What Is the CISA? Glossary & Key Terms

CISA
Certified Information Systems Auditor, an ISACA credential recognizing expertise in auditing, controlling, monitoring, and assessing information systems and business.
ISACA
A global professional association (formerly the Information Systems Audit and Control Association) that develops IT governance, audit, security, and risk certifications and frameworks including COBIT.
COBIT
Control Objectives for Information and Related Technologies; ISACA's framework for enterprise governance and management of IT, aligning IT processes with business objectives.
Audit Charter
A formal document approved by senior management that defines the purpose, authority, and responsibility of the internal audit function.
Inherent Risk
The level of risk that exists in a process or activity before any controls are applied.
Control Risk
The risk that a control will fail to prevent or detect a material error or misstatement in a timely manner.
Detection Risk
The risk that an auditor's testing procedures fail to identify a material error or misstatement that actually exists.
Segregation of Duties (SoD)
A control principle that divides key responsibilities among multiple people to prevent any single individual from having end-to-end control over a critical process.
Compensating Control
An alternative safeguard implemented to reduce risk to an acceptable level when a primary control is not feasible or is otherwise absent.
Business Impact Analysis (BIA)
A process that identifies critical business functions and quantifies the operational and financial impact of their disruption to prioritize recovery efforts.
Recovery Time Objective (RTO)
The maximum tolerable duration within which a business process or system must be restored after a disruption.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss, measured as a point in time to which data must be recoverable following a disruption.
Business Continuity Plan (BCP)
A documented, organization-wide plan for maintaining or quickly resuming critical business functions during and after a disruptive event.
Disaster Recovery Plan (DRP)
A technical plan focused on restoring IT systems, applications, and infrastructure following a disaster, typically a subset of the broader BCP.
System Development Life Cycle (SDLC)
The structured sequence of phases — planning, analysis, design, development, testing, implementation, and maintenance — used to build and deploy information systems.
Change Management
The formal process of requesting, evaluating, approving, testing, and documenting changes to IT systems to minimize disruption and preserve control integrity.
Least Privilege
A security principle granting users and processes only the minimum access rights necessary to perform their assigned functions.
Defense in Depth
A layered security strategy that combines multiple independent controls so that the failure of one does not compromise the entire system.
Digital Signature
A cryptographic mechanism using asymmetric key pairs that provides authentication, data integrity, and non-repudiation for a message or document.
Vulnerability Assessment
A systematic review process that identifies, classifies, and reports known security weaknesses in systems or networks without actively exploiting them.
Penetration Testing
An authorized, simulated attack against a system or network to actively exploit vulnerabilities and evaluate real-world exploitability and impact.
Data Classification
The practice of categorizing data by sensitivity or value (e.g., public, internal, confidential, restricted) to determine appropriate handling and protection requirements.
Continuous Auditing
An approach using automated tools to evaluate controls and transactions on an ongoing or near-real-time basis rather than through periodic manual review.
IT Governance
The leadership, structures, and processes that ensure an organization's IT investments and activities support and extend its strategic objectives.
Audit Evidence
Information gathered by an auditor during fieldwork that must be sufficient (adequate quantity) and appropriate (relevant and reliable) to support audit conclusions.