CISA Domain 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/213

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:34 PM on 9/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

214 Terms

1
New cards

What is EGIT?

Enterprise Governance of Information & Technology (EGIT) is a process used to monitor and control IT activities within an organization.

(EGIT ensures that IT supports business goals, risks are managed, and IT resources are used responsibly to deliver value.)

2
New cards

What are the three main objectives of EGIT?

1. Ensure alignment of IT activities with business objectives

2. Ensure IT risks are appropriately addressed

3. Ensure IT delivers value to business processes

3
New cards

What is the main objective of IT governance?

To ensure optimum use of technology resources.

(This means using IT systems, infrastructure, and investments efficiently to support business operations and growth.)

4
New cards

Who has the final responsibility for IT governance?

The Board of Directors.

(The Board of Directors has the highest level of accountability for the organization’s overall direction, risk management, and stakeholder protection. If a major data breach occurs due to poor governance, regulators and stakeholders hold the board accountable for inadequate oversight.)

5
New cards

How can an organization determine whether IT is adding value?

By evaluating the alignment of IT strategy with organizational strategy.

(When IT initiatives support business goals and improve efficiency, productivity, or revenue, IT is delivering value.)

6
New cards

What is the prime purpose of corporate governance?

To provide strategic business direction for the entire organization.

(Corporate governance ensures the organization operates responsibly, achieves objectives, and protects stakeholder interests.)

7
New cards

What is the relationship between corporate governance and IT governance?

IT governance is a subset of corporate governance.

(IT governance supports overall corporate governance by ensuring technology supports strategy, manages risks, and delivers value.)

8
New cards

How can the effectiveness of IT governance implementation be best determined?

By ensuring involvement of stakeholders and senior management verifying that IT is delivering value to the business.

(Effective IT governance is reflected when key stakeholders (such as business leaders, IT management, and risk teams) actively participate in decision-making and oversight. Additionally, IT initiatives should support business objectives, improve efficiency, manage risks, and provide measurable value. If IT investments align with business goals and produce tangible benefits, governance is functioning effectively.)


9
New cards

What is the most important method to ensure alignment between IT and business objectives?

Review the compatibility of the IT plan with the business plan.

(This review confirms that IT initiatives support organizational goals, priorities, and growth strategies. It helps ensure that technology investments, projects, and resources are focused on delivering business value rather than operating in isolation.

10
New cards

Strategic alignment can best be improved by?

Involvement of top management in aligning business and technology requirements.

(Top management participation ensures that technology decisions support strategic objectives and receive proper resources and support.)

11
New cards

What is a major risk of lack of top management support in IT strategic planning?

Lack of alignment between technology and business objectives.

(Without leadership support, IT initiatives may become disconnected from business needs, leading to wasted resources and reduced value.)

12
New cards

What is IT Portfolio Management?

The process of managing an organization's IT projects and resources to ensure alignment with business objectives and optimal return on investment.

13
New cards

What is a Policy?

A policy is a high-level statement that provides management’s intent and direction regarding acceptable and unacceptable behavior.

(It defines the organization’s expectations and serves as a foundation for rules, procedures, and security controls. For example, an Information Security Policy may state that all critical database must have defense in depth.)

14
New cards

What are Guidelines and Procedures?

Guidelines and procedures provide detailed instructions (dos and don’ts) to support and implement policies.

(While policies state what must be done, guidelines and procedures explain how to do it. Procedures provide step-by-step instructions to perform tasks correctly and consistently, whereas guidelines offer recommended practices to help employees make appropriate decisions.)

Example: An Information Security Policy may state that all critical databases must be protected using defense in depth. To support this policy:

· Procedures may define steps to configure access controls, enable encryption, and apply security patches.

· Guidelines may recommend monitoring database activity logs and implementing intrusion detection alerts.

15
New cards

What is a Standard?

A standard is a mandatory requirement that must be followed to comply with a framework or certification (e.g., ISO 27001).


(This distinction helps organizations understand governance direction, implementation methods, and compliance requirements.)



16
New cards

Who should approve the Information Security Policy?

The Board of Directors.

(Board approval ensures the policy has authority, aligns with governance expectations, and reflects organizational priorities.)

17
New cards

What is the first reference point for an IS auditor during an audit?

Approved policies.

(Approved policies are the primary reference for an IS auditor because they define management’s expectations, control requirements, and acceptable practices. Auditors use these policies as a benchmark to evaluate whether processes, controls, and employee actions comply with organizational requirements.)

18
New cards

What is the most important factor while developing an information security policy?

Consideration of business requirements.

(Security policies must support business operations rather than hinder productivity.)

19
New cards

What should drive the development of an information security policy?

Business objectives - not just IT department goals.

(Policies must support organizational goals and risk management needs.)

20
New cards

What is the most important action after dismissal of an employee?

Immediately disable access rights.

(This prevents unauthorized access and protects organizational data after termination.)

21
New cards

What is the major concern if HR policy lacks a termination process?

Security risks due to continued access after termination.

(Former employees may retain access, creating risk of data theft or misuse.)

22
New cards

What is the risk if employees are unaware of the information security policy?

Unintentional disclosure of sensitive information.

(If employees do not understand security policies, they may unknowingly share confidential data, use weak security practices, or mishandle sensitive information. This lack of awareness can lead to data breaches, compliance violations, and reputational damage.)

23
New cards

How can policy compliance best be ensured?

Through existing IT mechanisms and enforcement controls.

(Policy compliance is most effective when enforced through automated IT controls rather than relying solely on user behavior. Technical mechanisms such as system configurations, access controls, password enforcement, monitoring tools, and data loss prevention systems ensure that policies are consistently followed and violations are prevented or detected.)

24
New cards

What is a major risk of unstructured data and system ownership policies?

Unauthorized access due to unclear ownership.

(When data and systems do not have clearly defined owners, accountability for access control, classification, protection, and monitoring becomes weak. This can result in excessive permissions, delayed removal of access, and sensitive information being exposed to unauthorized users.)

25
New cards

What ensures policies comply with legal requirements?

Periodic review by a subject matter expert (SME).

(Laws, regulations, and compliance requirements change over time. Regular reviews by legal, compliance, or regulatory subject matter experts help ensure that organizational policies remain aligned with current legal obligations and industry standards. This reduces the risk of non-compliance, penalties, and legal exposure.)



26
New cards

Which of the following is a first step for the auditor having observed that IT policies are not approved by management?

To include this as a non compliance in an audit report

27
New cards

What is a Top-Down approach to policy development?

A Top-Down approach develops policies from a senior management perspective, aligned with business objectives.

(This approach begins at the highest level of the organization, where senior management defines policies based on strategic goals, regulatory obligations, and enterprise-wide risks. It ensures that policies support business direction, risk appetite, governance expectations, and compliance requirements. Because leadership sets the tone, this approach promotes accountability, uniform standards, and alignment between IT and organizational objectives.)

28
New cards

What is a Bottom-Up approach to policy development?

A Bottom-Up approach develops policies from the process owner and operational level perspective, based on process-level requirements.

(This approach starts at the operational level, where process owners and technical teams identify risks, control gaps, and practical challenges in day-to-day activities. Policies are shaped by real operational needs, workflow realities, and risk assessment findings. This ensures that policies are practical, implementable, and effective in addressing operational vulnerabilities.)

29
New cards

Which risks are addressed in Top-Down approach?

Major risks affecting business objectives

(Top management focuses on enterprise risks such as regulatory noncompliance, reputational damage, financial loss, cybersecurity threats, and business continuity disruptions. Addressing these risks ensures that policy decisions protect organizational strategy and stakeholder interests.)

30
New cards

Which risks are addressed in Bottom-Up approach?

Process-level risks, identified through risk assessments.

(This includes risks such as weak access controls, procedural errors, system misconfigurations, data handling weaknesses, and operational inefficiencies. Identifying these risks ensures that day-to-day controls function effectively and support overall security objectives.)

31
New cards

What is one advantage of the Top-Down approach?

Ensures consistency across the organization.

(Because policies originate from senior leadership, they create uniform standards, consistent control expectations, and standardized practices across departments. This reduces confusion, ensures compliance, and strengthens governance.)

32
New cards

What is one advantage of the Bottom-Up approach?

Policies are based on risk assessment results and operational realities.

(This ensures policies reflect actual risks, operational challenges, and practical implementation considerations. As a result, controls are more realistic, accepted by staff, and effective in daily operations.)

33
New cards

Which approach is best for developing policies? Bottom-Up or Top-Down?

Both approaches should be used together. They are complementary and should be applied simultaneously.

(Using both approaches ensures policies align with business strategy while remaining practical and effective at the operational level. Top-down provides direction and governance, while bottom-up ensures real-world applicability and risk coverage.)

34
New cards

What is the role of The Board of Directors?

The Board of Directors has ultimate responsibility for IT governance and strategic direction.

(Ultimate responsibility lies with the Board because governance decisions affect enterprise risk, compliance, financial performance, and stakeholder trust. The Board ensures IT investments and strategies align with organizational objectives.)

35
New cards

What is the role of the IT Strategic Committee?

To advise the Board on IT strategy and new IT initiatives. They give direction while steering committee drives.

• Ensure alignment of IT with business objectives
• Identify IT risks and exposure
• Advise on IT contributions to business
• Direct management on IT strategic matters

(This committee ensures technology investments support business value, identifies strategic risks, and guides leadership on leveraging IT for competitive advantage. It evaluates emerging technologies, long-term IT direction, innovation opportunities, and major IT investments. Its advisory role helps ensure IT strategy supports business growth and competitive advantage.)

36
New cards

What is the role of the IT Steering Committee?

To implement, monitor, and control IT projects. The committee ensures projects are completed on time, within budget, and aligned with business requirements. They drive the car while Strategy Committee gives directions.

• Approve project plans and budgets

• Set priorities and milestones

• Assign resources

• Monitor project cost and schedules

• Ensure alignment with business requirements

• Ensure efficient use of IT resources

• Escalate major issues to senior management/Board

(The IT Steering Committee acts as a governance body overseeing IT project execution, prioritization, and resource allocation. It ensures projects deliver value and remain aligned with business needs.)

37
New cards

What is the role of the User Management / Project Sponsor?

User Management / Project Sponsors assume ownership of project and resulting systems. They provide functional requirements and they review and approve deliverables.

(Ownership of a system or project typically rests with user management or the project sponsor because they are responsible for defining business requirements, approving funding, ensuring the system meets business needs, and accepting associated risks. IT may develop and maintain the system, but ownership remains with the business side. Example: For a payroll system, the HR department head may act as the system owner, ensuring it meets operational and compliance requirements.)

38
New cards

What is the role of System Development management?

To provide technical support.

39
New cards

Who assumes overall responsibility for system development projects?

The IT Steering Committee.

(The committee oversees project progress, ensures alignment with strategic priorities, and monitors risks, budgets, and timelines to support successful system implementation.)

40
New cards

Who assumes ownership of a system or project?

User Management / Project Sponsor.

(Ownership of a system or project typically rests with user management or the project sponsor because they are responsible for defining business requirements, approving funding, ensuring the system meets business needs, and accepting associated risks. IT may develop and maintain the system, but ownership remains with the business side. Example: For a payroll system, the HR department head may act as the system owner, ensuring it meets operational and compliance requirements.)

41
New cards

Who is responsible for defining system requirements?

The Project Sponsor (User Management).

(Business users define requirements because they understand operational needs, workflows, and expected outcomes.)

42
New cards

Who is accountable for maintaining appropriate security measures over information assets?

The Resource Owner (Data/Process/System Owner).

(The resource owner is responsible for classifying information, defining access rights, ensuring protection controls, and safeguarding the confidentiality, integrity, and availability of assets.)



43
New cards

Who are the members of the IT Strategy Committee?

Board members and specialized non-board members.

(This may include senior executives, technology experts, and external advisors who bring strategic, industry, and governance perspectives to IT decision-making.)

44
New cards

Who are the members of the IT Steering Committee?

Executives such as CEO and other key organizational functionaries.

(Members typically include senior business and IT leaders responsible for prioritizing projects, allocating resources, and ensuring successful execution.)

45
New cards

Who is responsible for monitoring project cost and schedule?

The IT Steering Committee.

(Monitoring costs and timelines ensures projects remain within approved budgets and schedules, preventing overruns and operational disruptions.)

46
New cards

What is the flow between the IT strategy committee, board of directors and the IT steering committee?

The IT Strategy Committee advises the board on IT strategy. Then, the Board of Directors makes the decision on the basis of the advice of the IT Strategy Committee and they instruct the IT Steering Committee for Implementation. Then the IT Steering Committee is responsible for the implementation and monitoring.

47
New cards

Who ensures efficient use of IT resources?

The IT Steering Committee.

(The committee allocates and monitors resources to ensure optimal utilization and maximum return on IT investments.)

48
New cards

If the Board does not approve all recommendations from the IT Strategy Committee, is it a control weakness?

No. The Strategy Committee only advises; the Board makes the final decision.

(The committee provides guidance, but the Board retains ultimate decision-making authority based on strategic priorities and risk considerations.)

49
New cards

Who monitors and approves major IT projects?

The IT Steering Committee.

(The committee reviews project progress, approves key milestones, and ensures initiatives remain aligned with organizational priorities.)

50
New cards

A request for proposal (RFP) to purchase a new system will most likely be approved by?

The project steering committee

51
New cards

The ultimate responsibility for requirement specifications rests with?

The project sponsor/user management

52
New cards

The most suitable person to be appointed as chair of the steering committee is:

A. A member of the board

B. An executive level officer

C. The CTO

D. The CIO

B. An executive level officer

53
New cards

What is Enterprise Architecture (EA)?

Enterprise Architecture defines the structure and operations of an organization and how all the operations are connected and work together.

(It provides a blueprint of business processes, information systems, technology infrastructure, and their relationships. EA helps organizations understand how components interact and ensures technology supports business operations effectively. Example: A bank’s EA may show how customer onboarding processes connect with mobile banking applications, core banking systems, identity verification services, and data centers. This blueprint ensures all systems work together smoothly and support secure, efficient customer services.)

54
New cards

What is the main focus of Enterprise Architecture?

To ensure that technology initiatives are compatible with the overall IT framework. To help the organization adopt the most suitable and successful technologies.


(EA ensures that new systems, applications, and technologies integrate smoothly with existing infrastructure, preventing fragmentation, redundancy, and incompatibility issues. It guides technology selection and implementation to ensure solutions align with business needs, support scalability, and provide long-term value.)

55
New cards

What must EA include to be considered complete?

Both current state and future state representation. If the future state is not included, EA is incomplete.

(The current state shows how systems operate today, while the future state defines the target architecture. Together, they enable strategic planning and a roadmap for transformation.)

56
New cards

What is the Zachman Framework?

One of the first Enterprise Architecture frameworks, created by John Zachman, providing a structured way to define and view an enterprise.

(The Zachman Framework organizes architecture artifacts into perspectives and dimensions, helping stakeholders understand the enterprise from multiple viewpoints such as data, function, network, and people.)

57
New cards

If an organization maintains two separate EAs (one current and one future under development), what should the auditor do?

Report it as an audit observation, since EA should provide a unified enterprise-wide view.

(Maintaining separate architectures can create confusion and misalignment. EA should present an integrated roadmap connecting the current environment to the future state.)

58
New cards

What is the main advantage of an Enterprise Architecture initiative?

It allows the company to invest in the most suitable technologies.

(EA ensures technology investments are aligned with business priorities, reduce duplication, and support long-term strategic growth.)

59
New cards

What is a major concern if IT is not involved in system selection procedures?

Application technologies may not be compatible with the organization’s architecture.

(Without IT involvement, selected solutions may not integrate properly, increasing costs, security risks, and operational inefficiencies.)

60
New cards

When a vendor develops proprietary application software, what is the most important contract clause?

Inclusion of source code escrow arrangement. To ensure availability of source code if the vendor becomes unavailable in the future. It protects the organization’s investment and ensures business continuity by allowing maintenance or migration if vendor support is lost.

(This clause ensures the organization can access the source code if the vendor ceases operations, fails to provide support, or breaches contractual obligations.)

61
New cards

What is the most valuable factor in environments with rapid technology transition?

Having sound processes in place.

(Strong processes ensure consistent control, risk management, and governance even when technologies change rapidly.)

62
New cards

Before making major infrastructure investments, what is the most critical factor to consider?

Risk analysis. Alignment is a part of risk analysis.

(Risk analysis helps evaluate financial, operational, security, and strategic risks to ensure informed investment decisions.)

63
New cards

What is the most important advantage of open system architecture?

It facilitates integration and compatibility with other systems, including proprietary components. Open systems architecture is a system design approach which aims to produce systems that are interoperable and connectable across vendors.

64
New cards

Which risk is not directly addressed by risk transfer?

Compliance risk. Risk of non adherence to legal rules and regulations. Transferring risk usually covers financial risk. The purpose of an insurance policy is to transfer the financial risk; however, a compliance risk continues to exist. (Risk transfer mechanisms like insurance may cover financial losses but cannot transfer legal or regulatory responsibility for compliance.)

65
New cards

What are the four main risk response options?

Remember using MAAT:

• M – Mitigation (Risk Reduction)

• A – Acceptance

• A – Avoidance

• T – Transfer (Risk Sharing)

66
New cards

What is Risk Mitigation and what is its objective?

Reducing risk to an acceptable level by lowering the probability or impact through controls. The objective is to ensure the risk is reduced within acceptable limits.

(Risk mitigation does not eliminate risk entirely but reduces its likelihood or impact by implementing safeguards such as technical controls, policies, or procedures.)

67
New cards

What is Risk Acceptance and when is it used?

Accepting the risk without taking any action. This approach is used when the risk is low or mitigation costs outweigh the potential loss.)

Example: An organization continues using a legacy internal tool that occasionally causes minor delays because replacing it would be expensive



68
New cards

What is Risk Avoidance and when is it used?

Eliminating the risk by stopping the activity or process causing it. It is used when potential losses outweigh expected benefits. It is usually the last choice when no other response is adequate.

Example:

A company decides not to launch an online payment feature because it lacks the security infrastructure to protect financial data, and the potential fraud and compliance risks outweigh the expected revenue

69
New cards

What is Risk Transfer and when is it used?

Shifting risk to another party through insurance or contractual agreement. It is used for low probability but high impact risks (e.g., natural disasters).

(This transfers financial consequences to a third party while the organization retains operational responsibility.)



70
New cards

Outsourcing a process to an expert organization is an example of?

Risk mitigation.

(Outsourcing reduces operational and security risks by relying on specialized expertise, better controls, and established processes.)

Why it is NOT risk transfer:

Risk transfer means shifting the financial impact or liability of a risk to another party (e.g., insurance). In outsourcing, the organization still retains accountability and ultimate responsibility for the process, compliance, and data protection. While the service provider performs the task, the organization must monitor performance, ensure controls, and manage vendor risk.

Example: Outsourcing payroll processing reduces errors and improves compliance (risk mitigation), but the organization remains responsible if employee data is mishandled.)

71
New cards

Best response for natural disasters?

Risk transfer (insurance).

(Insurance provides financial protection against catastrophic losses.)

72
New cards

What is the most risky approach among all risk responses? / Which risk response most likely increases liability?

Risk acceptance.

(This approach leaves the risk untreated and may result in losses if the risk event occurs. Accepting risk without proper evaluation may expose the organization to legal, financial, or regulatory consequences.))

73
New cards

When a risk practitioner recommends implementing controls, which of the four response is being used?

Risk mitigation.

(Implementing controls such as encryption, access controls, or monitoring systems reduces the likelihood or impact of risks.)



74
New cards

If cost of control exceeds cost of risk event, what is the best response?

Risk acceptance.

(Organizations accept the risk when mitigation is not cost-effective.)

75
New cards

What is the purpose of a business case in risk response?

To evaluate cost-benefit analysis of mitigation activities.

((A business case justifies investment in controls by comparing mitigation costs with potential risk impacts. Example: An organization considers implementing a 1000 USD security monitoring system to prevent potential cyberattacks that could cause losses of 2 million USD. The business case helps justify the investment by showing that the cost of mitigation is far lower than the potential impact.).)

76
New cards

What should be reviewed to ensure control deficiencies are remediated?

The risk mitigation plan.

(This plan tracks corrective actions, timelines, and responsibilities to ensure risks are properly addressed.)

77
New cards

What is risk analysis?

Risk analysis is the process of ranking various risks so that high-risk areas can be prioritized for treatment.

(Risk analysis helps organizations identify which risks require immediate attention by evaluating their likelihood and impact. This enables efficient allocation of resources and ensures critical risks are addressed first.)

78
New cards

What is Quantitative Risk Analysis?

Risk is measured using numerical values, such as:
• Dollar amount
• Percentage
• Statistical probability

(This method assigns measurable values to risks, enabling precise evaluation of potential losses and supporting financial decision-making. Example: Estimated loss from system downtime = ₹5,00,000)

79
New cards

What is Qualitative Risk Analysis?

Risk is assessed using descriptive categories such as High, Medium, Low. It is not expressed numerically.

(This method evaluates risks based on expert judgment and experience when numerical data is unavailable.)

80
New cards

What is Semi-Quantitative Risk Analysis?

A combination of qualitative and quantitative methods. Example: High = 5, Medium = 3, Low = 1. It is used when full quantitative analysis is not possible. It is also used to reduce subjectivity in qualitative analysis

(It provides a structured approach when data is limited but prioritization is still required.

(This method assigns numeric weights to qualitative ratings, reducing subjectivity while avoiding the complexity of full quantitative analysis.)

81
New cards

What is the biggest advantage of quantitative analysis?

Supports cost-benefit analysis because risk is expressed in monetary terms. A risk practitioner would always prefer quantitative approach.

(Monetary values allow management to compare mitigation costs with potential losses and make financially sound decisions.)

82
New cards

What is the biggest challenge in quantitative analysis?

Obtaining accurate frequency/probability data.

(Reliable historical data is often unavailable, making precise probability estimation difficult.)

83
New cards

When is qualitative analysis preferred?

When reliable numerical data is not available.

(It is useful in situations where historical data is limited or risks are difficult to quantify.)

84
New cards

Best way to get comprehensive qualitative results?

Develop scenarios with threats and impact.

(Scenario analysis helps visualize potential risk events and their consequences, improving risk understanding. Example: Scenario: “Employee clicks phishing email → credentials stolen → financial fraud.)

85
New cards

What is the primary factor in choosing between qualitative and quantitative methods?

Availability and reliability of data. The choice depends on whether accurate numerical data exists to support precise analysis.

Example: Use qualitative analysis when assessing new technology risks with no past data.

86
New cards

Which method is used to arrive at financial impact of a specific risk scenario?

Quantitative risk analysis.

(It calculates expected monetary loss for decision-making.)

87
New cards

Most difficult data to derive in quantitative analysis?

Accurate frequency / probability of occurrence. Without reliable historical data, estimating probability becomes challenging.

Example: Predicting frequency of cyber terrorism incidents.

88
New cards

What is Enterprise Risk Management (ERM)?

Enterprise Risk Management (ERM) covers the entire range of risks that affect an organization. These include:

  • IT risk

  • Operational risk

  • Investment risk

  • Market risk

  • Reputational risk

  • Legal risk

  • Compliance risk

In short, ERM includes all risks applicable to the enterprise. ERM is the practices, methods, and processes used by organizations to manage and monitor risks across the organization. It is a structured process for managing risks that may negatively impact business objectives.

89
New cards

Who is responsible for establishing the level of acceptable risk?

Senior business management.

They decide how much risk the organization is willing to accept.

(Risk tolerance must align with business goals and regulatory expectations. Example: Management may accept minor website downtime but not data breaches.)

90
New cards

Risk management results are used as input for what?

They are used for decision-making regarding security policies.

(Risk results guide security priorities and policy development. Example: High phishing risk leads to email filtering controls and awareness training.)

91
New cards

What is the first step in implementing a risk management program?

Identify assets, then determine threats and vulnerabilities affecting them.

(This sequence ensures risk assessment focuses on protecting critical resources. Example: Asset: payment gateway → Threat: fraud → Vulnerability: lack of monitoring.)

92
New cards

After identifying vulnerabilities in an e-business program, what should be done next?

Identify risks arising from vulnerabilities, likelihood of occurrence, and potential impact.

93
New cards

What is the best recommendation for a small IT organization without a dedicated risk management function?

Establish regular IT risk management meetings to define risks, assess risks, and develop contingency plans.

(Regular reviews help monitor risks even without formal risk teams. Example: Monthly meetings to review security incidents and mitigation actions.)

94
New cards

Which insurance covers losses caused by employee fraud?

Fidelity coverage.

(This insurance protects against financial losses due to employee dishonesty. Example: Coverage for funds stolen by an internal accountant.)

95
New cards

Why is it important for an IS auditor to confirm that all relevant risks are identified and categorized?

Without identifying risks, strategy cannot be effective.

(Identifying and categorizing risks ensures effective protection, prioritization, and informed management decisions. Complete risk identification ensures effective mitigation planning. Example: Ignoring vendor risk indicates incomplete risk coverage.)

96
New cards

Why should IT risks be presented from a business perspective to senior management?

Presenting IT risks in business terms helps senior management understand their real impact and prioritize decisions effectively. Executives focus on business outcomes such as financial loss, operational disruption, legal exposure, and reputational damage rather than technical details. Management responds better to business impact than technical terminology.

97
New cards

What is CMM?

Capability Maturity Model (CMM) is a framework used to determine the maturity level of an organization’s risk management processes. It measures how well processes are:
• Defined
• Managed
• Controlled
• Predictable
• Optimized

(CMM evaluates how structured, consistent, and effective organizational processes are. Example: A company with documented and monitored risk procedures has higher maturity than one using informal practices.)

98
New cards

How does maturity progress in CMM?

Each level improves upon the previous one.

EX:

1. Incomplete – Process does not achieve its intended purpose.

2. Performed – Process achieves its purpose.

3. Managed – Process is planned, monitored, and controlled.

4. Established – Process is defined, documented, standardized.

5. Predictable – Process operates within defined limits.

6. Optimized – Continuous improvement is in place.

Note: CISA exam does NOT usually test exact level names directly.

99
New cards

What are the main objectives of CMM?

  • To identify the gap between the current maturity level and the desired maturity level.

  • Continuous improvement.

  • Maturity models encourage ongoing enhancement rather than one-time fixes.

(This gap analysis helps organizations understand improvement needs.)

100
New cards

Why is identifying the gap important in CMM?

Because it helps the organization:
• Determine improvement areas
• Plan remediation actions
• Achieve continuous improvement

(Understanding gaps allows structured improvement planning.)