
Define auditing and the role of the auditor, analyze risk to determine risk burden, and examine internal controls to mitigate risk in the information systems audit process.
Explore the auditing process and the role of auditors, establishing a high-level framework so students understand who auditors are and how the process fits together.
Define audit and auditor, explain auditing of information systems for performance and compliance with standards such as HIPA and Sarbanes-Oxley, and emphasize CIA.
Explore the two auditor types—internal and external—and their independence, reporting lines, and on-demand versus scheduled audits, and learn how both can be used together for comprehensive information systems assurance.
Plan the auditing process thoroughly to map standards and marshal resources, ensuring a timely, efficient audit that yields quality information; execute after solid planning.
Balance short-term and long-term planning in audits, using short-term milestones to track progress toward long-term goals spanning five to fifteen years.
Identify new controls and upgrades to include in the audit planning, gather IT documentation, and define auditing techniques to ensure data-driven, goal-aligned, consistent evaluation.
Gather information from stakeholders to scope the audit, identify components, assess and analyze risk, review internal controls, and define the audit scope, objectives, auditing strategy, and required resources.
Explore risk analysis in topic b as the foundational framework for future lessons, defining what risk analysis is, how to perform it, and key considerations.
Define risk analysis as a technique to identify and assess risks that could threaten a process, then implement preventive or mitigating measures to reduce impact and probability.
Assess countermeasures in risk analysis with a cost-benefit analysis, weighing incident impact against management risk tolerance and applying controls such as least privilege and PCI compliance.
Identify risks through interviews and incident data during a risk assessment. Apply risk mitigation to align with tolerance, then reassess controls and loop back in a dynamic environment.
Identify threats and required controls through risk analysis to understand countermeasures such as firewall, permissions, and antivirus, and assess their effectiveness in keeping risk in a tolerable region.
Explore the basics of internal controls and align our understanding for future discussions. Establish a clear foundation for controls.
Identify and implement controls to minimize risk, reassess to keep risk within tolerance, and ensure controls address key business objectives while providing management assurance that risks are identified and addressed.
Explore preventative, corrective, and detective controls, with examples like firewalls and antivirus, lockable file cabinets, and intrusion detection systems to reduce risk and detect incidents.
Implement preventative controls like background checks, access control with identity verification, and prescribed policies and procedures to reduce risk before it arises.
Review detective controls by generating and reviewing reports, spotting anomalies in intrusion detection and firewall logs, and using a SIM system to coordinate logs and milestones to track security objectives.
Learn how internal controls use corrective controls, contingency planning, preventive controls, and detective controls to keep operations running after incidents, with emphasis on backups and testing.
Explore how internal controls govern accounting operations and day-to-day functions, including procedural or technical controls, to implement policy, ensure compliance, and protect assets against regulatory and legal risks.
Establish authentication, authorization, and accounting to enforce access control and track users, preserve data integrity, ensure availability through fault tolerance and backups, and govern changes via formal configuration management.
Identify and implement general control methods, including internal accounting, operational and administrative controls, and organizational security policies. Emphasize documentation, facility security considerations, and data center and it resource-specific controls.
Identify audit level and implement phases using a risk-based approach that prioritizes addressing risk and evidence, with Katz and CSA to be revisited in the IRS audit process.
Explore audit classifications by examining financial audits, integrated audits, and operational audits that assess financial aspects, system integration, and day-to-day controls and policies.
Identify administrative, information system, specialized, and forensic audit classifications, and their distinctive focus areas. Examine hippo requirement, random audits, and secure handling of health information.
Define the audit subject and objective, set the scope and mission parameters, keep the assessment focused, and proceed to pre-audit planning after agreement and sign-off.
navigate the audit process from pre-audit planning and data gathering to reporting, collecting logs and documents for fact finding, applying standard-based procedures, with a designated management contact and objective findings.
Identify inherent, control, and detection risks that can arise during audits, and understand how unobtrusive testing and deep digging may reveal audit risks within the process.
Gather data, plan the audit, evaluate internal controls, and perform compliance testing to verify standards are met; address risks by strengthening controls above minimum and testing system integration.
Explore forensic auditing and the handling of evidence, emphasizing the need for forensically trained professionals, rigorous procedures, objectivity, and timing to meet a higher standard.
Explore evidence gathering techniques through observations, documentation, interviews, and process reviews, with data sampling, statistics, and computer-assisted analysis to support third-party audits for objectivity.
Explore computer assisted audit with Cisco router tools like security device manager and wizards that automatically collect and report information, enabling centralized log bundles for analysis in a lab setting.
Apply control self-assessment as an ongoing process to analyze control documents and user interactions for early risk detection. Improve internal controls and support security awareness training for mission-critical controls.
Explore the auditing process and its components, and how technical, administrative, and physical controls strengthen security. Examine risk-based assessments, control self-assessments, and specialized audits.
Define and explore the role of governance, and understand how governance fits within an organization and your place in it. Examine policies, procedures, risk, information technology governance, and personnel management.
Explore the role of governance within organizations and how it guides and shapes key processes in information systems auditing.
Explore IT governance and information security governance, aligning IT and security goals with organizational objectives, guiding practices, and outlining the auditor's role in maintaining alignment.
Navigate the complexity of information technology governance by aligning mandates, standards, and regulations with business objectives, while building a diverse team to manage risk and deliver value per Isaka's definition.
Define governance as ethical behavior by directors to preserve the company and its wealth, including intellectual property, and distribute decision rights through structures like committees.
Explore how the governance structure aligns stakeholders, their strategic positioning, and key team members to deliver information technology value through information technology risk management, performance management, and security.
As an information systems auditor, participate in governance processes with varying roles and authority, requiring strong IT expertise, thoroughness, and clear reporting to add value.
An auditor offers recommendations to senior management, guides governance, and leads ongoing, scheduled monitoring with technology reports, ensuring clear documentation and compliance with internal and outside audits.
Align governance with enterprise goals to optimize operations, create a margin of safety, and manage finite IT and information security resources to reduce risk.
Report issues to senior management in a timely, clear manner and establish IT strategy and steering committees to guide enterprise information security changes, with testing and gradual rollout.
Guard corporate information assets by upholding CIA—confidentiality, integrity, and availability—through dedicated governance. Secure top-level sponsorship to gain legitimacy, resources, and a clear conduit to executive direction.
Clarify governance responsibilities for legal and regulatory exposure, ensure policy compliance, and maintain security during transition periods to reduce risk and ensure consistent protection of information.
Information governance forms the foundation for resource allocation and data-driven decision making, ensuring data is monitored, collected, and interpreted correctly.
Identify and report how security governance aligns business and organizational objectives, monitor risk management, optimize resource use, and communicate outcomes and gaps.
Define a strategic approach to security governance by developing policies, standards, and procedures, and establish a conflict-free security structure with effective monitoring and reporting.
Explore how policies, procedures, and risk form the administrative backbone of security and auditing, and learn how these elements come together to guide security and auditing practices.
Explore IT governance as alignment with organizational goals and build policies, procedures, and a risk management process. Learn enterprise-level risk analysis methods to accurately evaluate risk.
Define policy as a document of intent and security strategy that states an organization's philosophy, justification, and high-level goals, with subordinate policies aligned under a top-down framework and limited exceptions.
Reassess information security policies as the world changes, with COVID-19 remote work, VPNs, bring-your-own-device access, and ensure governance and procedures stay aligned.
Explore how to craft an information security policy document with clear definitions, scope, and objectives. Apply risk assessments and management references, and maintain consistent formatting with in line definitions.
Establish a regular review schedule for information security policies, such as every three months, and record last updated dates to ensure validity and avoid legal risk.
Review policy documents by gathering feedback on verbiage and changes, track results and compliance, examine WSAZ reports and incidents, and document changes with trend analysis using a document management system.
Improve the review with purposeful corrections, not changes for change's sake, and clearly separate concerns as questions for management seeking more information.
Procedures translate policy into action, detailing specific steps, routes, and stops. Auditors test procedures to ensure they still function as intended amid changing contexts.
Identify and apply risk management approaches: avoid, mitigate, transfer, accept, and eliminate, using examples like phishing awareness, antivirus, insurance, and compliance to reduce organizational risk.
Identify and classify risk types, assess threats and vulnerabilities, and conduct impact analyses to present an overall risk view. Actively manage existing and planned controls as risk evolves.
Explore IT risk management levels, from the operational level—day-to-day activities—to the project level during implementation, with the aim of moving initiatives to operations.
Explore IT governance through the lens of personnel, recognizing that people are the most important part of any system and influence decision making throughout the process.
Define personnel management and navigate insourcing and outsourcing decisions, including cloud services, risk-reward considerations, and controlled change management. Apply quality and performance management to maintain standards.
Implement robust personnel management by prioritizing training and education to reduce security and operational risk, justify training budgets, ensure coverage, and schedule vacations with regular evaluations.
Explore insourcing versus outsourcing for information systems, from historical in-house practices to modern cloud hosting. Understand security considerations and how hybrid models combine both approaches in contemporary organizations.
Align insourcing and outsourcing strategy with a steering committee to assess governance, risks, and impact on the environment, defining goals and mitigating risk for successful implementation.
Learn insourcing and outsourcing strategies, including a hybrid model, with careful contract review, service level agreements, and performance measures, plus awareness of globalization challenges and cross-border data issues.
Apply change management to govern proposed modifications by clarifying approval and execution roles and documenting rationale. Document what changed and why to support IT sponsorship and avoid undocumented shifts.
Explore change management with a focus on clear communication and trackable updates using tools like SharePoint. Involve appropriate team members, secure two-signature sign-offs, and assess financial and operational impact.
Explore how a quality management system, including ISO 9001, uses documents, manuals, and records to ensure an efficient, safe, secure, and stable end product while meeting organizational and legal standards.
Auditors assess quality management systems by checking implementation, documenting data per standards like ISO 9001, and ensuring performance measures align with defined formats for consistency across functions.
Quality management builds a predictable, stable environment that minimizes risk and sustains reliable performance, often achieving standard certification through audits. Use gap analyses against ISO standards to address missing requirements.
Explore how performance management uses metrics, baselines, and accountability to monitor information technology and information security. Learn to establish baselines, assign responsibility, collect and analyze data, and consider outsourcing.
Use built-in and third-party monitoring tools to collect data from logs and reports, supporting quality management by revealing organizational and technology performance, outages, and environment health.
Governance aligns information security and information technology programs with business goals through policies, risk evaluation, and personnel management, tailoring controls to specific environments and incorporating an extra set of eyeballs.
Operate, maintain, and support deployed systems while examining project management basics, software development and acquisition (in-house or third-party), and infrastructure development and acquisition for auditors.
Explore Topic A, project management, and learn how structure and processes shepherd multiple projects toward desirable, well-maintained outcomes.
Master the structure of project management to balance time, money, and people for a defined deliverable, then break work into manageable phases guided by a project charter.
Explore the project management structure from initiation and planning to coordination, execution, and closure, including cyclical upgrades and milestones to keep infrastructure projects on track.
Explore a project-centered organizational chart that supports governance with a steering committee, system development and user project committees, powered by power users and pilot feedback, plus security and support roles.
Align timeline, cost, and deliverables to meet project goals while considering scope and scale. Adjust resources, personnel, and budget as deadlines tighten or extend.
Apply a practical project management approach by following five phases—initiation, planning, managing, controlling, and closing—focusing on milestones, resources, and finishing the project with adaptable frameworks.
Explore the core elements of Topic B within project management, focusing on self-development, software development, and the acquisition of new software for use in your organization under audit.
Examine in-house software development, blending off-the-shelf components with tools like Visual Studio, SQL Server, or Oracle to build web and Android apps, within the systems development lifecycle and agile practices.
Identify common software development models like the Waterfall and V model within the SDLC. Understand how line of business applications drive data actions critical to business operations.
The traditional sdlc approach guides auditors through feasibility, requirements, design and selection, development, configuration, testing, deployment, and post-implementation maintenance, highlighting cost-benefit analysis and outsourcing risks.
Explore how the SDLC reduces software development risks by enforcing a defined process to meet user needs, track goals, plan, execute, review, and ensure data backups across units.
Explore alternative development methods beyond the waterfall model and examine newer software approaches that address evolving modern development challenges.
Explore alternative development methods and how they fit within the SDLC and the business application development and operation planning phase.
Agile development breaks tasks into bite-sized chunks, enabling nimble pivots and reprioritization as requirements change, with small, self-directed teams and just-in-time planning.
Use prototyping and evolutionary development to create a basic, operational model that proves feasibility, then adjust, add functionality, and evolve into a production-ready system.
Explore flexible prototyping approaches for information systems; build a core model or skeleton, then design, optimize, and polish the product, or progressively add features to meet the goal.
Leverage rapid application development (rad) through iterative prototyping and case tools to balance usability with functionality, delivering a finished product quickly with tight time management.
Rapid application development defines the concept, designs, develops, and deploys a product quickly, using high-level definition, modeling, pseudocode, real coding, and deployment.
Explore alternative development methods, including reverse engineering, and examine how breaking down existing software can reveal lessons to inform new product design within development standards.
Assess and vet infrastructure assets for line-of-business applications, including email servers, database servers, domain controllers, and web servers, through controlled acquisition to ensure secure, compatible integration within the ecosystem.
Analyze current infrastructure and set goals to bridge the gap through infrastructure development and acquisition of components, while reducing total cost of ownership via maintenance, training, and data conversion considerations.
Analyze the current network architecture using up-to-date documents, verify design accuracy, and avoid outdated references. Then reanalyze the architecture, draft functional requirements, prioritize them, and develop a proof of concept.
Plan the software implementation by evaluating sourcing options—buy off the shelf, in-house development, or in-house from third-party components and services—and then plan installation, testing, and security-conscious rollout to minimize disruption.
Identify hardware and software requirements shaping acquisition, including Windows compatibility, memory, storage, network, data protection, and constraints like mobility, adaptability, and virtualization for legacy applications.
Maintain information systems through rigorous change management and configuration controls, documenting change requests, testing, auditing, emergency changes, fast lane exemptions, and authorized versus unauthorized changes within policy.
Explore example change management standards, noting their names and publication dates, and understand how these references help address and catch changes in the information systems environment.
Examine change management standards in information systems auditing, compare familiar RC and change request approaches, and explore alternative viewpoints on implementing effective change management.
Explore how application controls safeguard data consistency, confidentiality, integrity, and availability across systems, ensuring data is properly edited, disclosed, and available when needed.
An information systems auditor analyzes information flow and control effectiveness by mapping data paths, identifying touchpoints and protections, documenting findings, and flagging deficiencies early for compliant and cost-effective improvements.
Enforce input controls and validation to ensure incoming data matches required formats before entering the system. Suppress detailed error messages in production to protect the system from exposure.
Apply data validation checks to verify ranges and lengths for fields like addresses and phone numbers, balance thoroughness with system performance, and ensure data meets accuracy requirements.
Explore examples in a database, perform table lookups, and search for duplicate entries to illustrate validation checks.
Explore output controls in information systems, leveraging real-time validation, logging, error handling, and digital signatures to ensure authentic, properly formatted data leaving the system.
Explore how project management aligns resources, timeframes, and goals to deliver compliant, auditable outcomes for information systems audits, then examine software development, acquisition, and deployment in distributed environments.
Examine network models and auditing concerns on the technical side, then focus on business resilience and continuity to keep operations running in a weakened state and recover from problems.
Explore networking models and why they matter, stepping back to put a face on them, understand how they fit in, and why they make a difference in information systems.
Explore networking models, focusing on the OCI model and its layers, and how an industry-wide, agreed framework improves system integration and interoperability.
Reference models define seven layers with responsibilities, establishing universal standards such as OCI to enable consistency, interoperability, and auditing and verification across hardware, software, and applications beyond the operating system.
Explore the osi model and how different parts of the network stack on client and server systems enable interoperable communication across networks, designed for reproducible interactions.
Examine how reliability relies on TCP within the IP stack and the TCP/IP suite, enabling verification that transmissions reach the remote recipient, as described by the OSA model.
Explore network infrastructure with a focus on how it supports a more resilient, stable, and secure organization while enabling the business, avoiding deep technical minutiae.
Explore the spectrum of network types from pan and wlan to lan, can, and wan; understand coverage, data movement, and access controls across local and wide area networks.
Distinguish physical wiring from logical data flow across bus, star, and ring topologies. Compare deterministic ring versus non deterministic, contention based bus and star networks, noting breaks and data flow.
Explore how VPNs enable remote access by encapsulating data for transmission over the internet, operate across layers 3 through 7, and support site-to-site connections with server and client components.
Explore IEEE 802 wireless standards, especially 802.11 wifi, their frequencies, speeds, and security features like WPA2. Learn how Bluetooth and Zigbee fall under 802.15 and WiMAX under 802.16.
Apply risk-reduction insights to business continuity and disaster recovery, ensuring a safety net for incidents; develop plans to restore operations and stop the bleeding when problems occur.
Learn how business continuity planning and disaster recovery safeguard operations after incidents, restore services to a minimal level, and apply recovery strategies and existing data to improve resilience.
Define business continuity planning and disaster recovery, prioritizing essential services to restore operations, and explain impact analysis and risk analysis with asset value, downtime costs, and qualitative versus quantitative assessments.
Craft policies that align with regulations for business continuity, perform a business impact analysis, classify operations by criticality, then write procedures, train, test, implement, monitor, and review policies.
Develop an incident classification scheme to quickly communicate severity, trigger escalation, and predefined criteria for major crises affecting systems or people, with clear guidelines for consistent understanding.
Conduct a business impact analysis by identifying potential incidents, gathering data via interviews, meetings, and questionnaires, consult subject matter experts, and prioritize risks to reinforce protection and resilience.
Examine MTD, RPO, and RTO to guide disaster recovery planning and business continuity. Analyze outage scenarios, backup timing, and data loss implications to set practical recovery limits.
Explore how recovery strategies blend preventive, corrective, and detective controls to prevent issues, reduce risk, and minimize impact, with examples like two-factor authentication and monitoring for aberrations.
Take a closer look at the recovery process in information systems, highlighting its steps and implications for auditors.
Identify and categorize core resources for business recovery, assessing how critical each asset is and the downtime threshold that causes negative impact, using risk analysis data.
Assess facilities, materials, and supplies after a disaster, identify damage, and plan alternate facilities and remote work to maintain operations.
Identify critical assets and maintain both digital and hard-copy documentation so information stays accessible during power outages, while transportation and logistics manage supporting equipment.
Understand data recovery after incidents, combining on-site and off-site backups, cloud copies, and recovery options like remote journaling, database shadowing, and standby services.
Explore disaster recovery techniques and their purpose within information systems auditing, linking technical methods to practical reasons for implementing recovery strategies.
Plan ahead for disasters by provisioning training, drills, and ready equipment; establish a formal disaster declaration process, assign responsibilities, and contract service level agreements with internal or external partners.
Identify and assemble the disaster recovery team with skills, equipment, and leadership from key stakeholders to support incident response.
Explore the key components of a business continuity plan, including continuity of ops, IT contingency, disaster recovery, and communication strategies, with mirrored infrastructure and post-mortem restoration.
Raid provides data protection against hard drive failures with quick recovery, not a failure guarantee, and can be implemented in software or hardware, including hot swapping, aiding disaster recovery planning.
Test the business continuity plan to reveal holes, adjust the plan, and verify interdepartmental coordination, using pretest, test, and post-test steps, and conduct regular audits.
Assess bcp/dr testing strategies from checklists to full interruption tests, showing how each method, including structured walkthroughs, simulations, and parallel testing, probes incident response and planning.
Assess the placement of the bcp/dr plan within the organization, identify key components, business processes, and documents to review, and verify compliance with legal and organizational requirements.
Explore organizations linked to disaster recovery, business continuity, and infrastructure, noting FEMA offers free online courses with certificates to demonstrate familiarity.
Explore how business continuity management uses industry-specific guidance from HIPA and broader regulatory guidance from bodies like FERC, and how to apply it to your organization.
Analyze network models, technical issues, and standards within the context of disasters to inform business continuity and disaster recovery planning, testing, and training for failure scenarios.
Protect information assets by applying protective measures and access restrictions to data, the organization's most valuable resource after people, across five focused topics.
Explore protecting data from a high-level perspective and outline what goes into data protection before examining related topics.
Gain practical insight into protecting information assets through senior management endorsement, clear policies, staff education, and ongoing compliance testing, monitoring, and incident response to keep business risk low.
Explore the key elements, roles, and responsibilities in information systems governance, including CIO, CISO, and the potential chief policy officer, and how large organizations delegate policy reviews to specialists.
Classify information assets by importance, business criticality, and cost of losing it or redevelopment to determine protection. Identify ownership, access rights, and documentation, then reclassify assets to safeguard them effectively.
Develop and manage system access by defining object interactions, enforcing physical and logical access across databases and applications, and building roles and permissions using existing organization roles where possible.
Explore threats and vulnerabilities and examine what they mean for information systems auditing in practice.
Explore four attack categories by comparing unstructured versus structured attacks and insider versus outsider origins, highlighting planning, impact, and response considerations for information systems auditing.
Explore examples of exposures and vulnerabilities, including asynchronous attacks, denial of service attacks, data leakage, logic bombs, piggybacking, and salami and rounding down attacks.
Explore exposures and vulnerabilities such as viruses, malware, trap doors, and backdoors, including hidden features that bypass security. Learn how anti-malware and awareness of phishing scams help mitigate these risks.
Map wireless networks with GPS to identify targets and exploit weak protections through war driving. Spreading worms across wireless networks causes performance degradation.
Identify how access control determines who accesses what, the level of interaction, and the required permissions, including view versus modify data files, across devices and mechanisms.
Identify how robust authentication protects access controls by moving from basic passwords to multi-factor authentication and single sign on, with auditing to detect weaknesses.
Explore strong password policy concepts, including longer passwords, alphanumeric and special characters, multi-factor authentication, periodic changes, password history, one password per user, and dual administrator accounts with credential elevation.
Learn how authentication proves identity rather than granting access, and how passwords, tokens, and biometrics work together, with encryption to protect password confidentiality and integrity in storage and transit.
Protect data at rest, in transit, and in use across storage, retrieval, transport, and disposal; use encryption, IPsec or VPN, and secure disposal methods.
Secure distributed client-server systems across cloud and local components by controlling USB ports, removing legacy drives, enforcing strong authentication, and scanning for rogue access points to protect data security.
Explore network level firewalls as gatekeepers between trusted zones such as internet and intranet. Understand how firewall generations—from packet filtering to application firewalls and unified threat management—balance functionality and performance.
Intrusion detection reveals attempts to intrude or exit your network, while intrusion prevention service (IPS) actively detects and stops attacks, requiring extra monitoring and tuning for accurate responses.
Honeypots act as decoys that lure attackers, attractive yet controlled, enabling detection, deflecting intrusions, and pulling security resources behind the wall.
Examine encryption in context, focusing on different types and modalities and the minutia auditors need to understand to verify encryption as part of a system's protective function.
Protect confidentiality and integrity with encryption, enable authentication and anti-replay protection, and secure data in transit, at rest, or during use, while noting its limits and export laws.
Explore how encryption mechanisms fit different scenarios, applying confidentiality algorithms and using hashing for data integrity, and combine with RSA digital signatures to verify origin.
Explore symmetric vs. asymmetric encryption, including key pairs and public/private keys, and why DES, triple DES, and RSA underpin confidentiality and authentication while pairing fast symmetric with slower asymmetric methods.
Delve into auditing practices and identify practical tools you can use, then connect how these elements fit into the overall information systems audit framework.
Select and apply an auditing framework; review administrative policies, legal requirements, security awareness training, onboarding and termination processes, access controls, and accountability across physical, technical, and administrative domains.
Audit logical access by evaluating how data is accessed through logical paths, assessing risks, controls, and security features, and reviewing IT environment familiarity.
Penetration testing uses the tools and techniques of attackers with permission to test defenses, report findings, and guide remediation, using black box, white box, or gray box approaches.
Apply a structured computer forensics process to uncover, gather, and analyze evidence after an incident, distinguishing courtroom from internal investigations and keeping the system on to preserve memory.
Examine recovery and data protection, encryption basics, access controls including multifactor methods, and auditing practices like pen testing and forensics to improve incident response and policy enforcement.
Information systems have become an integral part of any modern organization. Many of the business processes are now dependent on the information systems and the data contained in these systems is of critical importance to any enterprise. The need to protect and safeguard these systems is also directly proportional to the increase in their usage. With the information systems becoming so important, the attacks and threats including but not limited to ransomware, data theft, hacking, forgery and brute force are also on the rise. More and more attackers are targeting organization with less control and protection. This course prepares the candidates to put in place effective controls and policies to protect their information systems and assets from unauthorized access and leakage.
Information systems auditor course is a comprehensive course designed with the objective of preparing the candidates to be able to familiarize themselves with the IS audit process, governance, management of IT, IS operations, maintenance and support, IS operations and business resilience as well as protection of information assets.
These information systems or assets can be in the form of databases, files, images, documents and software. The course covers the protection methods and techniques regardless of the form the data is residing within the organization.
After successfully completing this course, the students will be able to:
· Understand the IS audit process
· Plan audit
· Perform risk analysis
· Put in place internal controls
· Learn about different phases of IS audit
· Understand the role of governance in IT/IS
· Make policies, procedures and identify risks
· Create information security policy document
· Conduct management reviews of the policy document
· Perform risk management
· Create in-sourcing and outsourcing strategy
· Perform organizational quality management
· Create project management structure
· Introduce application development best practices
· Plan IS operations and business resiliency plans
· Define RPO/RTO
· Develop disaster recovery plan
· Protect information assets
· Identify exposures and vulnerabilities
· Understand role of encryption in data protection
· Learn the basics of computer forensics
Overall, the course touches all the aspects required to become an effective information systems auditor and perform the taks efficiently. This course also helps the candidates to prepare for the relevant certification, i.e., CISA as the exam topics are in alignment with the concepts taught in this course.