Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Information Systems Auditor
Rating: 4.3 out of 5(98 ratings)
488 students

Information Systems Auditor

All about Audit
Last updated 4/2022
English
English [Auto],

What you'll learn

  • Understand the IS audit process
  • Plan audit and Perform risk analysis
  • Learn about different phases of IS audit
  • Understand the role of governance in IT/IS
  • Make policies, procedures and identify risks
  • Create information security policy document
  • Conduct management reviews of the policy document
  • Create insourcing and outsourcing strategy

Course content

5 sections184 lectures10h 6m total length
  • The IS Audit Process1:52

    Define auditing and the role of the auditor, analyze risk to determine risk burden, and examine internal controls to mitigate risk in the information systems audit process.

  • Topic A: The Auditing Process and Auditors0:41

    Explore the auditing process and the role of auditors, establishing a high-level framework so students understand who auditors are and how the process fits together.

  • Definitions4:46

    Define audit and auditor, explain auditing of information systems for performance and compliance with standards such as HIPA and Sarbanes-Oxley, and emphasize CIA.

  • Types of Auditors5:33

    Explore the two auditor types—internal and external—and their independence, reporting lines, and on-demand versus scheduled audits, and learn how both can be used together for comprehensive information systems assurance.

  • The Auditing Process1:46

    Plan the auditing process thoroughly to map standards and marshal resources, ensuring a timely, efficient audit that yields quality information; execute after solid planning.

  • The Auditing Process2:05

    Balance short-term and long-term planning in audits, using short-term milestones to track progress toward long-term goals spanning five to fifteen years.

  • The Auditing Process4:15

    Identify new controls and upgrades to include in the audit planning, gather IT documentation, and define auditing techniques to ensure data-driven, goal-aligned, consistent evaluation.

  • Audit Planning Process12:58

    Gather information from stakeholders to scope the audit, identify components, assess and analyze risk, review internal controls, and define the audit scope, objectives, auditing strategy, and required resources.

  • Topic B: Risk Analysis0:50

    Explore risk analysis in topic b as the foundational framework for future lessons, defining what risk analysis is, how to perform it, and key considerations.

  • Risk Analysis Defined9:30

    Define risk analysis as a technique to identify and assess risks that could threaten a process, then implement preventive or mitigating measures to reduce impact and probability.

  • Assessing Countermeasures14:28

    Assess countermeasures in risk analysis with a cost-benefit analysis, weighing incident impact against management risk tolerance and applying controls such as least privilege and PCI compliance.

  • Steps of Assessment2:18

    Identify risks through interviews and incident data during a risk assessment. Apply risk mitigation to align with tolerance, then reassess controls and loop back in a dynamic environment.

  • Motivations for Risk Analysis2:59

    Identify threats and required controls through risk analysis to understand countermeasures such as firewall, permissions, and antivirus, and assess their effectiveness in keeping risk in a tolerable region.

  • Topic C: Internal Controls0:44

    Explore the basics of internal controls and align our understanding for future discussions. Establish a clear foundation for controls.

  • Internal Controls: Objectives & Procedures6:25

    Identify and implement controls to minimize risk, reassess to keep risk within tolerance, and ensure controls address key business objectives while providing management assurance that risks are identified and addressed.

  • Internal Control Types5:28

    Explore preventative, corrective, and detective controls, with examples like firewalls and antivirus, lockable file cabinets, and intrusion detection systems to reduce risk and detect incidents.

  • Internal Controls (Preventative)0:47

    Implement preventative controls like background checks, access control with identity verification, and prescribed policies and procedures to reduce risk before it arises.

  • Internal Controls (Detective)1:09

    Review detective controls by generating and reviewing reports, spotting anomalies in intrusion detection and firewall logs, and using a SIM system to coordinate logs and milestones to track security objectives.

  • Internal Controls (Corrective)3:30

    Learn how internal controls use corrective controls, contingency planning, preventive controls, and detective controls to keep operations running after incidents, with emphasis on backups and testing.

  • Goals of Internal Controls1:09

    Explore how internal controls govern accounting operations and day-to-day functions, including procedural or technical controls, to implement policy, ensure compliance, and protect assets against regulatory and legal risks.

  • Goals of Internal Controls2:10

    Establish authentication, authorization, and accounting to enforce access control and track users, preserve data integrity, ensure availability through fault tolerance and backups, and govern changes via formal configuration management.

  • General Control Methods/Types2:41

    Identify and implement general control methods, including internal accounting, operational and administrative controls, and organizational security policies. Emphasize documentation, facility security considerations, and data center and it resource-specific controls.

  • The IS Audit Process1:26

    Identify audit level and implement phases using a risk-based approach that prioritizes addressing risk and evidence, with Katz and CSA to be revisited in the IRS audit process.

  • Audit Classifications0:47

    Explore audit classifications by examining financial audits, integrated audits, and operational audits that assess financial aspects, system integration, and day-to-day controls and policies.

  • Audit Classifications4:51

    Identify administrative, information system, specialized, and forensic audit classifications, and their distinctive focus areas. Examine hippo requirement, random audits, and secure handling of health information.

  • Phases of the Audit Process (Page 1)0:58

    Define the audit subject and objective, set the scope and mission parameters, keep the assessment focused, and proceed to pre-audit planning after agreement and sign-off.

  • Phases of the Audit Process (Page 2)4:05

    navigate the audit process from pre-audit planning and data gathering to reporting, collecting logs and documents for fact finding, applying standard-based procedures, with a designated management contact and objective findings.

  • Inherent Risks During Audits0:57

    Identify inherent, control, and detection risks that can arise during audits, and understand how unobtrusive testing and deep digging may reveal audit risks within the process.

  • A Risk-Based Audit Approach1:46

    Gather data, plan the audit, evaluate internal controls, and perform compliance testing to verify standards are met; address risks by strengthening controls above minimum and testing system integration.

  • Evidence1:58

    Explore forensic auditing and the handling of evidence, emphasizing the need for forensically trained professionals, rigorous procedures, objectivity, and timing to meet a higher standard.

  • Evidence Gathering Techniques1:04

    Explore evidence gathering techniques through observations, documentation, interviews, and process reviews, with data sampling, statistics, and computer-assisted analysis to support third-party audits for objectivity.

  • Computer Assisted Audit0:39

    Explore computer assisted audit with Cisco router tools like security device manager and wizards that automatically collect and report information, enabling centralized log bundles for analysis in a lab setting.

  • Control Self-Assessment (CSA)1:14

    Apply control self-assessment as an ongoing process to analyze control documents and user interactions for early risk detection. Improve internal controls and support security awareness training for mission-critical controls.

  • Chapter 1 Review1:47

    Explore the auditing process and its components, and how technical, administrative, and physical controls strengthen security. Examine risk-based assessments, control self-assessments, and specialized audits.

  • Quiz 1

Requirements

  • It is expected that the candidates taking part in this course have a basic know-how of the information security management, business critical information, cyber security, data loss protection and other technologies.
  • However, this course comprehensively covers the topics related to information systems auditing and policy making.

Description

Information systems have become an integral part of any modern organization. Many of the business processes are now dependent on the information systems and the data contained in these systems is of critical importance to any enterprise. The need to protect and safeguard these systems is also directly proportional to the increase in their usage. With the information systems becoming so important, the attacks and threats including but not limited to ransomware, data theft, hacking, forgery and brute force are also on the rise. More and more attackers are targeting organization with less control and protection. This course prepares the candidates to put in place effective controls and policies to protect their information systems and assets from unauthorized access and leakage.

Information systems auditor course is a comprehensive course designed with the objective of preparing the candidates to be able to familiarize themselves with the IS audit process, governance, management of IT, IS operations, maintenance and support, IS operations and business resilience as well as protection of information assets.

These information systems or assets can be in the form of databases, files, images, documents and software. The course covers the protection methods and techniques regardless of the form the data is residing within the organization.

After successfully completing this course, the students will be able to:

· Understand the IS audit process

· Plan audit

· Perform risk analysis

· Put in place internal controls

· Learn about different phases of IS audit

· Understand the role of governance in IT/IS

· Make policies, procedures and identify risks

· Create information security policy document

· Conduct management reviews of the policy document

· Perform risk management

· Create in-sourcing and outsourcing strategy

· Perform organizational quality management

· Create project management structure

· Introduce application development best practices

· Plan IS operations and business resiliency plans

· Define RPO/RTO

· Develop disaster recovery plan

· Protect information assets

· Identify exposures and vulnerabilities

· Understand role of encryption in data protection

· Learn the basics of computer forensics

Overall, the course touches all the aspects required to become an effective information systems auditor and perform the taks efficiently. This course also helps the candidates to prepare for the relevant certification, i.e., CISA as the exam topics are in alignment with the concepts taught in this course.

Who this course is for:

  • Information systems auditors
  • Chief information security officers
  • Manager information security
  • Manager cyber security
  • Information system managers
  • Candidates aspiring for CISA certification