Certificate
Course Outline
Domain 1—The Process of Auditing Information Systems (14%)
Deliver audit services in compliance with IT audit standards to help the organization protect and control its information systems.
- 1.1 Develop and implement a risk-based IT audit strategy compliant with IT audit standards to ensure key areas are covered.
- 1.2 Plan specific audits to determine if information systems are protected, controlled, and delivering value to the organization.
- 1.3 Conduct audits in accordance with IT audit standards to achieve planned objectives.
- 1.4 Report audit findings and provide recommendations to key stakeholders to communicate results and drive necessary changes.
- 1.5 Perform follow-ups or prepare status reports to ensure management has taken appropriate actions in a timely manner.
Domain 2—Governance and Management of IT (14%)
Assure that adequate leadership, organizational structure, and processes are in place to achieve objectives and support the organization's strategy.
- 2.1 Assess the effectiveness of the IT governance structure to ensure IT decisions, directions, and performance align with organizational strategies and objectives.
- 2.2 Evaluate the IT organizational structure and human resources management to determine alignment with organizational strategies and objectives.
- 2.3 Assess the IT strategy, including direction, and the processes for development, approval, implementation, and maintenance to ensure alignment with organizational strategies and objectives.
- 2.4 Review the organization’s IT policies, standards, and procedures, along with their development, approval, implementation, maintenance, and monitoring processes, to ensure support for the IT strategy and compliance with regulatory and legal requirements.
- 2.5 Assess the adequacy of the quality management system to determine if it supports organizational strategies and objectives cost-effectively.
- 2.6 Evaluate IT management and control monitoring (e.g., continuous monitoring, QA) for compliance with the organization’s policies, standards, and procedures.
- 2.7 Review IT resource investment, usage, and allocation practices, including prioritization criteria, to ensure alignment with organizational strategies and objectives.
- 2.8 Assess IT contracting strategies, policies, and contract management practices to determine support for organizational strategies and objectives.
- 2.9 Evaluate risk management practices to determine if the organization’s IT-related risks are properly managed.
- 2.10 Review monitoring and assurance practices to ensure the board and executive management receive sufficient and timely information on IT performance.
- 2.11 Assess the organization’s business continuity plan to determine its ability to maintain essential business operations during an IT disruption.
Domain 3—Information Systems Acquisition, Development, and Implementation (19%)
Assure that practices for acquiring, developing, testing, and implementing information systems meet organizational strategies and objectives.
- 3.1 Evaluate the business case for proposed investments in information system acquisition, development, maintenance, and retirement to ensure alignment with business objectives.
- 3.2 Assess project management practices and controls to determine if business requirements are met cost-effectively while managing organizational risks.
- 3.3 Conduct reviews to verify that projects progress according to plans, are adequately documented, and have accurate status reporting.
- 3.4 Evaluate controls during the requirements, acquisition, development, and testing phases for compliance with organizational policies, standards, procedures, and external requirements.
- 3.5 Assess information system readiness for implementation and migration into production to ensure project deliverables, controls, and organizational requirements are met.
- 3.6 Conduct post-implementation reviews to determine if project deliverables, controls, and organizational requirements have been satisfied.
Domain 4—Information Systems Operations, Maintenance and Support (23%)
Assure that processes for information systems operations, maintenance, and support align with organizational strategies and objectives.
- 4.1 Perform periodic reviews of information systems to ensure they continue to meet organizational objectives.
- 4.2 Assess service level management practices to determine if service levels from internal and external providers are defined and managed appropriately.
- 4.3 Evaluate third-party management practices to ensure providers adhere to the control levels expected by the organization.
- 4.4 Review operations and end-user procedures to determine if scheduled and unscheduled processes are managed to completion.
- 4.5 Assess information systems maintenance processes to ensure they are effectively controlled and continue to support organizational objectives.
- 4.6 Evaluate data administration practices to determine database integrity and optimization.
- 4.7 Assess the use of capacity and performance monitoring tools and techniques to verify that IT services meet organizational objectives.
- 4.8 Review problem and incident management practices to ensure incidents, problems, or errors are recorded, analyzed, and resolved promptly.
- 4.9 Evaluate change, configuration, and release management practices to determine if scheduled and unscheduled changes to the production environment are adequately controlled and documented.
- 4.10 Assess backup and restore provisions to determine the availability of information required to resume processing.
- 4.11 Evaluate the organization’s disaster recovery plan to ensure it enables the recovery of IT processing capabilities following a disaster.
Domain 5—Protection of Information Assets (30%)
Assure that the organization’s security policies, standards, procedures, and controls ensure the confidentiality, integrity, and availability of information assets.
- 5.1 Evaluate information security policies, standards, and procedures for completeness and alignment with generally accepted practices.
- 5.2 Assess the design, implementation, and monitoring of system and logical security controls to verify the confidentiality, integrity, and availability of information.
- 5.3 Evaluate the design, implementation, and monitoring of data classification processes and procedures for alignment with organizational policies, standards, procedures, and applicable external requirements.
- 5.4 Assess the design, implementation, and monitoring of physical access and environmental controls to determine if information assets are adequately safeguarded.
- 5.5 Review processes and procedures for storing, retrieving, transporting, and disposing of information assets (e.g., backup media, offsite storage, hard copy/print data, softcopy media) to ensure adequate safeguarding.
Requirements
There are no formal prerequisites for enrolling in this course. However, ISACA requires a minimum of five years of professional work experience in information systems auditing, control, or security to qualify for full certification. Candidates may take the CISA exam before meeting these experience requirements, but the official CISA designation is granted only after the experience criteria are fulfilled. Our trainers recommend that delegates clear the CISA exam as early in their career as possible to establish a foundation in globally accepted IT auditing practices.
Testimonials (2)
Being approachable and pushing us into interaction
Daniel - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
The way to receive the information from the trainer