Practical Aspects of Information System Audit (For Beginner)

所在平台: Udemy

课程主页: https://www.udemy.com/course/information-system-audit/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:信息系统审计的实用方面(初学者) 课程概述:本课程旨在为信息系统审计的初学者提供实际的培训体验,而非理论学习。除简单的介绍外,本课程不包含其他幻灯片示例。我们将模拟真实的工作环境,为学员提供一个实用的职业培训课程。课程分为12个步骤,涵盖信息系统审计的基本方面。完成本培训后,您将具备独立处理信息系统审计的能力。 课程内容包括: - 每个步骤都有专门设计的视频,帮助学员理解相关的数据要求、审计程序、所需评估的证据及如何撰写审计报告。 - 第一步:检查信息安全政策,包括政策的可用性、批准情况及定期更新等。 - 第二步:审核应用程序的控制措施,如应用程序的分类及用户访问审查。 - 第三步:审查数据库控制,包括更新操作系统和备份安排。 - 第四步:审计数据中心的控制,如定期审计和服务水平协议的存在。 - 第五步:检查网络设备的所有权及配置审查。 - 第六步:审核终端设备的资产管理和防病毒措施。 - 第七步:审查电子邮件控制措施,如SPF和DMARC启用状况。 - 第八步:检查外包服务的服务协议及定期审计。 - 第九步:确认桌面安全的操作系统和防病毒措施。 - 第十步:审核业务连续性和事件管理政策及其测试情况。 - 第十一步:检查用户的安全培训和背景验证。 - 第十二步:根据审计目标回顾所有其他检查点。 通过这12个步骤,课程覆盖了几乎所有信息安全的关键要求,旨在帮助初学者建立扎实的审计能力。

课程评论(0条)

课程详情

We assure you that this is not a theory class. Except for this introduction, there will be no other PPTs.We have designed the course in such as a way that it simulates on-the job kind of training. This course is primarily designed for the beginners/freshers in information system audit and hence we will start from basic aspects of IS audits.We assure you that after completion of this training program, you will be able to independently handle the IS audits.For effective and efficient audit program, we have bifurcated Information System audits into 12 step processes. For your easy understanding we have designed exclusive video for each step.For each step we will guide you about data requirements, audit procedure, evidence to be evaluated and how to write the audit report.Also, you can download readymade templates from resource section of this course.Step-wise Audit Program:Step 1 is about checking the information security policy. In this step, as an auditor you need to check:o availability of the policy,o whether policy is approved by appropriate authority?o whether policy is updated at periodic interval and other aspect with respect to policy?We will discuss in detail about how to audit and validate these controls in our step 1 video.Step 2 is about auditing the controls related to applications. In this step, as an auditor you need to check:o whether application is appropriately categorized?o Whether each application is owned by dedicated owner?o How many factors of authentication is applied?o Whether user access review in conducted for each application at periodic level?We will discuss in detail about how to audit and validate these controls in our step 2 video.Step 3 is about auditing the controls related to database. We checko whether database is appropriately categorized?o Whether each database is owned by dedicated owner?o Whether Operating system is updated? Organization should not be using end of life/end of support OS.o Whether backup arrangement is appropriate?We will discuss in detail how to audit and validate these controls in our step 3 video.Step 4 is about auditing the controls related to datacenter. You need to checko whether datacentre is audited at periodic interval?o Whether SLA is available for external datacentre?o Whether secondary datacentre is at offsite location?Step 5 is about auditing the controls related to network devices. You need to checko Whether device is owned by dedicated owner?o Whether device configuration is reviewed at period interval?Step 6 is about auditing the controls related to endpoint devices like computers, laptops, tablets, mobile etc. You need to checko Whether asset inventory is maintained and updated?o Whether end point device is owned by dedicated owner?o Whether anti-virus is installed for all the devices?Step 7 is about auditing the controls related to email. You need to checko whether SPF is enabled? Don't worry about technical terms. We will simplify the same while discussing the step 7.o whether DMARC is enabled?o whether attachments are scanned before downloading?Step 8 is about auditing the controls related to outsourcing. You need to checko Whether service level agreement is available for the outsourced services?o whether service provider is audited at periodic interval?Step 9 is about auditing the controls related to desktop security You need to checko Whether operating system is updated and licensed?o Whether anti-virus is installed and signatures are updated?o Various user restrictions are implemented?o Use of latest browsers.Step 10 is about auditing the controls related to BCP and Incident management. You need to checko Whether Business Continuity Policy & Incident Management policy is available?o Whether Business Continuity plan is tested at periodic interval?Step 11 is about auditing the controls related to users. You need to checko Whether users are trained at periodic interval on information security?o whether background verification is conducted for new hires?These 11 steps cover almost all the important and critical information security requirements. As a step 12, you need to review all other checkpoints as required by the objective of audit.

课程标签

0人关注该课程

主题相关的课程