ISC S1 - S4

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/269

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:02 AM on 7/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

270 Terms

1
New cards

types of services provided by a service organization

  • outsourced payroll processors

  • CSPs

  • credit card processing orgs

  • enterprise IT outsourcing services

  • fintech services

  • customer support services

2
New cards

SOC 1 engagements for service orgs

  • ICOFR

  • use restricted to:

    • management of the service org

    • user entities of the service org

    • independent auditors

    • & excludes potential users of the service org

3
New cards

SOC 2 engagement for service orgs

  • 5 trust services criteria (TSC)

  • use intended for those who have sufficient knowledge and understanding of:

    • the service org

    • the services it provides

    • the system used to provide those services

    • etc.

  • service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service commitments and system requirements were achieved

4
New cards

SOC 3 engagement for service orgs

  • 5 trust services criteria (TSC)

  • same as SOC 2, but intended for general use (those who lack the knowledge and understanding required for a SOC 2 report)

  • service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service commitments and system requirements were achieved

5
New cards

type 1 report

reports on fairness of the presentation of management’s description of the service org’s system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date

6
New cards

type 2 report

reports on fairness of the presentation of management’s description of the service org’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period

7
New cards

5 trust services categories

  1. confidentiality

  2. availability

  3. processing integrity

  4. privacy

  5. security

8
New cards

5 components of COSO framework

  1. control environment

  2. risk assessment

  3. (existing) control activities

  4. information and communication

  5. monitoring activities

9
New cards

what should the service auditor evaluate when forming an opinion on the subject matter of a SOC engagement?

  • the sufficiency and appropriateness of the evidence obtained

  • whether uncorrected misstatements, individually or in the aggregate, are material

10
New cards

what does the opinion of a service auditor in a SOC engagement focus on?

  • fair presentation of management’s description of the service org’s system

  • the suitability of the design of the controls related to the control objectives stated in management’s description

  • type 2 only → the effective operation of the controls stated in management’s description

11
New cards

4 key components of a SOC report

  1. management’s description of the system

  2. management’s assertion

  3. independent service auditor’s report

  4. auditor’s ToC and results of tests

12
New cards

responsibility of service org’s management - SOC 1

documenting the description of the service org’s system, which must be sufficient to allow a user auditor to understand how the service org’s processing affects the user entity’s FS and to assess the RMM of the user entity’s financial statements

13
New cards

responsibility of service org’s management - SOC 2

presenting a description of the system to enable report users, such as user entities, business partners, or other relevant parties, to understand the system and the processing and flow of data throughout and from the system

14
New cards

SOC 1 & 2 report elements

  1. title

  2. addressee

  3. scope

  4. service org’s responsibilities

  5. service auditor’s responsibilities

  6. inherent limitations

  7. type 2 only → description of ToC

  8. type 1 only → other matter

  9. opinion

  10. restricted use

  11. service auditor’s signature, city and state, date of service auditor’s report

15
New cards

when would a vendor used by a service org be considered a subservice org for SOC 1 engagements?

  • the services provided by the vendor are likely relevant to the user entities’ ICOFR

  • controls implemented at the subservice org are necessary to achieve the control objectives stated in management’s description of the service org’s system

16
New cards

when would a vendor used by a service org be considered a subservice org for SOC 2 & 3 engagements?

  • the services provided by the vendor are relevant to report users’ understanding of the service org’s system as it relates to the applicable TSC

  • controls at the subservice org are necessary, in combination with the service org’s controls, to provide reasonable assurance that the service commitments and system requirements are achieved

17
New cards

carve-out method

addresses the services provided by a subservice org in which the complementary subservice organization controls (CSOCs) of the subservice org are excluded from the description of the service org’s system and from the scope of the engagement

18
New cards

inclusive method

addresses the services provided by a subservice org in which the description of the service org’s system includes a description of the nature of the services provided by the subservice org and the components of the subservice org’s system used to provide services to the service org

19
New cards

complementary user entity controls (CUECs)

controls that are necessary to be implemented by the user entity, in combination with the service org’s controls, to provide reasonable assurance that the control objectives stated in the management’s description of the service org’s system (SOC 1) or the service org’s service commitments and system requirements (SOC 2) were achieved

20
New cards

examples of CUECs

  • security monitoring

  • managed service provider (MSP) environment changes

  • encrypted financial data

  • physical access controls

  • authorization policies

21
New cards

key differences between CSOCs and CUECs

  • CSOCs are controls that a subservice org must execute in order for a service org’s controls to function effectively

  • CUECs are controls that a user must employ for the service org’s controls to function

  • in both, the service org relies on other entities, vendor or client, for their own controls to work properly

22
New cards

what must a service auditor do in the report when a modified opinion is appropriate during a SOC engagement?

a separate paragraph should be added to the service auditor’s report to explain the matter giving rise to the modification

23
New cards

before accepting a SOC engagment, what is the service auditor required to do?

establish an understanding with the service org’s management about its responsibilities and the responsibilities of the service auditor

24
New cards

in a SOC 1 engagement, what is the management of the service org required to disclose to the service auditor?

  • incidents of noncompliance w laws and regulations, fraud, or uncorrected misstatements that may affect user entities

  • knowledge of any intentional acts that could adversely affect the description presentation of the service org’s system or the completeness or achievement of the control objectives stated in the description

  • any known deficiencies in the design of controls

  • all instances where controls have not operated as described

  • any events subsequent to the period covered by the description of the service org’s system, up to the date of the report, that could have a significant effect on management’s assertion

25
New cards

key difference between management responsibilities in a SOC 2 vs. 3 engagement

management does not prepare a system description in a SOC 3 engagement

26
New cards

responsibilities of the service auditor during SOC engagement planning

  • determining whether to accept or continue the engagement

  • agreeing on engagement terms

  • reaching an understanding w management regarding a written assertion

27
New cards

additional responsibilities of the service auditor during SOC 1 engagement planning

  • assessing RMM

  • obtaining an understanding of the service org’s system and assessing the suitability of the criteria used by management in preparing its system description

28
New cards

additional responsibilities of the service auditor during SOC 2 & 3 engagement planning

  • establishing an overall strategy for the engagement

  • performing risk assessment procedures

29
New cards

common terms when discussing misstatements related to the different subject matters in a SOC engagement

  • description misstatement

  • deviation or exception

  • deficiency in the design

  • deficiency in the operating effectiveness

30
New cards

system (in the context of a SOC 2 engagement)

the infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve 1+ of the org’s specific business objectives in accordance with management-specified requirements

31
New cards

deficiency in the design

refers to either necessary controls that are missing, or existing controls that are not designed properly to achieve their control objectives

32
New cards

deficiency in the operating effectiveness

refers to when properly designed controls fail to operate as designed, or when the person performing the control does not possess the competency necessary to perform the control effectively

33
New cards

written assertion (in the context of a SOC engagement)

a statement made by the responsible party that addresses the measurement or evaluation of the subject matter against the criteria (SOC 1) or the subject matters in the examination (SOC 2 & 3)

34
New cards

key areas of engagement performance once initial risk assessment procedures by the service auditor are complete

  1. respond to assessed risks

  2. evaluate whether management’s description of the service org’s system is fairly presented in accordance with the description criteria

  3. obtain and evaluate evidence regarding the suitability of the design of controls

  4. type 2 only → obtain and evaluate evidence regarding the operating effectiveness of controls

  5. evaluate the results of the procedures

  6. form the opinion

35
New cards

assessment of the RMM is impacted by the following factors when performing a SOC engagment:

  • materiality considerations

  • the service auditor’s understanding of the effectiveness of the control environment

  • other components of internal control related to the service provided to user entities and business partners

36
New cards

overall responses by the service auditor to address the assessed RMM:

  • maintaining professional skepticism

  • assigning more experienced staff using specialists

  • providing additional supervision over audit procedures

  • incorporating elements of unpredictability in the selection of procedures to be performed

  • making changed to the NET of procedures

37
New cards

procedures the service auditor may perform to evaluate whether the description of the service org’s system is fairly presented in a SOC 1 engagement:

  • considering the nature of the user entities

  • reading contracts with user entities

  • observing procedures performed by personnel

  • reviewing the service org’s policies and procedures and other system documentation

  • performing WT of transactions through the service org’s system

38
New cards

what makes a description of a service org’s system in a SOC 2 engagement present in accordance with the description criteria?

  • describes the system that the service org has implemented

  • includes info about each description criterion, to the extent it is relevant to the system being described

  • does not inadvertently or intentionally omit or distort info that is likely to be relevant to report users’ decisions

39
New cards

additional engagement disclosures in a SOC 2 engagement

  • significant interpretations made in applying the criteria in the engagement circumstances

  • subsequent events, depending on nature and significance

40
New cards

procedures that can be performed when obtaining evidence about the suitability of the design of controls in a SOC 2 engagement

  • inquiry of service org personnel about the design and operation of controls or system events

  • inspection of documentation

  • additional WTs

  • reading applicable supporting system documentation

  • determining whether attacks, vulnerability exploitations, emerging risks, or threats have been adequately addressed

41
New cards

potential actions a service auditor should take if management refuses to disclose a subsequent event that, if undisclosed, would mislead report users

  • modifying the auditor’s report and disclosing the event

  • withdrawing from the engagement

42
New cards

description criteria (in the context of a SOC engagement)

the criteria used to determine whether the description of the service org’s system is presented fairly and includes relevant information

43
New cards

3 primary components to manage cybersecurity risk (NIST CSF)

  1. CSF core

  2. CSF tiers

  3. CSF organizational profiles

44
New cards

NIST CSF core

  1. govern

  2. identify

  3. protect

  4. detect

  5. respond

  6. recover

represents different points in the cybersecurity risk management life cycle

45
New cards

NIST CSF tier levels

  1. tier 1 partial

  2. tier 2 risk-informed

  3. tier 3 repeatable

  4. tier 4 adaptive

46
New cards

current profile

the outcome that an organization is achieving or attempting to achieve based on the current cybersecurity posture

47
New cards

target profile

the desired outcome that an organization is prioritizing achieving, considering the anticipated changes to the organization’s cybersecurity posture

48
New cards

gap analysis

analysis to identify the differences between the current and future state

49
New cards

NIST privacy framework core

  1. identify-p

  2. govern-p

  3. control-p

  4. communicate-p

  5. protect-p

50
New cards

common (inheritable) implementation

implementation approach in which controls are implemented at the organizational level, which are adopted by information systems

51
New cards

system-specific implementation

implementation approach in which controls are implemented at the information system level

52
New cards

hybrid implementation

implementation approach in which controls are implemented at the organizational level where appropriate, and the remainder at the information system level

53
New cards

system and information integrity (SI)

a control family in NIST SP 800-53 concerning the protection of accuracy, completeness, and reliability of information and the systems that process it

54
New cards

control implementations

3 approaches outlined in NIST SP 800-53 for implementing controls

  1. common (inheritable)

  2. system-specific

  3. hybrid

*applied on a per-control basis

55
New cards

control objectives - NIST privacy framework

expressed as the framework core; consists of 8 functions and 29 categories, subdivided into 100 subcategories

56
New cards

organizational profiles

mechanisms by which NIST recommends companies measure cybersecurity risk and establish a roadmap to minimize such risk

57
New cards

NIST CSF tiers

act as benchmarks for an organization’s information security infrastructure sophistication, indicating the degree to which cybersecurity practices are integrated throughout the organization

58
New cards

cybersecurity risk governance

a component of CSF tiers focusing on the policies, procedures, and structures put in place by an organization’s leadership to oversee and manage cybersecurity risks

  • involves establishing accountability, defining roles and responsibilities, and ensuring that cybersecurity risk management aligns with the organization’s overall risk

59
New cards

cybersecurity risk management

a component of CSF tiers referring to the continuous process of identifying, assessing, and responding to cybersecurity threats and vulnerabilities to minimize impact on an organization’s operations, assets, and reputation

  • GOAL: balance needs of cybersecurity with business objectives

60
New cards

detective measures (NIST)

security measures that focus on identifying and detecting potential threats or breaches after they occur, such as monitoring and incident response systems

61
New cards

organizational responsibilities (NIST SP 800-53)

requirements, including well-defined security and privacy requirements, trustworthy information system components, security and privacy planning, and continuous monitoring of information systems

62
New cards

unintentional data breach

results from negligence from error

63
New cards

intentional data breach

results from bad actors illegally gaining access to data

64
New cards

HIPAA safeguards

  1. administrative

  2. physical

  3. technical

65
New cards

principles for processing data (GDPR)

  • lawfulness, fairness, and transparency

  • purpose limitation

  • data minimization

  • accuracy

  • storage limitation

  • integrity and confidentiality

ALL processors or controllers of data shall be responsible for and able to demonstrate compliance with these principles (accountability)

66
New cards

goals of PCI DSS

  1. build and maintain a secure network and systems

  2. protect account data

  3. maintain a vulnerability management program

  4. implement strong access control measures

  5. regularly monitor and test networks

  6. maintain an information security policy

67
New cards

data privacy

the right of an individual to exercise control over how their personal data is collected, used, and shared by organizations

68
New cards

data privacy laws

legal regulations designed to protect an individual’s private life and personal details from being disclosed to the public

  • establishes rules for collecting, processing, maintaining, and disclosing private information to build trust between consumers and enterprises

69
New cards

breach notification rules (HIPAA)

a requirement added by HITECH; covered entities are required to notify individuals affected by a data breach within 60 days of discovery

70
New cards

control 01: inventory and control of enterprise assets

actively manage all enterprise assets connected to the infrastructure, physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise

71
New cards

control 02: inventory and control of software assets

actively manage all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution

72
New cards

control 03: data protection

develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data

73
New cards

control 04: secure configuration of enterprise assets and software

establish and maintain the secure configuration of enterprise assets and software

74
New cards

control 05: account management

use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts as well as service accounts, to enterprise assets and software

75
New cards

control 06: access control management

use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software

76
New cards

control 07: continuous vulnerability management

develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise’s infrastructure, in order to remediate and minimize the window of opportunity for attackers

  • monitor public and private industry sources for new threat and vulnerability management

77
New cards

control 08: audit log management

collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack

78
New cards

control 09: email and web browser protections

improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement

79
New cards

CIS controls - design principles - context

an enhancement to the scope and practical applicability of safeguards through incorporation of examples and explanations

80
New cards

CIS controls - design principles - coexistence

alignment with evolving industry standards and frameworks, including NIST CSF 2.0 framework

81
New cards

CIS controls - design principles - consistency

disruption to controls users are minimized, not impacting implementation groups

82
New cards

CIS benchmarks

publicly available security standards, used by organizations as a starting point for asset reconfiguration

  • adhering to these standards helps organizations in complying with any applicable laws and regulations

83
New cards

CIS controls

a set of recommended actions, processes, and best practices for organizations to strengthen their cybersecurity defenses

  • they include measures to track and manage software applications, protect data, and configure enterprise assets securely

84
New cards

control 10: malware defenses

prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets

85
New cards

control 11: data recovery

establish and maintain data recovery practices sufficient to restore in-scope enterprise assets to a pre-incident and trusted state

86
New cards

control 12: network infrastructure management

establish, implement, and actively manage network devices in order to prevent attackers from exploiting vulnerable services and access points

87
New cards

control 13: network monitoring and defense

operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise’s network infrastructure and user base

88
New cards

control 14: security awareness and skills training

establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise

89
New cards

control 15: service provider management

develop a process to evaluate service providers who hold sensitive data or are responsible for an enterprise’s critical IT platforms or processes to ensure these providers are protecting those platforms and data appropriately

90
New cards

control 16: application software security

manage the life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses before they can impact the enterprise

91
New cards

control 17: incident response management

establish a program to develop and maintain an incident response capability to prepare, detect, and quickly respond to an attack

92
New cards

control 18: penetration testing

test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and tech), and simulating the objectives and actions of an attacker

93
New cards

penetration testing

a testing technique that simulates actual attacks to identify and exploit technical vulnerabilities in a defined scope (network/application/system)

94
New cards

red team exercises

a holistic, objective-driven adversarial simulation mimicking the tactics, techniques, and procedures (TTPs) of real-word attackers to test an organization’s detection and response capabilities

95
New cards

living-off-the-land (LotL) - control 10: malware defenses

a tactic used by attackers that leverages existing tools and applications within an organization against itself to avoid detection

96
New cards

COBIT framework - purpose

provides a roadmap that organizations can use to implement best practices IT governance and management

97
New cards

components used for development of COBIT 2019

  • COBIT 5

  • 6 principles for a governance system

  • 3 principles for a governance framework

  • other standards and regulations

  • community contribution

98
New cards

6 governance system principles (COBIT)

  1. provide stakeholder value

  2. holistic approach

  3. dynamic governance system

  4. governance distinct from management

  5. tailored to enterprise needs

  6. end-to-end governance system

99
New cards

3 principles for a governance framework (COBIT)

  1. based on conceptual model

  2. open and flexible

  3. aligned to major standards

100
New cards

based on conceptual model

principle for a governance framework; governance frameworks should identify key components as well as the relationships between those components