CISA (Certified Information Systems Auditor) – Information Systems Auditing, Governance, and Control will help you evaluate, manage, and ensure the compliance, efficiency, and security of an organization’s IT infrastructure, information security, and business processes. The course is based on ISACA’s globally recognized methodology, which serves as the gold standard in IT audit and control.
Within the course, you will gain comprehensive knowledge on how to conduct risk-based IT audits, evaluate IT governance, assess system acquisition, development, and implementation processes, ensure business resilience, and protect information assets in a modern digital environment.
The course fee includes both the training and the international certification exam (exam voucher).
Who Should Attend?
This training is designed for IT auditors, internal and external auditors, information security and risk management specialists, IT managers, compliance officers, and IT professionals looking to deepen their expertise and prepare for the international CISA certification.
In addition to the theoretical foundation, the course includes practical case studies tailored to the Georgian business and regulatory environment. The training is delivered entirely in Georgian.
Mentor:
Lasha-Giorgi Chelidze – ISACA Accredited Trainer
Benefits & Certification
Participants enrolled in the course will receive access to the official training materials and comprehensive preparation for the internationally recognized CISA certification exam.
Upon successful completion of the training, you will be able to:
earn IS audit standards and risk-based audit planning principles;
Evaluate the effectiveness of IT governance, strategy, and risk management;
Audit information systems acquisition, development, and implementation processes;
Assess IT operations, databases, incident management, and business continuity (BCP/DRP) plans;
Analyze control mechanisms for information asset protection, Identity and Access Management (IAM), network security, and cloud environments;
Apply audit data analytics and evidence collection techniques;
Be ready to sit for the CISA (Certified Information Systems Auditor) international exam.
Information System Auditing Process
IS audit standards, guidelines, functions, and codes of ethics
Types of audits, assessments, and reviews
Risk-based audit planning
Types of controls and considerations
Audit project management
Audit testing and sampling methodology
Audit evidence collection techniques
Audit data analytics
Reporting and communication techniques
Quality assurance and improvement of the audit process
Governance and Management of IT
Laws, regulations, and industry standards
Organizational structure, IT governance, and IT strategy
IT policies, standards, procedures, and guidelines
● Enterprise architecture and considerations
Enterprise risk management (ERM)
Data privacy program and principles
Data governance and classification
IT resource and vendor management
IT performance monitoring and reporting
Quality assurance and quality management of IT
Information Systems Acquisition, Development & Implementation
Project governance and management
Business case and feasibility analysis
System development methodologies
Control identification and design
System readiness and implementation testing
Configuration and release management
System migration, infrastructure deployment, and data conversion
Post-implementation review
Information Systems Operations and Business Resilience
IT components, asset management, and job scheduling
System interfaces; end-user computing and shadow IT
Systems availability and capacity management
Problem and incident management
IT change, configuration, and patch management
Operational log management and IT service level management
Database management
Business impact analysis; system and operational resilience
Data backup, storage, and restoration
Business continuity and disaster recovery plans
Protection of Information Assets
Information asset security policies, frameworks, and standards
Physical and environmental controls
Identity and access management
Network and endpoint security; data loss prevention
Data encryption and public key infrastructure (PKI)
Cloud and virtualized environments
Mobile, wireless, and Internet-of-Things device security
Security awareness training and programs
Attack methods, security testing tools, and monitoring
Security incident response, evidence collection, and forensics