Ch 2 Flashcards
Name some soft skills
Honest Ethical Attention to detail Professionalism Listening Leadership
Name some hard skills
Technical competence Knowledge needed to accomplish work writing Thinking Project Mgmt Critical Thinking
Honest
soft
Ethical
soft
Attention to detail
soft
Verbal and written skill
Hard
Analytic skill
Hard
Interpersonal skill
Soft
Professional and willingness to take lead
Soft
Project management and Organizational skill
Hard
Critical Thinking
Hard
Professional Ethics describe
principles and values that govern acceptable behaivor
What does client mean
Leadership of the area you are auditing
CISA auditors must be
Honest and Transparent
Define Standards
Mandatory actions, Explicit Rules or Controls designed to support and conform to policy through hardware, software or behaivor
What makes policy more meaningful and effective
Standards
Standards should always point to
Policy
Procedures are
Written steps to execute policy
Which one is more detailed Policy or Procedures?
Procedures
What is an outline for a statement of conduct
Guideline
Are guidelines mandatory to follow
No
Do guidelines provide general guidance
Yes
Are guidelines Requirements that need to met or are they recommended
Recommended
Whats a baseline
specific rules that are accepted across the industry as providing the most effective approach to a specific implementation
Name some regulatory standards
HIPPA SOX Base III PCI FISMA COSO SCADA FACTA
HIPPA
Healthcare
SOX
Financial
Base III
Risk Mgmt Bankin
PCI
Credit Cards
FISMA
US Govt Security Standards
COSO
Financial Fraud Reporting
SCADA
Security for Automated Systems
FACTA
Reduce Fraud and ID Theft
Is regulatory guidance early, on time, or late
Late
Most cyber laws are written before or after a major breach
After
Name some industry guidance organizations
COBIT
ISO
NIST
FIPS
Name the types of audits
Financial
Integrated
Operational
What is a financial audit
Audit of financial statements and processes. Usually doesn’t include the IT auditor