A Practical Revision Guide for Information Asset Security and Controls in CISA Domain 5
CISA Domain 5 (Part A) · Protection of Information Assets · Updated October 2026
CISA Domain 5 focuses on protecting organizational information assets through appropriate security controls. This Part A study guide explains information asset security frameworks, identity and access management, physical security, encryption, network protection, and cloud security from an IT auditor’s perspective
📌 Quick Answer
Domain 5 Part A is about protecting information assets through governance, policies, processes, and technical, physical, and environmental controls that match business risk. For a CISA auditor, the central question is, are the controls appropriately designed, implemented, and operating effectively to protect the confidentiality, integrity, and availability of information assets?
🔑 Key Takeaways
- Controls must be risk-based: the most expensive control is not necessarily the most appropriate one.
- A policy is not evidence of implementation: auditors look for proof the control actually operates.
- Authentication verifies identity; authorization decides permissions.
- Cloud security is shared, and outsourcing a service never outsources accountability.
- Encryption, hashing, and digital signatures do different jobs: know which protects what.
Information is one of an organization’s most valuable assets. Customer records, financial information, intellectual property, business applications, operational technology, and communication systems all require protection against unauthorized access, alteration, disclosure, destruction, and disruption.
The objective of information security is not simply to deploy security technologies. It is to ensure that appropriate governance, policies, processes, and technical, physical, and environmental controls protect information assets in accordance with business requirements and risk.
This article is a consolidated revision of Domain 5, Part A: Information Asset Security and Control, with an emphasis on the concepts an IT auditor needs to understand.
Understanding Information Asset Security
What Is an Information Asset?
An information asset is information or a resource that supports the organization’s business objectives and requires protection. An asset may contain information directly or provide the means to store, process, transmit, or protect information. Examples include:
customer and employee databases, financial and accounting records, business applications, source code, and operating systems servers
The CIA Triad
The three fundamental objectives of information security are
| Objective | Meaning | Examples of security controls |
|---|---|---|
| Confidentiality | Information is accessible only to authorized individuals, systems, or processes. | Access controls, encryption, data classification, DLP |
| Integrity | Information remains accurate, complete, and protected against unauthorized modification. | Hashing, digital signatures, input validation, change controls |
| Availability | Information and systems are accessible when required by authorized users. | Redundancy, backups, disaster recovery, UPS, capacity management |
💡 Example: A Hospital Patient-Record System
- Confidentiality: only authorized medical staff can view patient records.
- Integrity: patient prescriptions cannot be altered without authorization.
- Availability: doctors can access critical records during an emergency.
A control that improves one security objective may affect another. For example, highly restrictive access controls may improve confidentiality but could reduce availability if legitimate users cannot access information when needed.
🔍 Auditor’s Perspective
An auditor should determine whether:
- Information assets have been identified and assigned appropriate ownership;
- Assets have been classified according to their sensitivity and business importance;
- Risks to confidentiality, integrity, and availability have been assessed;
- Security controls address the identified risks;
- controls are implemented and operating effectively;
- Security requirements are reviewed when systems, threats, or business processes change.
Policies, Frameworks, Standards, and Guidelines
Security policies establish management’s direction. Frameworks organize security practices. Standards define mandatory requirements, while procedures explain how activities are performed.
Policies, Standards, Procedures, and Guidelines
| Document | Purpose | Example |
|---|---|---|
| Policy | Establishes management’s high-level direction, objectives, and mandatory expectations. | “Access to sensitive information shall be restricted to authorized users.” |
| Standard | Defines specific, mandatory technical or operational requirements. | “Privileged accounts must use multifactor authentication.” |
| Procedure | Describes the steps required to perform an activity. | Steps for creating, approving, modifying, and disabling a user account. |
| Guideline | Provides recommended practices or advice where flexibility may be appropriate. | Recommendations for secure remote working. |
| Baseline | Defines a minimum approved configuration or security level. | Approved server-hardening configuration. |
What Should an Auditor Examine?
An effective information security policy framework should have:
- management approval and sponsorship;
- clear scope and applicability;
- defined roles and responsibilities;
- alignment with business objectives and risk appetite;
- requirements for access, data protection, incident reporting, and compliance;
- defined exceptions and approval mechanisms;
- communication to relevant personnel;
- periodic review and update;
- evidence of implementation and enforcement.
A policy that exists only as a document, without implementation or monitoring, does not demonstrate effective security governance.
💡 Example: Access Revocation for Leavers
An organization’s policy states that all terminated employees must have their access revoked immediately. The auditor should not conclude that the control is effective merely because the policy exists. The auditor should examine termination notifications, HR and IT integration, account-disabling records, access logs, evidence of timely revocation, and exceptions or delayed deprovisioning.
Information Security Frameworks
A framework provides a structured approach to managing security risks and implementing controls. Common frameworks and standards include
| Framework or standard | Main purpose | Auditor’s focus |
|---|---|---|
| ISO/IEC 27001 | Requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). | ISMS governance, risk assessment, control selection, Statement of Applicability, monitoring, and continual improvement. |
| ISO/IEC 27002 | Guidance for implementing information security controls. | Whether selected controls are appropriately designed and implemented. |
| NIST Cybersecurity Framework (CSF) | Organizes cybersecurity risk management activities. CSF 2.0 uses Govern, Identify, Protect, Detect, Respond, and Recover. | Whether cybersecurity activities address organizational risk across the framework functions. |
| NIST SP 800-53 | Comprehensive catalogue of security and privacy controls. | Control selection, tailoring, implementation, and assessment. |
| COBIT | Framework for governance and management of enterprise information and technology. | Governance, accountability, risk, control objectives, and alignment with enterprise goals. |
| CIS Critical Security Controls | Prioritized set of safeguards for improving cybersecurity. | Implementation of prioritized safeguards and measurement of control effectiveness. |
| PCI DSS | Security requirements for entities handling payment-card data within its scope. | Compliance with applicable payment-card security requirements. |
| CSA Cloud Controls Matrix (CCM) | Cloud security control framework. | Cloud-specific risks, responsibilities, and control coverage. |
Risk-Based Control Selection
Organizations cannot implement every possible security control at the same level. Controls should be selected based on:
asset criticality threats vulnerabilities business impact
Physical and Environmental Controls
Information security is not limited to software and networks. Physical and environmental threats can compromise information assets, even when logical controls are strong.
Physical Security Controls
Physical controls protect facilities, equipment, media, and personnel from unauthorized access, theft, damage, or disruption.
| Control | Purpose |
|---|---|
| Security guards | Deter and respond to unauthorized physical access. |
| Perimeter fencing and barriers | Restrict access to facilities. |
| Access cards and biometric systems | Authenticate individuals entering protected areas. |
| Visitor registration | Record and control visitors. |
| CCTV | Support monitoring and investigation. |
| Mantraps | Prevent unauthorized individuals from following authorized personnel through access points. |
| Locked server racks | Protect equipment from unauthorized physical access. |
| Secure media storage | Protect backup tapes, disks, and other media. |
| Physical access logs | Provide evidence of entry and exit. |
| Security zones | Apply different levels of protection according to asset sensitivity. |
An auditor may review:
Physical access authorization lists access card logs. visitor records CCTV retention and monitoring periodic access reviews physical security incidents data center entry procedures access revocation for departed employees
Environmental Controls
Environmental controls protect information assets against conditions that can damage equipment or interrupt operations.
| Threat | Potential impact | Typical controls |
|---|---|---|
| Fire | Equipment destruction and service interruption | Fire detection, alarms, suppression systems |
| Water leakage | Equipment damage and data center outage | Leak detection, drainage, raised floors where appropriate |
| Excessive temperature | Hardware failure or reduced equipment life | HVAC, temperature monitoring |
| High humidity | Condensation or equipment damage | Humidity monitoring and environmental controls |
| Low humidity | Static electricity and electrostatic discharge | Humidity management and electrostatic discharge (ESD) controls |
| Dust | Equipment contamination and overheating | Filtration and housekeeping |
| Power failure | System outage and data loss | UPS, generators, redundant power |
| Voltage fluctuation | Hardware damage | Surge protection and power conditioning |
| Natural disasters | Facility damage and service disruption | Site selection, redundancy, disaster recovery arrangements |
| Electromagnetic interference | Communication or equipment malfunction | Appropriate shielding and equipment placement |
UPS versus Generator
| Control | Primary purpose |
|---|---|
| UPS | Provides immediate backup power and protects against short interruptions and power-quality problems. |
| Generator | Provides extended backup power during prolonged outages, subject to fuel, maintenance and startup requirements. |
A generator may not provide uninterrupted power during the time required to start. Therefore, a UPS is commonly used to bridge the gap.
🎯 Exam Reminder
The presence of environmental equipment is not enough. The auditor should examine whether it is tested, maintained, monitored and appropriate for the risk.
Industrial Control System (ICS) Security
Industrial Control Systems are used to monitor and control physical processes. ICS environments include technologies such as:
- SCADA: Supervisory Control and Data Acquisition systems
- PLC: Programmable Logic Controllers
- DCS: Distributed Control Systems
- HMI: Human-Machine Interfaces
- RTU: Remote Terminal Units
- industrial sensors and actuators
Why ICS Security Is Different
Traditional IT systems generally prioritize information confidentiality, integrity and availability. ICS environments must also consider:
human safety physical process safety equipment protection continuous operation real-time requirements reliability and deterministic behavior
A security control that is appropriate for an office network may not be suitable for a production control system. Important security objectives include:
- Identify critical devices, systems and dependencies.
- Limit unauthorized movement between environments.
- Prevent unauthorized vendor or engineer access.
- Restrict communication between critical systems.
- Reduce unnecessary services and insecure settings.
- Restrict unauthorized software execution.
- Reduce malware and unauthorized data-transfer risks.
- Ensure security actions do not create safety hazards.
ICS Patching: An Important Audit Issue
In a conventional IT environment, applying security patches quickly may be desirable. In an ICS environment, patching may require:
vendor approval testing in a representative environment planned maintenance windows safety assessment operational approval rollback planning
🔍 The Right Auditor Question for ICS
Has the organization assessed the risk, established a documented vulnerability-management approach, and implemented suitable compensating controls where immediate patching is not feasible?
Identity and Access Management (IAM)
Identity and Access Management ensures that the right individuals and systems receive the right access to the right resources at the right time.
Identification, Authentication, Authorization and Accountability
These terms are frequently tested in CISA examinations.
| Concept | Meaning | Example |
|---|---|---|
| Identification | A user or entity claims an identity. | Entering a username. |
| Authentication | The system verifies the claimed identity. | Password, smart card or biometric verification. |
| Authorization | Determines what an authenticated entity is allowed to do. | Permission to read patient records but not modify them. |
| Accountability | Actions can be traced to a specific individual or entity. | Audit logs showing which user approved a transaction. |
Authentication Factors
| Factor | Examples |
|---|---|
| Something you know | Password, PIN |
| Something you have | Hardware token, smart card, authenticator application |
| Something you are | Fingerprint, facial recognition, iris |
Multifactor authentication requires authentication factors from at least two different categories. A password combined with a hardware token is an example of multifactor authentication.
🔍 Authentication Considerations for Auditors
- Are passwords subject to appropriate complexity and length requirements?
- Are default passwords changed?
- Is multifactor authentication used for sensitive access?
- Are failed login attempts monitored?
- Are inactive accounts disabled?
- Are privileged accounts separately controlled?
- Are authentication methods appropriate to the risk?
- Are biometric systems protected against misuse and spoofing?
- Are service accounts managed and reviewed?
Authorization and Access-Control Principles
- Least privilege: users and systems should receive only the access necessary to perform authorized duties.
- Need to know: access to information should be granted only when the user has a legitimate business requirement to know it.
- Segregation of duties: critical activities should be divided among individuals so that one person cannot improperly control an entire transaction or process.
- Privileged accounts have elevated permissions, such as administrator, database administrator or root access, and need tighter control.
User Access Lifecycle
IAM should cover the complete identity lifecycle:
Joiner → Mover → Leaver
| Stage | Required controls |
|---|---|
| Joiner | Approved request, identity verification, role assignment, appropriate access provisioning |
| Mover | Review of existing access, removal of unnecessary permissions, assignment of new role-based access |
| Leaver | Timely account disabling, revocation of physical and logical access, recovery of assets |
Auditor’s evidence may include:
HR records access request forms approval workflows user-account listings privileged-account reports access review records termination reports system access logs periodic recertification
⚠️ Common Audit Finding
Access remains active after an employee has left the organization.
Access-Control Models
| Model | Description | Typical use |
|---|---|---|
| DAC — Discretionary Access Control | Resource owners can decide who receives access. | File-sharing environments |
| MAC — Mandatory Access Control | Access is based on centrally defined security classifications and rules. | High-security environments |
| RBAC — Role-Based Access Control | Permissions are assigned to roles, and users are assigned to roles. | Enterprise applications |
| ABAC — Attribute-Based Access Control | Access decisions use attributes such as user, resource, location, device and time. | Context-aware access environments |
Zero Trust Architecture (ZTA)
Zero Trust is a security approach based on the principle that no user, device, application or network location should automatically be trusted.
Traditional security models often relied heavily on a trusted internal network and an untrusted external network. Zero Trust recognizes that threats may exist inside or outside organizational boundaries. A Zero Trust approach generally emphasizes:
verify explicitly least-privilege access assume breach continuously evaluate risk policy based on identity, device, resource and context
Zero Trust does not mean that every request must necessarily use a password. It means that access decisions should be based on appropriate verification and policy rather than implicit trust.
🔍 Auditor’s Perspective
The auditor should examine whether:
- access decisions are based on defined policies;
- users and devices are appropriately authenticated;
- privileges are limited;
- device posture is evaluated where required;
- access is logged and monitored;
- segmentation is implemented according to risk;
- access is re-evaluated when relevant conditions change;
- service accounts and non-human identities are included.
🎯 Exam Insight
Zero Trust is not a single product. It is an architecture and security approach supported by multiple controls.
Information Security and External Parties
Organizations depend on suppliers, contractors, consultants, cloud providers, managed service providers and business partners. Security must be managed across the whole relationship:
- Due diligence. Before engaging a third party, assess its security capabilities, relevant certifications and independent assurance reports, and data protection practices.
- Contractual requirements. Contracts should address security responsibilities, confidentiality, access controls, data protection, incident notification, audit and assurance rights, vulnerability management, subcontractor controls, data retention and deletion, business continuity, and termination and data return.
- Ongoing monitoring. Security assurance should continue after contract signing.
- Termination. When a relationship ends, access should be revoked, organizational assets returned, data returned or securely destroyed as applicable, and credentials and certificates invalidated.
When services are outsourced, the organization does not automatically outsource its accountability. The exact responsibilities depend on the service model and contract.
🔍 Auditor’s Question
Has the organization clearly defined, assigned and monitored security responsibilities between itself and external parties?
Remote Access Security
Remote access allows users, administrators, vendors and contractors to connect to organizational systems from outside the organization’s physical premises. Common remote-access risks include:
stolen credentials unmanaged devices insecure Wi-Fi malware on endpoints weak authentication excessive privileges uncontrolled vendor access unencrypted communication split tunneling risks inadequate logging
Remote Administration
Administrative remote access should receive stronger controls than ordinary user access. An auditor may examine whether:
- administrative access is approved;
- MFA is enforced;
- access is restricted to authorized devices;
- sessions are recorded or logged where appropriate;
- access is time-limited;
- vendor activity is monitored;
- emergency access is controlled.
Federated Identity Management
Federated identity management allows users to access services across organizational or system boundaries using trusted identity relationships.
Instead of creating a separate account in every application, an organization may rely on an identity provider to authenticate the user and provide trusted identity information to a service provider. For example, an employee signs in through the organization’s identity provider and then accesses an approved external business application without creating a separate password for that application.
Common Technologies
| Technology | What it does |
|---|---|
| SAML | Security Assertion Markup Language exchanges authentication and authorization information between an identity provider and a service provider. Frequently used in enterprise Single Sign-On. |
| OAuth 2.0 | Primarily an authorization framework. It allows an application to obtain limited access to resources on behalf of a user or another client. OAuth itself is not an authentication protocol. |
| OpenID Connect (OIDC) | Adds an identity layer on top of OAuth 2.0 and is used for authentication. |
| Kerberos | A ticket-based authentication protocol commonly used in enterprise environments, including Active Directory domains. |
🔍 Auditor’s Concerns
- Is the trust relationship formally approved?
- Are identity assertions or tokens protected?
- Are signing keys managed securely?
- Is MFA enforced where required?
- Are user attributes mapped correctly?
- Is access revoked when the identity is disabled?
- Are federated sessions appropriately managed?
- Are logs available at the identity and service-provider sides?
- Are external applications included in access reviews?
🎯 Important Exam Distinction
SSO is a user experience or access capability; federation is a trust arrangement between identity domains or organizations. They are related but not identical.
Network and Endpoint Security
Network and endpoint controls protect communication infrastructure, devices, applications and the information flowing through them. Common network controls include:
firewalls intrusion detection and prevention network access control secure network configuration network segmentation secure routing access-control lists secure protocols network monitoring DDoS protection secure DNS services network device hardening
Endpoint security controls may include:
secure configuration anti-malware / EDR patch management host-based firewalls disk encryption application control USB restrictions device management vulnerability management local administrator restrictions security logging
VPN Protocols and Secure Communication
A Virtual Private Network creates a protected communication channel over an underlying network, often the public internet.
| Technology | Description | Audit considerations |
|---|---|---|
| IPsec | A suite of protocols for protecting IP communications. | Authentication, encryption, key management, configuration and secure algorithms. |
| IKE/IKEv2 | Negotiates security associations and cryptographic parameters for IPsec. | Strong authentication and secure configuration. |
| SSL/TLS VPN | Uses TLS to protect application or remote-access communication. | Certificate validation, TLS configuration, MFA, access restrictions. |
| WireGuard | A modern VPN protocol designed around secure cryptography and relatively simple configuration. | Key management, endpoint authorization, configuration and logging. |
| PPTP | An older VPN technology with significant security weaknesses. | Should not be treated as an appropriate modern secure-VPN choice. |
🔍 Auditor’s VPN Checklist
- Are weak or obsolete protocols disabled?
- Are strong encryption algorithms used?
- Are cryptographic keys protected?
- Is MFA enabled where appropriate?
- Are VPN users authorized?
- Are remote-access privileges limited?
- Are VPN logs monitored?
- Are inactive sessions terminated?
- Are VPN gateways patched and securely configured?
- Is split tunneling permitted only when justified by risk?
Content Delivery Networks (CDNs)
A Content Delivery Network is a distributed network of servers that delivers web content and services closer to end users. A CDN may cache static content, distribute traffic and provide edge-based security services.
Security risks include:
incorrect caching of sensitive information misconfigured origin servers exposed origin IP addresses improper TLS configuration insecure API access cache poisoning inadequate access controls incorrect cache invalidation
🔍 Auditor’s Focus
- Is sensitive content excluded from inappropriate caching?
- Are TLS certificates managed securely?
- Are CDN configurations reviewed?
- Is access to the origin server restricted?
- Are security logs available?
- Are changes to CDN rules authorized?
- Are DDoS and availability requirements addressed?
🎯 Important
A CDN does not automatically secure the application behind it. The origin server and application still require appropriate security controls.
Network Infrastructure Security
Network infrastructure includes routers, switches, firewalls, wireless controllers, DNS servers, load balancers and other communication components.
Common network infrastructure risks:
default credentials unnecessary services insecure management protocols weak administrative access poor configuration management unpatched firmware flat networks inadequate logging unauthorized configuration changes single points of failure
Auditor’s evidence:
network diagrams device inventories configuration baselines firewall rules change records configuration backups vulnerability reports access-control lists administrative logs high-availability test results
Unified Threat Management (UTM)
Unified Threat Management refers to security solutions that combine several security functions within a single platform. A UTM appliance may provide:
firewall services intrusion prevention antivirus / malware filtering web filtering email security VPN application control traffic monitoring
🔍 Auditor’s Perspective
The auditor should not assume that an organization is secure simply because it has a UTM appliance. The audit should examine whether:
- the device is appropriately configured;
- security services are enabled;
- signatures and software are updated;
- policies are reviewed;
- logs are monitored;
- high availability is required;
- performance is adequate;
- the UTM covers the organization’s actual risks.
Network Segmentation
Network segmentation divides a network into separate logical or physical zones to control communication and reduce security exposure.
| Technique | Description |
|---|---|
| VLANs | Logically separate networks at Layer 2. |
| Subnets | Divide IP networks into separate address ranges. |
| Firewalls | Control traffic between network zones. |
| DMZ | Places externally accessible systems in a controlled network zone. |
| Microsegmentation | Applies granular security policies between workloads or individual systems. |
| Air gap | Physically separates systems from other networks. |
| Jump server | Provides a controlled access point for administration of restricted systems. |
🔍 Auditor’s Questions
- Is segmentation based on risk and asset criticality?
- Are firewall rules documented and approved?
- Are unnecessary connections blocked?
- Are sensitive systems isolated?
- Are network diagrams current?
- Is segmentation tested?
- Are administrative paths controlled?
- Can users or attackers bypass the intended segmentation?
🎯 Important Distinction
A VLAN alone is not necessarily a security boundary. Effective security segmentation requires appropriate access-control enforcement.
Data Loss Prevention (DLP)
Data Loss Prevention technologies and processes help identify, monitor and prevent unauthorized disclosure, transmission or misuse of sensitive information.
🔍 Auditor’s Perspective
The auditor should evaluate whether:
- sensitive data has been identified and classified;
- DLP rules align with business requirements;
- policies cover relevant data channels;
- exceptions are approved;
- alerts are reviewed;
- DLP controls are tested;
- privacy and employee-monitoring requirements are considered;
- DLP policies are updated when data usage changes.
🎯 Exam Insight
DLP is not a replacement for access control, encryption or data classification. It is one component of a broader data-protection program.
Data Encryption, Hashing and Digital Signatures
Encryption primarily supports confidentiality, although authenticated encryption can also provide integrity and authenticity protections. For example:
- Symmetric: a database is encrypted using AES. The authorized application uses the appropriate key to decrypt data when required.
- Asymmetric: a sender encrypts information using the recipient’s public key. The recipient uses the corresponding private key to decrypt it.
Hashing
A cryptographic hash function converts data into a fixed-length digest. Hashing is generally designed to be one-way, meaning it should be computationally infeasible to recover the original input from the digest. Examples of cryptographic hash functions include SHA-256 and SHA-3.
⚠️ Password Storage
Passwords should not normally be stored using simple unsalted hashes. Password-specific hashing algorithms, such as Argon2id, bcrypt or scrypt, are designed for this purpose.
Digital Signatures
A digital signature provides mechanisms for:
- integrity;
- authentication of the signing entity;
- non-repudiation-related assurance, subject to the legal and technical context.
🧠 Important Distinction
Encryption protects confidentiality. Digital signatures primarily support integrity and authentication of the signed content.
Key Management
Encryption is only as strong as the protection of its keys.
🔍 Auditor’s Checklist
- Are cryptographic algorithms approved?
- Are obsolete algorithms disabled?
- Are keys protected against unauthorized access?
- Are key-management responsibilities defined?
- Are keys rotated according to risk and policy?
- Are encryption keys backed up securely where required?
- Are revoked or compromised keys handled appropriately?
- Is access to keys logged and reviewed?
- Are encryption requirements aligned with data classification?
Public Key Infrastructure (PKI)
Public Key Infrastructure is a system of technologies, processes, policies and trusted entities used to manage public-key cryptography and digital certificates.
| Component | Function |
|---|---|
| Public/private key pair | Supports asymmetric cryptographic operations. |
| Digital certificate | Binds an identity or subject to a public key through a trusted certificate structure. |
| Certificate Authority (CA) | Issues and signs certificates. |
| Registration Authority (RA) | Performs or supports identity verification and registration activities. |
| Certificate repository | Stores certificates and related information. |
| Certificate Revocation List (CRL) | Lists certificates that have been revoked. |
| OCSP | Supports online checking of certificate status. |
| Certificate policy | Defines rules and requirements for certificate issuance and use. |
An auditor should examine:
CA governance certificate issuance controls identity verification private-key protection certificate inventory renewal processes revocation procedures CRL or OCSP availability certificate-policy compliance root and intermediate CA protection
🎯 Important Distinction
A certificate does not prove that a website or organization is trustworthy in every respect. It establishes a cryptographic identity binding within the applicable trust model.
Cloud and Virtualized Environments
Cloud computing provides on-demand access to computing resources such as servers, storage, applications and networks. Common cloud service models are:
| Model | Description | Customer responsibility |
|---|---|---|
| IaaS — Infrastructure as a Service | Provider supplies infrastructure such as virtual machines, storage and networks. | Operating systems, applications, configurations, identities and data, depending on the service. |
| PaaS — Platform as a Service | Provider manages the platform used to develop and run applications. | Applications, data, identities and customer configurations, depending on the service. |
| SaaS — Software as a Service | Provider delivers a complete application. | User access, data governance, configurations and customer-side security responsibilities. |
Cloud Deployment Models
- Public cloud: services are provided through shared provider infrastructure.
- Private cloud: cloud infrastructure is dedicated to a particular organization.
- Hybrid cloud: combines private and public cloud environments.
- Community cloud: infrastructure is shared by organizations with common requirements.
Cloud security responsibilities are divided between the provider and the customer. The exact division depends on the service model, architecture, contract and provider.
🔍 Auditor’s Focus
- Are responsibilities documented?
- Is cloud configuration securely managed?
- Are identities and privileges controlled?
- Is data appropriately classified?
- Are encryption requirements defined?
- Are logs available and monitored?
- Are backups and recovery capabilities adequate?
- Are provider assurance reports reviewed?
- Are regulatory and data-residency requirements addressed?
- Are subcontractors and fourth parties considered?
Virtualization Security
Virtualization allows multiple virtual machines to operate on a physical host. Components may include:
hypervisor virtual machines virtual networks virtual storage virtual switches management consoles templates and images
Security controls include:
- harden hypervisors;
- restrict management access and apply MFA;
- separate management networks;
- secure virtual-machine templates;
- patch hosts and guest systems;
- control snapshots and images;
- monitor administrative actions;
- segment virtual networks;
- review resource and access configurations.
🎯 Important
Virtual machines are not automatically secure merely because they are isolated logically. Their security depends on the hypervisor, configuration, management plane, guest operating systems and network architecture.
Secure Cloud Migration
Cloud migration involves transferring applications, data, services or infrastructure from an existing environment to a cloud environment. Security should be integrated into the migration lifecycle rather than addressed after migration.
1. Assessment and planning → 2. Architecture and design → 3. Migration preparation → 4. Migration execution → 5. Post-migration validation
🔍 Auditor’s Key Question
Has the organization demonstrated that security, privacy, integrity, availability and compliance requirements were maintained throughout the migration?
Mobile, Wireless and IoT Devices
Mobile devices include smartphones, tablets and portable computing devices used to access organizational resources. Mobile security controls include:
Mobile Device Management (MDM) Enterprise Mobility Management (EMM) Mobile Application Management (MAM) device encryption strong authentication screen-lock policies remote lock and wipe application restrictions secure configuration patch management device compliance checks separation of business and personal data
BYOD: Bring Your Own Device
BYOD allows employees to use personally owned devices for organizational activities. An auditor should examine whether:
- BYOD is formally authorized;
- security requirements are defined;
- organizational data can be separated from personal data;
- remote wipe is appropriately managed;
- privacy requirements are considered;
- access is revoked when employment ends;
- devices must meet minimum security standards.
Wireless Security
Wireless networks provide connectivity without physical network cables but introduce risks such as unauthorized access, eavesdropping, rogue access points and misconfiguration. Wireless security practices include using current, appropriately configured wireless security protocols, avoiding obsolete encryption mechanisms and enforcing strong authentication.
🔍 Auditor’s Questions
- Are wireless networks documented?
- Is the security protocol appropriate?
- Are guest and internal networks separated?
- Are access points securely configured?
- Are default credentials changed?
- Is unauthorized wireless equipment detected?
- Are wireless logs available?
- Is wireless access included in security testing?
Internet of Things (IoT)
IoT devices are connected devices that collect, transmit or process data and may interact with the physical environment. IoT security risks include:
default passwords insecure firmware limited patching capability poor asset visibility weak encryption insecure APIs unnecessary network exposure lack of device identity physical tampering vendor dependency privacy concerns
| IoT control | Purpose |
|---|---|
| Asset inventory | Identify devices and their owners. |
| Unique device identities | Avoid shared or default credentials. |
| Secure provisioning | Establish trusted device configuration. |
| Firmware management | Address vulnerabilities and updates. |
| Network segmentation | Limit device communication. |
| Encryption | Protect data in transit and at rest where appropriate. |
| Secure APIs | Protect communication with applications and platforms. |
| Device monitoring | Detect abnormal behavior. |
| Physical protection | Reduce tampering. |
| Secure decommissioning | Remove credentials and securely dispose of data. |
🔍 Auditor’s Perspective
The auditor should determine whether IoT devices are included in the organization’s information-security program. A device that cannot be patched may require compensating controls such as:
- network isolation;
- restricted communication;
- enhanced monitoring;
- replacement planning;
- removal of unnecessary functionality.
🎯 Important
IoT security is not only about the device itself. The supporting cloud service, mobile application, API, network and data-processing environment must also be assessed.
20 High-Value CISA Exam Reminders
- Security controls should be risk-based. The most expensive control is not necessarily the most appropriate control.
- A policy is not evidence of implementation.
- Authentication verifies identity; authorization determines permissions.
- Accountability requires traceability of actions to users or entities.
- Least privilege reduces unnecessary access.
- Segregation of duties reduces the risk of unauthorized activity.
- MFA requires different authentication factors, not merely multiple credentials.
- Zero Trust does not mean automatically trusting internal networks.
- Cloud security follows a shared-responsibility model.
- Outsourcing a service does not automatically outsource the organization’s accountability.
- A VLAN alone does not guarantee effective security segmentation.
- Encryption protects confidentiality; hashing supports integrity verification.
- Digital signatures are not the same as encryption.
- PKI depends on certificate and private-key management.
- DLP works best when sensitive data is identified and classified.
- ICS security must consider safety, availability, and operational constraints.
- Immediate patching is not always feasible in ICS environments; risk-based compensating controls may be necessary.
- A CDN improves delivery and may provide security services, but it does not automatically secure the origin application.
- A UTM appliance does not eliminate the need for proper configuration, monitoring and resilience.
- Security controls must be tested for design and operating effectiveness.
The Big Picture
An effective IT auditor should be able to move beyond the question “Does the organization have this security control?” and ask:
❓ The Question a CISA Auditor Should Always Ask
Is this control appropriate for the identified risk, properly designed, implemented as intended, and operating effectively?
That is the central perspective needed to understand and audit information asset security.
References and Further Reading
This article is structured around the subject areas in ISACA’s CISA examination content outline. Useful resources for further study:
- ISACA — CISA Exam Content Outline: defines the current five domains and the detailed topics under Domain 5.
- ISO/IEC 27001 and ISO/IEC 27002: information security management systems and control implementation guidance.
- NIST Cybersecurity Framework: cybersecurity risk-management framework.
- NIST SP 800-53: security and privacy controls.
- NIST SP 800-207: Zero Trust Architecture.
- NIST SP 800-82: Guide to Operational Technology Security.
- NIST SP 800-57: Key Management.
- NIST SP 800-63: Digital Identity Guidelines.
- Cloud Security Alliance Cloud Controls Matrix: cloud security controls and responsibilities.
Note: this is an independent educational revision guide, not official ISACA study material. Candidates should use the current ISACA Review Manual, official practice questions and examination guidance for comprehensive preparation.



