Book Image

CISA – Certified Information Systems Auditor Study Guide - Second Edition

By : Hemang Doshi
5 (3)
Book Image

CISA – Certified Information Systems Auditor Study Guide - Second Edition

5 (3)
By: Hemang Doshi

Overview of this book

With the latest updates and revised study material, this second edition of the Certified Information Systems Auditor Study Guide provides an excellent starting point for your CISA certification preparation. The book strengthens your grip on the core concepts through a three-step approach. First, it presents the fundamentals with easy-to-understand theoretical explanations. Next, it provides a list of key aspects that are crucial from the CISA exam perspective, ensuring you focus on important pointers for the exam. Finally, the book makes you an expert in specific topics by engaging you with self-assessment questions designed to align with the exam format, challenging you to apply your knowledge and sharpen your understanding. Moreover, the book comes with lifetime access to supplementary resources on an online platform, including CISA flashcards, practice questions, and valuable exam tips. With unlimited access to the website, you’ll have the flexibility to practice as many times as you desire, maximizing your exam readiness. By the end of this book, you’ll have developed the proficiency to successfully obtain the CISA certification and significantly upgrade your auditing career.
Table of Contents (14 chapters)

IT Performance Monitoring and Reporting

One of the important elements of IT governance is the monitoring of IT performance. The knowledge that IT operations are moving in the desired direction provides management with a level of comfort. It is extremely important to develop metrics for monitoring performance. The following sections explain these metrics.

Development of Performance Metrics

Developing performance metrics usually involves three steps:

Figure 4.3: Steps for developing performance metrics

Figure 4.3: Steps for developing performance metrics

  1. Identify the critical processes: The first step is to identify the critical processes that need to be monitored.
  2. Identify the expected output: The second step is to define the expected output or target for each process that needs to be monitored.
  3. Compare the actual output with the target: On a periodic basis, compare the actual output with the target. If the target is not achieved, conduct a root cause analysis to determine areas of improvement...