CHAPTER 3

The Audit Process

This chapter covers CISA Domain 1, “Information Systems Auditing Process,” and includes questions from the following topics:

•   Audit management

•   ISACA auditing standards and guidelines

•   Audit and risk analysis

•   Internal controls

•   Performing an audit

•   Control self-assessments

•   Audit recommendations

The topics in this chapter represent 21 percent of the CISA examination.

ISACA defines this domain as follows: “Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives.”

The IS audit process is the procedural and ethical structure used by auditors to assess and ...

Get CISA Certified Information Systems Auditor Practice Exams now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.