SlideShare a Scribd company logo
Page 1
AAPM American Academy of Financial Management AAFM ®
1670-F East Cheyenne Mtn. Blvd.; Box #293
Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923-
CONTACT LEGAL * info@certifiedprojectmanager.us
CERTIFIED INTERNATIONAL INFORMATION SYSTEM
AUDITOR (CIISA) COURSE OUTLINE
Course Certified Information System Auditor/CIISA
Instructor Certified American Academy Instructor
Descriptions The CIISA credential of a professionals I.S auditor is
valuable. This course delves into the unique
challenges of managing an audit and the knowledge
necessary to complete the task.
Information system auditors take up where the
financial auditors do not tread-into the design and
implementation effectiveness and operation
effectiveness of information system. The course will
focus on general computer control, application level
control auditing as well introducing of risk based
management approach.
The course is also designed to help candidates
familiar with IT audit concepts and rules for
regulatory compliance under Sarbanes-Oxely
(corporations), Gramm-Leach-Biley and FFIEC (both
financial), FISMA (government), HIPAA (medical
records), SCADA (utilities) and other regulators.
The course will also help you to become a true
management consultant in IT audit filed and will help
you well prepared for the American Academy
examination, which offered by American I.S Audit
and control Association.
The instructor-led classroom training covers the
Information System Audit body of knowledge to
build a working understanding of the material.
The training course will cover topics such as auditor
responsibilities, scope, audit charter, technical
material, privacy requirements, for CIISA exam
preparation. The course has updated the contents to
reflect the new subject material of the CIISA exam.
Page 2
AAPM American Academy of Financial Management AAFM ®
1670-F East Cheyenne Mtn. Blvd.; Box #293
Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923-
CONTACT LEGAL * info@certifiedprojectmanager.us
Durations 3 Days
Objectives At the completion of this course, the participants shall have
comprehensive undertandingand knowledge in Information
System and Technology Audit and encompassing such as:
 Participants shall obtain an expanded understanding the
role of IT auditors in evaluating IT-related operational
and control risk and in assessing the appropriateness and
adequacy of management control practices and IT-
related controls inside participants’ organization
 Participants shall obtain the capability in conducting IT
audit and implement techniques in performing
assurance, attestation, and audit engagements
 Participants shall obtain an expanded familiarity with
the principle references in IT governance, control and
security as related to IT audit
 Participants shall obtain the working ability to plan,
conduct, and report on information technology audits
 Participants shall obtain an understanding of the role of
IT auditors regarding IT-related compliance and
regulatory audits, such as evaluating control standards
 Participants shall be prepared and throughly confident
upon themselves to take CIISA professional certificate
examination
Target Audience  IT Managers
 Security Managers
 Auditing Staffs
 IT Operation Staffs
Course Contents and Descriptions
Module 1: IS Audit
Process
Course Contents and Descriptions
Module 2: IT
Governance
The class session will focus on IT audit concepts and
processes, which includes: review of some of the key
fundamentals of IT auditing, including general auditing
standards, risk-based auditing, pre-audit objectives,
determining scope and audit objectives, and the process of
performing an IT audit.
Page 3
AAPM American Academy of Financial Management AAFM ®
1670-F East Cheyenne Mtn. Blvd.; Box #293
Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923-
CONTACT LEGAL * info@certifiedprojectmanager.us
The class session will include discussion on IT
performance, controls, control self-assessment, risk
analysis, and the objectives of the IT audit or assurance
report.
Module 3: System and
Infrastructure Life Cycle
The class session shall describe on practical methodology in
conducting the effective and efficient IT audit, expand upon
the need for appropriate controls and assurance processes
for business and IT environment. The participants will be
geared toward gaining a working understanding of the
content and value of the management guidelines and
assurance methodology.
Discussion will focus on the importance of measurement in
achieving organizational and IT objectives. The session will
also focus on the business and IT environments subject to
operational and control assessments (audit).
Module 4: IT Service
Delivery and Support
Provide assurance that the IT service management
practices will ensure delivery of the level of service
required to meet the organization’s objectives. The module
describes as follows:
• Evaluate service level management practices to ensure
that the level of service from internal and external
service providers is defined and managed
• Evaluate operations management to ensure that IT
support functions effectively meet business needs
• Evaluate data administration practices to ensure the
integrity and optimization of databases
• Evaluate the use of capacity and performance
monitoring tools and techniques to ensure that IT
services meet the organization’s objectives
• Evaluate change, configuration and release management
practices to ensure that changes made to the
organization's production environment are adequately
controlled and documented
• Evaluate problem and incident management practices to
ensure that incidents, problems or errors are recorded,
analyzed and resolved in a timely manner
• Evaluate the functionality of the IT infrastructure (e.g.,
network components, hardware, system software) to
ensure that it supports the organization's objectives
Module 5: Protection of
Information Assets
Provide assurance that the security architecture
policies, standards, procedures and controls) ensures
the confidentiality, integrity and availability of
Page 4
AAPM American Academy of Financial Management AAFM ®
1670-F East Cheyenne Mtn. Blvd.; Box #293
Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923-
CONTACT LEGAL * info@certifiedprojectmanager.us
information assets. The module descriptions are as
follows:
• Evaluate the design, implementation and
monitoring of logical access controls to ensure the
confidentiality, integrity, availability and
authorized use of information assets
• Evaluate network infrastructure security to ensure
confidentiality, integrity, availability and
authorized use of the network and the information
transmitted
• Evaluate the design, implementation and
monitoring of environmental controls to prevent or
minimize loss
• Evaluate the design, implementation and
monitoring of physical access controls to ensure
that information assets are adequately safeguarded
• Evaluate the processes and procedures used to
store, retrieve, transport and dispose of confidential
information assets
Module 6: Business
Continuity Plan
Provide assurance that in the event of a disruption
the business continuity and disaster recovery
processes will ensure the timely resumption of
IT service, while minimizing the business
impacts. The module covers as described below:
• Evaluate the adequacy of backup and restore
provisions to ensure the availability of
information required to resume processing
• Evaluate the organization's disaster recovery
plan to ensure that it enables the recovery of IT
processing capabilities in the event of a disaster
• Evaluate the organization's business continuity
plan to ensure the organization's ability to
continue essential business operations during
the period of an IT disruption
Case Studies Case-based discussions will be conducted with topics
related to the subjects of training. Exam exercises and
questions evaluation.

More Related Content

Similar to Syllabus CIISA ( Certified Internasional Information System Auditor ).pdf

Architecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk ManagementArchitecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk Management
jadams6
 
Overview-of-an-IT-Audit-Lesson-1.pptx
Overview-of-an-IT-Audit-Lesson-1.pptxOverview-of-an-IT-Audit-Lesson-1.pptx
Overview-of-an-IT-Audit-Lesson-1.pptx
JoshJaro
 
Seven Elements Of Effective Compliance Programs
Seven Elements Of Effective Compliance ProgramsSeven Elements Of Effective Compliance Programs
Seven Elements Of Effective Compliance Programs
Maria Macri
 
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
LynellBull52
 
It Audit Expectations High Detail
It Audit Expectations   High DetailIt Audit Expectations   High Detail
It Audit Expectations High Detail
ecarrow
 
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdfInfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
priyanshamadhwal2
 
2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College SectorNikhat Rasheed
 
D1 security and risk management v1.62
D1 security and risk management  v1.62D1 security and risk management  v1.62
D1 security and risk management v1.62
AlliedConSapCourses
 
Ch2 2009 cisa
Ch2 2009 cisaCh2 2009 cisa
Ch2 2009 cisa
asrulsani09
 
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
Mohammad Abdul Matin Emon
 
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
n|u - The Open Security Community
 
Ensuring SOC 2 Compliance A Comp Checklist.pdf
Ensuring SOC 2 Compliance A Comp Checklist.pdfEnsuring SOC 2 Compliance A Comp Checklist.pdf
Ensuring SOC 2 Compliance A Comp Checklist.pdf
socurely
 
ISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An IntorductionISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An Intorduction
n|u - The Open Security Community
 
Governance and management of IT.pptx
Governance and management of IT.pptxGovernance and management of IT.pptx
Governance and management of IT.pptx
Prashant Singh
 
CompTIA CySA Domain 5 Compliance and Assessment.pptx
CompTIA CySA Domain 5 Compliance and Assessment.pptxCompTIA CySA Domain 5 Compliance and Assessment.pptx
CompTIA CySA Domain 5 Compliance and Assessment.pptx
Infosectrain3
 
Developing an Information Security Program
Developing an Information Security ProgramDeveloping an Information Security Program
Developing an Information Security Program
Shauna_Cox
 
Auditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
Auditor Sistem Informasi dalam Kurikulum Magister Sistem InformasiAuditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
Auditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
Yeffry Handoko
 
Quality management system processes
Quality management system processesQuality management system processes
Quality management system processesselinasimpson2801
 
Implementing Asset Management System with ISO 55001
Implementing Asset Management System with ISO 55001Implementing Asset Management System with ISO 55001
Implementing Asset Management System with ISO 55001
PECB
 
It management audits it management templates
It management audits   it management templatesIt management audits   it management templates
It management audits it management templates
IT-Toolkits.org
 

Similar to Syllabus CIISA ( Certified Internasional Information System Auditor ).pdf (20)

Architecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk ManagementArchitecting the Framework for Compliance & Risk Management
Architecting the Framework for Compliance & Risk Management
 
Overview-of-an-IT-Audit-Lesson-1.pptx
Overview-of-an-IT-Audit-Lesson-1.pptxOverview-of-an-IT-Audit-Lesson-1.pptx
Overview-of-an-IT-Audit-Lesson-1.pptx
 
Seven Elements Of Effective Compliance Programs
Seven Elements Of Effective Compliance ProgramsSeven Elements Of Effective Compliance Programs
Seven Elements Of Effective Compliance Programs
 
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
· Processed on 09-Dec-2014 901 PM CST · ID 488406360 · Word .docx
 
It Audit Expectations High Detail
It Audit Expectations   High DetailIt Audit Expectations   High Detail
It Audit Expectations High Detail
 
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdfInfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
InfosecTrain_Certified_Information_Systems_Auditor_CISA_Course_Content.pdf
 
2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector2008 Pioneering The Employment Services Audit In The Ontario College Sector
2008 Pioneering The Employment Services Audit In The Ontario College Sector
 
D1 security and risk management v1.62
D1 security and risk management  v1.62D1 security and risk management  v1.62
D1 security and risk management v1.62
 
Ch2 2009 cisa
Ch2 2009 cisaCh2 2009 cisa
Ch2 2009 cisa
 
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT SystemsICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
ICAB - ITK Chapter 5 Set 1 - Internal Control in IT Systems
 
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
 
Ensuring SOC 2 Compliance A Comp Checklist.pdf
Ensuring SOC 2 Compliance A Comp Checklist.pdfEnsuring SOC 2 Compliance A Comp Checklist.pdf
Ensuring SOC 2 Compliance A Comp Checklist.pdf
 
ISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An IntorductionISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An Intorduction
 
Governance and management of IT.pptx
Governance and management of IT.pptxGovernance and management of IT.pptx
Governance and management of IT.pptx
 
CompTIA CySA Domain 5 Compliance and Assessment.pptx
CompTIA CySA Domain 5 Compliance and Assessment.pptxCompTIA CySA Domain 5 Compliance and Assessment.pptx
CompTIA CySA Domain 5 Compliance and Assessment.pptx
 
Developing an Information Security Program
Developing an Information Security ProgramDeveloping an Information Security Program
Developing an Information Security Program
 
Auditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
Auditor Sistem Informasi dalam Kurikulum Magister Sistem InformasiAuditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
Auditor Sistem Informasi dalam Kurikulum Magister Sistem Informasi
 
Quality management system processes
Quality management system processesQuality management system processes
Quality management system processes
 
Implementing Asset Management System with ISO 55001
Implementing Asset Management System with ISO 55001Implementing Asset Management System with ISO 55001
Implementing Asset Management System with ISO 55001
 
It management audits it management templates
It management audits   it management templatesIt management audits   it management templates
It management audits it management templates
 

More from Yoyo Sudaryo

Syllabus-Financial Planner.doc
Syllabus-Financial Planner.docSyllabus-Financial Planner.doc
Syllabus-Financial Planner.doc
Yoyo Sudaryo
 
Syllabus-Certified Asset Management Professional.doc
Syllabus-Certified Asset Management Professional.docSyllabus-Certified Asset Management Professional.doc
Syllabus-Certified Asset Management Professional.doc
Yoyo Sudaryo
 
Syllabus Chartered Portfolio Analyst.docx
Syllabus Chartered Portfolio Analyst.docxSyllabus Chartered Portfolio Analyst.docx
Syllabus Chartered Portfolio Analyst.docx
Yoyo Sudaryo
 
Syllabus Certified Strategic Business Analyst.doc
Syllabus Certified Strategic Business Analyst.docSyllabus Certified Strategic Business Analyst.doc
Syllabus Certified Strategic Business Analyst.doc
Yoyo Sudaryo
 
Syllabus-Financial Risk Management.docx
Syllabus-Financial Risk Management.docxSyllabus-Financial Risk Management.docx
Syllabus-Financial Risk Management.docx
Yoyo Sudaryo
 
silabi Financial Planner Analist.pdf
silabi Financial Planner Analist.pdfsilabi Financial Planner Analist.pdf
silabi Financial Planner Analist.pdf
Yoyo Sudaryo
 
DF.pdf
DF.pdfDF.pdf
DF.pdf
Yoyo Sudaryo
 
Kuliah perdana manajemen keuangan (program mm)
Kuliah perdana manajemen keuangan (program mm)Kuliah perdana manajemen keuangan (program mm)
Kuliah perdana manajemen keuangan (program mm)
Yoyo Sudaryo
 
Manajemen Risiko mm/S1
Manajemen Risiko mm/S1Manajemen Risiko mm/S1
Manajemen Risiko mm/S1
Yoyo Sudaryo
 
Mnd013 aibk-RPS
Mnd013 aibk-RPSMnd013 aibk-RPS
Mnd013 aibk-RPS
Yoyo Sudaryo
 
Factors that affect financial distress
Factors that affect financial distressFactors that affect financial distress
Factors that affect financial distress
Yoyo Sudaryo
 
Perwalian sesi 2
Perwalian sesi 2Perwalian sesi 2
Perwalian sesi 2
Yoyo Sudaryo
 
MJ STRATEGIK CSR 15
MJ STRATEGIK CSR 15MJ STRATEGIK CSR 15
MJ STRATEGIK CSR 15
Yoyo Sudaryo
 
Kuliah 1-15 mj strategik paran
Kuliah 1-15 mj strategik paranKuliah 1-15 mj strategik paran
Kuliah 1-15 mj strategik paran
Yoyo Sudaryo
 
Review Strategik 15
Review Strategik 15 Review Strategik 15
Review Strategik 15
Yoyo Sudaryo
 
Mnd013 AIBK-materi-sesi 15
Mnd013 AIBK-materi-sesi 15Mnd013 AIBK-materi-sesi 15
Mnd013 AIBK-materi-sesi 15
Yoyo Sudaryo
 
An overview of international financial management
An overview of international financial management An overview of international financial management
An overview of international financial management
Yoyo Sudaryo
 
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
Yoyo Sudaryo
 
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
Yoyo Sudaryo
 
6. mnc004 modul- mnj. strategi - sesi 6 - 2020
6. mnc004   modul- mnj. strategi - sesi 6 - 20206. mnc004   modul- mnj. strategi - sesi 6 - 2020
6. mnc004 modul- mnj. strategi - sesi 6 - 2020
Yoyo Sudaryo
 

More from Yoyo Sudaryo (20)

Syllabus-Financial Planner.doc
Syllabus-Financial Planner.docSyllabus-Financial Planner.doc
Syllabus-Financial Planner.doc
 
Syllabus-Certified Asset Management Professional.doc
Syllabus-Certified Asset Management Professional.docSyllabus-Certified Asset Management Professional.doc
Syllabus-Certified Asset Management Professional.doc
 
Syllabus Chartered Portfolio Analyst.docx
Syllabus Chartered Portfolio Analyst.docxSyllabus Chartered Portfolio Analyst.docx
Syllabus Chartered Portfolio Analyst.docx
 
Syllabus Certified Strategic Business Analyst.doc
Syllabus Certified Strategic Business Analyst.docSyllabus Certified Strategic Business Analyst.doc
Syllabus Certified Strategic Business Analyst.doc
 
Syllabus-Financial Risk Management.docx
Syllabus-Financial Risk Management.docxSyllabus-Financial Risk Management.docx
Syllabus-Financial Risk Management.docx
 
silabi Financial Planner Analist.pdf
silabi Financial Planner Analist.pdfsilabi Financial Planner Analist.pdf
silabi Financial Planner Analist.pdf
 
DF.pdf
DF.pdfDF.pdf
DF.pdf
 
Kuliah perdana manajemen keuangan (program mm)
Kuliah perdana manajemen keuangan (program mm)Kuliah perdana manajemen keuangan (program mm)
Kuliah perdana manajemen keuangan (program mm)
 
Manajemen Risiko mm/S1
Manajemen Risiko mm/S1Manajemen Risiko mm/S1
Manajemen Risiko mm/S1
 
Mnd013 aibk-RPS
Mnd013 aibk-RPSMnd013 aibk-RPS
Mnd013 aibk-RPS
 
Factors that affect financial distress
Factors that affect financial distressFactors that affect financial distress
Factors that affect financial distress
 
Perwalian sesi 2
Perwalian sesi 2Perwalian sesi 2
Perwalian sesi 2
 
MJ STRATEGIK CSR 15
MJ STRATEGIK CSR 15MJ STRATEGIK CSR 15
MJ STRATEGIK CSR 15
 
Kuliah 1-15 mj strategik paran
Kuliah 1-15 mj strategik paranKuliah 1-15 mj strategik paran
Kuliah 1-15 mj strategik paran
 
Review Strategik 15
Review Strategik 15 Review Strategik 15
Review Strategik 15
 
Mnd013 AIBK-materi-sesi 15
Mnd013 AIBK-materi-sesi 15Mnd013 AIBK-materi-sesi 15
Mnd013 AIBK-materi-sesi 15
 
An overview of international financial management
An overview of international financial management An overview of international financial management
An overview of international financial management
 
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-modul-sesi 6
 
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
Mnd013 analisis inv bank dan lembaga keuangan-materi-sesi 6
 
6. mnc004 modul- mnj. strategi - sesi 6 - 2020
6. mnc004   modul- mnj. strategi - sesi 6 - 20206. mnc004   modul- mnj. strategi - sesi 6 - 2020
6. mnc004 modul- mnj. strategi - sesi 6 - 2020
 

Recently uploaded

Architectural Portfolio Sean Lockwood
Architectural Portfolio Sean LockwoodArchitectural Portfolio Sean Lockwood
Architectural Portfolio Sean Lockwood
seandesed
 
Investor-Presentation-Q1FY2024 investor presentation document.pptx
Investor-Presentation-Q1FY2024 investor presentation document.pptxInvestor-Presentation-Q1FY2024 investor presentation document.pptx
Investor-Presentation-Q1FY2024 investor presentation document.pptx
AmarGB2
 
Gen AI Study Jams _ For the GDSC Leads in India.pdf
Gen AI Study Jams _ For the GDSC Leads in India.pdfGen AI Study Jams _ For the GDSC Leads in India.pdf
Gen AI Study Jams _ For the GDSC Leads in India.pdf
gdsczhcet
 
The role of big data in decision making.
The role of big data in decision making.The role of big data in decision making.
The role of big data in decision making.
ankuprajapati0525
 
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdfAKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
SamSarthak3
 
J.Yang, ICLR 2024, MLILAB, KAIST AI.pdf
J.Yang,  ICLR 2024, MLILAB, KAIST AI.pdfJ.Yang,  ICLR 2024, MLILAB, KAIST AI.pdf
J.Yang, ICLR 2024, MLILAB, KAIST AI.pdf
MLILAB
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
zwunae
 
space technology lecture notes on satellite
space technology lecture notes on satellitespace technology lecture notes on satellite
space technology lecture notes on satellite
ongomchris
 
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdfGoverning Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
WENKENLI1
 
MCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdfMCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdf
Osamah Alsalih
 
CME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional ElectiveCME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional Elective
karthi keyan
 
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
obonagu
 
The Benefits and Techniques of Trenchless Pipe Repair.pdf
The Benefits and Techniques of Trenchless Pipe Repair.pdfThe Benefits and Techniques of Trenchless Pipe Repair.pdf
The Benefits and Techniques of Trenchless Pipe Repair.pdf
Pipe Restoration Solutions
 
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
bakpo1
 
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
ydteq
 
Planning Of Procurement o different goods and services
Planning Of Procurement o different goods and servicesPlanning Of Procurement o different goods and services
Planning Of Procurement o different goods and services
JoytuBarua2
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Dr.Costas Sachpazis
 
ethical hacking-mobile hacking methods.ppt
ethical hacking-mobile hacking methods.pptethical hacking-mobile hacking methods.ppt
ethical hacking-mobile hacking methods.ppt
Jayaprasanna4
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Teleport Manpower Consultant
 
English lab ppt no titlespecENG PPTt.pdf
English lab ppt no titlespecENG PPTt.pdfEnglish lab ppt no titlespecENG PPTt.pdf
English lab ppt no titlespecENG PPTt.pdf
BrazilAccount1
 

Recently uploaded (20)

Architectural Portfolio Sean Lockwood
Architectural Portfolio Sean LockwoodArchitectural Portfolio Sean Lockwood
Architectural Portfolio Sean Lockwood
 
Investor-Presentation-Q1FY2024 investor presentation document.pptx
Investor-Presentation-Q1FY2024 investor presentation document.pptxInvestor-Presentation-Q1FY2024 investor presentation document.pptx
Investor-Presentation-Q1FY2024 investor presentation document.pptx
 
Gen AI Study Jams _ For the GDSC Leads in India.pdf
Gen AI Study Jams _ For the GDSC Leads in India.pdfGen AI Study Jams _ For the GDSC Leads in India.pdf
Gen AI Study Jams _ For the GDSC Leads in India.pdf
 
The role of big data in decision making.
The role of big data in decision making.The role of big data in decision making.
The role of big data in decision making.
 
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdfAKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
AKS UNIVERSITY Satna Final Year Project By OM Hardaha.pdf
 
J.Yang, ICLR 2024, MLILAB, KAIST AI.pdf
J.Yang,  ICLR 2024, MLILAB, KAIST AI.pdfJ.Yang,  ICLR 2024, MLILAB, KAIST AI.pdf
J.Yang, ICLR 2024, MLILAB, KAIST AI.pdf
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单专业办理
 
space technology lecture notes on satellite
space technology lecture notes on satellitespace technology lecture notes on satellite
space technology lecture notes on satellite
 
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdfGoverning Equations for Fundamental Aerodynamics_Anderson2010.pdf
Governing Equations for Fundamental Aerodynamics_Anderson2010.pdf
 
MCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdfMCQ Soil mechanics questions (Soil shear strength).pdf
MCQ Soil mechanics questions (Soil shear strength).pdf
 
CME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional ElectiveCME397 Surface Engineering- Professional Elective
CME397 Surface Engineering- Professional Elective
 
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
在线办理(ANU毕业证书)澳洲国立大学毕业证录取通知书一模一样
 
The Benefits and Techniques of Trenchless Pipe Repair.pdf
The Benefits and Techniques of Trenchless Pipe Repair.pdfThe Benefits and Techniques of Trenchless Pipe Repair.pdf
The Benefits and Techniques of Trenchless Pipe Repair.pdf
 
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
一比一原版(SFU毕业证)西蒙菲莎大学毕业证成绩单如何办理
 
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
一比一原版(UofT毕业证)多伦多大学毕业证成绩单如何办理
 
Planning Of Procurement o different goods and services
Planning Of Procurement o different goods and servicesPlanning Of Procurement o different goods and services
Planning Of Procurement o different goods and services
 
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
Sachpazis:Terzaghi Bearing Capacity Estimation in simple terms with Calculati...
 
ethical hacking-mobile hacking methods.ppt
ethical hacking-mobile hacking methods.pptethical hacking-mobile hacking methods.ppt
ethical hacking-mobile hacking methods.ppt
 
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdfTop 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
Top 10 Oil and Gas Projects in Saudi Arabia 2024.pdf
 
English lab ppt no titlespecENG PPTt.pdf
English lab ppt no titlespecENG PPTt.pdfEnglish lab ppt no titlespecENG PPTt.pdf
English lab ppt no titlespecENG PPTt.pdf
 

Syllabus CIISA ( Certified Internasional Information System Auditor ).pdf

  • 1. Page 1 AAPM American Academy of Financial Management AAFM ® 1670-F East Cheyenne Mtn. Blvd.; Box #293 Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923- CONTACT LEGAL * info@certifiedprojectmanager.us CERTIFIED INTERNATIONAL INFORMATION SYSTEM AUDITOR (CIISA) COURSE OUTLINE Course Certified Information System Auditor/CIISA Instructor Certified American Academy Instructor Descriptions The CIISA credential of a professionals I.S auditor is valuable. This course delves into the unique challenges of managing an audit and the knowledge necessary to complete the task. Information system auditors take up where the financial auditors do not tread-into the design and implementation effectiveness and operation effectiveness of information system. The course will focus on general computer control, application level control auditing as well introducing of risk based management approach. The course is also designed to help candidates familiar with IT audit concepts and rules for regulatory compliance under Sarbanes-Oxely (corporations), Gramm-Leach-Biley and FFIEC (both financial), FISMA (government), HIPAA (medical records), SCADA (utilities) and other regulators. The course will also help you to become a true management consultant in IT audit filed and will help you well prepared for the American Academy examination, which offered by American I.S Audit and control Association. The instructor-led classroom training covers the Information System Audit body of knowledge to build a working understanding of the material. The training course will cover topics such as auditor responsibilities, scope, audit charter, technical material, privacy requirements, for CIISA exam preparation. The course has updated the contents to reflect the new subject material of the CIISA exam.
  • 2. Page 2 AAPM American Academy of Financial Management AAFM ® 1670-F East Cheyenne Mtn. Blvd.; Box #293 Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923- CONTACT LEGAL * info@certifiedprojectmanager.us Durations 3 Days Objectives At the completion of this course, the participants shall have comprehensive undertandingand knowledge in Information System and Technology Audit and encompassing such as:  Participants shall obtain an expanded understanding the role of IT auditors in evaluating IT-related operational and control risk and in assessing the appropriateness and adequacy of management control practices and IT- related controls inside participants’ organization  Participants shall obtain the capability in conducting IT audit and implement techniques in performing assurance, attestation, and audit engagements  Participants shall obtain an expanded familiarity with the principle references in IT governance, control and security as related to IT audit  Participants shall obtain the working ability to plan, conduct, and report on information technology audits  Participants shall obtain an understanding of the role of IT auditors regarding IT-related compliance and regulatory audits, such as evaluating control standards  Participants shall be prepared and throughly confident upon themselves to take CIISA professional certificate examination Target Audience  IT Managers  Security Managers  Auditing Staffs  IT Operation Staffs Course Contents and Descriptions Module 1: IS Audit Process Course Contents and Descriptions Module 2: IT Governance The class session will focus on IT audit concepts and processes, which includes: review of some of the key fundamentals of IT auditing, including general auditing standards, risk-based auditing, pre-audit objectives, determining scope and audit objectives, and the process of performing an IT audit.
  • 3. Page 3 AAPM American Academy of Financial Management AAFM ® 1670-F East Cheyenne Mtn. Blvd.; Box #293 Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923- CONTACT LEGAL * info@certifiedprojectmanager.us The class session will include discussion on IT performance, controls, control self-assessment, risk analysis, and the objectives of the IT audit or assurance report. Module 3: System and Infrastructure Life Cycle The class session shall describe on practical methodology in conducting the effective and efficient IT audit, expand upon the need for appropriate controls and assurance processes for business and IT environment. The participants will be geared toward gaining a working understanding of the content and value of the management guidelines and assurance methodology. Discussion will focus on the importance of measurement in achieving organizational and IT objectives. The session will also focus on the business and IT environments subject to operational and control assessments (audit). Module 4: IT Service Delivery and Support Provide assurance that the IT service management practices will ensure delivery of the level of service required to meet the organization’s objectives. The module describes as follows: • Evaluate service level management practices to ensure that the level of service from internal and external service providers is defined and managed • Evaluate operations management to ensure that IT support functions effectively meet business needs • Evaluate data administration practices to ensure the integrity and optimization of databases • Evaluate the use of capacity and performance monitoring tools and techniques to ensure that IT services meet the organization’s objectives • Evaluate change, configuration and release management practices to ensure that changes made to the organization's production environment are adequately controlled and documented • Evaluate problem and incident management practices to ensure that incidents, problems or errors are recorded, analyzed and resolved in a timely manner • Evaluate the functionality of the IT infrastructure (e.g., network components, hardware, system software) to ensure that it supports the organization's objectives Module 5: Protection of Information Assets Provide assurance that the security architecture policies, standards, procedures and controls) ensures the confidentiality, integrity and availability of
  • 4. Page 4 AAPM American Academy of Financial Management AAFM ® 1670-F East Cheyenne Mtn. Blvd.; Box #293 Colorado Springs CO 80906 -USA504-495-1748 Fax: 419-828-4923- CONTACT LEGAL * info@certifiedprojectmanager.us information assets. The module descriptions are as follows: • Evaluate the design, implementation and monitoring of logical access controls to ensure the confidentiality, integrity, availability and authorized use of information assets • Evaluate network infrastructure security to ensure confidentiality, integrity, availability and authorized use of the network and the information transmitted • Evaluate the design, implementation and monitoring of environmental controls to prevent or minimize loss • Evaluate the design, implementation and monitoring of physical access controls to ensure that information assets are adequately safeguarded • Evaluate the processes and procedures used to store, retrieve, transport and dispose of confidential information assets Module 6: Business Continuity Plan Provide assurance that in the event of a disruption the business continuity and disaster recovery processes will ensure the timely resumption of IT service, while minimizing the business impacts. The module covers as described below: • Evaluate the adequacy of backup and restore provisions to ensure the availability of information required to resume processing • Evaluate the organization's disaster recovery plan to ensure that it enables the recovery of IT processing capabilities in the event of a disaster • Evaluate the organization's business continuity plan to ensure the organization's ability to continue essential business operations during the period of an IT disruption Case Studies Case-based discussions will be conducted with topics related to the subjects of training. Exam exercises and questions evaluation.