Showing posts with label Auditing (ISMS). Show all posts
Showing posts with label Auditing (ISMS). Show all posts

Tuesday, 2 October 2012

Information System Auditing


1. What is informaton system?
Information system is any combination of information technology and human operation managemen and dececion making.

2. What is information system auditing?
Ron Weber opinion (1999,p.10), “EDP auditing is the process of collecting and evaluating evidence to determine whether a computer systems safeguard assets, and consumes resources effiently ”.Understanding in general is the process of collecting and evaluating evidence to determine whether a computerized application system has been set and implement the system, adequate internal controls, all assets are protected well / not abused, and ensuring data integrity, reliability and the effectiveness and efficiency of the system computer-based information.

Saturday, 29 September 2012

CISA Review Manual 2012 - Powered By ISACA


The CISA Review Manual 2012 is a comprehensive reference guide designed to help individuals prepare for the CISA exam and understand the roles and responsibilities of an information systems (IS) auditor. The manual has been enhanced over the past editions and represents the most current, comprehensive, peer-reviewed IS audit, assurance, security and control resource available worldwide.

The 2012 manual is organized to assist candidates in understanding essential concepts and studying the following updated job practice areas:
  1. The Process of Auditing Information Systems.
  2. Governance and Management of IT.
  3. Information Systems Acquisition, Development and Implementation.
  4. Information Systems Operations, Maintenance and Support.
  5. Protection of Information Assets.

Sunday, 2 September 2012

Syness-The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments | For ISO 27001(BS7979), PCI-DSS, HIPPA, FISCAM, COBIT


The IT Regulatory and Standards Compliance Handbook: How to Survive Information Systems Audit and Assessments

Publisher: Syngress 2008 | 750 Pages | ISBN: 1597492663 | PDF | 11 MB

This book provides comprehensive methodology, enabling the staff charged with an IT security audit to create a sound framework, allowing them to meet the challenges of compliance in a way that aligns with both business and technical needs. This “roadmap” provides a way of interpreting complex, often confusing, compliance requirements within the larger scope of an organization’s overall needs.

Monday, 28 May 2012

ISO 27001 Implementation Checklist



ISO/IEC 27001, part of the growing ISO/IEC 27000 family of standards, is an Information Security Management System (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

Its full name is ISO/IEC 27001:2005 - Information technology -- Security techniques -- Information security management systems -- Requirements.


If you are starting to implement ISO 27001, you are probably looking for an easy way to implement it. Let me disappoint you: there is no easy way to do it.However, I'll try to make your job easier - here is the list of sixteen steps you have to go through if you want to achieve ISO 27001 certification: