Certified Information Systems Auditor (CISA)
Definition: A global professional certification for IT auditing, control, and security.
Issued by: ISACA (Information Systems Audit and Control Association).
Core Focus: Validates expertise in evaluating vulnerabilities and managing compliance.
Key Domains:
- Information systems auditing process
- Governance and management of IT
- IS acquisition, development, and implementation
- IS operations and business resilience
- Protection of information assets
Introduction
Imagine going on a treasure hunt without a map. In the world of information technology, wandering without a plan could mean missing a critical system vulnerability that leaves millions of users exposed. That’s why planning is the cornerstone of the Information System (IS) auditing process, representing a massive 18% of the CISA exam!
By completing this lesson, you will be able to:
- Explain the relationship between ISACA Standards, Guidelines, and Code of Professional Ethics.
- Define the unique purpose and authority of the Audit Charter.
- Contrast various audit types, focusing on the collaborative power of Control Self-Assessments (CSAs).
- Apply the risk-based audit approach and define the components of audit risk.
- Categorize internal controls into preventive, detective, corrective, deterrent, and compensating types.
The Auditor’s Rulebook: Standards, Guidelines, and the Audit Charter
Before an auditor ever looks at a line of code or a server room, they must establish their boundaries and authority. This foundation is built on three levels of professional guidance:
- Standards: These are mandatory requirements. They define the minimum acceptable performance required for any IS audit.
- Guidelines: These provide illustrative guidance on how to actually apply the standards. Auditors must consider them, and any departure from them must be professionally justified.
- Tools and Techniques: These are practical examples and steps an auditor might follow, but they do not set mandatory requirements.
The Source of Authority: The Audit Charter
Where does an auditor get the right to inspect sensitive system data? It comes from the Audit Charter. This is an overarching, high-level document approved by the board of directors and the audit committee. It clearly outlines the auditor’s responsibility, authority, and accountability.
Analogy: Think of the Audit Charter as a passport that grants permanent entry into all areas of an organization’s IT landscape. In contrast, an Engagement Letter is like a single-trip visa—it is focused entirely on a specific, individual audit exercise with a narrow objective.

