Skip to content

CMA Final · Cost and Management Audit

Information Systems Security Audit: formula sheet

Full chapter guide

Key formulas

Core objectives of IS audit (memory aid)
Safeguard assets + Data integrity + Effectiveness + Efficiency + Compliance
Use these as headings in an objectives answer. Add confidentiality and availability if the question stresses security.
Security triad
Confidentiality, Integrity, Availability (CIA)
Most IS audit security concerns map to one of these three.
Audit focus contrast
Financial audit: true and fair view of statements | IS audit: reliability and security of systems
Use this one-line contrast to open any comparison answer.
CIA triad
Information security = Confidentiality + Integrity + Availability
Name the goal that is breached in each scenario. One incident can breach more than one goal.
Risk relationship
Risk arises when Threat exploits Vulnerability and causes Impact on an asset
A threat without a matching vulnerability gives little risk. Fixing the vulnerability reduces risk.
Threat versus vulnerability
Threat = potential cause of harm; Vulnerability = weakness that can be exploited
Example: phishing email is the threat; untrained staff is the vulnerability.
Control types
Preventive, Detective, Corrective
Match the control to the stage: stop it, spot it, or recover from it.
Two levels of IS controls
IS controls = General IT controls (environment) + Application controls (each application)
General controls apply to all applications. Application controls apply to one application or process.
General IT control areas
Access + Operations + Change management + Development/acquisition
Use these four headings to structure any answer on general controls.
Application control areas
Input + Processing + Output
Add master data and interface controls if the question asks for more.
Classification by purpose
Preventive (before) | Detective (during or after) | Corrective (fix and recover)
Classify by what the control does, not by where it sits.
Reliance sequence
Test general controls → if effective, test application controls → reduce substantive work
Weak general controls undermine reliance on application controls.
Authentication vs authorisation
Authentication = proving identity; Authorisation = permitted actions after identity is proved
Authentication always comes first. Say this order in answers.
Authentication factors
Something you know + something you have + something you are
Two or more different factors make multi-factor authentication. Two passwords are not multi-factor.
Logical vs physical
Logical = software-based, protects data and systems; Physical = hardware and premises-based, protects facilities and devices
Use this as the first line of any difference question.
Digital signature assurance
Digital signature = authenticity + integrity + non-repudiation
It does not by itself keep content secret. That is encryption's job.
Principle of least privilege
Give each user only the access needed for their job
Link it to segregation of duties in audit answers.
BCP vs DRP
BCP = whole business continues; DRP = IT systems and data restored
DRP is a subset of BCP. Say this in every comparison answer.
Recovery Time Objective
RTO = maximum acceptable downtime
Decides the type of recovery site you need.
Recovery Point Objective
RPO = maximum acceptable data loss, measured in time
Decides how often backups or replication must run.
Restore sequence: incremental
Last full backup + every incremental taken after it, in order
Faster to back up, slower to restore.
Restore sequence: differential
Last full backup + latest differential only
Slower to back up as days pass, faster to restore.
Recovery site speed and cost
Hot (fastest, costliest) > Warm > Cold (slowest, cheapest)
Match the site to the RTO.
Stages of an IS audit
Planning → Risk assessment → Audit programme and fieldwork → Evidence evaluation → Reporting → Follow-up
Use this order as the skeleton of any process answer. Exact stage names vary by source, but the sequence is the same.
Audit risk model
Audit risk = Inherent risk × Control risk × Detection risk
A conceptual relationship, not a numerical calculation. Weak controls raise control risk, so the auditor must do more substantive testing to keep detection risk low.
Test data vs ITF
Test data: dummy transactions in a separate, controlled run. ITF: dummy entity and transactions inside the live system.
ITF tests the system continuously during live processing but risks contaminating live data if not reversed.
Parallel simulation
Real data → auditor's independent program → compare output with entity's output
Tests the processing logic using real data, so it needs a program that replicates the system's logic.
CAAT documentation
Objective, data source, procedure, results, conclusion
Record these for every CAAT used so another auditor can repeat the work.
Security triad (CIA)
Information security = Confidentiality + Integrity + Availability
The core objective protected by an ISMS under ISO 27001.
ISMS improvement cycle
Plan → Do → Check → Act
A way to remember that an ISMS is continually reviewed and improved, not a one-time project.
Framework purpose match
COBIT = governance; ISO 27001 = security management; ITIL = service management
Use this to choose the right framework in a scenario question.
Legal status
Frameworks = voluntary good practice; IT Act 2000 = binding law
ISO 27001 certification is voluntary unless a regulator or contract requires it.

Quick revision

  • IS security rests on confidentiality, integrity and availability.
  • General IT controls cover the whole IT environment; application controls work within a specific application.
  • Application controls are commonly grouped as input, processing and output controls.
  • Preventive controls stop an error, detective controls find it, corrective controls fix it.
  • Logical access controls protect data and software, for example through passwords and authorisation levels.
  • Physical access controls protect hardware and premises, for example locks and restricted entry.
  • A business continuity plan keeps operations running; a disaster recovery plan restores IT systems.
  • Regular, tested and off-site backups are central to recovery.
  • CAATs let the auditor test large volumes of data directly instead of relying only on samples.
  • Segregation of duties reduces the chance of fraud and error in IT processes.
  • IT governance links IT to business goals and manages IT risk.
  • Check the exact wording of the IT Act provisions and framework names in your study material before the exam.

Common mistakes

  • Treating IS audit as only checking computer hardware. Fix: Include software, data, networks, people, processes and controls in the definition and scope.
  • Saying IS audit replaces financial or cost audit. Fix: State that it supports them by giving assurance on the systems that produce the data.
  • Using threat and vulnerability as the same thing. Fix: A threat acts from outside the weakness; a vulnerability is the weakness itself. Write both separately in answers.
  • Mapping every incident to confidentiality only. Fix: Ask whether data leaked, changed or became unusable. Ransomware that locks files mainly hits availability.
  • Calling access controls an application control in every case. Fix: Treat logical access to systems, databases and networks as general. Menu-level rights inside one module can be application-specific, so read the context.
  • Confusing change management with development controls. Fix: Development is building or buying a new system. Change management is modifying a system already in use.
  • Using authentication and authorisation as if they mean the same thing. Fix: Remember: authentication proves identity; authorisation sets permitted actions afterwards. Always write them in that order.
  • Saying a firewall protects against all threats, including viruses and insider misuse. Fix: State that a firewall filters network traffic by rules. It needs antivirus, access rights and monitoring beside it.
  • Treating BCP and DRP as the same thing. Fix: Write that BCP covers the whole business and DRP is the IT recovery part within it.
  • Mixing up incremental and differential backups. Fix: Incremental: changes since the last backup of any type. Differential: changes since the last full backup.

Exam tips

  • Begin every answer with a short definition. Examiners award marks for it even in 2-mark MCQs on meaning.
  • Use numbered points. Objectives, scope and need questions are marked by the number of distinct, relevant points.
  • In case-based questions, name the system in the case, such as ERP, payroll or inventory software, and tie your points to it.
  • For comparisons, give at least five bases of difference in a table-like two-column format.
  • Do not drift into detailed controls. Those belong to the topics on general and application controls and access controls.
  • In MCQs, decode the scenario by verb: leaked means confidentiality, altered means integrity, unavailable means availability.
  • In case answers, structure as asset, threat, vulnerability, CIA impact, controls. Examiners look for this chain.
  • Always mention insider fraud when asked for threats, and pair it with least privilege and segregation of duties.