
Audit and monitor system activity by enabling automated logs of file versions, program access to sensitive data, OS operations, and database monitoring to support performance, capacity planning, and security.
Database management systems are software that organize data for applications, reduce redundancy, and support access control through fields defined by a data dictionary in a relational database management system.
Determine LAN technology by assessing applications, such as voice over IP, to ensure low latency and crystal-clear calls, while evaluating bandwidth, coverage area, physical constraints, budget, and security needs.
Explore wide area networks that connect local area networks. Observe how layers 1–3 support simplex to full duplex flows, and note shift to ethernet services replacing frame relay.
Overview of the wireless application protocol, a multilayered set of technologies that brings internet content to wireless mobile devices, with examples like the PDA.
Explore the recovery point objective and recovery time objective, defining acceptable data loss and downtime, and note how tighter time requirements raise recovery costs.
Explore data storage disaster recovery methods focusing on raid, the redundant array of independent disks, which protects against hardware failure using two or more disks and emphasizes documenting the approach.
Develop disaster recovery procedures, including declaration criteria, plant activation linked to overarching plans, and recovery team roles with notification lists. Outline step-by-step recovery processes and vendor contacts for replacement hardware.
Assess information system operations maintenance and support to meet service level expectations, derive objectives from business goals, and ensure hardware, networks, communication paths, protocols, and operating systems integrity.
Download Supporting files here
Clarify and establish defined and documented security management roles and responsibilities, then communicate them to all relevant personnel and management to ensure accountability.
Enforce security before granting customer access by establishing justification and authorization, and ongoing monitoring of internal assets; protect assets with vulnerability management and incident reporting, and allow revocation of access.
Identify and secure points of entry to front-end or back-end systems to control access from an organization's networking or telecommunications infrastructure into information resources, including network connectivity and remote access.
Consolidate users into a single architecture to enable a single sign-on, reducing password management and cross-server logins, but raising cross-platform deployment costs and a potential single point of failure.
Define authorization as what you can do, driven by access rules that specify who can access what. Set file-level permissions like read, write, create, update, delete, and execute.
Examine centralized and decentralized logical access security administration, highlighting onsite management and timely incident response in locations. Consider risks from local branch standards diverging from headquarters and gaps in audits.
Explore common firewall attacks, including IP spoofing and fragment attacks, that bypass packet filters with spoofed source addresses. Understand source routing and legacy IP routing behavior.
Learn how encryption turns plain text into ciphertext to protect data in transit and at rest, hashing detects changes, authenticates data, and algorithms and key length influence security.
This lecture shows how encryption protects e-commerce, detailing ssl/tls, ipsec for vpn, secure email, and set for card processing, while stressing that security rests on key randomness and length.
Private branch exchange enables digital phone networks, routing voice like voip with a network, switch, hubs, and cables, separate from data network and facing theft of service and unauthorized access.
Audit network infrastructure security by mapping connectivity with diagrams, identifying designs, IP naming and subnet schemes, and evaluating security policies, SLAs, and upgrade procedures for vulnerabilities.
Audit remote access by testing connections, analyzing risks, and ensuring cost-effective, risk-based controls. Inspect email outside the local area network, marketing channels, and e-commerce to identify security risks.
Explore computer forensics to identify, preserve, analyze, and present digital evidence in legally acceptable ways, maintain chain of custody, secure originals, and apply inventory, indexing, and analysis techniques.
Assess and assure that policies, standards, procedures, and controls protect information assets by ensuring confidentiality, integrity, and availability, while evaluating data classifications, physical access, and storage, transport, and disposal processes.
The Technology Systems Auditing course has become the industry standard for the IT auditing, control and security. The course helps the students to gain relevant, up-to-date and concise knowledge along with hands-on practice exams.
If you’re a professional with experience of participating, leading and directing information system projects, this IT Systems Auditing course will help you prepare for a lucrative and highly sought after position in this exciting and challenging field of information technology.
Completing this course showcases your knowledge of IS auditing, and demonstrates you are capable to assess vulnerabilities, report on compliance and institute controls within an enterprise. After completing this training course you will be able to leverage standards, manage vulnerabilities, you will understand ensure compliance, offer solutions, institute controls and deliver value to an enterprise, and the acquisition process and testing process.
IT Systems Auditing is one of the most popular and high-demand IT employment options available. The course offers the ability for students to gain comprehensive knowledge in concepts that are required to get into the field of IT Systems Auditing.
Get your start in the world of IT Systems Auditing by taking this course today. Part 2 of this course is also available to complete your education.
This course is in no way sponsored or endorsed by, or in any way affiliated with, ISACA.
** This course is in 2 parts. Please purchase Part 1 as well for complete course.**