BIA

A Business Impact Analysis (BIA) identifies critical processes and the impact of their disruption to prioritize recovery. CISA uses the BIA to derive recovery objectives such as RTO and RPO for resilience planning.

All CISA Terms

IS Audit

IS Audit is the formal, independent examination of information systems, controls, and processes to assess whether they safeguard assets, maintain integrity, and meet objectives.

Audit Evidence

Audit Evidence is the information an auditor gathers — through inspection, observation, inquiry, and reperformance — to support audit conclusions.

Sampling

Sampling is testing a subset of a population to draw conclusions about the whole, using statistical or judgmental methods.

Control Self-Assessment

Control Self-Assessment (CSA) is a process in which business process owners themselves evaluate the effectiveness of their controls.

Internal Control

An Internal Control is a policy, procedure, or mechanism that reduces risk and provides reasonable assurance that objectives are met.

IT Governance

IT Governance is the framework of leadership, structures, and processes that ensures IT sustains and extends the organization's strategy and objectives.

Segregation of Duties

Segregation of Duties (SoD) divides critical tasks among different people so no single individual can both perpetrate and conceal an error or fraud.

SDLC

The System Development Life Cycle (SDLC) is the structured process for acquiring, developing, and implementing information systems.

Change Management

Change Management is the controlled process for requesting, approving, testing, and deploying changes to systems.

Post-Implementation Review

A Post-Implementation Review evaluates a completed system against its objectives, budget, and expected benefits after go-live.

BIA

A Business Impact Analysis (BIA) identifies critical processes and the impact of their disruption to prioritize recovery.

RTO and RPO

RTO and RPO are recovery objectives: Recovery Time Objective is the target time to restore a process, and Recovery Point Objective is the maximum tolerable data loss measured in time.

Disaster Recovery

Disaster Recovery is the set of plans and capabilities for restoring IT systems and data after a disruptive event.

Identity and Access Management

Identity and Access Management (IAM) governs how identities are provisioned and what resources they may access, enforcing least privilege.

Encryption

Encryption transforms readable data into ciphertext reversible only with a key, protecting confidentiality in storage and transit.