statistical sampling, 51

stop-and-go sampling, 52

SURRE rule, 49

third-party audits, 126-127

variable sampling, 52

vendors, 94-96

work-related skills, 27-28


automated WP, 51

leveraging WP, 54

ISA (Interconnection Security Agreements), 215

ISACA (Information Systems Audit and Control Association)

baselines, 31-34

CISA exams

applying for certification, 8

CBT, 13

CPE policies, 16

credit tracking, 16-17

earning CPE hours, 17-18

exam domains, 10-13

getting scores, 15

grading, 13

ISACA agreements, 9-10

maintaining certification, 16

question formats, 14-15

registration, 7

reporting CPE hours earned, 16-17

requirements for, 6-8

retaking, 16

scheduling exams, 6

work experience waivers, 8

COBIT 5, 31, 37, 41-42, 55

Code of Professional Ethics, 27-30


earning hours, 17-18

policies, 16

reporting hours earned, 16-17

credit tracking, 16-17

guidelines, 31-34

ISACA website, Code of Professional Ethics, 9-10

My Certifications, 7, 15-17

procedures, 31-34

standards, 31-34

ISDN (Integrated Services Digital Network), 314

ISO (International Organization for Standardization), 37, 111

ISO 9001 certification, quality management, 114-115

ISO 20000, 273-274

Isolation (ACID tests), 245, 282

IT acquisition, software

escrow agreements, 185

licensing agreements, 185-186

IT governance

accountability, 77

auditing, 80

best practices, 77

CMM, 116-119

compliance, managing, 119-121

corporate structures, 77

defining, 71

employee management

audit trails, 106

background checks, 103, 107

compensating controls, 106

dual control, 102, 107

exception reports, 106

forced vacations, 102, 107

handbooks, 100-101

hiring practices, 100

job rotation, 106

NDA, 102, 107

performance assessments, 101

reconciliation audits, 106

roles/responsibilities, 103-104

rotation of assignments, 102, 107

separation events (termination), 102-103

SoD, 105-107

supervisor reviews, 106

training, 101, 107

transaction logs, 106


asset identification, 82

qualitative risk analysis, 86-87

quantitative risk analysis, 84-87

risk management teams, 81

threat identification, 82-83

Three Lines of Defense model, 87-89

frameworks, 77

COBIT 5, 78-79

ITIL, 78-79

overlapping of, 79

funding system services, 77

goals of, 77

IT steering committees, 75-76

ITSM, 79

management and control frameworks

change management, 113

COBIT 5, 111, 117-118

COSO, 110, 115-116

CSF, 111

EA, 111-112

ISO, 111, 114-115

quality management, 114-119

maturity models, 116-119


contract management, 127-128

performance monitoring, 128

relationship management, 129-130

third-party audits, 126-127

third-party outsourcing, 125-126

performance management, 107

BSC, 109-110

KGI, 109

KPI, 109

metrics, 108-109

risk thresholds, 109

target values, 108

thresholds, 109

units, 108


defining supporting policies, 77

developing, 90-99


defining supporting processes, 77

optimizing, 121-125

IT suppliers, outsourcing

contract management, 127-128

performance monitoring, 128

relationship management, 129-130

third-party audits, 126-127

third-party outsourcing, 125-126

ITF (Integrated Test Facilities), 52

ITIL (IT Infrastructure Library), 78-79, 273

ITSM (IT Service Management), 79


JBOD (Just a Bunch of Disks), hardware recovery, 165

job rotation, employee management, 106

John the Ripper, 413

judgmental sampling, 51

jurisdictions (computer crime), 429


Kali Linux, 379

Kerberos, 341-342

key verification (edit controls), 240

keyloggers, information asset protection, 371

KGI (Key Goal Indicators), performance management, 109

KLOC (Kilo Lines of Code), software size estimation, 195

knowledge, authentication by, 336-337

knowledge-driven DSS (Decision Support Systems), BI, 258

known plaintext attacks, 374

KPI (Key Performance Indicators), performance management, 109


L2TP (Layer 2 Tunneling Protocol), 348

labeling (internal/external), 242

lagging risk indicators, 120

LAN (Local Area Networks), 284

last-mile protection, telecommunications recovery, 170

laws/regulatory standards

Basel III, 35

compliance with, 38

COSO, 35

EU Privacy Shield law, 35

FACTA, 35, 120

FFIEC Handbook, 36

FISMA, 35, 120

HIPAA, 35, 119

knowledge of, 35-36

PCI standards, 35-36, 119


SOX, 35, 119

layer 2 switches, 304

leading risk indicators, 120

least privilege (security policies), principle of, 99


DRM, 283


EULA, 282

illegal software, 283

licensing agreements, 185-186

lighting, physical/environmental access control, 351, 354

limit checks

data integrity controls, 241

edit controls, 239

link-state encryption, 368

link-state routing protocols, 295


Bastille Linux, 392

Kali Linux, 379

live VM migration, 222

load balancing, capacity planning, 318

lockout thresholds, 337, 379

locks, physical/environmental access control, 353-354

logic bombs, 411

logical relationship checks (edit controls), 240


OS logs, 393

reviewing/auditing, 414-415

transaction logs, 106, 242

LOIC (Low Orbit Ion Cannons), 403

long-haul diversity, telecommunications recovery, 170

long-term business goals, defined, 237



BIA criticality analysis, 148

quantitative risk analysis, 85

defining, 83

quantitative risk analysis, 85-86


BIA criticality analysis, 147

quantitative risk analysis, 85

threats and, 83

lost/stolen smartphones/tablets, 302

LTO (Linear Tape-Open) backups, 166


MAC (Media Access Control) addresses, 293, 304

MAID (Massive Array of Inactive Disks), 166

maintenance error reports, 242

maintenance/operation phase (NIST SDLC)

patch management, 210

review process, 211

vulnerability assessments, 210

malicious software, 379

malware, 404-405

MAN (Metropolitan Area Networks), 284

man-in-the-middle attacks, 375

managed switches, 304

management services, OSI reference model, 291



attack methods/techniques, 399-413

prevention/detection tools/techniques, 414-418

problem/incident management, 418-429

security controls, 391-397

change, 113

changes, 418

compliance, 119-121

contracts, 127-128

customers, CRM and BI, 258


audit trails, 106

background checks, 103, 107

compensating controls, 106

dual control, 102, 107

exception reports, 106

forced vacations, 102, 107

handbooks, 100-101

hiring practices, 100

job rotation, 106

NDA, 102, 107

performance assessments, 101

reconciliation audits, 106

roles/responsibilities, 103-104

rotation of assignments, 102, 107

separation events (termination), 102-103

SoD, 105-107

supervisor reviews, 106

training, 101, 107

transaction logs, 106

management and control frameworks

change management, 113

COBIT 5, 111, 117-118

COSO, 110, 115-116

CSF, 111

EA, 111-112

ISO, 111, 114-115

quality management, 114-119

performance, 107

BSC, 109-110

KGI, 109

KPI, 109

metrics, 108-109

risk thresholds, 109

target values, 108

thresholds, 109

units, 108

problem/incident management

change management, 418

computer crime jurisdictions, 429

escalation/response procedures, 424

forensic investigation, 425-428

fraud risk factors, 419-420

incident response, 420-422

processes/procedures, 422-424

prosecuting computer crime, 429


defining requirements, 251

design/development, 251

feasibility, 251

implementation phase, 251

post-implementation phase, 252

software acquisition process, 251

system change procedures, 252

systems controls, 250-251

testing, 251


CMM, 116-119

COSO, 115-116

ISO, 114-115

relationships (contractors/IS suppliers/vendors), 129-130


acceptance, 45

analysis, 44

avoidance, 44

Basel III, 35

Coca-Cola, 43

defining, 44

ERM, 80-89

lagging risk indicators, 120

leading risk indicators, 120

management teams (ERM), 81

monitoring, 45

organizational risk, quantitative risk analysis, 85

qualitative risk analysis, 86-87

quantitative risk analysis, 84-87

reduction, 44

tolerance, 45-47

transference, 45

threats, defining, 44

Three Lines of Defense, 87-89

supply chains. See SCM

manipulation controls (EDI), 254

manual application controls, 236-237

manual authorization controls, 238

manual recalculations (data integrity controls), 240

mapping (application testing), 246

master license agreements, 186

material (risk management), defining, 41

maturity models, 116-119

maximum acceptable outages, BCP, 158

maximum tolerable outages, BCP, 158

media-rotation strategies (backups)

grandfather-father-son rotation method, 168

simple rotation method, 167

Tower of Hanoi rotation method, 168


buffer overflow attacks, 409

RAM lookup tables, 304

smartphones/tablets, 302

virtual memory, 277

memory tables, final exam preparation, 441-442

mesh topologies (networks), 319

message boards, security, 397


IM security, 396-397

pretexting attacks, 400

metadata, 278

metrics (performance management), 108-109

Microsoft Attack Surface Analyzer, 409


data migration and data conversion tools, 209

VM migration (live), 222

MIMO (Multiple Input, Multiple Output), 301

mining data, 278

mirroring ports, 317

MITM (Man-In-The-Middle) attacks, 401

mobile sites, disaster recovery planning, 160

model-driven DSS (Decision Support Systems), BI, 257

modems, 305

MOM (Means, Opportunity, and Motive), fraud risk factors, 419


audit monitors, EDI, 254-255

continuous monitoring, 55-56

DAM, 394

embedded audit modules, 52

information asset protection, 371-372

OSI reference model, 290

performance, 130

IT suppliers, 128

systems/capacity planning, 315-323

risk (risk management), 45

RMON, 290

third-party monitoring, 318

MOU (Memorandums of Understanding), 215

MPLS (Multiprotocol Label Switching), 313

MTBF (Mean Time Between Failures), hardware recovery, 163

MTD (Maximum Tolerable Downtime), 158-159. See also maximum acceptable outages

MTTF (Mean Time To Failure), hardware recovery, 163

MTTR (Mean Time To Repair), hardware recovery, 164

MU-MIMO (Multi-user Multiple Input, Multiple Output), 301

multi-platform authentication, Federation, 343-345

multicast addresses, 294

multiple encryption, 361

multiplexing, OFDM, 300

My Certifications (ISACA website), 7, 15-17


n-tier, application development, 220-221

NAC (Network Access Control), 415

NAT (Network Address Translation), 310

natural disasters, recovery planning, 140

NDA (Non-Disclosure Agreements), 102, 107

NDMS (Network Database-Management Systems), 279

negotiations/conflict resolution, 58-59

NetFlow, 415

network access layer (TCP/IP reference model), 292-293

network administrators, 104

network analyzers

port mirroring, 317

Wireshark, 316

network forensics, 427

network layer (OSI reference model), 288

network sniffers, 400

networking cards (wireless), 299

networks, 283

802.11 wireless standard, 299-301

anycast addresses, 294

ARP, 294

Bluetooth, 298-299

broadcast addresses, 294

bus topologies, 319


attenuation, 320

baseband transmissions, 320

broadband transmissions, 321

coaxial cabling, 321-322

copper cabling, 322

fiber-optic cabling, 321-322

plenum-grade cabling, 321

twisted-pair cabling, 321

collision domains, 303

DHCP, 297

DMZ, 306, 309

DNS, 291, 297, 312


edge devices, 306-312

Ethernet, 292-293


configuring, 308-310

packet filter firewalls, 307-308

proxies, 307

screened host firewalls, 309

WAF, 308

FQDN, 292

FTP, 290

full-mesh networks, 320

GAN, 284

gateways, 305, 308

hubs, 303-305

IDP, 310


anomaly detection IDS, 312

HIDS, 310

NIDS, 310

pattern-matching (signature) IDS, 311

protocol decoding IDS, 312

IMAP, 291, 297

IP, VoIP, 313

IPS, 310

ISDN, 314

LAN, 284

MAC addresses, 293

MAN, 284

mesh topologies, 319

modems, 305

monitoring, 290

multicast addresses, 294

NAT, 310

OSI reference model, 286

application layer, 287

data link layer, 289

directory services, 291

email services, 290

file sharing services, 290

HTTP, 292

IP address verification services, 290

management services, 291

monitoring services, 290

network layer, 288

physical layer, 289

presentation layer, 287

print services, 291

processing data, 289-290

protocol analysis services, 290

session layer, 288

TCP/IP model versus, 292

transport layer, 288

PAN, 284

ping, 290

POP3, 291, 297

PPTP, 293

protocols, 285-286

RAM lookup tables, 304

repeaters, 303

ring topologies, 319

RIP, 295

RMON, 290

routers, 304-305

SAN, 285

SMTP, 290

SNMP, 291

social networks, BI, 260

SSH, 291

standards, 285-286

star topologies, 319

subnets, 293, 309

switches, 304-305

TCP, 295

TCP/IP reference model

application layer, 296-297

DHCP, 297

DNS, 297, 312


host-to-host/transport layer, 295

Internet layer, 293-295

network access layer, 292-293

OSI model versus, 292

Telnet, 291

Token Ring protocol, 293

traceroute, 290

UDP, 295

unicast addresses, 294

VoIP, 295, 313

VPN, 293, 347-348

WAN, 284

circuit switching, 313-314

packet switching, 312-313

WAP, 305

wireless technologies

802.11 wireless standard, 299-301

Bluetooth, 298-299

BYOD policies, 302-303

DSSS, 300

encryption, 299

FHSS, 300

frequency bands, 301

hotspots, 302-303

MIMO, 301

MU-MIMO, 301

OFDM, 300

smartphones, 302-303

spreading codes, 300

SSID, 299

tablets, 302-303

WAP, 299

WEP, 299-301

wireless networking card, 299

WPA, 299

WLAN, 322

WPAN, 284

NIDS (Network-based Intrusion Detection Systems), 310

NIST (National Institute of Standards and Technology), 37

CSF, 111

penetration testing, 417-418

SDLC, waterfall model, 200-201

development phase, 204-208

disposal phase, 211

implementation phase, 208-209

initiation phase, 202-204

operation/maintenance phase, 210

NOC (Net Present Value), ROI, 192

nonstatistical sampling, 51


objectives/culture of projects (project management), 189

observation, application controls, 244, 248

OBS (Object Breakdown Structure), project management, 189

occurrence (rates of), ARO and quantitative risk analysis, 85

OFDM (Orthogonal Frequency-Division Multiplexing), 300

Office Space, 412

offsite storage (backups), 167

OLA (Operating Level Agreements), 215

one-to-many search process. See identification

one-to-one checking (data file controls), 242

one-to-one search process. See authentication

online auditing (continuous), 247-249

online data integrity (data integrity controls), 245

onsite storage (backups), 167

OOSD (Object-Oriented System Development), 220

open Wi-Fi, data breaches, 377

OpenID, SOA, 344

operation/maintenance phase (NIST SDLC), 210

patch management, 210

review process, 211

vulnerability assessments, 210

operational audits, 40

operational interruptions, BCP recovery strategies, 149

opinions (audit reports), 52, 58

optimizing processes, 121

PDCA method, 123-125

Taguchi method, 122-125

organizational forms (project management), 188-189

organizational risks, quantitative risk analysis, 85


accountability, 95

expectations of, 95

OS (Operating Systems), 275-276

encryption, 393

hardening, 392

log security, 393

password security, 393

patch security, 393

secondary storage, 277

security, 391-393

technical controls (security controls), 391-393

user account security, 393

utility software, 277

virtual memory, 277

vulnerability assessments, security, 393

OSI (Open Systems Interconnection) reference model, 286

application layer, 287

data link layer, 289

directory services, 291

encryption, 367-368

file sharing services, 290

HTTP, 292

IP address verification services, 290

IP email services, 290

management services, 291

monitoring services, 290

network layer, 288

physical layer, 289

presentation layer, 287

print services, 291

processing data, 289-290

protocol analysis services, 290

session layer, 288

TCP/IP model versus, 292

transport layer, 288

OSPF (Open Shortest Path First), 295

OSSTMM (Open Source Security Testing Methodology Manual), penetration testing, 417

outages, BCP, 158

output controls (business process controls), 242

output/input controls, 205

outsider fraud risk factors (problem/incident management), 419-420

outsourcing, 214. See also vendors

BPA, 215

contract management, 127-128

ISA, 215

MOU, 215

OLA, 215

performance monitoring, 128

relationship management, 129-130

third-party audits, 126-127

third-party outsourcing, 125-126

UA, 215

oversight boards (project management), 188

oversubscription, disaster recovery planning, 163

OWASP top 10 security concerns, 393

ownership, authentication by, 338


Pac-Man, 412

packet filtering, firewalls, 307-308

packet switching, 312-313

PAN (Personal Area Networks), 284

parallel operation

application testing, 246

changeover techniques, 209

parallel simulations, 52, 246

parallel testing, 207

parity checking (data file controls), 242

passive discovery stage (penetration testing), 417


as authorization control, 238

brute-force attacks, 413

changing, 337

clipping levels, 379

comparative analysis, 412

complexity of, 337

cracking programs, 412-413

dictionary attacks, 412

dual-factor authentication, 93

good password characteristics, 337

hybrid attacks, 412-413

John the Ripper, 413

lockout thresholds, 337-379

OS security, 393

password controls (business process controls), 242

rainbow tables, 413

thunder tables, 413

verification policies, 337

weak passwords, 378


managing, 210

OS patching, 393

unpatched systems, 378

pattern-matching (signature) IDS, 311

payback analysis, 211

payback period (ROI), 192

PBX (Private Branch Exchange) systems, voice communication security, 357

PCI (Payment Card Industry) standards, 35-36, 119

PCI-DSS (Payment Card Industry Data Security Standard), 370

PDCA (Plan-Do-Check-Act) process optimization technique, 123-125

Pearson IT Certification website, 438

Pearson Test Prep software, 437, 442

offline access, 438-439

online access, 438-439

practice exams

customizing, 439-440

Flash Card Mode, 439

Practice Exam Mode, 439

Study Mode, 439

updating, 440

Premium Edition, 440

website, 438

PEM (Privacy Enhanced Mail), 255

penetration testing, 416-418


assessments, employee management, 101

capacity planning

cloud providers, 318

flow analysis, 315

load balancing, 318

network analyzers, 316-317

network cabling, 320-322

network design, 318-319

SNMP, 315

utilization reports, 315-317

vendors, 318

Windows Performance Monitor, 315

wireless systems, 322-323

managing, 107

BSC, 109-110

KGI, 109

KPI, 109

metrics, 108-109

risk thresholds, 109

target values, 108

thresholds, 109

units, 108

monitoring, 128-130

systems performance monitoring

cloud providers, 318

flow analysis, 315

load balancing, 318

network analyzers, 316-317

network cabling, 320-322

network design, 318-319

SNMP, 315

utilization reports, 315-317

vendors, 318

Windows Performance Monitor, 315

wireless systems, 322-323

perimeter security control

bollards, 350

CCTV systems, 352, 355-356

dogs, 351

entry points, 351

fences, 349-350

gates, 350

guards, 352

HVAC, 356

lighting, 351, 354

locks, 353-354

turnstiles, 352

personal data, classifying, 97

PERT (Program Evaluation and Review Technique), 197-198

PGP (Pretty Good Privacy), 255, 369

phased changeover (changeover techniques), 209

PHI (Protected Health Information), data classification, 97

phishing, 400

phreakers, 356, 419

physical layer (OSI reference model), 289

physical/environmental access control

bollards, 350

CCTV systems, 352, 355-356

dogs, 351

entry points, 351

fences, 349-350

gates, 350

guards, 352

HVAC, 356

lighting, 351, 354

locks, 353-354

turnstiles, 352

PIA (Privacy Impact Analysis), 372

picking locks, 354

PII (Personal Identifiable Information), data classification, 97

pilot changeover (changeover techniques), 209

pilot testing, 207

pineapples (Wi-Fi), 376

ping, 290

ping of death, 402

PKI (Public Key Infrastructure), 365-366

plaintext (encryption), 358, 374

planning audits. See also audit universes

planning phase (project management)

CPM, 198

scheduling tasks, 197-198


costs, 193-194

size, 195-196

timebox management, 199

planning stage (penetration testing), 417

plenum-grade cabling, 321

pod slurping, 376

point-in-time backups, 169

policy development (IT governance), 90

advisory policies, 91

auditing, 94-96

baselines, 92-96

bottom-up policy development, 91

data classification, 96-98

defining policies, 91

documentation, 92

informative policies, 92

procedures, 92-96

regulatory policies, 91

security policies, 98-99


auditing, 94-96

documentation, 92

supporting policies, 77

top-down policy development, 91

POP (Post Office Protocol), 255

POP3 (Post Office Protocol), 291, 297


common port numbers, 297

mirroring, 317

USB ports (uncontrolled), data breaches, 377

post-implementation phase (project management), 252

POTS (Plain Old Telephone Service), 314

power supplies, UPS, 171

PPTP (Point-to-Point Tunneling Protocol), 293, 348

practice exams

customizing, 439-440

Flash Card Mode, 439

Practice Exam Mode, 439

Study Mode, 439

updating, 440

pre-disaster planning. See problem/incident management

preparedness tests, BCP, 155-156

preparing for CISA exams

chapter-ending review tools, 441

DITKA questions, 442

memory tables, 441-442

Pearson Test Prep software, 437, 442

customizing exams, 439

customizing practice exams, 440

Flash Card Mode, 439

offline access, 438-439

online access, 438-439

Practice Exam Mode, 439

Premium Edition, 440

Study Mode, 439

updating exams, 440

website, 438

review questions, 442

presentation layer

BI data architectures, 256

OSI reference model, 287

pretexting attacks, 400

prevention/detection tools/techniques

attack-detection tools, 414

audit-reduction tools, 415

integrity checks, 414

log reviews, 414-415

NAC, 415

NetFlow, 415

security testing, 416-418

SIEM, 415

trend-detection tools, 414

variance-detection tools, 414

preventive controls, 47, 143

PRI (Primary Rate Interface), ISDN, 314

primary keys (ERD), 203

principle of least privilege (security policies), 99

print services, OSI reference model, 291

printing controls (business process controls), 242

privacy controls, 372

private clouds, 216

private key encryption

3DES, 359

AES, 362

Blowfish, 359

DES, 359-361

RC4, 360

RC5, 360

Rijndael, 360-362

SAFER, 360


escalation of privileges, virtualization, 222

principle of least privilege, security policies, 99

security policies, 99

PRM (Performance Reference Model), FEAF, 112

problem/incident management

change management, 418

computer crime jurisdictions, 429

criminal hackers, 419

fraud risk factors, 419-420

hackers, 419

incident response

defining incidents, 422

documentation, 421, 424

escalation/response procedures, 424

event analysis, 422

forensic investigation, 425-428

honeypots, 422

incident response teams, 420-422

processes/procedures, 422-424

phreakers, 419

prosecuting computer crime, 429

script kiddies, 419

terrorists, 420


documentation, 92

IT governance, 93

policy development, 93


IT governance, defining supporting processes, 77

optimization techniques, 121

PDCA method, 123-125

Taguchi method, 122-125

processing controls (business process controls)

data integrity controls, 240-241

edit controls, 239

program change documents, 243

programmed application controls. See automation, application controls

programming controls (data integrity controls), 240

project management

attributes of projects, 187

closing phase, 199

constraints of, 187, 192

control/execution phase, 199

cost, 187

critical tasks, 198

culture/objectives, 189

design/development, 251

feasibility, 251

gap analysis, 192

implementation phase, 251

initiation phase, 193

investment in projects

business case analysis, 190

feasibility studies, 191

ROI, 191

objectives/culture, 189

OBS, 189

organizational forms, 188-189

oversight boards, 188

planning phase

CPM, 198

scheduling tasks, 197-198

software costs, 193-194

software size, 195-196

timebox management, 199

post-implementation phase, 252

project managers, 188

QA, 188

requirements, defining, 251

responsibilities in, 188-189

roles in, 188-189

scope, 187, 192

scope creep, 204

security requirements, 191

senior management, 188

software acquisition process, 251

sponsors, 188

stakeholders, 188

steering committees, 188

structure of, 188-189

system change procedures, 252

systems controls, 250-251

teams, 188

testing, 251

time, 187

WBS, 190

prosecuting computer crime, 429

protocol decoding IDS, 312


analyzing, OSI reference model, 290

network protocols, 285-286

prototyping, 212

proxies, 307

public clouds, 216

public key encryption

digital signatures, 365

ECC, 363

hashing, 364

PKI, 365-366

quantum cryptography, 364

RSA, 363

trap door functions, 362


QA (Quality Assurance), 56-57

project management, 188

quality assurance employees, 104

qualified opinions (audit reports), 58

qualitative analysis, risk assessment, 86-87

qualitative judgments, risk assessment, 43

quality assurance, systems controls, 250-251

quality management

CMM, 116-119

COSO, 115-116

ISO, 114-115

quantitative analysis, risk assessment, 42-43, 84-87

quantum cryptography, 364


CISA exams, format of, 14-15

DITKA questions, final exam preparation, 442

review questions, final exam preparation, 442


RA (Registration Authorities), PKI, 366

RAD (Rapid Application Development), 212

RADIUS (Remote Access Dial-In User Service), 345-346

RAID (Redundant Array of Independent Disks), 164-165

rainbow tables, 413

RAM (Random Access Memory) lookup tables, 304

range checks (edit controls), 239

ransomware, 395

rates of occurrence, ARO and quantitative risk analysis, 85

rating audit reports, 59

RC4 (Rivest Cipher 4) encryption, 360

RC5 (Rivest Cipher 5) encryption, 360

RDMS (Relational Database-Management Systems), 281

reasonableness checks (edit controls), 239

reasonableness verification (data integrity controls), 240

recalculations (manual), data integrity controls, 240

reciprocal agreements, disaster recovery planning, 162-163

reconciliation audits, employee management, 106

reconciliation of file totals (data integrity controls), 241

recovery planning

alternate processing sites, 160

cold sites, 161

hot sites, 160

mobile sites, 160

oversubscription, 163

reciprocal agreements, 162-163

subscription services, 160, 163

warm sites, 161

alternative processing agreements, reviewing, 171

BCP, 142

administrative support teams, 154

auditor role, 143

BIA, 144-149

communications teams, 154

coordination teams, 154

core processes, 158

corrective controls, 143

damage assessment teams, 153

detective controls, 143

development phase, 149-150

discretionary processes, 159

emergency management teams, 153

emergency operations teams, 154

emergency response teams, 153

final plan design, 151-152

finance teams, 154

impact analysis phase, 144-149

implementation phase, 151-156

incident response teams, 153

initiation phase, 143

interruptions, 149-150

maintenance phase, 156

maximum acceptable outages, 158

maximum tolerable outages, 158

metrics, 157-158

monitoring phase, 156

preventive controls, 143

project management, 143

recovery strategies, 149-150

recovery test teams, 154

relocation teams, 154

responsibilities, 152-153

reviewing results, 157-158

reviewing tasks, 170

RPO, 157

RTO, 157-159

salvage teams, 153

SDO, 158

security teams, 154

supplies teams, 154

supporting processes, 158

team responsibilities, 143

testing phase, 153-156

training and awareness, 152-153

transportation teams, 154

verifying tasks, 170

WRT, 158

contracts, reviewing, 171

COOP websites, 172

data recovery, 165-169

disaster life cycle, 172-173

disaster recovery checklist, 172

hardware recovery

clustering, 164

fault tolerance, 164

MTBF, 163

MTTF, 163

MTTR, 164

RAID, 164-165

SLA, 164

incident classification, 141-142

insurance, reviewing, 171

MTD, 159

natural disasters, 140

power supplies, 171

recovery times, 161-162

redundant processing sites, 160

reviewing tasks, 170

telecommunications recovery, 169-170

verifying tasks, 170

recovery test teams (BCP), 154

recovery times, disaster recovery planning, 161-162

red team activities. See penetration testing

reducing risk (risk management), 44

redundancy, telecommunications recovery, 169

redundant processing sites, 160

reengineering, 213

referential data integrity (data integrity controls), 245

registering for CISA exams, 7

regression testing, 207

regulatory compliance risk assessments (audit universes), 236

regulatory policies, 91

regulatory standards

compliance with, 38

knowledge of, 35-36

relational data integrity (data integrity controls), 245

relations (databases), 278

relationship management (contractors/IT suppliers/vendors), 129, 130

relocation teams (BCP), 154

remanence (data), VM, 222

remote access

Diameter, 346

encryption, 347

RADIUS, 345-346

risks of, 347

security, 396


VPN, 347-348

repeaters, 303

reporting stage (penetration testing), 417


audit reports, 49, 57

opinions, 52-53, 58

rating, 59

writing, 53-54

before-and-after image reports, 242

distribution on (application controls), 244

exception reports, 106, 241

financial reports, COSO, 35

maintenance error reports, 242

transaction logs, 242

residual risk, 42

restoring data, 302

retaking CISA exams, 16

reverse engineering, 205

reviewing projects, 211

review questions, final exam preparation, 442

RFP (Requests for Proposal), 204

right-to-audit clauses, 127

Rijndael encryption, 360-362

ring topologies (networks), 319

RIP (Routing Information Protocol), 295

risk analysis, 44

risk assessment, 40

audit risk, 42

audit universe risk ranking, 236

control risk, 41-42

detection risk, 41-42

information asset protection, 372

inherent risk, 41

material, defining, 41

qualitative analysis, 86-87

qualitative judgments, 43

quantitative analysis, 42-43, 87

ALE, 85

ARO, 85

costs of losses, 85-86

exposure factor, 84

organizational risks, 85

SLE, 85

stochastic events, 85

residual risk, 42

risk management

Basel III, 35

Coca-Cola, 43

ERM, 80

asset identification, 82

qualitative risk analysis, 86-87

quantitative risk analysis, 84-87

risk management teams, 81

threat identification, 82-83

Three Lines of Defense model, 87-89

lagging risk indicators, 120

leading risk indicators, 120

organizational risk, quantitative risk analysis, 85

risk acceptance, 45

risk analysis, 44

risk avoidance, 44

risk monitoring, 45

risk reduction, 44

risk, defining, 44

risk tolerance, 45-47

risk transference, 45

threats, defining, 44

risk thresholds, performance management, 109

Rivest, Ron, 363

RMON (Remote Network Monitoring), 290

ROI (Return on Investment), 191, 211

rotating jobs, employee management, 106

rotation of assignments (employee management), 102, 107

rounding-down attacks, 412

routing, 304-305

protocols, 294-295

telecommunications recovery, 170

Royce, W.W., 200

RPO (Recovery Point Objectives), BCP, 157

RSA (Rivest, Shamir, Adleman) encryption, 363

RTO (Recovery Time Objectives), BCP, 157-159

RUDY (R U Dead Yet?), 403

run-to-run totals (data integrity controls), 240


S/MIME (Secure/Multipurpose Internet Mail Extensions), 255, 369

SAFER (Secure and Fast Encryption Routine), 360

salami technique, 412

sales automation (CRM), 259

salvage teams (BCP), 153

SAML (Security Assertion Markup Language), SOA, 344

SAN (Storage Area Networks), 166, 285

SCSI, 168

snapshots, 169

VSAN, 168

Sarbanes-Oxley Act (SOX), 4-5, 35, 119

satisfactory audit reports, 58

SCADA (U.S. Supervisory Controls and Data Acquisition), 35

SCARF/EAM (Systems Control Audit Review File/Embedded Audit Modules), continuous online auditing, 247


CISA exams, 6

tasks, project management, 197-198

schemas, 278

SCM (Supply Chain Management), BI, 259

scope of projects (project management)

project management, 187, 192

scope creep, 204

scores (CISA exams), getting, 15

screened host firewalls, 309

screened subnets, 309

script kiddies, 419

scripting, XSS attacks, 411

scrubbing locks, 354

scrums, software development, 213

SCSI (Small Computer System Interface), SAN, 168

SDLC (Systems Development Life Cycle)

auditor’s role in, 249


software development, 212-213

systems-development methodology, 200-211

software development

agile development, 213

incremental development, 212

prototyping, 212

RAD, 212

reengineering, 213

scrums, 213

spiral development, 212

sprints, 213

XP, 213

waterfall model, systems-development methodology, 200-201

development phase, 204-208

disposal phase, 211

implementation phase, 208-209

initiation phase, 202-204

operation/maintenance phase, 210

SDO (Service Delivery Objectives), BCP, 158

secondary storage, virtual memory, 277


architects, 104

asynchronous attacks, 411

backups, 395

black-box testing, 409

blogs, 397

Bluetooth, 406

botnets, 403-404

brute-force attacks, 413

buffer overflow attacks, 409

bypass label processing, 414

cloud computing, 219

DAM, 394

databases, 408-409

backups, 395

DAM, 394

EDR, 394

OWASP top 10 security concerns, 393

shadowing, 395

WAF, 393

DDoS attacks, 402-403

dictionary attacks, 412

DoS attacks, 402-403

droppers, 405

dumpster diving attacks, 400

EDR, 394

email attacks, 400

FIPS, 37

FISMA, 35, 120

fuzzing, 409

hijacking attacks, 401

HOIC, 403

hping, 403

hybrid attacks, 412-413

IM, 396-397

integer overflow attacks, 412

labels, bypassing, 414

log reviews/audits, 414-415

logic bombs, 411

LOIC, 403

malware, 404-405

message boards, 397

MITM attacks, 401

NIST, 37

OS, 391

encryption, 393

hardening OS, 392

logs, 393

passwords, 393

patches, 393

user accounts, 393

vulnerability assessments, 393

OWASP top 10 security concerns, 393


brute-force attacks, 413

comparative analysis, 412

cracking programs, 412-413

dictionary attacks, 412

hybrid attacks, 412-413

John the Ripper, 413

OS security, 393

rainbow tables, 413

thunder tables, 413

penetration testing, 416-418

phishing attacks, 400

ping of death, 402

policies, 98-99

pretexting attacks, 400

project management, 191

ransomware, 395

rounding-down attacks, 412

RUDY, 403

salami technique, 412

security teams (BCP), 154

slowloris, 403

smurfing attacks, 402

sniffing attacks, 400

social media, 397-398

social-engineering attacks, 399-400

spear phishing attacks, 400

spoofing attacks, 400

SQL injection attacks, 394, 408-409

syn flooding, 403


penetration testing, 416-418

vulnerability scanning, 416

TOCTOU attacks, 411

trap doors, 411

Trojans, 405

virtualization, 395-396

viruses, 405

VM, hardening, 395

vulnerability scanning, 416

WAF, 393

WAP, 406-407

websites, 397

whaling attacks, 400

wireless networks, 406

worms, 405

wrappers, 405

XSRF attacks, 411

XSS attacks, 411

zero-day attacks, 404

security controls

administrative controls

blogs, 397

IM, 396-397

message boards, 397

social media, 397-398

websites, 397


3DES, 359

AES, 362

algorithms, 358

asymmetric encryption, 358-359, 362-368

Atbash, 357

block ciphers, 361

Blowfish, 359

Caesar’s cipher, 357

ciphertext, 358

cryptanalysis, 358

cryptography, 358, 363-364, 367-368, 374-375

data breaches, 374-375

DES, 359-361

digital signatures, 365

ECC, 363

end-to-end encryption, 368

hashing, 364

key length, 358

link-state encryption, 368

multiple encryption, 361

OSI reference model, 367-368

PKI, 365-366

plaintext, 358

private key encryption, 359-362

public key encryption, 362-366

quantum cryptography, 364

RC4, 360

RC5, 360

Rijndael, 360-362

RSA, 363

SAFER, 360

stream ciphers, 361

symmetric encryption, 358-362, 367-368

hardware, voice communications, 356-357

information asset protection, 372


encryption, 357-368

voice communications, 356-357

technical controls

cloud computing, 391

databases, 393-395

OS, 391-393

virtualization, 395-396

voice communications

PBX systems, 357

phreakers, 356

VoIP, 357

security teams (BCP), 154

semi-quantitative analysis (qualitative risk analysis), 87

senior management (project management), 188

separating duties (application controls), 244

separation events (termination), 102-103

sequence checks (edit controls), 239


certificate servers, PKI, 366

clustering, hardware recovery, 164

virtual servers, 221, 395-396

service management frameworks

COBIT, 273-274


ACID tests, 282

aggregation, 278

attributes, 278

CRM, 279

data integrity, 281

data mining, 278

data warehouses, 279

database-management systems, 278-281

fields, 278

foreign keys, 278

granularity, 278

HDMS, 279

metadata, 278

NDMS, 279

RDMS, 281

relations, 278

schemas, 278

tuples, 281

DRM, 283

eTOM, 273-275

FitSM, 273-274

ISO 20000, 273-274

ITIL, 273

OS, 275-277

software licensing

EULA, 282

illegal software, 283


SOA, 344-345

SPML, 344

session layer (OSI reference model), 288

SET (Secure Electronic Transaction), 368

shadowing databases (standby), 169

Shamir, Adi, 363

shared cost corporate structures, 77

sharing files, OSI reference model, 290

Shewart, Walter A., 123

Shibboleth, SOA, 344-345

Shodan, 420

short-term business goals, defined, 237

shrink-wrap license agreements, 186

SIEM (Security Information and Event Management), 394, 415. See also DAM


as authorization control, 238

digital signatures, 365

simple backup rotation method, 167

site-to-site VPN, 348

size of software (project management, planning phase), 195-196

skills (work-related) for IS auditing, 27-28

SLA (Service Level Agreements), 127-128, 164

SLE (Single Loss Expectancy)

BIA criticality analysis, 147

quantitative risk analysis, 85

SLOC (Source Lines of Code), software size estimation, 195

slowloris, 403

smartphones/tablets, 302-303, 377

SMTP (Simple Mail Transfer Protocol), 255, 290

smurfing attacks, 402


application testing, 246

continuous online auditing, 248

SAN, 169

sniffing attacks, 400

SNMP (Simple Network Management Protocol), 291, 315

SOA (Service-Oriented Architectures)

OpenID, 344

SAML, 344

Shibboleth, 344-345

SPML, 344

WAYF, 345

WS Security, 344

XML, 344

sociability testing, 207

social media

BI, 260

security, 397-398

social-engineering attacks, 399-400

SoD (Segregation of Duties), employee management, 105-107

soft skills, IS auditing, 27


acquisition process (project management), 251

antivirus software, virtualization, 395

buffer overflow attacks, 409

COCOMO II software estimation, 194

costs of (project management, planning phase), 193-194

data recovery, 165-169

development tools/methods

agile development, 213

incremental development, 212

prototyping, 212

RAD, 212

reengineering, 213

scrums, 213

spiral development, 212

sprints, 213

XP, 213

escrow agreements, 185

forensics, 427

licensing, 185

click-wrap agreements, 186

DMCA, 186

EULA, 282

illegal software, 283

master agreements, 186

shrink-wrap agreements, 186

malicious software, 379

malware, 404-405

Pearson Test Prep software, 437, 442

customizing practice exams, 439-440

Flash Card Mode, 439

offline access, 438-439

online access, 438-439

Practice Exam Mode, 439

Premium Edition, 440

Study Mode, 439

updating practice exams, 440

website, 438

ransomware, 395

security controls

encryption, 357-368

voice communications, 356-357

size estimation (project management, planning phase), 195-196

utility software, 277

somewhere you are systems, authentication by, 340

SOX (Sarbanes-Oxley) Act, 4-5, 35, 119

spear phishing, 400

spiral software development, 212

SPML (Service Provisioning Markup Language), SOA, 344


project management, 188

sponsor pays corporate structures, 77

spoofing attacks, 400

spreading codes, 300

sprints, software development, 213

SQL injection attacks, 394, 408-409

SRM (Security Reference Model), FEAF, 112

SSAE 16 (Statement on Standards for Attestation Engagements 16) assessments, 127

SSAE 18 (Statement on Standards for Attestation Engagements 18) assessments, 127

SSH (Secure Shell), 291, 347, 368

SSID (Service Set ID), 299

SSL (Secure Sockets Layer), 348

SSO (Single Sign-On), 340

advantages of, 341

Kerberos, 341-342

stakeholders (project management), 188


documentation, 92

IT governance, 92

networks, 285-286

policy development, 92

SSAE 16, 127

SSAE 18, 127

standby database shadowing, 169

star topologies (networks), 319

stateless connections, 292

static data (data categories), 241

static forensic analysis, 428

statistical sampling, 51

steering committees (project management), 188

stochastic events, 85

stolen/lost smartphones/tablets, 302

stop-and-go sampling, 52



electronic vaulting, 169

grandfather-father-son rotation method, 168

location redundancy, 168

media-rotation strategies, 167-168

offsite storage, 167

onsite storage, 167

security, 169

simple rotation method, 167

standby database shadowing, 169

testing, 167

Tower of Hanoi rotation method, 168

offsite storage, 167

onsite storage, 167

storage cards, smartphones/tablets, 302

store-and-forward switches, 304

stream ciphers, 361

striping, RAID, 164-165

Study Mode (practice exams), 439

subnets, 293, 309

subscription services, disaster recovery planning, 160, 163

substantive tests, 39, 45

Summary view (Wireshark), 316

Superman III, 412

superusers (privileged accounts), 99

supervisor reviews, employee management, 106

supplies teams (BCP), 154

supply chains, managing. SCM, 259

supply interruptions, BCP recovery strategies, 149

supporting processes, BCP, 158

SURRE rule, evidence handling, 49

switches, 304-305

symmetric encryption, 358, 367-368

3DES, 359

AES, 362

Blowfish, 359

DES, 359-361

RC4, 360

RC5, 360

Rijndael, 360-362

SAFER, 360

syn flooding, 403


administrators, 104

alternative system development

CBD, 220

cloud computing, 216-219

DOSD, 219

n-tier, 220-221

OOSD, 220

outsourcing, 214-215

virtualization, 221-222

WBAD, 220

analysts, 104

change procedures (project management), 252


parameters (data categories), 241

project management, 250-251

quality assurance, 250-251

SDLC, auditor’s role in, 249

copy software entries here, 186

performance monitoring

cloud providers, 318

flow analysis, 315

load balancing, 318

network analyzers, 316-317

network cabling, 320-322

network design, 318-319

SNMP, 315

utilization reports, 315-317

vendors, 318

Windows Performance Monitor, 315

wireless systems, 322-323

testing, 206


T-carriers, 314

table lookups (edit controls), 240


database tables, 241-242

memory tables, final exam preparation, 441-442

rainbow tables, 413

thunder tables, 413

tablets/smartphones, 302-303

TACACS (Terminal Access Control Access Control System), 346

tagging (application testing), 246

Taguchi process optimization technique, 122-125

tape backups, 166

tape librarians, 167

target values (performance management), 108

TCO (Total Cost of Ownership), ROI, 192

TCP (Transmission Control Protocol), 288, 295

TCP/IP reference model

application layer, 296-297

DHCP, 297

DNS, 297, 312


host-to-host/transport layer, 295

Internet layer

distance-vector protocols, 295

IP addressing, 293-294

link-state routing protocols, 295

routing protocols, 294-295

network access layer, 292-293

OSI model versus, 292

teams (project management), 188

technical controls (security controls)

cloud computing, 391

databases, 393-395

OS, 391-393

virtualization, 395-396

telecommunications recovery, 169-170

Telnet, 291, 347

tension wrenches, picking locks, 354

termination (separation events), 102-103

terrorists, incident/problem management, 420

TES (Terminal-Emulation Software), 291


ACID tests, 245

alpha testing, 207

application controls, 244, 248

applications, 246-249

backups, 167

BCP, 153-154

full operation tests, 156

paper tests, 155

preparedness tests, 155-156

beta testing, 207-209

black-box testing, 207, 409

bottom-up testing, 206

CISA tests

applying for certification, 8

CBT, 13

CPE, 16-18

credit tracking, 16-17

exam domains, 10-13

getting scores, 15

grading exams, 13

importance of certification, 4-5

intent of, 3-4

ISACA agreements, 9-10

maintaining certification, 16

mission statement, 3

passing, 9

Pearson Test Prep software, 437-442

popularity of, 5

question formats, 14-15

registering for exams, 7

requirements for, 6-8

retaking, 16

scheduling exams, 6

strategies for, 18-19

tips/tricks, 18-19

work experience waivers, 8

compliance tests, 39

final acceptance testing, 206

function testing, 207

integrated testing facilities

application testing, 246

continuous online auditing, 247

interface testing, 206

ITF, 52

parallel testing, 207

Pearson Test Prep software, 437, 442

customizing practice exams, 439-440

Flash Card Mode, 439

offline access, 438-439

online access, 438-439

Practice Exam Mode, 439

Premium Edition, 440

Study Mode, 439

updating practice exams, 440

website, 438

pilot testing, 207

practice tests

customizing, 439-440

Flash Card Mode, 439

Practice Exam Mode, 439

Study Mode, 439

updating, 440

project management, 251

regression testing, 207


penetration testing, 416-418

vulnerability scanning, 416

socialability testing, 207

substantive tests, 39, 45

system testing, 206

top-down testing, 206

UAT, 207-209

unit testing, 206

walk-through testing, 155

white-box testing, 207

text messaging, pretexting attacks, 400

third-party audits, 94-96, 126-127

third-party monitoring, 318

third-party outsourcing, 125-126, 214-215

third-party vendors, capacity planning, 318

threat analysis, ARO and BIA criticality analysis, 147

ThreatExpert, dynamic forensic analysis, 427


categorizing, 83

defining, 44, 83

identifying (ERM), 82-83

losses and, 83

risk management, defining, 44

vulnerabilities and, 83

Three Lines of Defense model (ERM), 87-89

thresholds (performance management), 109

thumb drives, data breaches, 375

thunder tables, 413

time, project management, 187, 192

critical tasks, planning, 198

scheduling tasks, 197-198

timebox management, project management, 199

TLS (Transport Layer Security), 348

TOCTOU (Time-Of-Check, Time-Of-Use) attacks, 411

Token Ring protocol, 293

tokenization, 219. See also encryption

tokens, authentication by, 338

tolerating risk (risk management), 45-47

top-down policy development (IT governance), 91

top-down testing, 206

total document numbers (batch controls), 238

total dollar amounts (batch controls), 238

total item counts (batch controls), 238

Tower of Hanoi backup rotation method, 168

traceroute, 290

tracing (application testing), 246

tracking changes, 418

traffic monitoring, add capacity planning entries, 316


BCP, 152-153

cloud computing, 218

employees, 101, 107

transaction files (data categories), 241

transaction logs, 106, 242

transaction selection (application testing), 246


data, 302

risk (risk management), 45

transmission controls (EDI), 254

transport layer (OSI reference model), 288

transport/host-to-host layer (TCP/IP reference model), 295

transportation teams (BCP), 154

trap door functions, public key encryption, 362

trap doors, 411

trend-detection tools, 414

Trojans, 405

tubular locks, 353

tumbler locks, 353

tunneling, 348

tuples (databases), 281

turnstiles (access control), 352

twisted-pair cabling, 321

two-factor authentication, 338


U.S. government laws/regulations

FACTA, 35, 120

FIPS, 37

FISMA, 35, 120

HIPAA, 35, 119

NIST, 37


SOX, 35, 119

UA (Uptime Agreements), 215

UAT (User Acceptance Testing), 207-209

Ubertooth, 406

UDP (User Datagram Protocol), 288, 295

unauthorized changes, information systems maintenance, 214

unicast addresses, 294

unit testing, 206

units (performance management), 108

unpatched systems, 378

unqualified opinions (audit reports), 58

unrated audit reports, 58

unsatisfactory audit reports, 58

unsecured devices, data breaches, 375-378

untied websites, 397

updating practice exams, 440

UPS (Uninterruptible Power Supplies), 171

USB drives, data breaches, 375

USB Killer, 375

USB ports (uncontrolled), data breaches, 377

USB Rubber Ducky, 376

user location systems. See somewhere you are systems


access control

authentication, 336-345

exterior security control, 349-356

Federation, 343-345

identification, 336

perimeter security control, 349-356

physical/environmental access control, 349-356

remote access, 345-348

SSH, 347

SSO, 340-342

Telnet, 347

BYOD policies, data breaches, 377-378

CRM, BI, 258

customer service (CRM), 259

identification as authorization control, 238

logic bombs, 411

security, 393

user accounts, 393

utility software, 277

utilization reports, capacity planning, 315-317


vacations (forced), 102, 107

validity checks (edit controls), 239

variable sampling, 52

variance-detection tools, 414

vaulting (electronic), 169

vendors. See also outsourcing

accountability, 95

auditing, 94-96

BPA, 215

capacity planning, 318

expectations of, 95

ISA, 215

MOU, 215

OLA, 215

outsourcing, 214-215

quality of, 95

relationship management, 129-130

RFP, 204

UA, 215

ventilation (data centers), 356


BCP tasks, 170

conformity, 39

disaster recovery tasks, 170

IP addresses, 290

key verification (edit controls), 240

passwords, 337

reasonableness verification (data integrity controls), 240

regulatory compliance, 38

virtual memory, 277

virtual servers, 221


application development, 221-222

authentication, 395

encryption, 395

fabric virtualization. See VSAN

physical controls, security, 395

remote access services, security, 396

resource access, security, 396

security, 395-396

servers, 395-396

technical controls (security controls), 395-396

VM escapes, 395

viruses, 405

VLAN (Virtual Local Area Networks), 304-305

VM (Virtual Machines), 221

data remanence, 222

escapes, 395

hardening, 395

live VM migration, 222

security, hardening, 395

voice communications

recovery, telecommunications recovery, 170

security controls

PBX systems, 357

phreakers, 356

VoIP, 357

VoIP (Voice over Internet Protocol), 295, 313, 357

VPN (Virtual Private Networks), 293, 347-348

VSAN (Virtual Storage Area Networks), 168


assessments, 210

defining, 83

OS vulnerability assessments, 393

scanning, 416

threats and, 83


WAF (Web Application Firewalls), 308, 393

walk-through testing, 155

WAN (Wide Area Networks), 284

circuit switching, 313-314

packet switching, 312-313

WAP (Wireless Access Points), 299, 305, 406-407

warded locks, 353

warehouses (data), 279

warm sites, disaster recovery planning, 161

WAYF (Where Are You From), SOA, 345

WBAD (Web-based Application Development), 220

WBS (Work Breakdown Structure), project management, 190

web pages, XSS attacks, 411


Basel III, 35

COOP websites, 172

COSO, 35




ISACA website

Code of Professional Ethics, 9-10

CPE policies, 16

credit tracking, 16-17

earning CPE hours, 17-18

ethics/standards/competency agreements, 9-10

getting CISA exam scores, 15

maintaining CISA certification, 16

My Certifications, 7, 15-17

registering for CISA exams, 7

reporting CPE hours earned, 16-17

laws/regulatory standards, 35

PCI standards, 35-36

Pearson IT Certification website, 438

Pearson Test Prep website, 438


security, 397

SOX, 35, 119

untied websites, 397

XSRF attacks, 411

WEP (Wired Equivalent Privacy), 299-301, 407

whaling, 400

white-box testing, 207


open Wi-Fi, data breaches, 377

pineapples, 376

Wigle, WAP security, 406

Windows Performance Monitor, 315

wireless networks, 406-407

wireless technologies

802.11 wireless standard, 299-301

Bluetooth, 298-299

BYOD policies, 302-303

DSSS, 300

encryption, 299

FHSS, 300

frequency bands, 301

hotspots, 302-303

MIMO, 301

MU-MIMO, 301

OFDM, 300

smartphones, 302-303

spreading codes, 300

SSID, 299

tablets, 302-303

WAP, 299

WEP, 299-301

wireless networking cards, 299

WPA, 299

Wireshark, 316, 400

WLAN (Wireless Local Area Networks), 299-301, 322

work experience waivers, CISA certification, 8

worms, 405

WP (Work Papers), 50

automated WP, 51

leveraging WP, 54

WPA (Wi-Fi Protected Access), 299, 407

WPA2 (Wi-Fi Protected Access 2), 407

WPAN (Wireless Personal Area Networks), 284

wrappers, 405

wrenches (tension), picking locks, 354

writing audit reports, 53-54

WRT (Work Recovery Time), BCP, 158

WS Security (Web Services Security), SOA, 344


X.25, 313

X.509 standard, PKI, 366

XML (Extensible Markup Language), SOA, 344

XP (Extreme Programming) development model, 213

XSRF (Cross-Site Request Forgery) attacks, 411

XSS (Cross-Site Scripting) attacks, 411


Zachman, John, 112

zero-day attacks, 404

