CMA Final · Cost and Management Audit
Information Systems Security Audit: formula sheet
Key formulas
- Core objectives of IS audit (memory aid)
- Safeguard assets + Data integrity + Effectiveness + Efficiency + Compliance
- Use these as headings in an objectives answer. Add confidentiality and availability if the question stresses security.
- Security triad
- Confidentiality, Integrity, Availability (CIA)
- Most IS audit security concerns map to one of these three.
- Audit focus contrast
- Financial audit: true and fair view of statements | IS audit: reliability and security of systems
- Use this one-line contrast to open any comparison answer.
- CIA triad
- Information security = Confidentiality + Integrity + Availability
- Name the goal that is breached in each scenario. One incident can breach more than one goal.
- Risk relationship
- Risk arises when Threat exploits Vulnerability and causes Impact on an asset
- A threat without a matching vulnerability gives little risk. Fixing the vulnerability reduces risk.
- Threat versus vulnerability
- Threat = potential cause of harm; Vulnerability = weakness that can be exploited
- Example: phishing email is the threat; untrained staff is the vulnerability.
- Control types
- Preventive, Detective, Corrective
- Match the control to the stage: stop it, spot it, or recover from it.
- Two levels of IS controls
- IS controls = General IT controls (environment) + Application controls (each application)
- General controls apply to all applications. Application controls apply to one application or process.
- General IT control areas
- Access + Operations + Change management + Development/acquisition
- Use these four headings to structure any answer on general controls.
- Application control areas
- Input + Processing + Output
- Add master data and interface controls if the question asks for more.
- Classification by purpose
- Preventive (before) | Detective (during or after) | Corrective (fix and recover)
- Classify by what the control does, not by where it sits.
- Reliance sequence
- Test general controls → if effective, test application controls → reduce substantive work
- Weak general controls undermine reliance on application controls.
- Authentication vs authorisation
- Authentication = proving identity; Authorisation = permitted actions after identity is proved
- Authentication always comes first. Say this order in answers.
- Authentication factors
- Something you know + something you have + something you are
- Two or more different factors make multi-factor authentication. Two passwords are not multi-factor.
- Logical vs physical
- Logical = software-based, protects data and systems; Physical = hardware and premises-based, protects facilities and devices
- Use this as the first line of any difference question.
- Digital signature assurance
- Digital signature = authenticity + integrity + non-repudiation
- It does not by itself keep content secret. That is encryption's job.
- Principle of least privilege
- Give each user only the access needed for their job
- Link it to segregation of duties in audit answers.
- BCP vs DRP
- BCP = whole business continues; DRP = IT systems and data restored
- DRP is a subset of BCP. Say this in every comparison answer.
- Recovery Time Objective
- RTO = maximum acceptable downtime
- Decides the type of recovery site you need.
- Recovery Point Objective
- RPO = maximum acceptable data loss, measured in time
- Decides how often backups or replication must run.
- Restore sequence: incremental
- Last full backup + every incremental taken after it, in order
- Faster to back up, slower to restore.
- Restore sequence: differential
- Last full backup + latest differential only
- Slower to back up as days pass, faster to restore.
- Recovery site speed and cost
- Hot (fastest, costliest) > Warm > Cold (slowest, cheapest)
- Match the site to the RTO.
- Stages of an IS audit
- Planning → Risk assessment → Audit programme and fieldwork → Evidence evaluation → Reporting → Follow-up
- Use this order as the skeleton of any process answer. Exact stage names vary by source, but the sequence is the same.
- Audit risk model
- Audit risk = Inherent risk × Control risk × Detection risk
- A conceptual relationship, not a numerical calculation. Weak controls raise control risk, so the auditor must do more substantive testing to keep detection risk low.
- Test data vs ITF
- Test data: dummy transactions in a separate, controlled run. ITF: dummy entity and transactions inside the live system.
- ITF tests the system continuously during live processing but risks contaminating live data if not reversed.
- Parallel simulation
- Real data → auditor's independent program → compare output with entity's output
- Tests the processing logic using real data, so it needs a program that replicates the system's logic.
- CAAT documentation
- Objective, data source, procedure, results, conclusion
- Record these for every CAAT used so another auditor can repeat the work.
- Security triad (CIA)
- Information security = Confidentiality + Integrity + Availability
- The core objective protected by an ISMS under ISO 27001.
- ISMS improvement cycle
- Plan → Do → Check → Act
- A way to remember that an ISMS is continually reviewed and improved, not a one-time project.
- Framework purpose match
- COBIT = governance; ISO 27001 = security management; ITIL = service management
- Use this to choose the right framework in a scenario question.
- Legal status
- Frameworks = voluntary good practice; IT Act 2000 = binding law
- ISO 27001 certification is voluntary unless a regulator or contract requires it.
Quick revision
- IS security rests on confidentiality, integrity and availability.
- General IT controls cover the whole IT environment; application controls work within a specific application.
- Application controls are commonly grouped as input, processing and output controls.
- Preventive controls stop an error, detective controls find it, corrective controls fix it.
- Logical access controls protect data and software, for example through passwords and authorisation levels.
- Physical access controls protect hardware and premises, for example locks and restricted entry.
- A business continuity plan keeps operations running; a disaster recovery plan restores IT systems.
- Regular, tested and off-site backups are central to recovery.
- CAATs let the auditor test large volumes of data directly instead of relying only on samples.
- Segregation of duties reduces the chance of fraud and error in IT processes.
- IT governance links IT to business goals and manages IT risk.
- Check the exact wording of the IT Act provisions and framework names in your study material before the exam.
Common mistakes
- Treating IS audit as only checking computer hardware. Fix: Include software, data, networks, people, processes and controls in the definition and scope.
- Saying IS audit replaces financial or cost audit. Fix: State that it supports them by giving assurance on the systems that produce the data.
- Using threat and vulnerability as the same thing. Fix: A threat acts from outside the weakness; a vulnerability is the weakness itself. Write both separately in answers.
- Mapping every incident to confidentiality only. Fix: Ask whether data leaked, changed or became unusable. Ransomware that locks files mainly hits availability.
- Calling access controls an application control in every case. Fix: Treat logical access to systems, databases and networks as general. Menu-level rights inside one module can be application-specific, so read the context.
- Confusing change management with development controls. Fix: Development is building or buying a new system. Change management is modifying a system already in use.
- Using authentication and authorisation as if they mean the same thing. Fix: Remember: authentication proves identity; authorisation sets permitted actions afterwards. Always write them in that order.
- Saying a firewall protects against all threats, including viruses and insider misuse. Fix: State that a firewall filters network traffic by rules. It needs antivirus, access rights and monitoring beside it.
- Treating BCP and DRP as the same thing. Fix: Write that BCP covers the whole business and DRP is the IT recovery part within it.
- Mixing up incremental and differential backups. Fix: Incremental: changes since the last backup of any type. Differential: changes since the last full backup.
Exam tips
- Begin every answer with a short definition. Examiners award marks for it even in 2-mark MCQs on meaning.
- Use numbered points. Objectives, scope and need questions are marked by the number of distinct, relevant points.
- In case-based questions, name the system in the case, such as ERP, payroll or inventory software, and tie your points to it.
- For comparisons, give at least five bases of difference in a table-like two-column format.
- Do not drift into detailed controls. Those belong to the topics on general and application controls and access controls.
- In MCQs, decode the scenario by verb: leaked means confidentiality, altered means integrity, unavailable means availability.
- In case answers, structure as asset, threat, vulnerability, CIA impact, controls. Examiners look for this chain.
- Always mention insider fraud when asked for threats, and pair it with least privilege and segregation of duties.