Introduction
Instructor overview and welcome to CISA
()
CISA overview
()
1. Information System Auditing Process
IS audit standards
()
Types of audits
()
Risk-based audit planning
()
Types of controls and control considerations for auditing
()
Audit execution and audit program/project management
()
Audit testing, sampling, and evidence collection
()
Audit data analytics
()
Audit reporting and quality improvement
()
2. Governance and Management of IT
Governance, risk, and compliance (GRC) of IT
()
IT organizational structure
()
External factors of IT governance
()
Policies, standards, and procedures
()
Key enterprise governance of IT programs and auditing
()
Key IT management programs and auditing
()
Performance monitoring and reporting
()
Auditing IT governance
()
3. Information Systems Acquisition, Development, and Implementation
IT project management
()
System development methodologies and tools
()
Software development methodologies
()
Infrastructure development and acquisition
()
Hardware, software, and system software acquisition
()
Application controls and output controls
()
System readiness and implementation testing
()
Configuration and release management
()
System migration, deployment, and data conversion
()
Post-implementation review
()
4. Information Systems Operations and Business Resilience
IT components overview
()
IT components deepdive: Networking
()
IT components deepdive: Hardware and maintenance
()
IT components deep dive: Back-end devices and other technologies
()
IT asset management
()
Job scheduling
()
System interfaces
()
End-user computing
()
Systems availability and capacity management
()
Problem and incident management
()
IT change, configuration, and patch management
()
IT operations and operational log management
()
IT service level management
()
Database management
()
Business resilience and business impact assessments (BIAs)
()
Backup and recovery methods
()
Business continuity planning, testing, and auditing
()
Disaster recovery
()
5. Protection of Information Assets
Information asset security governance documents
()
Physical and environmental controls
()
Identity and access management basics
()
Identity and access management
()
Network and endpoint security
()
Data loss prevention
()
Data encryption
()
Public key infrastructure
()
Cloud and virtualized environment
()
Mobile and wireless
()
Security awareness and training
()
Information system attack methods
()
Security testing tools and techniques
()
Security monitoring logs, tools, and techniques
()
Security incident response management
()
Evidence collection and forensics
()
Course wrap-up
()