Book Image

CISA – Certified Information Systems Auditor Study Guide

By : Hemang Doshi
Book Image

CISA – Certified Information Systems Auditor Study Guide

By: Hemang Doshi

Overview of this book

Are you looking to prepare for the CISA exam and understand the roles and responsibilities of an information systems (IS) auditor? The CISA - Certified Information Systems Auditor Study Guide is here to help you get started with CISA exam prep. This book covers all the five CISA domains in detail to help you pass the exam. You’ll start by getting up and running with the practical aspects of an information systems audit. The book then shows you how to govern and manage IT, before getting you up to speed with acquiring information systems. As you progress, you’ll gain knowledge of information systems operations and understand how to maintain business resilience, which will help you tackle various real-world business problems. Finally, you’ll be able to assist your organization in effectively protecting and controlling information systems with IT audit standards. By the end of this CISA book, you'll not only have covered the essential concepts and techniques you need to know to pass the CISA certification exam but also have the ability to apply them in the real world.
Table of Contents (19 chapters)
1
Section 1: Information System Auditing Process
4
Section 2: Governance and Management of IT
7
Section 3: Information Systems Acquisition, Development, and Implementation
10
Section 4: Information System Operations and Business Resilience
13
Section 5: Protection of Information Assets

IT-related frameworks

IT-related processes should be defined and documented in a structured way. The adoption of IT-related frameworks helps an organization to add value to its stakeholders and also ensures confidentiality, integrity, and the availability of IT assets. The following are some of the EGIT frameworks:

Framework

Description

COBIT
  • COBIT is developed by ISACA
  • Stands for Control Objective for Information Technology.
  • COBIT is an EGIT framework that ensures that IT is aligned with the business and delivers value for the business.
ISO 27000 series
  • The ISO 27000 series is a set of best practices for information security programs.
  • ISO/IEC 27001 is a well-recognized standard for ISMS (Information Security Management System).
ITIL
  • Stands for Information Technology Infrastructure Library.
  • Developed by the UK Office of Government Commerce (OGC) in partnership with the IT Service Management Forum.
  • ITIL is a detailed framework for the operational service management...