CISA Cert Prep: 2 Information Technology Governance and Management for IS Auditors
2hIntermediate2021-04-20
Authors

Michael Lester
CTO of WindTalker LLC

Human Element LLC
Founded as Logical Security by legendary security expert Shon Harris
Course details
Earning a CISA certification validates your ability to audit, control, and monitor information systems. The CISA Cert Prep series prepares you to tackle this exam and acquire the skills you need to confidently manage IT security audits. This course—the second in the series—teaches the concepts of IT governance and management that the CISA candidate needs to know.
Instructor Michael Lester starts out with a description of IT governance and the role of IT policies, processes, and standards, providing examples of many of the most common types. He reviews three key areas for auditing: risk management, business continuity, and disaster recovery planning. He also explains how an IT department and its auditing team should be organized. At each stage, he explains how the auditor would address these topics in a typical audit environment.
Topics include:
IT governance
Policies, processes, and standards
Risk management
IT organization
Business continuity
Disaster recovery
Instructor Michael Lester starts out with a description of IT governance and the role of IT policies, processes, and standards, providing examples of many of the most common types. He reviews three key areas for auditing: risk management, business continuity, and disaster recovery planning. He also explains how an IT department and its auditing team should be organized. At each stage, he explains how the auditor would address these topics in a typical audit environment.
Topics include:
IT governance
Policies, processes, and standards
Risk management
IT organization
Business continuity
Disaster recovery
Skills covered
Governance, Risk, and ComplianceCert PrepCybersecurity
Concepts
Introduction
- Welcome
Governance
- IT governance
Enterprise architecture
- Enterprise architecture
- Policies
- Auditing governance and documentation
Risk Management
- Risk management process
- Planning
- Collect information Part 1
- Collect information Part 2
- Dealing with risk
- Auditing risk management
IT Management Structure and Responsibilities
- IT organization
- Audting management structure
Business Continuity and Disaster Recovery
- Introduction
- BCP step-by-step
- Business impact analysis
- Recovery strategies and solutions
- Developing and implementing the plan
- Testing training and maintenance
- Auditing business continuity and disaster recovery
Maturity Models
- Maturity models
Conclusion
- Next steps