IT with business needs.
- Enterprise architecture
Show answerHide answer
A blueprint of business processes, data, applications, and technology and how they fit together.
- Policy
Show answerHide answer
A high-level statement of management intent and goals; mandatory direction for the organization.
- Standard
Show answerHide answer
A specific, mandatory requirement that supports a policy (e.g., 'use AES-256 for data at rest').
- Procedure
Show answerHide answer
Detailed, step-by-step instructions for performing a task in line with policy and standards.
- Guideline
Show answerHide answer
Recommended, discretionary best practice — the only document type that is not mandatory.
- Baseline
Show answerHide answer
A defined minimum level of security or configuration that systems must meet.
- Segregation of duties (SoD)
Show answerHide answer
Splitting a sensitive task so no one person can both perform and conceal an error or fraud.
- RACI chart
Show answerHide answer
A responsibility matrix: who is Responsible, Accountable, Consulted, and Informed for each activity.
- Accountable vs. responsible
Show answerHide answer
Accountable = ultimately answerable (one person); responsible = does the work (one or more people).
- Enterprise risk management (ERM)
Show answerHide answer
The organization-wide process to identify, assess, treat, and monitor risk against the risk appetite.
- Risk appetite
Show answerHide answer
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
- Risk tolerance
Show answerHide answer
The acceptable variation around the risk appetite for a specific objective or activity.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; senior management formally accepts it.
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls.
- Risk transfer
Show answerHide answer
Shifting the financial impact of a risk to a third party, such as via insurance.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk and its potential impact.
- Maturity model
Show answerHide answer
A scale (e.g., 0–5) used to assess and improve how capable and consistent a process is.
- Key performance indicator (KPI)
Show answerHide answer
A metric that measures how well an activity achieves its objective (e.g., uptime, project on-time rate).
- Key risk indicator (KRI)
Show answerHide answer
A metric that signals rising exposure to a risk before it materializes.
- Balanced scorecard
Show answerHide answer
A performance tool linking objectives across financial, customer, internal, and learning perspectives.
- IT portfolio management
Show answerHide answer
Managing the set of IT investments to maximize value and align with strategy.
- Benefits realization
Show answerHide answer
Confirming that an IT investment actually delivered the value promised in its business case.
- Outsourcing
Show answerHide answer
Contracting a third party to perform an IT function; the organization retains accountability for risk.
- Service provider governance
Show answerHide answer
Overseeing outsourced/cloud providers via contracts, SLAs, right-to-audit clauses, and monitoring.
- Right-to-audit clause
Show answerHide answer
A contract term allowing the customer (or its auditors) to audit a service provider's controls.
- Data governance
Show answerHide answer
The framework of roles, policies, and standards ensuring data is accurate, available, and controlled.
- Data owner
Show answerHide answer
The senior business manager accountable for data who sets its classification and protection requirements.
- Data custodian
Show answerHide answer
The party (usually IT) responsible for implementing and maintaining controls protecting data day to day.
- Privacy by design
Show answerHide answer
Embedding privacy protections into systems and processes from the outset, not as an add-on.
- Regulatory compliance
Show answerHide answer
Adhering to applicable laws, regulations, and industry standards (e.g., GDPR, SOX, PCI DSS).
- PCI DSS
Show answerHide answer
The Payment Card Industry Data Security Standard governing the handling of cardholder data.
- Conflict of interest
Show answerHide answer
A situation where a person's private interest could improperly influence their professional duties.
- Quality management system (QMS)
Show answerHide answer
A documented set of processes ensuring IT services and products consistently meet requirements.
- Capacity planning (governance)
Show answerHide answer
Aligning IT resource investment with forecast business demand to deliver value efficiently.
- Strategic alignment
Show answerHide answer
Ensuring IT plans, investments, and operations directly support business goals.
- Tone at the top
Show answerHide answer
The ethical climate set by leadership, which strongly shapes the organization's control environment.
- Control environment
Show answerHide answer
The overall attitude, awareness, and actions regarding controls — the foundation of internal control.
- COSO
Show answerHide answer
A framework defining internal control over five components, widely used for governance and SOX compliance.
- SOX
Show answerHide answer
The Sarbanes-Oxley Act — U.S. law requiring management/auditors to assess internal control over financial reporting.
- GDPR
Show answerHide answer
The EU General Data Protection Regulation governing the processing and protection of personal data.
- Data controller
Show answerHide answer
Under privacy law, the entity that decides why and how personal data is processed.
- Data processor
Show answerHide answer
A party that processes personal data on behalf of, and on the instructions of, the controller.
- Vendor risk management
Show answerHide answer
Assessing and monitoring the risk introduced by third-party suppliers and service providers.
- Cloud governance
Show answerHide answer
Overseeing cloud services for security, compliance, cost, and the shared-responsibility model.
- Shared responsibility model
Show answerHide answer
Cloud security split between provider (of the cloud) and customer (in the cloud).
- Key goal indicator (KGI)
Show answerHide answer
A metric that shows whether an IT process achieved its business goal (outcome-focused).
- IT balanced scorecard
Show answerHide answer
Aligning IT performance to business value across multiple perspectives, not just cost.
IS Acquisition, Development & Implementation (50)
- SDLC
Show answerHide answer
System Development Lifecycle — feasibility, requirements, design, build, test, implement, and review.
- Feasibility study
Show answerHide answer
An early analysis of whether a proposed system is technically, operationally, and economically viable.
- Business case
Show answerHide answer
The justification for a project — costs, benefits, risks, and alignment with strategy.
- Requirements definition
Show answerHide answer
Capturing what the system must do (functional) and how well (non-functional) before design.
- Waterfall
Show answerHide answer
A sequential SDLC where each phase completes before the next; suits stable, well-understood requirements.
- Agile
Show answerHide answer
An iterative SDLC delivering working software in short sprints; suits changing requirements and fast feedback.
- Prototyping
Show answerHide answer
Building an early working model to refine unclear requirements before full development.
- DevOps
Show answerHide answer
Integrating development and operations to deliver and run software faster and more reliably.
- Function point analysis
Show answerHide answer
A method to estimate software size/effort from the functionality delivered to the user.
- Project management
Show answerHide answer
Planning, executing, and controlling a project's scope, schedule, cost, quality, and risk.
- PMO
Show answerHide answer
Project Management Office — the function that governs and supports project delivery and standards.
- Critical path method
Show answerHide answer
Scheduling technique identifying the longest sequence of dependent tasks that sets the minimum duration.
- Gantt chart
Show answerHide answer
A bar chart showing project tasks against a timeline, used to plan and track schedule.
- Scope creep
Show answerHide answer
Uncontrolled growth of project scope without corresponding adjustments to time, cost, or resources.
- Unit testing
Show answerHide answer
Testing individual components or modules in isolation to confirm each works correctly.
- Integration testing
Show answerHide answer
Testing that combined components work together as expected.
- System testing
Show answerHide answer
Testing the complete, integrated system against its requirements.
- User acceptance testing (UAT)
Show answerHide answer
Testing by end users to confirm the system meets business requirements before go-live.
- Regression testing
Show answerHide answer
Re-testing after a change to confirm existing functionality still works.
- Parallel changeover
Show answerHide answer
Running old and new systems together until the new one is proven — safest, but most costly.
- Phased changeover
Show answerHide answer
Rolling out a new system in stages (by module, site, or function) to limit risk.
- Pilot changeover
Show answerHide answer
Deploying a new system to one group/location first before a wider rollout.
- Direct changeover
Show answerHide answer
Switching the old system off and the new one on at once (big-bang) — cheapest but riskiest.
- Data conversion
Show answerHide answer
Migrating data from the old system to the new one — must be complete, accurate, and reconciled.
- Post-implementation review
Show answerHide answer
An after-stabilization evaluation of whether a system met its objectives, benefits, and controls.
- Configuration management (dev)
Show answerHide answer
Controlling and tracking versions of code, documents, and components throughout development.
- Change control (dev)
Show answerHide answer
Managing approved changes to requirements, design, or code during a project.
- Source code escrow
Show answerHide answer
Depositing source code with a third party so the customer can access it if the vendor fails.
- Quality assurance (QA)
Show answerHide answer
Process-focused activities that build quality into development (vs. QC, which inspects the product).
- Quality control (QC)
Show answerHide answer
Product-focused inspection and testing to detect defects in the deliverable.
- System interface
Show answerHide answer
A connection allowing two systems to exchange data; a key control and audit point during integration.
- Decision support system (DSS)
Show answerHide answer
A system that helps managers analyze data and make semi-structured decisions.
- ERP system
Show answerHide answer
Enterprise Resource Planning — an integrated suite managing core business processes on shared data.
- Cutover plan
Show answerHide answer
The detailed plan and checklist for switching from the old system to the new one, including fallback.
- Fallback / rollback plan
Show answerHide answer
A documented way to revert to the prior system or state if an implementation fails.
- Application controls
Show answerHide answer
Controls within an application over input, processing, and output of transactions.
- Input controls
Show answerHide answer
Application controls ensuring data entered is accurate, complete, and authorized (e.g., edit checks).
- Edit check / validation
Show answerHide answer
An input control that verifies data meets defined rules (range, format, completeness) before processing.
- Output controls
Show answerHide answer
Controls ensuring processed results are accurate, complete, and distributed only to authorized recipients.
- Sign-off (go-live)
Show answerHide answer
Formal management/user approval that a system is ready to move into production.
- Object-oriented design
Show answerHide answer
Designing software around reusable objects that bundle data and behavior.
- Rapid application development (RAD)
Show answerHide answer
A fast, iterative methodology using prototyping and user feedback to speed delivery.
- Spiral model
Show answerHide answer
An iterative SDLC that performs heavy risk analysis at each cycle before proceeding.
- Requirements traceability
Show answerHide answer
Linking each requirement to its design, build, and test so nothing is missed or unverified.
- Test plan
Show answerHide answer
A document defining test scope, approach, cases, data, and pass/fail criteria.
- Black-box testing
Show answerHide answer
Testing functionality against requirements without knowledge of internal code.
- White-box testing
Show answerHide answer
Testing based on knowledge of internal code structure and logic.
- Code review
Show answerHide answer
Examining source code to find defects and security flaws (static analysis or peer review).
- Library control software
Show answerHide answer
Tools that control and track access to and movement of program source and object code.
- Acceptance criteria
Show answerHide answer
The conditions a deliverable must meet for users to accept it as complete and correct.
IS Operations & Business Resilience (55)
- RTO
Show answerHide answer
Recovery Time Objective — the target time to restore a system after disruption; must be less than the MTD.
- RPO
Show answerHide answer
Recovery Point Objective — the maximum acceptable data loss measured backward in time; drives backup frequency.
- MTD
Show answerHide answer
Maximum Tolerable Downtime — the longest a process can be unavailable before unacceptable harm.
- Business Impact Analysis (BIA)
Show answerHide answer
Identifies critical processes and sets recovery objectives (MTD, RTO, RPO); the heart of resilience planning.
- Business continuity plan (BCP)
Show answerHide answer
A plan to keep critical business functions operating during and after a disruption.
- Disaster recovery plan (DRP)
Show answerHide answer
The IT-focused plan to restore systems, data, and infrastructure; it supports the broader BCP.
- Hot site
Show answerHide answer
A fully equipped recovery site with near-real-time data, ready for near-immediate failover (costliest).
- Warm site
Show answerHide answer
A recovery site with hardware and connectivity but needing data restored and configuration (moderate).
- Cold site
Show answerHide answer
A recovery site with power and cooling only (empty space) — cheapest, slowest to bring online.
- Reciprocal agreement
Show answerHide answer
A mutual-aid arrangement where two organizations agree to host each other in a disaster (rarely reliable).
- Mirror site
Show answerHide answer
A fully redundant site kept in sync with production for the fastest possible failover.
- Full backup
Show answerHide answer
A backup of all selected data — fastest to restore (one set), slowest/largest to create.
- Incremental backup
Show answerHide answer
Backs up data changed since the last backup of any type — fast backup, slow restore (full + all increments).
- Differential backup
Show answerHide answer
Backs up data changed since the last full backup — slower backup, faster restore (full + one differential).
- Grandfather-father-son
Show answerHide answer
A backup rotation scheme keeping daily (son), weekly (father), and monthly (grandfather) copies.
- Electronic vaulting
Show answerHide answer
Transmitting backup data to an offsite location to reduce data loss and speed recovery.
- Change management
Show answerHide answer
The controlled process to request, approve, test, document, and deploy changes to production.
- Emergency change
Show answerHide answer
An urgent change that follows an expedited path but still requires after-the-fact review and documentation.
- Configuration management
Show answerHide answer
Maintaining an accurate baseline of what hardware and software is in production and controlling changes.
- Configuration item (CI)
Show answerHide answer
A discrete, tracked component (hardware, software, service) recorded in the configuration baseline.
- Patch management
Show answerHide answer
Acquiring, testing, and applying software updates that fix vulnerabilities and defects.
- Release management
Show answerHide answer
Planning, scheduling, and controlling the build, test, and deployment of releases into production.
- Incident management
Show answerHide answer
Detecting, responding to, recovering from, and learning from disruptions and service incidents.
- Problem management
Show answerHide answer
Finding and eliminating the root cause of recurring incidents to prevent recurrence.
- Service level agreement (SLA)
Show answerHide answer
A documented agreement defining service targets (e.g., uptime) and how they are measured.
- Operating level agreement (OLA)
Show answerHide answer
An internal agreement between IT teams that supports delivery of an external-facing SLA.
- Capacity management
Show answerHide answer
Ensuring IT resources meet current and forecast demand, using trend analysis.
- Availability management
Show answerHide answer
Ensuring services meet agreed availability targets, measured by metrics like MTBF and MTTR.
- MTBF
Show answerHide answer
Mean Time Between Failures — the average operating time between failures; higher is more reliable.
- MTTR
Show answerHide answer
Mean Time To Repair — the average time to restore a failed component; lower is better.
- Job scheduling
Show answerHide answer
Automating and sequencing batch jobs so they run, complete, and are monitored for failure.
- End-user computing (EUC)
Show answerHide answer
User-built tools (spreadsheets, small apps) — a common, under-controlled operational risk.
- Help desk / service desk
Show answerHide answer
The single point of contact that logs, triages, and routes user incidents and requests.
- Database management system (DBMS)
Show answerHide answer
Software that stores, retrieves, and controls access to data with integrity and concurrency controls.
- Database normalization
Show answerHide answer
Organizing data to reduce redundancy and improve integrity by structuring tables and relationships.
- Referential integrity
Show answerHide answer
A database control ensuring relationships between tables stay valid (no orphaned foreign keys).
- RAID
Show answerHide answer
Redundant Array of Independent Disks — combines drives for fault tolerance and/or performance.
- Fault tolerance
Show answerHide answer
A system's ability to keep operating despite the failure of a component (e.g., redundancy).
- High availability
Show answerHide answer
Designing systems to minimize downtime, often via clustering, redundancy, and failover.
- Plan testing (BCP)
Show answerHide answer
Validating a plan: checklist, structured walk-through (tabletop), simulation, parallel, full interruption.
- Tabletop exercise
Show answerHide answer
A discussion-based test where the team walks through the plan against a scenario, no systems affected.
- Parallel test (BCP)
Show answerHide answer
Bringing up recovery systems alongside production to verify they work, without stopping production.
- Full interruption test
Show answerHide answer
Shutting down production and running on recovery systems — the most realistic and riskiest test.
- Recovery strategy
Show answerHide answer
The chosen approach (sites, backups, redundancy) that meets the RTO and RPO set by the BIA.
- Single point of failure
Show answerHide answer
A component whose failure would stop the whole system; eliminated through redundancy.
- Hash total
Show answerHide answer
A control total computed over a field to detect data loss or alteration in processing or transfer.
- Checkpoint / restart
Show answerHide answer
A recovery feature that saves processing state so a long job can resume after failure.
- Storage area network (SAN)
Show answerHide answer
A high-speed network providing block-level shared storage to servers.
- Network-attached storage (NAS)
Show answerHide answer
File-level shared storage attached to a network for multiple clients.
- Cloud backup
Show answerHide answer
Offsite backup to a cloud provider, improving resilience and offsite copy management.
- Crisis management team
Show answerHide answer
The group that leads response and decision-making during a major disruption.
- Call tree
Show answerHide answer
A pre-defined contact chain for rapidly notifying staff during an incident or disaster.
- Service continuity
Show answerHide answer
Ensuring IT services can be restored within agreed timeframes after a disruption.
- Patch testing
Show answerHide answer
Validating patches in a non-production environment before deploying to production.
- Capacity threshold
Show answerHide answer
A defined utilization level that triggers action before performance degrades.
Protection of Information Assets (66)
- Least privilege
Show answerHide answer
Granting users and processes only the minimum access needed to do their job, and nothing more.
- Authentication
Show answerHide answer
Proving a claimed identity with a credential — something you know, have, or are.
- Authorization
Show answerHide answer
Determining what an authenticated identity is permitted to access and do.
- Identification
Show answerHide answer
A subject claiming an identity (e.g., a username) — the first step of access control.
- Accountability
Show answerHide answer
Tying actions back to a specific identity through logging and monitoring.
- Multi-factor authentication (MFA)
Show answerHide answer
Using two or more factors from different categories — something you know, have, and are.
- Something you know
Show answerHide answer
An authentication factor based on knowledge — password, PIN, or passphrase.
- Something you have
Show answerHide answer
An authentication factor based on possession — token, smart card, or phone.
- Something you are
Show answerHide answer
An authentication factor based on a biometric — fingerprint, iris, or face.
- Need-to-know
Show answerHide answer
Restricting access to the specific information required to perform a task, even within a clearance level.
- Access recertification
Show answerHide answer
Periodic review of user access rights to catch privilege creep and remove unneeded access.
- Discretionary access control (DAC)
Show answerHide answer
Access decided by the data owner (e.g., file permissions, access control lists).
- Mandatory access control (MAC)
Show answerHide answer
Access enforced by the system from labels and clearances; rigid and high-security.
- Role-based access control (RBAC)
Show answerHide answer
Access granted by job role rather than the individual; scales well in enterprises.
- Attribute-based access control (ABAC)
Show answerHide answer
Access decided by attributes and policy (user, resource, time, location); the most granular.
- Single sign-on (SSO)
Show answerHide answer
One authentication that grants access to multiple systems (e.g., via Kerberos or SAML).
- Privileged access management (PAM)
Show answerHide answer
Controls that secure, monitor, and limit the use of high-privilege accounts.
- Symmetric encryption
Show answerHide answer
Encryption using one shared secret key for both encryption and decryption (e.g., AES); fast.
- Asymmetric encryption
Show answerHide answer
Encryption using a public/private key pair (e.g., RSA, ECC); solves key exchange and enables signatures.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256); not reversible.
- Digital signature
Show answerHide answer
A hash of a message encrypted with the sender's private key — integrity, authenticity, non-repudiation.
- Public Key Infrastructure (PKI)
Show answerHide answer
The certificate authorities, certificates, and policies that manage public keys and trust.
- Certificate authority (CA)
Show answerHide answer
A trusted entity that issues and signs digital certificates binding identities to public keys.
- Non-repudiation
Show answerHide answer
Assurance that a party cannot deny having performed an action, via digital signatures and logging.
- Encrypt for confidentiality
Show answerHide answer
Encrypt with the RECIPIENT's public key — only their private key can decrypt.
- Sign for authenticity
Show answerHide answer
Sign with YOUR private key — anyone can verify with your public key.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so that if one fails, others still protect the asset.
- Firewall
Show answerHide answer
A network control that permits or blocks traffic between networks based on a defined ruleset.
- Intrusion detection system (IDS)
Show answerHide answer
A control that detects and alerts on malicious or anomalous network/host activity.
- Intrusion prevention system (IPS)
Show answerHide answer
A control that detects and actively blocks malicious traffic in line.
- Network segmentation
Show answerHide answer
Dividing a network into zones (VLANs/subnets) to limit the spread of an attack.
- DMZ
Show answerHide answer
A buffer network segment between the internet and the internal network that hosts public-facing services.
- VPN
Show answerHide answer
A Virtual Private Network — an encrypted tunnel that protects data in transit over an untrusted network.
- TLS
Show answerHide answer
Transport Layer Security — encrypts application traffic in transit (e.g., HTTPS).
- IPsec
Show answerHide answer
A protocol suite that secures IP traffic at the network layer, commonly used for VPN tunnels.
- Data classification
Show answerHide answer
Labeling data by sensitivity so the right level of protection is applied throughout its lifecycle.
- Data loss prevention (DLP)
Show answerHide answer
Controls that detect and block unauthorized movement or exfiltration of sensitive data.
- Data at rest
Show answerHide answer
Stored data — protected with full-disk or database encryption.
- Data in transit
Show answerHide answer
Moving data — protected with TLS, IPsec, or VPNs.
- Data remanence
Show answerHide answer
Residual data left on media after deletion or formatting that may still be recoverable.
- Media sanitization
Show answerHide answer
Removing data via clearing, purging, or destruction so it cannot be recovered (NIST SP 800-88).
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs for detection and analysis.
- Vulnerability scan
Show answerHide answer
An automated check that identifies known weaknesses without exploiting them.
- Penetration test
Show answerHide answer
An authorized, simulated attack that actively exploits weaknesses to demonstrate real impact.
- Social engineering
Show answerHide answer
Manipulating people into revealing information or granting access (e.g., phishing, pretexting).
- Phishing
Show answerHide answer
A social-engineering attack using fraudulent messages to steal credentials or deliver malware.
- Malware
Show answerHide answer
Malicious software (viruses, worms, ransomware, trojans) designed to harm or exploit systems.
- Chain of custody
Show answerHide answer
Documentation showing who handled evidence and when, preserving its integrity for legal use.
- Incident response lifecycle
Show answerHide answer
Prepare, detect & analyze, contain, eradicate, recover, and conduct post-incident review.
- Containment
Show answerHide answer
Limiting the spread and damage of a security incident before eradication and recovery.
- Physical access control
Show answerHide answer
Controls protecting facilities and equipment (badges, locks, mantraps, guards, cameras).
- Environmental control
Show answerHide answer
Protection against environmental threats — HVAC, fire suppression, UPS, and water detection.
- Security awareness training
Show answerHide answer
Educating users to recognize and resist threats — a key administrative control.
- Honeypot
Show answerHide answer
A decoy system that lures attackers to detect, study, and divert malicious activity.
- Kerberos
Show answerHide answer
A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).
- SAML
Show answerHide answer
An XML standard for exchanging authentication and authorization data for web SSO and federation.
- OAuth
Show answerHide answer
An authorization framework that lets apps access resources on a user's behalf without sharing credentials.
- Biometric false acceptance rate
Show answerHide answer
FAR — the rate at which a biometric system wrongly accepts an unauthorized user.
- Biometric false rejection rate
Show answerHide answer
FRR — the rate at which a biometric system wrongly rejects an authorized user.
- Crossover error rate (CER)
Show answerHide answer
The point where a biometric's FAR equals its FRR; lower CER means a more accurate system.
- Mantrap
Show answerHide answer
A physical access control with two interlocking doors that allows one person through at a time.
- Zero trust
Show answerHide answer
A security model that trusts no user or device by default and verifies every access request.
- Tokenization
Show answerHide answer
Replacing sensitive data with a non-sensitive token, keeping the real data in a secure vault.
- Endpoint protection
Show answerHide answer
Controls (anti-malware, EDR, hardening) that secure end-user devices and servers.
- Security incident
Show answerHide answer
An event that actually or potentially compromises the confidentiality, integrity, or availability of an asset.
- Forensic analysis
Show answerHide answer
The disciplined collection and examination of digital evidence to investigate an incident.
References
- 1.ISACA. “CISA Exam Content Outline (effective 1 August 2024).” isaca.org. ↑
- 2.ISACA. “CISA — Certified Information Systems Auditor.” isaca.org. ↑
- 3.ISACA. “COBIT — Framework for Governance & Management of Enterprise IT.” isaca.org. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
