Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Technology Systems Auditing
Rating: 4.0 out of 5(19 ratings)
66 students

Technology Systems Auditing

Technology Systems Auditing Training Course
Last updated 6/2021
English
English [Auto],

What you'll learn

  • Understand the IS audit process
  • Plan audit and Perform risk analysis
  • Put in place internal controls
  • Learn about different phases of IS audit
  • Understand the role of governance in IT/IS
  • Make policies, procedures and identify risks
  • Create information security policy document
  • Conduct management reviews of the policy document
  • Perform risk management
  • Create insourcing and outsourcing strategy
  • Perform organizational quality management
  • Create project management structure
  • Introduce application development best practices
  • Plan IS operations and business resiliency plans
  • Define RPO/RTO
  • Develop disaster recovery plan
  • Protect information assets
  • Identify exposures and vulnerabilities
  • Understand role of encryption in data protection
  • Learn the basics of computer forensics

Course content

5 sections183 lectures10h 5m total length
  • The IS Audit Process1:52

    Explore the information system audit process, defining auditing and the auditor, mastering risk analysis, and examining internal controls and countermeasures to manage risk effectively.

  • Topic A: The Auditing Process and Auditors0:41

    Introduce the auditing process and the role of auditors, establishing a high-level framework to connect upcoming topics in technology systems auditing.

  • Definitions4:46

    Define audit and auditor, explaining their role in checking information systems for efficacy and compliance with industry standards, including CIA in EDP audits.

  • Types of Auditors5:33

    Compare internal and external auditors, their independence, and how reporting to the board or C-level management ensures clear, actionable audits; use both on demand and annually or semiannually.

  • The Auditing Process (1)1:46

    Plan the audit by mapping out tasks, applicable standards, and resources to ensure timely, efficient execution and high-quality information.

  • The Auditing Process (2)2:05

    Define planning in technology systems auditing by distinguishing short-term and long-term horizons, using milestones and progress checks to align quarterly, yearly, or multi-year goals with ongoing audits.

  • The Auditing Process (3)4:15

    Develop a planning process for audits by identifying new controls, changes and upgrades, and assess their data-driven impact on organizational goals using established techniques.

  • Audit Planning Process12:58

    Gather information from stakeholders to define the audit scope and components, and assess risk. Define objectives, craft an auditing strategy, and allocate essential resources like time and budget.

  • Topic B: Risk Analysis0:50

    Explore topic b as a foundational look at risk analysis, learn what risk analysis is, how to perform it, and the key considerations for future lessons.

  • Risk Analysis Defined9:30

    Identify and assess factors that threaten a process or goal using risk analysis techniques. Evaluate threats, impact, and probability to guide mitigation and recommendations.

  • Assessing Countermeasures14:28

    Conduct a cost-benefit analysis of countermeasures during risk assessment, weighing impact, probability, and risk tolerance to guide compliance-aware mitigation decisions.

  • Steps of Assessment2:18

    Perform a thorough risk assessment by interviewing stakeholders and reviewing incident data to identify risks, then mitigate to tolerance and reassess to verify controls.

  • Motivations for Risk Analysis2:59

    Identify threats and countermeasures through risk analysis, determine if existing controls keep risk in a tolerable range, and adjust audit scope as risk evolves to guide defense in depth.

  • Topic C: Internal Controls0:44

    Explore the basics of internal controls and align on what controls are trying to accomplish within technology systems.

  • Internal Controls: Objectives & Procedures6:25

    Identify and implement internal controls and procedures to reduce risk and provide assurance to management. Align these controls with key business and operational objectives to protect the organization.

  • Internal Control Types5:28

    Identify three control types—preventative, corrective, and detective—that reduce risk, fix deficiencies, or detect incidents, with examples like firewalls, locking file cabinets, and intrusion detection systems.

  • Internal Controls (Preventative)0:47

    Explore preventive controls such as background checks, access control, and policies and procedures to hire safely, enforce prescribed, tested methods, and minimize risk.

  • Internal Controls (Detective)1:09

    Detective controls rely on generated reports and reviews of intrusion detection logs, firewall logs, coordinated by a SIM system, to detect anomalies and use milestones as checkpoints to ensure progress.

  • Internal Controls (Corrective)3:30

    Learn how corrective controls, contingency planning, and backups safeguard operations, with preventive and detective controls and testing as key tools to detect deficiencies and keep systems running.

  • Goals of Internal Controls1:09

    Technology systems auditing course explains how internal controls govern accounting operations and day-to-day functions, using procedural or technical controls, enforcing policy, protecting assets, and addressing compliance and legal issues.

  • Goals of Internal Controls2:10

    Implement authentication, authorization, and accounting to enforce access control. Preserve data integrity with acceptable input and output formats, fault tolerance, backups, and documented change management.

  • General Control Methods/Types2:41

    Explore common control methods for technology systems auditing, including internal accounting, operational checks, administrative policies, organizational security policies, careful documentation, and facilities considerations for data centers and IT resources.

  • The IS Audit Process1:26

    Outline the information systems audit process by identifying scope and level, implementing audit phases, and applying a risk-based approach focused on evidence to address risk rather than compliance.

  • Audit Classifications0:47

    Explore audit classifications, including financial audits focusing on financial aspects, integrated audits examining how a system fits together, and operational audits evaluating day-to-day controls and procedures.

  • Audit Classifications4:51

    Explore audit classifications—administrative, information system, specialized, and forensic—and see how specialized health audits protect patient information and ensure accurate case evaluations.

  • Phases of the Audit Process (Page 1)0:58

    Identify the audit subject and define the objective to determine what you are assessing. Set the scope and mission parameters, stay within the targeted area, and plan after sign-off.

  • Phases of the Audit Process (Page 2)4:05

    Gather data through planning and fact-finding, then sift and evaluate logs and documents to form findings. Prepare a report with findings, tests, and recommendations, and present it to management.

  • Inherent Risks During Audits0:57

    Identify inherent risks during audits, including inherent risk, control risk, and detection risk, and recognize how unobtrusive testing can still expose new risks.

  • A Risk-Based Audit Approach1:46

    This lecture outlines a risk-based audit approach: gather data, evaluate internal controls, and perform compliance testing against standards, with a focus on raising controls above minimum and testing system integration.

  • Evidence1:58

    Collect evidence reliably in a forensic audit by qualified, forensically trained personnel following strict procedures. Maintain objectivity, document timing, and avoid subjective conclusions to ensure admissible results.

  • Evidence Gathering Techniques1:04

    Gather evidence through observations, documentation review, interviews, and process examination. Use sampling, random samples, and statistics to identify trends and support objective analysis, with third-party auditors and computational tools.

  • Computer Assisted Audit0:39

    Explore computer assisted auditing with tools like security device manager and wizard-driven data collection, which pull logs from diverse sources into a single bundle for analysis and reporting.

  • Control Self-Assessment (CSA)1:14

    Perform targeted control self-assessments to monitor mission-critical internal controls, analyze control documents, capture user interactions for early detection, and strengthen controls while informing security awareness training.

  • Chapter 1 Review1:47

    Assess the auditing process and its role in evaluating an environment, identify internal controls, which are technical, administrative, or physical, and explore risk-based and control self-assessment types.

  • Quiz 1

Requirements

  • It is expected that the candidates taking part in this course have a basic know-how of the information security management, business critical information, cyber security, data loss protection and other technologies. However, this course comprehensively covers the topics related to information systems auditing and policy making.

Description

Information systems have become a crucial component of modern organizations, with many business processes relying heavily on these systems. The data contained within these systems is critical for any enterprise's operations. As the usage of information systems grows, so does the need to protect and secure them. With this increased reliance, the risks of cyberattacks and security threats—such as ransomware, data theft, hacking, forgery, and brute-force attacks—are also on the rise. Attackers are increasingly targeting organizations with inadequate control and protection mechanisms. This course equips candidates with the knowledge and tools necessary to implement effective controls and policies to safeguard their information systems and assets from unauthorized access and data breaches.

The Information Systems Auditor course is a comprehensive program designed to familiarize candidates with the IS audit process, governance, IT management, and the maintenance and support of information systems. It covers key aspects such as business resilience and the protection of information assets. These assets can take various forms, including databases, files, documents, images, and software. The course emphasizes techniques and methods for protecting data, regardless of its format within the organization.

The course covers all essential areas required to become an effective information systems auditor, providing participants with the skills and knowledge to perform audits efficiently. Additionally, the course serves as valuable preparation for relevant certifications, enhancing candidates’ professional qualifications in the field of information systems auditing.

Who this course is for:

  • Information systems auditors
  • Chief information security officers
  • Manager information security
  • Manager cyber security
  • Information system managers
  • Candidates aspiring for CISA certification