CISA Domain 5: Protection of Information Assets : Part A

CISA Domain 5

Table of Contents

A Practical Revision Guide for Information Asset Security and Controls in CISA Domain 5

CISA Domain 5 (Part A) · Protection of Information Assets · Updated October 2026

CISA Domain 5 focuses on protecting organizational information assets through appropriate security controls. This Part A study guide explains information asset security frameworks, identity and access management, physical security, encryption, network protection, and cloud security from an IT auditor’s perspective

📌 Quick Answer

Domain 5 Part A is about protecting information assets through governance, policies, processes, and technical, physical, and environmental controls that match business risk. For a CISA auditor, the central question is, are the controls appropriately designed, implemented, and operating effectively to protect the confidentiality, integrity, and availability of information assets?

🔑 Key Takeaways

  • Controls must be risk-based: the most expensive control is not necessarily the most appropriate one.
  • A policy is not evidence of implementation: auditors look for proof the control actually operates.
  • Authentication verifies identity; authorization decides permissions.
  • Cloud security is shared, and outsourcing a service never outsources accountability.
  • Encryption, hashing, and digital signatures do different jobs: know which protects what.

Information is one of an organization’s most valuable assets. Customer records, financial information, intellectual property, business applications, operational technology, and communication systems all require protection against unauthorized access, alteration, disclosure, destruction, and disruption.

The objective of information security is not simply to deploy security technologies. It is to ensure that appropriate governance, policies, processes, and technical, physical, and environmental controls protect information assets in accordance with business requirements and risk.

This article is a consolidated revision of Domain 5, Part A: Information Asset Security and Control, with an emphasis on the concepts an IT auditor needs to understand.

Understanding Information Asset Security

What Is an Information Asset?

An information asset is information or a resource that supports the organization’s business objectives and requires protection. An asset may contain information directly or provide the means to store, process, transmit, or protect information. Examples include:

customer and employee databases, financial and accounting records, business applications, source code, and operating systems servers

The CIA Triad

The three fundamental objectives of information security are

Objective Meaning Examples of security controls
Confidentiality Information is accessible only to authorized individuals, systems, or processes. Access controls, encryption, data classification, DLP
Integrity Information remains accurate, complete, and protected against unauthorized modification. Hashing, digital signatures, input validation, change controls
Availability Information and systems are accessible when required by authorized users. Redundancy, backups, disaster recovery, UPS, capacity management

💡 Example: A Hospital Patient-Record System

  • Confidentiality: only authorized medical staff can view patient records.
  • Integrity: patient prescriptions cannot be altered without authorization.
  • Availability: doctors can access critical records during an emergency.

A control that improves one security objective may affect another. For example, highly restrictive access controls may improve confidentiality but could reduce availability if legitimate users cannot access information when needed.

🔍 Auditor’s Perspective

An auditor should determine whether:

  • Information assets have been identified and assigned appropriate ownership;
  • Assets have been classified according to their sensitivity and business importance;
  • Risks to confidentiality, integrity, and availability have been assessed;
  • Security controls address the identified risks;
  • controls are implemented and operating effectively;
  • Security requirements are reviewed when systems, threats, or business processes change.

Policies, Frameworks, Standards, and Guidelines

Security policies establish management’s direction. Frameworks organize security practices. Standards define mandatory requirements, while procedures explain how activities are performed.

Policies, Standards, Procedures, and Guidelines

Document Purpose Example
Policy Establishes management’s high-level direction, objectives, and mandatory expectations. “Access to sensitive information shall be restricted to authorized users.”
Standard Defines specific, mandatory technical or operational requirements. “Privileged accounts must use multifactor authentication.”
Procedure Describes the steps required to perform an activity. Steps for creating, approving, modifying, and disabling a user account.
Guideline Provides recommended practices or advice where flexibility may be appropriate. Recommendations for secure remote working.
Baseline Defines a minimum approved configuration or security level. Approved server-hardening configuration.

What Should an Auditor Examine?

An effective information security policy framework should have:

  • management approval and sponsorship;
  • clear scope and applicability;
  • defined roles and responsibilities;
  • alignment with business objectives and risk appetite;
  • requirements for access, data protection, incident reporting, and compliance;
  • defined exceptions and approval mechanisms;
  • communication to relevant personnel;
  • periodic review and update;
  • evidence of implementation and enforcement.

A policy that exists only as a document, without implementation or monitoring, does not demonstrate effective security governance.

💡 Example: Access Revocation for Leavers

An organization’s policy states that all terminated employees must have their access revoked immediately. The auditor should not conclude that the control is effective merely because the policy exists. The auditor should examine termination notifications, HR and IT integration, account-disabling records, access logs, evidence of timely revocation, and exceptions or delayed deprovisioning.

Information Security Frameworks

A framework provides a structured approach to managing security risks and implementing controls. Common frameworks and standards include

Framework or standard Main purpose Auditor’s focus
ISO/IEC 27001 Requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). ISMS governance, risk assessment, control selection, Statement of Applicability, monitoring, and continual improvement.
ISO/IEC 27002 Guidance for implementing information security controls. Whether selected controls are appropriately designed and implemented.
NIST Cybersecurity Framework (CSF) Organizes cybersecurity risk management activities. CSF 2.0 uses Govern, Identify, Protect, Detect, Respond, and Recover. Whether cybersecurity activities address organizational risk across the framework functions.
NIST SP 800-53 Comprehensive catalogue of security and privacy controls. Control selection, tailoring, implementation, and assessment.
COBIT Framework for governance and management of enterprise information and technology. Governance, accountability, risk, control objectives, and alignment with enterprise goals.
CIS Critical Security Controls Prioritized set of safeguards for improving cybersecurity. Implementation of prioritized safeguards and measurement of control effectiveness.
PCI DSS Security requirements for entities handling payment-card data within its scope. Compliance with applicable payment-card security requirements.
CSA Cloud Controls Matrix (CCM) Cloud security control framework. Cloud-specific risks, responsibilities, and control coverage.

Risk-Based Control Selection

Organizations cannot implement every possible security control at the same level. Controls should be selected based on:

asset criticality threats vulnerabilities business impact

Physical and Environmental Controls

Information security is not limited to software and networks. Physical and environmental threats can compromise information assets, even when logical controls are strong.

Physical Security Controls

Physical controls protect facilities, equipment, media, and personnel from unauthorized access, theft, damage, or disruption.

Control Purpose
Security guards Deter and respond to unauthorized physical access.
Perimeter fencing and barriers Restrict access to facilities.
Access cards and biometric systems Authenticate individuals entering protected areas.
Visitor registration Record and control visitors.
CCTV Support monitoring and investigation.
Mantraps Prevent unauthorized individuals from following authorized personnel through access points.
Locked server racks Protect equipment from unauthorized physical access.
Secure media storage Protect backup tapes, disks, and other media.
Physical access logs Provide evidence of entry and exit.
Security zones Apply different levels of protection according to asset sensitivity.

An auditor may review:

Physical access authorization lists access card logs. visitor records CCTV retention and monitoring periodic access reviews physical security incidents data center entry procedures access revocation for departed employees

Environmental Controls

Environmental controls protect information assets against conditions that can damage equipment or interrupt operations.

Threat Potential impact Typical controls
Fire Equipment destruction and service interruption Fire detection, alarms, suppression systems
Water leakage Equipment damage and data center outage Leak detection, drainage, raised floors where appropriate
Excessive temperature Hardware failure or reduced equipment life HVAC, temperature monitoring
High humidity Condensation or equipment damage Humidity monitoring and environmental controls
Low humidity Static electricity and electrostatic discharge Humidity management and electrostatic discharge (ESD) controls
Dust Equipment contamination and overheating Filtration and housekeeping
Power failure System outage and data loss UPS, generators, redundant power
Voltage fluctuation Hardware damage Surge protection and power conditioning
Natural disasters Facility damage and service disruption Site selection, redundancy, disaster recovery arrangements
Electromagnetic interference Communication or equipment malfunction Appropriate shielding and equipment placement

UPS versus Generator

Control Primary purpose
UPS Provides immediate backup power and protects against short interruptions and power-quality problems.
Generator Provides extended backup power during prolonged outages, subject to fuel, maintenance and startup requirements.

A generator may not provide uninterrupted power during the time required to start. Therefore, a UPS is commonly used to bridge the gap.

🎯 Exam Reminder

The presence of environmental equipment is not enough. The auditor should examine whether it is tested, maintained, monitored and appropriate for the risk.

Industrial Control System (ICS) Security

Industrial Control Systems are used to monitor and control physical processes. ICS environments include technologies such as:

  • SCADA: Supervisory Control and Data Acquisition systems
  • PLC: Programmable Logic Controllers
  • DCS: Distributed Control Systems
  • HMI: Human-Machine Interfaces
  • RTU: Remote Terminal Units
  • industrial sensors and actuators

Why ICS Security Is Different

Traditional IT systems generally prioritize information confidentiality, integrity and availability. ICS environments must also consider:

human safety physical process safety equipment protection continuous operation real-time requirements reliability and deterministic behavior

A security control that is appropriate for an office network may not be suitable for a production control system. Important security objectives include:

  1. Identify critical devices, systems and dependencies.
  2. Limit unauthorized movement between environments.
  3. Prevent unauthorized vendor or engineer access.
  4. Restrict communication between critical systems.
  5. Reduce unnecessary services and insecure settings.
  6. Restrict unauthorized software execution.
  7. Reduce malware and unauthorized data-transfer risks.
  8. Ensure security actions do not create safety hazards.

ICS Patching: An Important Audit Issue

In a conventional IT environment, applying security patches quickly may be desirable. In an ICS environment, patching may require:

vendor approval testing in a representative environment planned maintenance windows safety assessment operational approval rollback planning

🔍 The Right Auditor Question for ICS

Has the organization assessed the risk, established a documented vulnerability-management approach, and implemented suitable compensating controls where immediate patching is not feasible?

Identity and Access Management (IAM)

Identity and Access Management ensures that the right individuals and systems receive the right access to the right resources at the right time.

Identification, Authentication, Authorization and Accountability

These terms are frequently tested in CISA examinations.

Concept Meaning Example
Identification A user or entity claims an identity. Entering a username.
Authentication The system verifies the claimed identity. Password, smart card or biometric verification.
Authorization Determines what an authenticated entity is allowed to do. Permission to read patient records but not modify them.
Accountability Actions can be traced to a specific individual or entity. Audit logs showing which user approved a transaction.

Authentication Factors

Factor Examples
Something you know Password, PIN
Something you have Hardware token, smart card, authenticator application
Something you are Fingerprint, facial recognition, iris

Multifactor authentication requires authentication factors from at least two different categories. A password combined with a hardware token is an example of multifactor authentication.

🔍 Authentication Considerations for Auditors

  • Are passwords subject to appropriate complexity and length requirements?
  • Are default passwords changed?
  • Is multifactor authentication used for sensitive access?
  • Are failed login attempts monitored?
  • Are inactive accounts disabled?
  • Are privileged accounts separately controlled?
  • Are authentication methods appropriate to the risk?
  • Are biometric systems protected against misuse and spoofing?
  • Are service accounts managed and reviewed?

Authorization and Access-Control Principles

  • Least privilege: users and systems should receive only the access necessary to perform authorized duties.
  • Need to know: access to information should be granted only when the user has a legitimate business requirement to know it.
  • Segregation of duties: critical activities should be divided among individuals so that one person cannot improperly control an entire transaction or process.
  • Privileged accounts have elevated permissions, such as administrator, database administrator or root access, and need tighter control.

User Access Lifecycle

IAM should cover the complete identity lifecycle:

Joiner → Mover → Leaver

Stage Required controls
Joiner Approved request, identity verification, role assignment, appropriate access provisioning
Mover Review of existing access, removal of unnecessary permissions, assignment of new role-based access
Leaver Timely account disabling, revocation of physical and logical access, recovery of assets

Auditor’s evidence may include:

HR records access request forms approval workflows user-account listings privileged-account reports access review records termination reports system access logs periodic recertification

⚠️ Common Audit Finding

Access remains active after an employee has left the organization.

Access-Control Models

Model Description Typical use
DAC — Discretionary Access Control Resource owners can decide who receives access. File-sharing environments
MAC — Mandatory Access Control Access is based on centrally defined security classifications and rules. High-security environments
RBAC — Role-Based Access Control Permissions are assigned to roles, and users are assigned to roles. Enterprise applications
ABAC — Attribute-Based Access Control Access decisions use attributes such as user, resource, location, device and time. Context-aware access environments

Zero Trust Architecture (ZTA)

Zero Trust is a security approach based on the principle that no user, device, application or network location should automatically be trusted.

Traditional security models often relied heavily on a trusted internal network and an untrusted external network. Zero Trust recognizes that threats may exist inside or outside organizational boundaries. A Zero Trust approach generally emphasizes:

verify explicitly least-privilege access assume breach continuously evaluate risk policy based on identity, device, resource and context

Zero Trust does not mean that every request must necessarily use a password. It means that access decisions should be based on appropriate verification and policy rather than implicit trust.

🔍 Auditor’s Perspective

The auditor should examine whether:

  • access decisions are based on defined policies;
  • users and devices are appropriately authenticated;
  • privileges are limited;
  • device posture is evaluated where required;
  • access is logged and monitored;
  • segmentation is implemented according to risk;
  • access is re-evaluated when relevant conditions change;
  • service accounts and non-human identities are included.

🎯 Exam Insight

Zero Trust is not a single product. It is an architecture and security approach supported by multiple controls.

Information Security and External Parties

Organizations depend on suppliers, contractors, consultants, cloud providers, managed service providers and business partners. Security must be managed across the whole relationship:

  1. Due diligence. Before engaging a third party, assess its security capabilities, relevant certifications and independent assurance reports, and data protection practices.
  2. Contractual requirements. Contracts should address security responsibilities, confidentiality, access controls, data protection, incident notification, audit and assurance rights, vulnerability management, subcontractor controls, data retention and deletion, business continuity, and termination and data return.
  3. Ongoing monitoring. Security assurance should continue after contract signing.
  4. Termination. When a relationship ends, access should be revoked, organizational assets returned, data returned or securely destroyed as applicable, and credentials and certificates invalidated.

When services are outsourced, the organization does not automatically outsource its accountability. The exact responsibilities depend on the service model and contract.

🔍 Auditor’s Question

Has the organization clearly defined, assigned and monitored security responsibilities between itself and external parties?

Remote Access Security

Remote access allows users, administrators, vendors and contractors to connect to organizational systems from outside the organization’s physical premises. Common remote-access risks include:

stolen credentials unmanaged devices insecure Wi-Fi malware on endpoints weak authentication excessive privileges uncontrolled vendor access unencrypted communication split tunneling risks inadequate logging

Remote Administration

Administrative remote access should receive stronger controls than ordinary user access. An auditor may examine whether:

  • administrative access is approved;
  • MFA is enforced;
  • access is restricted to authorized devices;
  • sessions are recorded or logged where appropriate;
  • access is time-limited;
  • vendor activity is monitored;
  • emergency access is controlled.

Federated Identity Management

Federated identity management allows users to access services across organizational or system boundaries using trusted identity relationships.

Instead of creating a separate account in every application, an organization may rely on an identity provider to authenticate the user and provide trusted identity information to a service provider. For example, an employee signs in through the organization’s identity provider and then accesses an approved external business application without creating a separate password for that application.

Common Technologies

Technology What it does
SAML Security Assertion Markup Language exchanges authentication and authorization information between an identity provider and a service provider. Frequently used in enterprise Single Sign-On.
OAuth 2.0 Primarily an authorization framework. It allows an application to obtain limited access to resources on behalf of a user or another client. OAuth itself is not an authentication protocol.
OpenID Connect (OIDC) Adds an identity layer on top of OAuth 2.0 and is used for authentication.
Kerberos A ticket-based authentication protocol commonly used in enterprise environments, including Active Directory domains.

🔍 Auditor’s Concerns

  • Is the trust relationship formally approved?
  • Are identity assertions or tokens protected?
  • Are signing keys managed securely?
  • Is MFA enforced where required?
  • Are user attributes mapped correctly?
  • Is access revoked when the identity is disabled?
  • Are federated sessions appropriately managed?
  • Are logs available at the identity and service-provider sides?
  • Are external applications included in access reviews?

🎯 Important Exam Distinction

SSO is a user experience or access capability; federation is a trust arrangement between identity domains or organizations. They are related but not identical.

Network and Endpoint Security

Network and endpoint controls protect communication infrastructure, devices, applications and the information flowing through them. Common network controls include:

firewalls intrusion detection and prevention network access control secure network configuration network segmentation secure routing access-control lists secure protocols network monitoring DDoS protection secure DNS services network device hardening

Endpoint security controls may include:

secure configuration anti-malware / EDR patch management host-based firewalls disk encryption application control USB restrictions device management vulnerability management local administrator restrictions security logging

VPN Protocols and Secure Communication

A Virtual Private Network creates a protected communication channel over an underlying network, often the public internet.

Technology Description Audit considerations
IPsec A suite of protocols for protecting IP communications. Authentication, encryption, key management, configuration and secure algorithms.
IKE/IKEv2 Negotiates security associations and cryptographic parameters for IPsec. Strong authentication and secure configuration.
SSL/TLS VPN Uses TLS to protect application or remote-access communication. Certificate validation, TLS configuration, MFA, access restrictions.
WireGuard A modern VPN protocol designed around secure cryptography and relatively simple configuration. Key management, endpoint authorization, configuration and logging.
PPTP An older VPN technology with significant security weaknesses. Should not be treated as an appropriate modern secure-VPN choice.

🔍 Auditor’s VPN Checklist

  • Are weak or obsolete protocols disabled?
  • Are strong encryption algorithms used?
  • Are cryptographic keys protected?
  • Is MFA enabled where appropriate?
  • Are VPN users authorized?
  • Are remote-access privileges limited?
  • Are VPN logs monitored?
  • Are inactive sessions terminated?
  • Are VPN gateways patched and securely configured?
  • Is split tunneling permitted only when justified by risk?

Content Delivery Networks (CDNs)

A Content Delivery Network is a distributed network of servers that delivers web content and services closer to end users. A CDN may cache static content, distribute traffic and provide edge-based security services.

Security risks include:

incorrect caching of sensitive information misconfigured origin servers exposed origin IP addresses improper TLS configuration insecure API access cache poisoning inadequate access controls incorrect cache invalidation

🔍 Auditor’s Focus

  • Is sensitive content excluded from inappropriate caching?
  • Are TLS certificates managed securely?
  • Are CDN configurations reviewed?
  • Is access to the origin server restricted?
  • Are security logs available?
  • Are changes to CDN rules authorized?
  • Are DDoS and availability requirements addressed?

🎯 Important

A CDN does not automatically secure the application behind it. The origin server and application still require appropriate security controls.

Network Infrastructure Security

Network infrastructure includes routers, switches, firewalls, wireless controllers, DNS servers, load balancers and other communication components.

Common network infrastructure risks:

default credentials unnecessary services insecure management protocols weak administrative access poor configuration management unpatched firmware flat networks inadequate logging unauthorized configuration changes single points of failure

Auditor’s evidence:

network diagrams device inventories configuration baselines firewall rules change records configuration backups vulnerability reports access-control lists administrative logs high-availability test results

Unified Threat Management (UTM)

Unified Threat Management refers to security solutions that combine several security functions within a single platform. A UTM appliance may provide:

firewall services intrusion prevention antivirus / malware filtering web filtering email security VPN application control traffic monitoring

🔍 Auditor’s Perspective

The auditor should not assume that an organization is secure simply because it has a UTM appliance. The audit should examine whether:

  • the device is appropriately configured;
  • security services are enabled;
  • signatures and software are updated;
  • policies are reviewed;
  • logs are monitored;
  • high availability is required;
  • performance is adequate;
  • the UTM covers the organization’s actual risks.

Network Segmentation

Network segmentation divides a network into separate logical or physical zones to control communication and reduce security exposure.

Technique Description
VLANs Logically separate networks at Layer 2.
Subnets Divide IP networks into separate address ranges.
Firewalls Control traffic between network zones.
DMZ Places externally accessible systems in a controlled network zone.
Microsegmentation Applies granular security policies between workloads or individual systems.
Air gap Physically separates systems from other networks.
Jump server Provides a controlled access point for administration of restricted systems.

🔍 Auditor’s Questions

  • Is segmentation based on risk and asset criticality?
  • Are firewall rules documented and approved?
  • Are unnecessary connections blocked?
  • Are sensitive systems isolated?
  • Are network diagrams current?
  • Is segmentation tested?
  • Are administrative paths controlled?
  • Can users or attackers bypass the intended segmentation?

🎯 Important Distinction

A VLAN alone is not necessarily a security boundary. Effective security segmentation requires appropriate access-control enforcement.

Data Loss Prevention (DLP)

Data Loss Prevention technologies and processes help identify, monitor and prevent unauthorized disclosure, transmission or misuse of sensitive information.

🔍 Auditor’s Perspective

The auditor should evaluate whether:

  • sensitive data has been identified and classified;
  • DLP rules align with business requirements;
  • policies cover relevant data channels;
  • exceptions are approved;
  • alerts are reviewed;
  • DLP controls are tested;
  • privacy and employee-monitoring requirements are considered;
  • DLP policies are updated when data usage changes.

🎯 Exam Insight

DLP is not a replacement for access control, encryption or data classification. It is one component of a broader data-protection program.

Data Encryption, Hashing and Digital Signatures

Encryption primarily supports confidentiality, although authenticated encryption can also provide integrity and authenticity protections. For example:

  • Symmetric: a database is encrypted using AES. The authorized application uses the appropriate key to decrypt data when required.
  • Asymmetric: a sender encrypts information using the recipient’s public key. The recipient uses the corresponding private key to decrypt it.

Hashing

A cryptographic hash function converts data into a fixed-length digest. Hashing is generally designed to be one-way, meaning it should be computationally infeasible to recover the original input from the digest. Examples of cryptographic hash functions include SHA-256 and SHA-3.

⚠️ Password Storage

Passwords should not normally be stored using simple unsalted hashes. Password-specific hashing algorithms, such as Argon2id, bcrypt or scrypt, are designed for this purpose.

Digital Signatures

A digital signature provides mechanisms for:

  • integrity;
  • authentication of the signing entity;
  • non-repudiation-related assurance, subject to the legal and technical context.

🧠 Important Distinction

Encryption protects confidentiality. Digital signatures primarily support integrity and authentication of the signed content.

Key Management

Encryption is only as strong as the protection of its keys.

🔍 Auditor’s Checklist

  • Are cryptographic algorithms approved?
  • Are obsolete algorithms disabled?
  • Are keys protected against unauthorized access?
  • Are key-management responsibilities defined?
  • Are keys rotated according to risk and policy?
  • Are encryption keys backed up securely where required?
  • Are revoked or compromised keys handled appropriately?
  • Is access to keys logged and reviewed?
  • Are encryption requirements aligned with data classification?

Public Key Infrastructure (PKI)

Public Key Infrastructure is a system of technologies, processes, policies and trusted entities used to manage public-key cryptography and digital certificates.

Component Function
Public/private key pair Supports asymmetric cryptographic operations.
Digital certificate Binds an identity or subject to a public key through a trusted certificate structure.
Certificate Authority (CA) Issues and signs certificates.
Registration Authority (RA) Performs or supports identity verification and registration activities.
Certificate repository Stores certificates and related information.
Certificate Revocation List (CRL) Lists certificates that have been revoked.
OCSP Supports online checking of certificate status.
Certificate policy Defines rules and requirements for certificate issuance and use.

An auditor should examine:

CA governance certificate issuance controls identity verification private-key protection certificate inventory renewal processes revocation procedures CRL or OCSP availability certificate-policy compliance root and intermediate CA protection

🎯 Important Distinction

A certificate does not prove that a website or organization is trustworthy in every respect. It establishes a cryptographic identity binding within the applicable trust model.

Cloud and Virtualized Environments

Cloud computing provides on-demand access to computing resources such as servers, storage, applications and networks. Common cloud service models are:

Model Description Customer responsibility
IaaS — Infrastructure as a Service Provider supplies infrastructure such as virtual machines, storage and networks. Operating systems, applications, configurations, identities and data, depending on the service.
PaaS — Platform as a Service Provider manages the platform used to develop and run applications. Applications, data, identities and customer configurations, depending on the service.
SaaS — Software as a Service Provider delivers a complete application. User access, data governance, configurations and customer-side security responsibilities.

Cloud Deployment Models

  • Public cloud: services are provided through shared provider infrastructure.
  • Private cloud: cloud infrastructure is dedicated to a particular organization.
  • Hybrid cloud: combines private and public cloud environments.
  • Community cloud: infrastructure is shared by organizations with common requirements.

Cloud security responsibilities are divided between the provider and the customer. The exact division depends on the service model, architecture, contract and provider.

🔍 Auditor’s Focus

  • Are responsibilities documented?
  • Is cloud configuration securely managed?
  • Are identities and privileges controlled?
  • Is data appropriately classified?
  • Are encryption requirements defined?
  • Are logs available and monitored?
  • Are backups and recovery capabilities adequate?
  • Are provider assurance reports reviewed?
  • Are regulatory and data-residency requirements addressed?
  • Are subcontractors and fourth parties considered?

Virtualization Security

Virtualization allows multiple virtual machines to operate on a physical host. Components may include:

hypervisor virtual machines virtual networks virtual storage virtual switches management consoles templates and images

Security controls include:

  • harden hypervisors;
  • restrict management access and apply MFA;
  • separate management networks;
  • secure virtual-machine templates;
  • patch hosts and guest systems;
  • control snapshots and images;
  • monitor administrative actions;
  • segment virtual networks;
  • review resource and access configurations.

🎯 Important

Virtual machines are not automatically secure merely because they are isolated logically. Their security depends on the hypervisor, configuration, management plane, guest operating systems and network architecture.

Secure Cloud Migration

Cloud migration involves transferring applications, data, services or infrastructure from an existing environment to a cloud environment. Security should be integrated into the migration lifecycle rather than addressed after migration.

1. Assessment and planning → 2. Architecture and design → 3. Migration preparation → 4. Migration execution → 5. Post-migration validation

🔍 Auditor’s Key Question

Has the organization demonstrated that security, privacy, integrity, availability and compliance requirements were maintained throughout the migration?

Mobile, Wireless and IoT Devices

Mobile devices include smartphones, tablets and portable computing devices used to access organizational resources. Mobile security controls include:

Mobile Device Management (MDM) Enterprise Mobility Management (EMM) Mobile Application Management (MAM) device encryption strong authentication screen-lock policies remote lock and wipe application restrictions secure configuration patch management device compliance checks separation of business and personal data

BYOD: Bring Your Own Device

BYOD allows employees to use personally owned devices for organizational activities. An auditor should examine whether:

  • BYOD is formally authorized;
  • security requirements are defined;
  • organizational data can be separated from personal data;
  • remote wipe is appropriately managed;
  • privacy requirements are considered;
  • access is revoked when employment ends;
  • devices must meet minimum security standards.

Wireless Security

Wireless networks provide connectivity without physical network cables but introduce risks such as unauthorized access, eavesdropping, rogue access points and misconfiguration. Wireless security practices include using current, appropriately configured wireless security protocols, avoiding obsolete encryption mechanisms and enforcing strong authentication.

🔍 Auditor’s Questions

  • Are wireless networks documented?
  • Is the security protocol appropriate?
  • Are guest and internal networks separated?
  • Are access points securely configured?
  • Are default credentials changed?
  • Is unauthorized wireless equipment detected?
  • Are wireless logs available?
  • Is wireless access included in security testing?

Internet of Things (IoT)

IoT devices are connected devices that collect, transmit or process data and may interact with the physical environment. IoT security risks include:

default passwords insecure firmware limited patching capability poor asset visibility weak encryption insecure APIs unnecessary network exposure lack of device identity physical tampering vendor dependency privacy concerns

IoT control Purpose
Asset inventory Identify devices and their owners.
Unique device identities Avoid shared or default credentials.
Secure provisioning Establish trusted device configuration.
Firmware management Address vulnerabilities and updates.
Network segmentation Limit device communication.
Encryption Protect data in transit and at rest where appropriate.
Secure APIs Protect communication with applications and platforms.
Device monitoring Detect abnormal behavior.
Physical protection Reduce tampering.
Secure decommissioning Remove credentials and securely dispose of data.

🔍 Auditor’s Perspective

The auditor should determine whether IoT devices are included in the organization’s information-security program. A device that cannot be patched may require compensating controls such as:

  • network isolation;
  • restricted communication;
  • enhanced monitoring;
  • replacement planning;
  • removal of unnecessary functionality.

🎯 Important

IoT security is not only about the device itself. The supporting cloud service, mobile application, API, network and data-processing environment must also be assessed.

20 High-Value CISA Exam Reminders

  1. Security controls should be risk-based. The most expensive control is not necessarily the most appropriate control.
  2. A policy is not evidence of implementation.
  3. Authentication verifies identity; authorization determines permissions.
  4. Accountability requires traceability of actions to users or entities.
  5. Least privilege reduces unnecessary access.
  6. Segregation of duties reduces the risk of unauthorized activity.
  7. MFA requires different authentication factors, not merely multiple credentials.
  8. Zero Trust does not mean automatically trusting internal networks.
  9. Cloud security follows a shared-responsibility model.
  10. Outsourcing a service does not automatically outsource the organization’s accountability.
  11. A VLAN alone does not guarantee effective security segmentation.
  12. Encryption protects confidentiality; hashing supports integrity verification.
  13. Digital signatures are not the same as encryption.
  14. PKI depends on certificate and private-key management.
  15. DLP works best when sensitive data is identified and classified.
  16. ICS security must consider safety, availability, and operational constraints.
  17. Immediate patching is not always feasible in ICS environments; risk-based compensating controls may be necessary.
  18. A CDN improves delivery and may provide security services, but it does not automatically secure the origin application.
  19. A UTM appliance does not eliminate the need for proper configuration, monitoring and resilience.
  20. Security controls must be tested for design and operating effectiveness.

The Big Picture

An effective IT auditor should be able to move beyond the question “Does the organization have this security control?” and ask:

❓ The Question a CISA Auditor Should Always Ask

Is this control appropriate for the identified risk, properly designed, implemented as intended, and operating effectively?

That is the central perspective needed to understand and audit information asset security.

References and Further Reading

This article is structured around the subject areas in ISACA’s CISA examination content outline. Useful resources for further study:

  • ISACA — CISA Exam Content Outline: defines the current five domains and the detailed topics under Domain 5.
  • ISO/IEC 27001 and ISO/IEC 27002: information security management systems and control implementation guidance.
  • NIST Cybersecurity Framework: cybersecurity risk-management framework.
  • NIST SP 800-53: security and privacy controls.
  • NIST SP 800-207: Zero Trust Architecture.
  • NIST SP 800-82: Guide to Operational Technology Security.
  • NIST SP 800-57: Key Management.
  • NIST SP 800-63: Digital Identity Guidelines.
  • Cloud Security Alliance Cloud Controls Matrix: cloud security controls and responsibilities.

Note: this is an independent educational revision guide, not official ISACA study material. Candidates should use the current ISACA Review Manual, official practice questions and examination guidance for comprehensive preparation.

https://thecyberskills.com/category/learn-train/cisa/

Scroll to Top