IT Audit Standards and Frameworks Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IT Audit Standards and Frameworks flashcards as text
In COBIT 2019, which governance domain is responsible for evaluating stakeholder needs and setting strategic direction for IT?
Answer: EDM — Evaluate, Direct and Monitor
The EDM (Evaluate, Direct and Monitor) domain is the sole governance domain in COBIT 2019 and is responsible for evaluating options, directing management, and monitoring performance.
ISO 27002 serves which purpose in relation to ISO 27001?
Answer: It provides a code of practice with guidance on information security controls
ISO 27002 is a companion standard to ISO 27001 that provides guidance and best practices for selecting and implementing information security controls.
Under ISACA's IS audit standards, an IS auditor's independence is described in which two forms?
Answer: Organizational independence and professional independence
ISACA standards require IS auditors to maintain both organizational independence (reporting structure free from conflicts) and professional independence (objective mindset).
The NIST Cybersecurity Framework (CSF) is built around which five core functions?
Answer: Identify, Protect, Detect, Respond, Recover
The NIST CSF organizes cybersecurity activities into five concurrent and continuous functions: Identify, Protect, Detect, Respond, and Recover.
In COBIT 2019, capability levels range from 0 to 5. What does a capability level of 0 indicate?
Answer: The process does not exist or fails to achieve its purpose
A capability level of 0 (Incomplete) indicates the process is either not implemented or fails to achieve its intended purpose.
The concept of 'due professional care' in IS auditing requires that an auditor:
Answer: Apply the care and skill expected of a reasonably prudent IS auditor
Due professional care requires IS auditors to exercise the skill and diligence expected of a reasonably prudent professional, not perfection or guaranteed outcomes.
ISO 20000 is the international standard for which domain?
Answer: IT service management
ISO 20000 is the international standard specifying requirements for an IT service management system (SMS), aligning closely with ITIL practices.