Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Technology Systems Auditing (Part 1 of 2)
Highest Rated
Rating: 4.6 out of 5(1,306 ratings)
6,401 students

Technology Systems Auditing (Part 1 of 2)

Technology Systems Auditing Training Course
Last updated 5/2021
English
English [Auto],

What you'll learn

  • IT audit process
  • IT governance
  • Systems and infrastructure lifecycle management
  • IT service delivery and support
  • Protection of information assets
  • Business continuity and disaster recovery

Course content

4 sections533 lectures11h 8m total length
  • Introduction1:51

    Download Supporting files here

  • Lesson 1: Management of the Audit Function1:40
  • Organization of the IS Audit Function3:12
  • IS Audit Resource Management1:05

    Manage audits by ensuring resource planning and keeping auditors technically competent through targeted training on new techniques and technology updates, as Sacca standards require.

  • Audit Planning Part11:08
  • Audit Planning Part21:48
  • Audit Planning Part31:32

    Gather essential information about the auditing environment, including interrelated data centers, their purposes and resilience, and document business practices, information systems, technologies, and regulatory requirements.

  • Audit Planning Part41:07

    Auditors align with professional standards by addressing audit objectives through a plan that links the organization's objectives to its technology infrastructure and IT architecture, guided by future directions.

  • Audit Planning Part52:01
  • Effect of Laws and Regulations on IS Audit Planning Part12:17
  • Effect of Laws and Regulations on IS Audit Planning Part20:56
  • Effect of Laws and Regulations on IS Audit Planning Part30:41
  • Effect of Laws and Regulations on IS Audit Planning Part40:45
  • Lesson 2: ISACA IT Audit and Assurance Standards and Guidelines Part12:02
  • IT Audit and Assurance Standards and Guidelines Part23:25
  • IT Audit and Assurance Standards and Guidelines Part30:41
  • IT Audit and Assurance Standards and Guidelines Part40:36
  • IT Audit And Assurance Standards Framework1:18
  • Auditing Standards Part11:53
  • Auditing Standards Part21:05

    Auditors maintain and update their skills to conduct audits professionally, applying planning to cover audit objectives and laws, and document timing and required resources.

  • Auditing Standards Part32:45

    Explore auditing standards that emphasize supervision, reliable evidence, and documentation to support audit findings and conclusions.

  • Auditing Standards Part40:28
  • Auditing Standards Part51:58
  • Auditing Standards Part61:25
  • Auditing Standards Part72:00
  • Auditing Standards Part80:41

    Assess outside work for qualifications and competencies, determine if it is adequate or incomplete, and document the review results as part of the evaluation process to support the audit.

  • Auditing Standards Part91:05

    Evaluate audit evidence sufficiency and internal IP controls, with auditors advising on control design; apply risk assessment to e-commerce to ensure properly controlled transactions.

  • Audit Guidelines Part10:33
  • Audit Guidelines Part21:07
  • Audit Guidelines Part31:38
  • Audit Guidelines Part43:07
  • Audit Guidelines Part51:57
  • Audit Guidelines Part61:28
  • Audit Guidelines Part71:41
  • Audit Guidelines Part81:58
  • Audit Guidelines Part91:57
  • Audit Guidelines Part101:31

    Audit guidelines cover B2C e-commerce, internet banking, VPN usage, IPsec, and mobile computing, guiding post-implementation review to verify the adoption of prior audit recommendations.

  • Audit Guidelines Part111:56
  • Audit Guidelines Part122:02

    Apply guidelines to evaluate IT organizations' efficiency, security management practices, and return on security investment, and implement continuous assurance through ongoing recommendations after audits.

  • Audit and Assurance Tools and Techniques0:45
  • Relationship Among Standards, Guidelines, and Tools and Techniques1:29
  • Information Technology Assurance Framework0:26

    Explore the information technology assurance framework (ITA) as a good-practice model guiding design, conduct, and reporting, while defining terms and establishing standards for the information technology audit and assurance profession.

  • Information Technology Assurance Framework Components2:23

    Explore the information technology assurance framework components, including standards, guidelines, and tools, and learn how planning, risk, and reporting drive IT audits.

  • ITAF General Standards (Section 2200) Part11:27

    Learn the Itaf section 2200 general standards, emphasizing independence and objectivity in IT assurance, and how auditors retain training, proficiency, knowledge, due care, and suitable criteria with management's acknowledgment.

  • ITAF General Standards (Section 2200) Part21:21
  • ITAF Performance Standards (Section 2400) Part13:02
  • ITAF Performance Standards (Section 2400) Part22:02
  • ITAF Performance Standards (Section 2400) Part30:33
  • ITAF Performance Standards (Section 2400) Part41:10
  • Reporting Standards (Section 2600) Part10:21
  • Reporting Standards (Section 2600) Part20:51
  • Reporting Standards (Section 2600) Part30:54

    Identify the reporting criteria, weigh subject matter, and state the level of assurance while noting any distribution reservations and the importance of auditor signatures as verification before issuance.

  • IT Assurance Guidelines (Section 3000) Part11:15

    Apply TAFE guidelines across section 3000's four areas: enterprise topics, IT management processes, IT audit and assurance processes, and IT assurance management, and learn planning, scoping, execution, and reporting.

  • IT Assurance Guidelines (Section 3000) Part20:51
  • IT Assurance Guidelines (Section 3000) Part31:30
  • IT Assurance Guidelines (Section 3000) Part41:31
  • IT Assurance Guidelines (Section 3000) Part52:06
  • IT Assurance Guidelines (Section 3000) Part60:20
  • IT Assurance Guidelines (Section 3000) Part71:22

    Explore how IT assurance guidelines integrate with other audit activities and guide the audit of general controls and application controls to plan comprehensive technology audits.

  • IT Assurance Guidelines (Section 3000) Part82:11
  • IT Assurance Guidelines (Section 3000) Part90:45
  • IT Assurance Guidelines (Section 3000) Part101:58
  • IT Assurance Guidelines (Section 3000) Part111:40
  • Lesson 3: Risk Analysis0:40

    Identify risks and vulnerabilities through risk analysis and plan controls to mitigate them, including common business risks and related technology risks. Reduce risk in the audit process through risk-control relationships.

  • Risk Analysis Part14:21
  • Risk Analysis Part23:06
  • Risk Analysis Part32:32
  • Risk Analysis Part41:26
  • Risk Analysis Part51:31

    Apply a risk assessment lifecycle by identifying business objectives and the important information assets, such as a customer database, and focus on systems that generate, store, and manipulate that information.

  • Risk Analysis Part64:10
  • Risk Analysis Part73:31

    Map business objectives to crucial assets, perform risk assessments, apply controls, and drive risk treatment in a risk lifecycle for audits and assurance.

  • Lesson 4: Internal Controls1:31

    Identify internal controls as written policies guiding practices and linking to physical controls, delivering assurance to meet business objectives while minimizing risk by clarifying what should be achieved and avoided.

  • Internal Control Objectives1:05
  • IS Control Objectives Part12:34
  • IS Control Objectives Part21:19
  • IS Control Objectives Part32:06

    Identify users and enforce authorization and authentication while ensuring accountability, operational efficiency, and policy compliance, and establish business continuity, disaster recovery, and incident response plans for various incidents.

  • COBIT0:35
  • General Controls Part10:48
  • General Controls Part23:23
  • IS Controls3:40

    Design and implement information system controls for sensitive functions, including access to data and programs, change control and methodologies, physical security, operations procedures, and business continuity and disaster recovery.

  • Lesson 5: Performing An IS Audit2:40
  • Performing an IS Audit1:08
  • Classification of Audits2:32
  • Audit Programs Part11:07
  • Audit Programs Part22:56
  • Audit Methodology Part13:02
  • Audit Methodology Part21:54
  • Audit Methodology Part31:26
  • Fraud Detection Part13:25

    Identify irregularities and signs of fraud by evaluating internal controls for failures, misconfigurations, or tampering, including unusual firewall rules and policy changes, and understand mandatory fraud disclosures to regulators.

  • Fraud Detection Part22:13

    Spot opportunities for fraud, acknowledging that internal controls do not eliminate it. Report findings to management and authorities and consider legal requirements when controls may be exploited.

  • Risk-Based Auditing Part11:12
  • Risk-Based Auditing Part20:53

    Identify inherent, control, and detection risks and assess internal and operational controls to reduce them, then apply cost-benefit analysis to decide which controls best mitigate known risks.

  • Risk-Based Auditing Part30:57
  • Audit Risk and Materiality Part11:11

    Apply a risk model assessment to identify and weight risks by likelihood and impact, prioritizing assets at greatest risk. Use weight-based ratings to emphasize significant threats and asset protection.

  • Audit Risk and Materiality Part21:18

    Explore audit risk and materiality, identifying inherent, control, and detection risks. Learn how their combination shapes overall audit risk and the possibility of undetected material errors.

  • Audit Risk and Materiality Part31:36
  • Audit Risk and Materiality Part41:05
  • Audit Risk and Materiality Part50:23
  • Risk Assessment and Treatment Part10:39
  • Risk Assessment and Treatment Part20:56

    Perform risk assessments as a systematic analysis that compares estimated risks against criteria to determine significance before audit planning, and repeat when the environment changes, including new equipment.

  • Risk Assessment and Treatment Part31:57
  • Risk Assessment and Treatment Part41:46
  • Risk Assessment and Treatment Part50:45
  • Risk Assessment Techniques Part12:04
  • Risk Assessment Techniques Part20:47
  • Risk Assessment Techniques Part30:18
  • Risk Assessment Techniques Part40:39
  • Audit Objectives Part11:06

    Define and translate broad goals into specific audit objectives that guide the audit plan. Verify internal controls exist to minimize business risks and function as required.

  • Audit Objectives Part20:40

    Translate general audit objectives into specific control objectives and map each control to a defined objective that supports the overall risk reduction in an information systems audit.

  • Compliance Versus Substantive Testing Part11:09
  • Compliance Versus Substantive Testing Part20:35
  • Compliance Versus Substantive Testing Part30:31
  • Evidence Part10:58
  • Evidence Part21:57
  • Evidence Part31:13

    Gather evidence from diverse locations, including policies, procedures, standards, and documentation. Interview personnel, observe performance, and walk through processes to compare practice with established procedures and compliance.

  • Interviewing and Observing Personnel in the Performance Of Their Duties1:09
  • Sampling Part11:21
  • Sampling Part22:19
  • Sampling Part31:56
  • Using The Services Of Other Auditors And Experts Part12:04
  • Using The Services Of Other Auditors And Experts Part20:30

    Recognize that using outside auditors does not absolve you of liability; communicate objectives, scope, and methodology, monitor ongoing reviews, and assess the usefulness of external results.

  • Computer-Assisted Audit Techniques (CAAT) Part10:43
  • Computer-Assisted Audit Techniques (CAAT) Part20:24

    Explore how CAAT software reads and accesses data across multiple database platforms, performing data selection, file organization, and statistical and mathematical functions for database auditing.

  • Evaluation Of Audit Strengths And Weaknesses Part10:48

    Review audit evidence to confirm that operations are well-controlled and effective, and use a control matrix to map errors to appropriate detection and correction controls.

  • Evaluation Of Audit Strengths And Weaknesses Part22:02
  • Evaluation Of Audit Strengths And Weaknesses Part30:57
  • Communicating Audit Results Part10:40

    Conduct exit interviews to capture facts for the audit report, verify accuracy, and present findings. Propose realistic, cost-effective recommendations with clear implementation dates.

  • Communicating Audit Results Part21:26
  • Communicating Audit Results Part30:25
  • Management Implementation Of Recommendations0:21
  • Audit Documentation1:15
  • Lesson 6: Control Self-Assessment Part10:50

    Apply control self-assessment to review objectives, risks, and internal controls, providing ongoing monitoring that reassures stakeholders about the organization’s reliability.

  • Control Self-Assessment Part21:12

    Explore how control self-assessment gathers information through questionnaires, workshops, and interviews with day-to-day staff, and apply CSA across technical, financial, or operational projects to mitigate risk and protect assets.

  • Control Self-Assessment Part31:38
  • Objectives of CSA1:19
  • Benefits of CSA0:56

    Leverage CSA for early risk detection through monitoring, strengthening internal controls and fostering ownership and awareness. Improve communication between operations and management, and reduce control costs while boosting stakeholder confidence.

  • Disadvantages of CSA0:37

    Self-assessment carries disadvantages, and it is not a replacement for an audit function. It can create extra work, lower morale, and hinder detecting weak controls.

  • Auditor Role in CSA1:21
  • Technology Drivers for CSA1:07

    Empower participants to gather information and participate in decision making, using feedback to improve processes and controls. Emphasize group decision making in workshop-based CSA to sustain morale and engagement.

  • Traditional Versus CSA Approach0:36
  • Lesson 7: The Evolving IS Audit Process0:09
  • Automated Work Papers Part11:20

    Automated work papers streamline reports, risk analysis, and evidence gathering; verify results for accuracy and use standard audit work paper packages as a supplement.

  • Automated Work Papers Part21:22
  • Integrated Auditing Part11:32

    Explore integrated auditing, blending audit disciplines to assess internal controls, infrastructure access, and business processes, using risk analysis and collaborative discussion among audit teams.

  • Integrated Auditing Part20:38
  • Integrated Auditing Part30:24
  • Continuous Auditing Part10:41
  • Continuous Auditing Part21:02

    Differentiate continuous auditing from continuous monitoring and show how automated procedures safeguard assets to meet fiduciary responsibilities, with independent auditors providing written assurances and excluding continuous monitoring results from audits.

  • Continuous Auditing Part30:48
  • Continuous Auditing Part42:12

    Continuous auditing applies to highly automated processes, enabling log observation and real-time anomaly detection during occurrences or alarms, and quickly informs auditors of results.

  • Continuous Auditing Part50:46
  • Module 01 Review1:37

    Master the domain processing of auditing information systems, from planning to reporting, and implement a risk-based IT audit strategy aligned with standards.

  • Module 01 - Quiz

Requirements

  • The course requires the candidates to have systems administration experience, familiarity with networking fundamentals such as TCP/IP, and an understanding of UNIX, Linux, and Windows operating systems.
  • This is an advanced level course and requires the students to have basic concepts and knowledge of the IT security and a minimum of 3-5 years practical experience.

Description

The IT Systems Auditing course has become the industry standard for the IT auditing, control and security. The course helps the students to gain relevant, up-to-date and concise knowledge along with hands-on practice exams.

If you’re a professional with experience of participating, leading and directing information system projects, this online IT Systems Auditing course will help you prepare for a lucrative and highly sought after position in this exciting and challenging field of information technology.

Completing this course showcases your knowledge of IS auditing, and demonstrates you are capable to assess vulnerabilities, report on compliance and institute controls within an enterprise. After completing this training course you will be able to leverage standards, manage vulnerabilities, you will understand ensure compliance, offer solutions, institute controls and deliver value to an enterprise, and the Acquisition process and testing process.

IT Systems Auditing is one of the most popular and high-demand IT employment options available. The course offers the ability for students to gain comprehensive knowledge in concepts that are required to get into the field of IT Systems Auditing.

Get your start in the world of IT Systems Auditing by taking this course today. Part 2 of this course is also available to complete your education.

This course is in no way sponsored or endorsed by, or in any way affiliated with, ISACA.


Who this course is for:

  • IT audit, control, assurance, and security professionals
  • IT consultants, auditors, and managers
  • Security policy writers
  • Privacy officers
  • Information security officers
  • Network and system administrators
  • Network security engineers