CISA Domain 1 & 2: CISA Chapter 1 Common
Terms & Definitions Questions With Correct
Answers
Save
Practice questions for this set
Learn 1 /7 Study with Learn
part of audit planning, and helps identify risks and vulnerabilities so the IS
auditor can determine the controls needed to mitigate those risks
Give this one a try later!
1 Audit Risk Risk analysis
3 Compliance Testing 4 Minor incidents
Don't know?
Terms in this set (176)
, document that states management's objectives for
and delegation of authority to IS audit. Should be
approved at the highest levels of management, and
Audit Charter
should outline the overall authority scope, and
responsibilities of the audit function. Should not
significantly change over time.
a letter that formalizes the contract between the
auditor and the client and outlines the responsibilities
Engagement Letter of both parties; focused on a particular audit exercise
that is sought to be initiated in an organization with a
specific objective in mind
A list of the audit procedures the auditors need to
perform to gather sufficient appropriate evidence on
Audit Plan which to base their opinion on the financial
statements; consists of both short-term and long-term
planning
Sarbanes-Oxley Act of Law that requires companies to maintain adequate
2002 systems of internal control
In all matters related to the audit, the IS auditor
Professional
should be independent of the auditee in both attitude
Independence
and appearance
The IS audit function should be independent of the
Organizational
area or activity being reviewed to permit objective
Independence
completion of the audit assignment
the risk that information may contain a material error
Audit Risk that may go undetected during the course of the
audit
Error Risk the risk of errors occurring in the area being audited
, provides an integrated process (involving technical
Information Technology and non-technical aspects) for developing and
Assurance Framework deploying IT systems with intrinsic and appropriate
(ITAF) security measures in order to meet the organizations
mission
standards that establish the guiding principles under
which the IT assurance profession operates; they
apply to the conduct of all assignments, and deal with
General standards
the IT audit and assurance professional's ethics,
independence, objectivity and due care, as well as
knowledge, competency and skill
standards that establish baseline expectations in the
conduct of IT assurance engagements; focused on
the design of the assurance work, the conduct of the
Performance standards
assurance, the evidence required, and the
development of assurance and audit findings and
conclusions
standards that address the types of audit reports,
Reporting standards means of communication, and information to be
communicated at the conclusion of an audit
part of audit planning, and helps identify risks and
Risk analysis vulnerabilities so the IS auditor can determine the
controls needed to mitigate those risks
the potential that a given threat will exploit
vulnerabilities of an asset or group of assets and
Risk thereby cause harm to the organization; the
combination of the probability of an event and its
consequence
a risk that may negatively impact the assets, processes
Business Risk
or objectives of a specific business or organization
the risk associated with the use, ownership, operation,
IT Risk involvement, influence, and adoption of IT within an
enterprise
Terms & Definitions Questions With Correct
Answers
Save
Practice questions for this set
Learn 1 /7 Study with Learn
part of audit planning, and helps identify risks and vulnerabilities so the IS
auditor can determine the controls needed to mitigate those risks
Give this one a try later!
1 Audit Risk Risk analysis
3 Compliance Testing 4 Minor incidents
Don't know?
Terms in this set (176)
, document that states management's objectives for
and delegation of authority to IS audit. Should be
approved at the highest levels of management, and
Audit Charter
should outline the overall authority scope, and
responsibilities of the audit function. Should not
significantly change over time.
a letter that formalizes the contract between the
auditor and the client and outlines the responsibilities
Engagement Letter of both parties; focused on a particular audit exercise
that is sought to be initiated in an organization with a
specific objective in mind
A list of the audit procedures the auditors need to
perform to gather sufficient appropriate evidence on
Audit Plan which to base their opinion on the financial
statements; consists of both short-term and long-term
planning
Sarbanes-Oxley Act of Law that requires companies to maintain adequate
2002 systems of internal control
In all matters related to the audit, the IS auditor
Professional
should be independent of the auditee in both attitude
Independence
and appearance
The IS audit function should be independent of the
Organizational
area or activity being reviewed to permit objective
Independence
completion of the audit assignment
the risk that information may contain a material error
Audit Risk that may go undetected during the course of the
audit
Error Risk the risk of errors occurring in the area being audited
, provides an integrated process (involving technical
Information Technology and non-technical aspects) for developing and
Assurance Framework deploying IT systems with intrinsic and appropriate
(ITAF) security measures in order to meet the organizations
mission
standards that establish the guiding principles under
which the IT assurance profession operates; they
apply to the conduct of all assignments, and deal with
General standards
the IT audit and assurance professional's ethics,
independence, objectivity and due care, as well as
knowledge, competency and skill
standards that establish baseline expectations in the
conduct of IT assurance engagements; focused on
the design of the assurance work, the conduct of the
Performance standards
assurance, the evidence required, and the
development of assurance and audit findings and
conclusions
standards that address the types of audit reports,
Reporting standards means of communication, and information to be
communicated at the conclusion of an audit
part of audit planning, and helps identify risks and
Risk analysis vulnerabilities so the IS auditor can determine the
controls needed to mitigate those risks
the potential that a given threat will exploit
vulnerabilities of an asset or group of assets and
Risk thereby cause harm to the organization; the
combination of the probability of an event and its
consequence
a risk that may negatively impact the assets, processes
Business Risk
or objectives of a specific business or organization
the risk associated with the use, ownership, operation,
IT Risk involvement, influence, and adoption of IT within an
enterprise