
Master information system auditing from scratch, prep for the CSA exam on the first attempt, and gain real life experience in planning, conducting, and reporting, including internal and external audits.
Explore the value, prerequisites, renewal, exam process, and domain coverage for the certified information system auditor. Check isaka.org for details on the certification, eligibility, application, and computer-based testing.
Explore CISA course outline across domains: auditing process, IT governance and management, information system acquisition, development and implementation, operation and business resilience, and security, with templates, documents, and step-by-step guides.
Explore audit overview fundamentals, including purpose, scope, and documentation, and learn how ISMS and ISO 27001 audits are conducted with real reports and structured findings.
Define governance, risk, and compliance within the GRC framework, showing how IT investments support business objectives and how risk, threat, and vulnerability drive audits via COBIT, ITIL, CMMI, and FAIR.
Explore how governance, risk, and compliance translate into realistic workflows, contrast manual vs automated GRC practices, and preview tools like Archer from RCA, SAP, ACL, and SAI.
Learn the IT audit framework ITAF by Isaca, outlining general, performance, and reporting parts, with emphasis on proper audit processes, independence, risk assessment, evidence, and free download.
Follow a scenario-based audit of a software house providing mobile apps, mapping findings to departments—HR with finance, sales with marketing, IT with network and development—using applicable frameworks and regulations.
Learn to align audit findings with ISO 27001 and ISO 2000 standards by mapping controls to domains, validating readiness, and using attached control lists for real audits.
Identify the task and the knowledge statement to see how audits validate logs, the data center, and the database, and understand their mapping for exam questions.
Senior management drives business success by defining goals, understanding requirements and risk, and providing strategy, sponsorship, and budget, with policy, standards, guidelines, and procedures to support governments, risk, and compliance.
Senior management translates governance, risk, and compliance into policy, standards, guidelines, and procedures, then implements controls, audits, and dashboards to assess residual risk and confirm management success.
Understand the four-layer ISACA organization structure: senior management sets governance and policy; steering and committee approve projects and policies; audit checks controls; program management runs projects; IT supports the business.
Learn to conduct an information system audit using a risk-based strategy, craft an audit plan, perform the audit, and report findings with executive and detailed reports.
Review an IS audit report sample to see how observations, non-conformities, and evidence are documented. Learn how internal and external auditors use these reports.
Identify and audit the information asset register (IRR) as the inventory of all information assets, from documents and software to people, with owners, custodians, and confidentiality, integrity, and availability ratings.
Explore IT risk assessment, risk analysis, and risk-based audit to map threats to business objectives and information assets using probability and impact, and apply mitigation and other risk management techniques.
Apply PMI-based audit planning and management to identify subject and scope, plan resources and timeline, gather information, evaluate systems, and report with a clear communication plan.
Audit document control in an IRS engagement by tracking document IDs, owners, authors, issue dates, file types, classifications, and versioning, and ensure proper approvals and annual reviews.
Map the business process to IT by first understanding what the organization does, its external factors, strategy, objectives, and performance measures, then assess how IT supports critical functions.
Recognize that law and regulation govern information system audits and vary by country; tailor evidence, retention, and reporting to each jurisdiction, with Hepa and US financial audit law as examples.
Learn to collect reliable, objective evidence from independent, qualified sources using interviews, documentation review, data gathering, and sampling. Validate evidence with witnessed collection and signed minutes.
Explore how sampling relates to evidence and compliance, examine statistical and judgment sampling in auditing, and validate controls before sampling with population size, precision, and risk.
Master the CIA triad—confidentiality, integrity, and availability—and see how security governance aligns protection with business objectives. Embrace due care, due diligence, and NIST 830-aligned compliance while protecting PII.
Empower your organization with targeted security awareness and training that educates employees on threats, phishing, and social engineering, aligns with GDPR and HIPAA, and reinforces resilient on the job practices.
Establish and apply IT audit standards and guidelines to plan, assess risks, collect evidence, report findings, and follow up, aligning audits with COBIT, ITIL, ISO, and organizational governance.
Apply the risk management framework with six steps—categorize, select, implement, assess, authorize, and monitor information systems—to align security with risks, policies, contingency planning, ISO 27,001, and business continuity objectives.
Security documentation provides the blueprint for defining protocols, responsibilities, and expectations, guiding governance, ensuring regulatory compliance, and unifying efforts through policies, standards, and procedures.
Identify and assess cybersecurity risks using asset-based and service-based methodologies, calculate risk by impact and likelihood, and prioritize actions with risk registers and heat maps.
Identify assets, threats, vulnerabilities, and risks, then mitigate them through structured threat modeling using stride and other frameworks to build proactive, compliant security.
Explore how to build a resilient organization with a BCP and BIA, defining scope, policy and authority, roles, testing, and disaster recovery integration, plus metrics like RPO, RTO, and MTD.
Explore how a robust information security policy underpins an organization's security framework, detailing objectives, types, documents, components, and a practical template to guide implementation.
Align IT with business strategy to deliver secure, reliable information, manage risk, and support strategic objectives with accountability.
Master governance and management of IT and learn how to audit IT governance in any organization, covering 11 tasks and 16 knowledge statements to prepare for the exam.
Align information security governance with business strategy to ensure regulatory compliance, protect client information, and manage risk through policies, culture, and KPIs.
Explore information system strategy driven by a streaming committee and strategic planning, aligning projects and change requests with the strategic plan, mission, and business plan, plus IT state assessment.
Define an effective IT organization by clarifying roles and responsibilities, establishing a governance committee and PMO, applying a RACI chart, and implementing a change management process.
Learn the differences between policy, procedures, standards, guidelines, and baselines, and how to maintain and audit information security and acceptable user policies with annual reviews and user awareness.
Build a comprehensive information security documentation framework for the ISMS by studying policy, standards, guidelines, and procedures, and by using templates from sans.org to implement management-approved, high-level policies and baselines.
Explore legal compliance in outsourcing and cross-border data exchange. Implement segregation of duties and control, with compensating controls and code-change approvals to prevent fraud.
Audit the quality management system by evaluating quality assurance versus quality control, ensuring measurable process compliance and improvements, and understanding ISO 9001 certification and internal audits.
Identify the three maturity models—CMMi, the ideal model, and Pam model—and learn their benefits: avoid reinventing the wheel, measure processes, and reduce costs.
Define and audit process optimization in IT operations by measuring performance with tools like KPIs, CSFs, PDCA, Six Sigma, and benchmarking, and illustrate with e-services performance.
Audit IT investments to ensure value for money and right allocation, considering financial and non-financial costs, and apply value optimization by evaluating, ensuring, and monitoring value.
Audit the IT supplier selection process from make-or-buy decisions to fair supplier evaluation, using a waiting system beyond price, and verify contracts, NDAs, ongoing status reports, and proper contract closure.
Apply make or buy analysis to decide renting or buying project resources, and master plan procurement management, procurement statements of work, and source selection criteria using a weighting system.
Assess risk across the organization by identifying risks, ranking them by likelihood and impact, and applying qualitative and quantitative methods to build a risk register and heat map.
Explore how to conduct a business impact analysis to identify and prioritize critical functions, determine recovery time objectives, and build a plan using templates and standards for availability.
Explore how information system acquisition, development and implementation align with project management frameworks, covering business cases, risk, reviews, compliance, implementation readiness, and post-implementation review in IT projects.
Learn how project governance ensures IT projects follow the organization’s management methodology and fit into the company portfolio, with key notions of portfolio, project, and PMO.
Explore functional, matrix (weak, balanced, strong), and project-based organizations, clarifying project management office terminology while project managers navigate dual operational roles, dedicated teams, and cross-department communication with functional managers.
Explore the PMI and PMP project management framework, including five process groups, ten knowledge areas, and 47 processes, from the project charter and planning to monitoring, execution, and closing.
Audit the IT architecture through its life cycle—from analysis to implementation—by reviewing the current data center, planning with vendor evaluation and a proof of concept, and assessing hardware and software.
Analyze plan procurement management, create RFP and statement of work, and evaluate contract types while auditing vendor selection and applying procurement terminology and steps.
Plan procurement management covers make-or-buy analysis, deciding buy or rent options, and creating the procurement statement of work and source selection criteria with a weighting system.
This lecture outlines information system operations as the domain of daily audit activities, covering 11 tasks from service level and third-party management to backup, disaster recovery, and incident handling.
Learn the fundamentals of IT service management and service level management, covering ITSM concepts, SLA definitions, known error databases, service desk, incident and problem management, and proactive service improvement.
Audit hardware, software, and network by examining organization-specific risks across mainframe, client-server, and cloud setups; address shoulder surfing, insecure printing, usb data handling, and virus and patching practices.
Audit software licensing by verifying license evidence and copies in inventory, prevent unlicensed software across machines, and apply Microsoft licensing and open source licensing knowledge to ensure compliance.
Align current and future capacity planning across processing, storage, memory, and network with business needs. Maintain an annual, cost-effective capacity plan that is continuously tuned to business growth and constraints.
Define incident versus problem, and map the incident management lifecycle from capture and categorization to priority, resolution, and closure, including root-cause analysis using the fishbone diagram.
Explore incident management and incident reports, detailing what should be inside, including root cause, corrective and preventive actions, and document control, with sample templates.
Explore backup concepts for availability, including media options such as tape drives, remote storage, remote journaling backups, and electronic vaulting, plus full, differential, and incremental backups and restoration.
Explore disaster recovery plans as the technical arm of business continuity, detailing risk, cost-benefit, and short-, mid-, and long-term priorities, with backup types like mirroring and full, incremental, differential backups.
Learn about alternative sites for business continuity, including hot site mirroring, warm, cold, portable sites, and mutual aid agreements, plus recovery and salvage teams restoring operations after a disaster.
Audit protection of information assets by examining information security policy, security awareness, data classification, incident handling, physical access, environmental controls, and data storage and backup aligned with the CIA triad.
Learn how access control integrates identification, authentication, authorization, logging, and accounting across technical, physical, and administrative security, with models like discretionary and mandatory access control, and role-based and time-based approaches.
Explore network architecture from hubs to switches, ARP vulnerabilities, and MAC address tables, then learn how routers use routing tables and dynamic protocols like rip and ospf.
Practice cryptography basics with Cryptool, explore the Caesar cipher through substitution and transposition, and understand that encryption provides confidentiality and integrity—but not availability, with public protocols and secret keys.
Explore physical security design by selecting fences, doors, and access controls; balance guards, intrusion detection, logs, and surveillance, with emphasis on personal safety and facility design.
Identify information assets and build an asset register with owner and custodian, apply classification levels and labeling (public, confidential, restricted) under policy and privacy laws.
Explore how law, regulation, and frameworks drive information security through policies and documentation. Learn to implement security policies, templates, and a policy framework in real-world organizations.
Are you preparing for the CISA exam and looking for a structured, exam-focused course that covers every domain?
The Certified Information Systems Auditor (CISA) is one of the most recognized credentials in IT auditing, governance, and security. Earning it can open doors to senior roles in audit, compliance, and information security — and this course is designed to help you get there.
What you will get:
Complete coverage of all 5 CISA exam domains
Real-world audit scenarios that reinforce every concept
Domain-by-domain practice questions for self-assessment
Content covering all CISA exam topics, updated for 2026
No prior experience required — structured from the ground up
This is an independent preparation course, not affiliated with or endorsed by ISACA.
Domain 1 – Information System Auditing Process
Audit planning, risk-based audit execution, evidence collection, sampling techniques, IT audit standards, professional ethics, and audit reporting.
Domain 2 – Governance and Management of IT
IT governance frameworks, strategic alignment, legal and regulatory compliance, business impact analysis, maturity models, and IT investment management.
Domain 3 – Information Systems Acquisition, Development and Implementation
Project governance, procurement management, SDLC, system architecture, and make-or-buy decisions.
Domain 4 – Information Systems Operations and Business Resilience
Incident and service level management, hardware and software operations, backup strategies, disaster recovery planning, and alternative site strategies.
Domain 5 – Protection of Information Assets
Access control frameworks, network security, cryptography, physical security controls, and data classification practices.
Who this course is for:
IT professionals transitioning into auditing, compliance, or GRC roles
Aspiring IT auditors preparing for the CISA exam
Security professionals looking to formalize their audit knowledge
Compliance officers seeking a structured understanding of IS auditing
Enroll now and take the next step toward your CISA certification.