Security Governance & Audit
ISACA CISA: Testing Access Controls in an Audit
Access-control audits fail when they treat identity as a list of accounts instead of a lifecycle of authorization decisions. An effective test asks who received access, why it was granted, how privileges changed as responsibilities changed, what technical enforcement exists, and whether the organization can remove access when the business justification ends. The current CISA scope places identity and access management within protection of information assets while audit execution includes sampling, evidence collection, analytics, and reporting. Within security governance, those disciplines come together in a test that connects entitlement data…
ISACA CISA: Reporting Audit Findings Clearly
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISACA CISA: IT Audit Scoping That Finds Real Risk
Audit scoping is where much of an engagement’s value is decided. A scope that is too broad produces shallow checklist coverage, while a scope that is too narrow can miss the dependency or control boundary where the material risk actually sits. Risk-based scoping creates a defensible connection between business objectives, technology, threats, control history, and the work the audit team will perform. Within Security Governance & Assurance, scoping should begin with the outcome the organization needs to protect. Systems, cloud accounts, vendors, applications, data stores, identities, and operational processes are…
ISACA CISA: Evidence Quality in IT Audits
An audit conclusion is only as strong as the evidence supporting it. Large quantities of screenshots, exported reports, policy documents, and interview notes can create the appearance of rigor while still failing to prove that a control operated as described across the relevant period and population. Within Security Governance & Assurance, evidence quality depends on relevance, reliability, completeness, timing, source, and the relationship between the artifact and the audit objective. The auditor should know what claim each piece of evidence supports and what uncertainty remains after reviewing it. Good evidence…
ISACA CISA: Auditing Cloud Environments
Cloud audits are difficult when reviewers treat the cloud as either someone else’s infrastructure or a long list of provider settings. The audit has to connect the provider’s control environment with the customer’s architecture, identity model, data handling, configuration, monitoring, and resilience responsibilities. Within Security Governance & Assurance, the first task is to identify the business services and data that depend on the cloud environment. Only then can the auditor decide which shared-responsibility boundaries, technical controls, provider attestations, and operational practices are relevant to the risk being assessed. A useful…
ISACA CISA: Auditing Change Management
Change management is designed to let organizations modify production systems without turning every release into an uncontrolled experiment. An audit therefore needs to evaluate more than whether a request was logged. It should test whether changes are authorized, assessed, implemented, reviewed, and recoverable in a way that preserves business service objectives. Within Security Governance & Assurance, change is a control chain that connects governance, development, operations, incident response, and business ownership. A technically successful deployment can still represent a control failure if it bypassed approval, lacked testing, or introduced risk…
ISC2 CISSP: Software Supply Chain Risk for CISSPs
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISC2 CISSP: Security Models Beyond Memorization
Security models matter when they help engineers and leaders reason about what information is allowed to flow, which subject may act on which object, and what property the system is trying to preserve. Memorizing labels such as Bell-LaPadula or Biba without understanding the problem each model addresses misses their practical value. The models are abstractions that make security assumptions explicit. The current CISSP exam outline includes fundamental security models in Security Architecture and Engineering, alongside secure design principles and system security requirements. Within Security Governance & Assurance, the useful question…
ISC2 CISSP: Security Leadership Across Eight Domains
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISC2 CISSP: Privacy Engineering for Security Leaders
Privacy engineering for security leaders turns privacy requirements into technical and operational decisions that can be implemented, tested, and monitored. Privacy and security overlap, but they are not identical. A system can be well protected from attackers and still collect too much data, retain it too long, use it for an unexpected purpose, or make it difficult to honor an individual’s rights. The current CISSP exam outline includes privacy-related legal and regulatory issues, data lifecycle, data roles, privacy by design, and security controls. Within Security Governance & Assurance, privacy engineering…
ISC2 CISSP: Physical Security in Hybrid Workplaces
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISC2 CISSP: Cryptographic Key Management at Scale
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISC2 CISSP: Business Continuity Without Paper Plans
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on terminology, responsibilities, tradeoffs, governance, and review questions.Use it as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISACA CISM: Security Governance That Drives Decisions
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.
ISACA CISM: Risk Appetite and Security Priorities
This certification-study article presents a concise conceptual overview for readers who need context before consulting implementation documentation. It is intentionally non-procedural and focuses on understanding terminology, responsibilities, tradeoffs, and review questions.Use the article as an orientation point for study, architecture discussion, governance, and operational planning. Product-specific configuration and execution details should be taken from the relevant vendor documentation and organizational standards.