- CISA
- Certified Information Systems Auditor, an ISACA credential recognizing expertise in auditing, controlling, monitoring, and assessing information systems and business.
- ISACA
- A global professional association (formerly the Information Systems Audit and Control Association) that develops IT governance, audit, security, and risk certifications and frameworks including COBIT.
- COBIT
- Control Objectives for Information and Related Technologies; ISACA's framework for enterprise governance and management of IT, aligning IT processes with business objectives.
- Audit Charter
- A formal document approved by senior management that defines the purpose, authority, and responsibility of the internal audit function.
- Inherent Risk
- The level of risk that exists in a process or activity before any controls are applied.
- Control Risk
- The risk that a control will fail to prevent or detect a material error or misstatement in a timely manner.
- Detection Risk
- The risk that an auditor's testing procedures fail to identify a material error or misstatement that actually exists.
- Segregation of Duties (SoD)
- A control principle that divides key responsibilities among multiple people to prevent any single individual from having end-to-end control over a critical process.
- Compensating Control
- An alternative safeguard implemented to reduce risk to an acceptable level when a primary control is not feasible or is otherwise absent.
- Business Impact Analysis (BIA)
- A process that identifies critical business functions and quantifies the operational and financial impact of their disruption to prioritize recovery efforts.
- Recovery Point Objective (RPO)
- The maximum acceptable amount of data loss, measured as a point in time to which data must be recoverable following a disruption.
- Business Continuity Plan (BCP)
- A documented, organization-wide plan for maintaining or quickly resuming critical business functions during and after a disruptive event.
- Disaster Recovery Plan (DRP)
- A technical plan focused on restoring IT systems, applications, and infrastructure following a disaster, typically a subset of the broader BCP.
- System Development Life Cycle (SDLC)
- The structured sequence of phases — planning, analysis, design, development, testing, implementation, and maintenance — used to build and deploy information systems.
- Change Management
- The formal process of requesting, evaluating, approving, testing, and documenting changes to IT systems to minimize disruption and preserve control integrity.
- Least Privilege
- A security principle granting users and processes only the minimum access rights necessary to perform their assigned functions.
- Defense in Depth
- A layered security strategy that combines multiple independent controls so that the failure of one does not compromise the entire system.
- Digital Signature
- A cryptographic mechanism using asymmetric key pairs that provides authentication, data integrity, and non-repudiation for a message or document.
- Vulnerability Assessment
- A systematic review process that identifies, classifies, and reports known security weaknesses in systems or networks without actively exploiting them.
- Penetration Testing
- An authorized, simulated attack against a system or network to actively exploit vulnerabilities and evaluate real-world exploitability and impact.
- Data Classification
- The practice of categorizing data by sensitivity or value (e.g., public, internal, confidential, restricted) to determine appropriate handling and protection requirements.
- Continuous Auditing
- An approach using automated tools to evaluate controls and transactions on an ongoing or near-real-time basis rather than through periodic manual review.
- IT Governance
- The leadership, structures, and processes that ensure an organization's IT investments and activities support and extend its strategic objectives.
- Audit Evidence
- Information gathered by an auditor during fieldwork that must be sufficient (adequate quantity) and appropriate (relevant and reliable) to support audit conclusions.