
Explore governance concepts across corporate, IT, and information security governance, and examine enterprise architecture, risk management, process maturity, outsourcing, and performance management for CISA domain 2 readiness.
Explore the Udemy review system, understand how ratings influence buyer decisions, and learn to leave constructive comments that guide improvements and content revisits.
Explore corporate governance and its link to IT governance, the roles of board and CEO, stakeholder interests, and auditing to ensure effective governance.
Understand how governance aligns IT with business goals, enhances performance, and manages risk through regulatory compliance, internal controls, and strategic IT investments in governance frameworks.
Define information security governance through a security strategy aligned with business objectives, supported by policies, procedures, standards, and a clear organization structure with monitoring for compliance and return of investment.
Explore how information technology frameworks provide guidelines for establishing information technology infrastructure and implementing information security controls to achieve business goals.
Assess policy ownership and approval, ensure policies address identified information technology risks, and verify effective implementation through training and staff awareness to mitigate information security risk.
Learn how governance hinges on board and senior management involvement, with emphasis on IT steering committees, risk control, and information security policy implementation.
Explore the roles in an IT department, from system and security administrators to data owners, custodians, and auditors, and learn how data classification, access controls, and SOC operations protect information.
Audit IT governance by identifying red flags such as budget overruns, high staff turnover, bribery, and security risks, and by reviewing IT strategy plans, organization charts, and change management documentation.
Explore enterprise architecture as a framework that aligns business, data, application, IT, and security perspectives to improve interoperability and guide changes across the organization.
Explore enterprise risk management by defining risk as threat multiplied by likelihood, evaluating threats and vulnerabilities, performing cost benefit analysis, and selecting safeguards to align residual risk with risk appetite.
Explore risk analysis in information security, valuing assets, assessing threats, and calculating single loss expectancy and annualized loss expectancy, while comparing quantitative, qualitative, and semiquantitative methods.
Explain the capability maturity model and the ideal model for process improvement, covering maturity levels from no planning to continuous optimization and initiating, diagnosing, establishing, acting, and learning phases.
Explore how human resource management governs information security through hiring, onboarding, and termination practices, including background checks, confidentiality agreements, non-disclosure agreements, non-compete clauses, and access control.
Explore insourced, outsourced, and hybrid IT service models, including onsite, nearshore, offsite, and offshore arrangements. Understand how service level agreements, audits, and accountability govern outsourced vendor relationships.
Establish critical processes, define measurable outputs, and set targets using pdca cycles to monitor performance, optimize service delivery, and align governance with business goals.
This course is the Second part of five-part video series where I will help you understand the Second domain of the CISA syllabus which is IT Governance. Here we will include the following topics:
1. Concept of corporate governance, IT governance, Information security governance
2. Information Technology Framework
3. Audit IT governance
4. Roles and responsibilities in IT Governance and IT department
5. Enterprise Architecture
6. Enterprise Risk Management and Risk Analysis
7. Process Maturity Cycle
8. Human Resource Management
9. Outsourcing IT services
10. IT performance Optimization and Performance Management
We are building concepts that we learned in First Part. The first and this second part is the foundation for CISA exam. You can safely assume that majority of the questions asked in the exam will have some relation to these domains.
This course discusses how organizational structure affects the overall risk of the organization and other various components relating to IT Governance.
My job here is to make you understand all the concepts and ideas which will help you become a good IT auditor. Having said that, this course should not be treated as a substitute of the CISA Review Manual. But, after taking this course, it will be very easy for you to understand the CISA Review Manual.
I have arranged this course in such a way that you understand IT audit is required in examining the impact of technology on business processes, where a major linkage between business risk and technology risk is becoming stronger. So in this course, I will help you to increase your understanding of the business process and other areas so that you can increase the quality of your work. My aim is not only to help you to pass the exam but also to guide you to apply this knowledge in real life.
My other objective in this course is to change your perspective. Many auditors focus too much on technical tasks, completely ignoring the overall business goals. You need to perform the consultative function for senior management and the
board of directors (BoD) advising them on mitigating information security risks in achieving organizational goals.
I have designed this course in such a way that it is suitable for all people from various backgrounds. You may be a non-auditor, with zero IT background, internal auditor, external auditor, IT consultant, project manager, or any cybersecurity professional. I will provide you with relevant examples, personal experience, and other valuable resources that will help you to pass this certification.
So, are you ready to continue your journey to become IT Auditor? Then, I hope to see you in this course.