CISA (Certified Information Systems Auditor) – ინფორმაციული სისტემების აუდიტი, მართვა და კონტროლი დაგეხმარებათ შეაფასოთ, მართოთ და უზრუნველყოთ ორგანიზაციის IT ინფრასტრუქტურის, ინფორმაციული უსაფრთხოებისა და ბიზნეს პროცესების შესაბამისობა, ეფექტურობა და უსაფრთხოება. კურსი ეფუძნება ISACA-ს გლობალურად აღიარებულ მეთოდოლოგიას, რომელიც წარმოადგენს ოქროს სტანდარტს IT აუდიტისა და კონტროლის სფეროში.
კურსის ფარგლებში მიიღებთ საფუძვლიან ცოდნას, თუ როგორ ჩაატაროთ რისკზე დაფუძნებული IT აუდიტი, შეაფასოთ IT მმართველობა (Governance), შეამოწმოთ სისტემების შემუშავებისა და დანერგვის პროცესები, უზრუნველყოთ ბიზნესის უწყვეტობა და დაიცვათ ინფორმაციული აქტივები თანამედროვე ციფრულ გარემოში.
ღირებულება მოიცავს როგორც ტრენინგს, ისე საერთაშორისო გამოცდაზე გასვლას/სერტიფიცირებას.
ვისთვის არის განკუთვნილი ტრენინგი:
ტრენინგი განკუთვნილია IT აუდიტორებისთვის, შიდა და გარე აუდიტორებისთვის, ინფორმაციული უსაფრთხოებისა და რისკების მართვის სპეციალისტებისთვის, IT მენეჯერებისთვის, Compliance (შესაბამისობის) ოფიცრებისთვის და IT პროფესიონალებისთვის, ვისაც სურს გაიღრმავოს ცოდნა და მოემზადოს CISA-ს საერთაშორისო სერტიფიცირებისთვის.
პროცესი, თეორიულ ნაწილთან ერთად, მოიცავს ქართულ რეალობას მორგებულ პრაქტიკულ მაგალითებსა და ქეისებს და წარიმართება სრულად ქართულ ენაზე.
ტრენერი
ლაშა-გიორგი ჭელიძე – ISACA-ს აკრედიტებული ტრენერი
ბენეფიტები და სერტიფიცირება
კურსზე დარეგისტრირებული მონაწილეები მიიღებენ წვდომას ოფიციალურ სასწავლო მასალებზე და მომზადდებიან CISM-ის საერთაშორისო სასერტიფიკაციო გამოცდისთვის.
კურსის დასრულების შემდეგ თქვენ:
შეისწავლით IS აუდიტის სტანდარტებსა და რისკზე დაფუძნებული აუდიტის დაგეგმვის პრინციპებს
შეძლებთ IT მმართველობის (Governance), სტრატეგიისა და რისკების მართვის ეფექტურობის შეფასებას
შეგეძლებათ ინფორმაციული სისტემების შესყიდვის, შემუშავებისა და დანერგვის პროცესების შემოწმება
შეაფასებთ IT ოპერაციებს, მონაცემთა ბაზებს, ინციდენტების მართვასა და ბიზნესის უწყვეტობის (BCP/DRP) გეგმებს
გააანალიზებთ ინფორმაციული აქტივების დაცვის, წვდომების მართვის (IAM), ქსელური უსაფრთხოებისა და ღრუბლოვანი გარემოების კონტროლის მექანიზმებს
გამოიყენებთ აუდიტის მონაცემთა ანალიტიკას (Audit Data Analytics) და მტკიცებულებების შეგროვების ტექნიკებს
იქნებით მზად CISA (Certified Information Systems Auditor) საერთაშორისო გამოცდაზე გასვლისთვის.
Information System Auditing Process
IS audit standards, guidelines, functions, and codes of ethics
Types of audits, assessments, and reviews
Risk-based audit planning
Types of controls and considerations
Audit project management
Audit testing and sampling methodology
Audit evidence collection techniques
Audit data analytics
Reporting and communication techniques
Quality assurance and improvement of the audit process
Governance and Management of IT
Laws, regulations, and industry standards
Organizational structure, IT governance, and IT strategy
IT policies, standards, procedures, and guidelines
Enterprise architecture and considerations
Enterprise risk management (ERM)
Data privacy program and principles
Data governance and classification
IT resource and vendor management
IT performance monitoring and reporting
Quality assurance and quality management of IT
Information Systems Acquisition, Development & Implementation
Project governance and management
Business case and feasibility analysis
System development methodologies
Control identification and design
System readiness and implementation testing
Configuration and release management
System migration, infrastructure deployment, and data conversion
Post-implementation review
Information Systems Operations and Business Resilience
IT components, asset management, and job scheduling
System interfaces; end-user computing and shadow IT
Systems availability and capacity management
Problem and incident management
IT change, configuration, and patch management
Operational log management and IT service level management
Database management
Business impact analysis; system and operational resilience
Data backup, storage, and restoration
Business continuity and disaster recovery plans
Protection of Information Assets
Information asset security policies, frameworks, and standards
Physical and environmental controls
Identity and access management
Network and endpoint security; data loss prevention
Data encryption and public key infrastructure (PKI)
Cloud and virtualized environments
Mobile, wireless, and Internet-of-Things device security
Security awareness training and programs
Attack methods, security testing tools, and monitoring
Security incident response, evidence collection, and forensics