|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/information-systems-auditor-c/
课程评论:没有评论
课程名称:信息系统审计师 课程概述: 随着信息系统成为现代组织不可或缺的一部分,许多业务流程现已依赖于这些系统,而其中的数据对任何企业都至关重要。因此,保护和维护这些系统的安全性和完整性也变得愈发重要。随着信息系统使用的增加,针对这些系统的攻击和威胁,如勒索软件、数据盗窃、黑客攻击、伪造和暴力破解等也在上升。越来越多的攻击者开始瞄准那些控制和保护措施较少的组织。 本课程致力于帮助学员建立有效的控制和政策,以保护信息系统及其资产免受未授权访问和数据泄露的威胁。信息系统审计师课程是一个全面的课程,旨在使学员熟悉信息系统审计过程、IT治理、信息系统的管理、运营、维护与支持、业务韧性及信息资产保护等方面的知识。这些信息资产可以采取数据库、文件、图像、文档和软件等多种形式。课程涵盖了保护方法和技术,无论数据在组织中的形式如何。 完成本课程后,学员将能够: - 理解信息系统审计流程 - 规划审计 - 进行风险分析 - 建立内部控制 - 学习信息系统审计的不同阶段 - 理解IT/IS中治理的角色 - 制定政策、程序并识别风险 - 创建信息安全政策文件 - 对政策文件进行管理评审 - 执行风险管理 - 制定内外包策略 - 进行组织质量管理 - 创建项目管理结构 - 引入应用开发最佳实践 - 规划信息系统运营和业务韧性计划 - 定义恢复点目标(RPO)和恢复时间目标(RTO) - 制定灾难恢复计划 - 保护信息资产 - 识别暴露和脆弱性 - 理解加密在数据保护中的作用 - 学习计算机取证的基础知识 总体来说,本课程涵盖了成为一名高效信息系统审计师所需的各个方面,并帮助学员准备相关认证,如CISA,因为考试主题与课程中教授的概念一致。
Information systems have become an integral part of any modern organization. Many of the business processes are now dependent on the information systems and the data contained in these systems is of critical importance to any enterprise. The need to protect and safeguard these systems is also directly proportional to the increase in their usage. With the information systems becoming so important, the attacks and threats including but not limited to ransomware, data theft, hacking, forgery and brute force are also on the rise. More and more attackers are targeting organization with less control and protection. This course prepares the candidates to put in place effective controls and policies to protect their information systems and assets from unauthorized access and leakage.Information systems auditor course is a comprehensive course designed with the objective of preparing the candidates to be able to familiarize themselves with the IS audit process, governance, management of IT, IS operations, maintenance and support, IS operations and business resilience as well as protection of information assets.These information systems or assets can be in the form of databases, files, images, documents and software. The course covers the protection methods and techniques regardless of the form the data is residing within the organization.After successfully completing this course, the students will be able to:· Understand the IS audit process· Plan audit· Perform risk analysis· Put in place internal controls· Learn about different phases of IS audit· Understand the role of governance in IT/IS· Make policies, procedures and identify risks· Create information security policy document· Conduct management reviews of the policy document· Perform risk management· Create in-sourcing and outsourcing strategy· Perform organizational quality management· Create project management structure· Introduce application development best practices· Plan IS operations and business resiliency plans· Define RPO/RTO· Develop disaster recovery plan· Protect information assets· Identify exposures and vulnerabilities· Understand role of encryption in data protection· Learn the basics of computer forensicsOverall, the course touches all the aspects required to become an effective information systems auditor and perform the taks efficiently. This course also helps the candidates to prepare for the relevant certification, i.e., CISA as the exam topics are in alignment with the concepts taught in this course.