Get in Touch

award icon svg Certificate

Course Outline

Domain 1—The Process of Auditing Information Systems (14%)

Deliver audit services aligned with established IT audit standards to support organizational efforts in safeguarding and controlling information systems for government operations.

  • 1.1 Formulate and execute a risk-based IT audit strategy consistent with professional standards to ensure coverage of critical areas.
  • 1.2 Design specific audits to assess whether information systems are adequately protected, controlled, and deliver value to the organization.
  • 1.3 Perform audits in accordance with IT audit standards to meet defined audit objectives.
  • 1.4 Communicate audit findings and recommendations to key stakeholders to facilitate necessary organizational changes.
  • 1.5 Monitor remediation efforts or prepare status reports to verify that management has taken timely and appropriate corrective actions.

Domain 2—Governance and Management of IT (14%)

Provide assurance that effective leadership, organizational structures, and processes are established to achieve strategic objectives and support the organization’s mission.

  • 2.1 Assess the effectiveness of the IT governance structure to confirm that IT decisions, direction, and performance align with organizational strategies and objectives.
  • 2.2 Evaluate the IT organizational structure and human resources management practices to ensure they support the organization’s strategies and objectives.
  • 2.3 Review the IT strategy, including its development, approval, implementation, and maintenance processes, for alignment with organizational goals.
  • 2.4 Assess IT policies, standards, and procedures, along with their lifecycle management, to verify support for the IT strategy and compliance with legal and regulatory requirements for government entities.
  • 2.5 Evaluate the quality management system to determine if it supports organizational strategies and objectives cost-effectively.
  • 2.6 Assess IT management and control monitoring practices, including continuous monitoring and quality assurance, for compliance with organizational policies and standards.
  • 2.7 Review IT resource investment, utilization, and allocation practices, including prioritization criteria, to ensure alignment with organizational strategies and objectives.
  • 2.8 Evaluate IT contracting strategies, policies, and management practices to confirm they support organizational strategies and objectives.
  • 2.9 Assess risk management practices to ensure IT-related risks are appropriately managed.
  • 2.10 Review monitoring and assurance practices to verify that the board and executive leadership receive sufficient and timely information on IT performance.
  • 2.11 Evaluate the business continuity plan to assess the organization’s ability to maintain essential operations during an IT disruption.

Domain 3—Information Systems Acquisition, Development, and Implementation (19%)

Provide assurance that practices for acquiring, developing, testing, and implementing information systems align with organizational strategies and objectives.

  • 3.1 Assess the business case for proposed information systems investments, including acquisition, development, maintenance, and retirement, to ensure alignment with business objectives.
  • 3.2 Evaluate project management practices and controls to verify that business requirements are met cost-effectively while managing organizational risks.
  • 3.3 Conduct reviews to determine if projects adhere to plans, are adequately documented, and produce accurate status reports.
  • 3.4 Assess controls during the requirements, acquisition, development, and testing phases for compliance with organizational policies, standards, procedures, and applicable external requirements.
  • 3.5 Evaluate system readiness for implementation and migration into production to ensure deliverables, controls, and organizational requirements are satisfied.
  • 3.6 Perform post-implementation reviews of systems to verify that deliverables, controls, and organizational requirements have been met.

Domain 4—Information Systems Operations, Maintenance and Support (23%)

Provide assurance that processes for information systems operations, maintenance, and support align with organizational strategies and objectives.

  • 4.1 Perform periodic reviews of information systems to confirm they continue to meet organizational objectives.
  • 4.2 Evaluate service level management practices to ensure service levels from internal and external providers are defined and managed effectively.
  • 4.3 Assess third-party management practices to verify adherence to required control levels by the provider.
  • 4.4 Review operations and end-user procedures to ensure scheduled and unscheduled processes are completed as intended.
  • 4.5 Evaluate information systems maintenance processes to confirm effective control and continued support for organizational objectives.
  • 4.6 Assess data administration practices to determine database integrity and optimization.
  • 4.7 Evaluate the use of capacity and performance monitoring tools and techniques to verify that IT services meet organizational objectives.
  • 4.8 Assess problem and incident management practices to ensure incidents, problems, or errors are recorded, analyzed, and resolved in a timely manner.
  • 4.9 Review change, configuration, and release management practices to confirm that changes to the production environment are adequately controlled and documented.
  • 4.10 Evaluate backup and restore provisions to ensure the availability of information required to resume processing operations.
  • <1.11 Assess the disaster recovery plan to determine if it enables the recovery of IT processing capabilities following a disaster.

Domain 5—Protection of Information Assets (30%)

Provide assurance that the organization’s security policies, standards, procedures, and controls ensure the confidentiality, integrity, and availability of information assets for government use.

  • 5.1 Evaluate information security policies, standards, and procedures for completeness and alignment with recognized best practices.
  • 5.2 Assess the design, implementation, and monitoring of system and logical security controls to verify the confidentiality, integrity, and availability of information.
  • 5.3 Evaluate the design, implementation, and monitoring of data classification processes to ensure alignment with organizational policies, standards, procedures, and applicable external requirements.
  • 5.4 Assess physical access and environmental controls to determine whether information assets are adequately protected.
  • 5.5 Review processes and procedures for the storage, retrieval, transport, and disposal of information assets, including backup media and hard copy data, to ensure adequate safeguarding.

Requirements

This course does not impose specific entry requirements. However, ISACA mandates a minimum of five years of professional experience in information systems auditing, control, or security for eligibility toward full certification. Candidates are permitted to sit for the CISA examination before fulfilling ISACA’s experience criteria, though the official qualification is granted only after those prerequisites are satisfied. Instructors recommend that delegates achieve CISA status at the earliest stage of their careers to apply globally recognized IT auditing standards within government operations.

 28 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories