|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/how-to-perform-an-it-audit/
课程评论:没有评论
课程名称:如何进行IT审计 课程概述:本课程旨在帮助学员学习如何进行IT审计,适合IT和信息安全专业人士,以及希望学习IT审计技巧的审计员或其他评估人员。课程将教授进行IT审计所需的知识和工具,包括审计的规划、实施以及结果报告。内容涵盖识别应评估的威胁及应实施的控制措施。课程由具有数十年信息安全评估经验、拥有CISA认证的讲师Adrian Resag授课。 课程内容: 1. 进行IT审计:学习IT审计的基本知识和技能。 2. 规划审计:掌握如何合理规划审计,包括确定目标、标准和范围,创建工作文件记录审计过程,并了解工作人员安排。 3. 执行审计:学习如何收集和分析审计信息,评估审计过程,及如何监督审计进展。 4. 结果沟通:掌握如何沟通审计结果和风险接受过程,并监控内部审计建议的实施进度。 5. IT治理、控制与框架:了解IT管理及其管理层次模型。 6. 系统开发:评估系统开发方法及其审计,包括系统开发生命周期(SDLC)模型及其审计,此外还涉及瀑布模型、螺旋模型、快速开发和敏捷方法的审计与应用测试方法。 7. 数据库:掌握关系数据库的评估技能。 8. 软件与应用控制:了解常见应用控制的必要性。 9. IT基础设施、框架与报告:了解IT基础设施控制及其测试方法。 10. 业务连续性与灾难恢复计划(BRP/DRP):了解如何测试业务连续性和灾难恢复的准备情况。 11. 数据备份与恢复控制:掌握测试数据备份和恢复控制的技能。 该课程为希望深入了解IT审计全过程的专业人士提供了全面的学习框架,是提升信息安全审计能力的理想选择。
We are glad to bring you a course to learn how to perform IT audits. This course is ideal for:IT and information security professionals who wish to learn techniques on how to assess their IT systems and the vulnerability of their IT systems; and Auditors or others performing assessments who wish to learn more about performing IT audits. The course will give you the knowledge and tools necessary to perform IT audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place. It is taught by Adrian Resag, an experienced and CISA certified IT and information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations. The course covers:Performing IT AuditsPlanning EngagementsUnderstand how to properly plan engagements by determining their objectives, criteria and scope. Know how to create working papers to document an audit and learn about different ways to staff an audit. Performing EngagementsLearn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements. Communicating Progress and ResultsLearn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations. IT Governance, Controls and FrameworksIT ManagementKnow about the management of IT and the layers model of IT management. Systems DevelopmentBe able to assess systems development methods, including the Systems Development Life Cycle (SDLC) model and how to audit it and the waterfall, spiral, rapid development and agile methods. Learn about application testing methods. DatabasesUnderstand and be able to assess relational databases. Software and Application controlsKnow about common application controls you should ensure are in place. IT Governance, Frameworks and ReportingLearn about IT governance, IT frameworks and reporting structures. IT InfrastructureKnow IT infrastructure controls and how to test them. Business Continuity and Disaster Recovery Planning (BRP/DRP)Know how to test preparedness Business Continuity Planning and Disaster Recovery Planning (BRP/DRP). Data Backup and Recovery ControlsBe able to test data backups and controls for recovery.