🇺🇸 Certified Information Systems Auditor (CISA) · flashcards
Certified Information Systems Auditor (CISA) Governance and Management of IT Flashcards
69 question-and-answer cards covering Governance and Management of IT as it is examined in Certified Information Systems Auditor (CISA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Governance and Management of IT deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What is a Service Level Agreement (SLA)?
A formal, measurable agreement between a service provider and customer defining the expected level of service—including metrics (e.g., availability, response/resolution times), responsibilities, reporting, and penalties/remedies for non-performance.
What is the difference between an SLA and an OLA?
An SLA is between the service provider and the (external) customer; an OLA (Operational Level Agreement) is an internal agreement between supporting teams within the provider organization that underpins the SLA.
What contractual clauses are important for governing an outsourcing/vendor relationship?
Right-to-audit, SLAs/penalties, confidentiality/data protection, compliance and security requirements, escrow (for source code), liability and indemnification, business continuity/DR obligations, and termination/exit (transition) provisions.
Why is ongoing monitoring of service providers important after contract signing?
To verify the provider continues to meet SLA commitments, security and compliance obligations, and to detect performance degradation or new risks—monitoring via SLA reports, independent assurance reports (e.g., SOC 2), audits, and periodic reviews.
What is a SOC 2 report and why is it relevant to vendor governance?
A SOC 2 report is an independent assurance report on a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy (Trust Services Criteria); it provides assurance over an outsourced provider's control environment.
What is the key governance principle of the shared responsibility model in cloud computing?
Security and compliance responsibilities are split between the cloud provider and customer based on service model—e.g., in IaaS the customer manages more (OS, apps, data), in SaaS the provider manages more—but the customer always retains accountability for its data and compliance.
Name the three primary cloud service models and what the customer manages in each.
IaaS (customer manages OS, runtime, applications, and data on provider's infrastructure); PaaS (customer manages applications and data on provider's platform); SaaS (customer manages mainly data/configuration/access while provider manages the application and below).
What is a key governance concern with cloud/managed services regarding vendor lock-in?
Difficulty and cost of migrating away from a provider due to proprietary technologies or data formats; mitigated through portability/interoperability requirements, clear exit/transition clauses, and data return/deletion provisions in the contract.
What is compliance management in an IT context?
The ongoing process of identifying applicable legal, regulatory, and contractual requirements, implementing controls to meet them, and monitoring/reporting adherence to avoid penalties, legal liability, and reputational damage.
How should an organization keep track of applicable laws and regulations affecting IT?
Maintain a compliance register/inventory of applicable legal, regulatory, and contractual requirements, assign ownership, map them to controls, and monitor for changes—ensuring continuous compliance and accountability.
What is the purpose of a privacy program within IT governance?
To govern the collection, use, storage, sharing, and protection of personal data in line with privacy laws and principles (e.g., data minimization, purpose limitation, consent, individual rights), assigning accountability (often a DPO) and managing privacy risk.
What is the difference between a data controller and a data processor under privacy law (e.g., GDPR)?
The data controller determines the purposes and means of processing personal data (and bears primary accountability); the data processor processes data on behalf of and under the instructions of the controller.
What is 'privacy by design'?
A principle requiring that privacy and data protection be embedded proactively into the design and architecture of systems, processes, and products from the outset—rather than added afterward—as a default setting.
What is a maturity model in the context of IT process capability?
A framework that rates the maturity/capability of processes along defined levels (e.g., from ad hoc to optimized), enabling assessment of current state, benchmarking, and a roadmap for improvement.
List the levels of the CMM/CMMI-style maturity scale (0-5) used to assess process maturity.
0 = Non-existent/Incomplete; 1 = Initial/Ad hoc; 2 = Managed/Repeatable; 3 = Defined; 4 = Quantitatively Managed/Measurable; 5 = Optimizing (continuous improvement).
In COBIT 2019, what scale is used to assess process capability and how does it differ from older maturity models?
COBIT 2019 uses a process capability level scale of 0-5 (based on ISO/IEC 33000), rating each individual process's capability, whereas older maturity models assessed overall maturity; COBIT 2019 also adds maturity levels at the focus-area level.
What is the value to an IS auditor of using a maturity/capability assessment?
It provides an objective baseline of current process capability, helps identify gaps against target levels, supports benchmarking, and prioritizes improvement recommendations.
What is a Quality Management System (QMS) for IT?
A formalized system documenting processes, policies, and responsibilities for achieving quality objectives and continually improving IT products/services to meet customer and regulatory requirements (e.g., aligned to ISO 9001).
What is the Plan-Do-Check-Act (PDCA) cycle and how does it relate to quality management?
PDCA is the continuous improvement cycle underpinning QMS: Plan (set objectives/processes), Do (implement), Check (measure/monitor results), Act (correct and improve)—driving ongoing quality enhancement.
What is the difference between quality assurance (QA) and quality control (QC)?
QA is process-oriented and proactive—ensuring processes are defined to prevent defects; QC is product-oriented and reactive—inspecting/testing the output to detect defects before delivery.
What is the role of the CIO versus the CISO in IT governance?
The CIO is responsible for the overall IT strategy, delivery, and operations enabling the business; the CISO is responsible for the information security strategy, risk, and program—ideally reporting independently of the CIO to avoid conflicts of interest.
Why should the information security function ideally not report directly to the CIO?
To preserve independence and avoid a conflict of interest, since the CIO's operational/delivery priorities (cost, speed) may conflict with security objectives; independent reporting (e.g., to the CEO, CRO, or board) strengthens objectivity.
What is a RACI chart and how is it used in IT governance?
A responsibility assignment matrix mapping activities/decisions to roles as Responsible, Accountable, Consulted, and Informed—clarifying who does the work, who is ultimately answerable, and who provides input or is kept informed. Each task has exactly one 'Accountable.'
What is the relationship between enterprise goals, alignment goals, and governance/management objectives in COBIT 2019's goals cascade?
The goals cascade translates stakeholder needs/drivers into enterprise goals, which cascade to alignment goals (IT-related goals), which in turn drive the selection and prioritization of governance and management objectives.
What this deck covers
The Governance and Management of IT deck follows the Certified Information Systems Auditor (CISA) Governance and Management of IT syllabus — 6 chapters and 25 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 11.5 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 231 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Governance and Management of IT flashcards FAQ
How many Governance and Management of IT flashcards are in this Certified Information Systems Auditor (CISA) deck?
69 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Information Systems Auditor (CISA) flashcards free?
Yes. The preview here is free to read with no signup, and the full 69-card deck is free inside the Examius app.
What do the Governance and Management of IT cards cover?
They follow the Certified Information Systems Auditor (CISA) Governance and Management of IT syllabus — 6 chapters and 25 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.