获得专家指导, 研究政策和程序,以便在IT审计和保证职业生涯中保持领先地位.

零信任审计计划

零信任审计计划

零信任是一种安全模型,它要求组织网络的所有用户都经过身份验证, 授权, 综述了, and validated periodically to ensure appropriate access privileges are granted and maintained and more importantly rights are deactivated when they are no longer needed to perform work duties.

谷歌云平台审计程序

谷歌云平台审计程序

随着谷歌的不断发展和普及® 云平台®),目前是第三大云服务提供商, ISACA has developed an audit program that helps auditors assess and test 控制 coverage adequacy and effectiveness of GCP® 服务.

身份和访问管理审核程序

身份和访问管理审核程序

ISACA的 身份和访问管理审核程序 provides specific testing and evaluation criteria to assist auditors in assessing the adequacy of safeguards in place to mitigate IAM risks.

审计从业者机器学习指南,第1部分

审计从业者机器学习指南,第1部分:技术

机器学习(ML), 人工智能的一个子集, 已被世界各地的澳门赌场官方下载和政府迅速采用.

审计从业者机器学习指南,第2部分

审计从业者机器学习指南,第2部分:合规风险

机器学习(ML), 人工智能的一个子集, 已被世界各地的澳门赌场官方下载和政府迅速采用.

物理和环境安全审计程序

物理和环境安全审计程序

网络安全 and audit practitioners may talk in terms of physical security being a part of cybersecurity or physical security being a subset of cybersecurity. 虽然在网络安全方面如何定义物理安全可能存在不同的意见, there is agreement that physical security may be overlooked while digital threats are considered from many perspectives.

数据库审计程序

数据库审计程序

数据库, 由数据和数据库管理系统组成, 存储数据,以便它们可以被不同的程序使用,而不必考虑数据结构或组织. 数据库容纳大量数据的能力, 导致数据库被广泛采用吗.

COBIT为DevOps审计程序

COBIT为DevOps审计程序

ISACA开发了这个审计程序,作为COBIT重点领域:开发运维,使用COBIT的伙伴® 2019. The focus area publication describes how COBIT framework concepts apply to DevOps and is intended to help enterprises evaluate management practices important to the development of an effective governance system over DevOps.

VPN安全审计程序

VPN安全审计程序

依靠虚拟专用网络(vpn),远程工作人员可以安全地访问公司网络. As the number of remote workers and the duration of remote work have increased (from remote working being temporary to potentially permanent), 人们对vpn的认识也在增长. 现在,澳门赌场官方下载开始质疑vpn的安全性.

MD-WHPAA

目标:敏捷审计

目标:敏捷审计, you will find a history lesson on Agile—from its beginning to more recent adoption approaches—as well as insight into the benefits of incorporating Agile into enterprise audit practices. 获得敏捷审计工具集使用的预览, 学习提高专业敏捷能力的方法, 并了解敏捷审计实践如何成功地集成到传统的计划中, 实地考察, 审计项目的报告阶段.

witaf4

IT审计框架,第四版

获得指导和技术,使您的审核具有一致性和有效性. 新的4th edition of ITAF outlines standards and best practices aligned with the sequence of the audit process (risk assessment, 计划和实地工作),以指导您评估澳门赌场官方下载的运营有效性

资讯科技审核抽样指引(指引2208)

资讯科技审核抽样指引(指引2208)

ISACA created the 信息技术 Audit Sampling guidelines (Guidelines 2208) as a companion to its 信息技术 Audit Framework (ITAF™). The purpose of these guidelines is to provide guidance to IT audit and assurance practitioners in designing and selecting an audit sample and evaluating sample results. 适当的抽样和评价有助于达到充分和适当证据的要求.

IT audit and assurance practitioners should consider these guidelines when reaching a conclusion about a total population when audit procedures are applied to less than 100 percent of that population.

Advance your expertise and add to your career potential or enterprise skillset with training developed and delivered by the experts in IT audit.

中钢协

注册资讯系统审核员(中钢协)

中钢协认证作为审计人员的成就标准而享誉世界, 控制, 监督和评估组织的信息技术和业务系统. 对于寻求职业发展杠杆的IT专业人员来说,这个认证是必须的. 中钢协考试现在可以通过远程监考!

了解更多

中钢协

来自ISACA的中钢协考试准备

Whether you prefer to prep on your own time or with the additional guidance and interaction that comes with live, 专家指导, ISACA为每位专业人士提供合适的备考解决方案. 选择适合你的时间表和学习需要的方法.

了解更多

零信任审计计划

零信任审计计划

零信任是一种安全模型,它要求组织网络的所有用户都经过身份验证, 授权, 综述了, and validated periodically to ensure appropriate access privileges are granted and maintained and more importantly rights are deactivated when they are no longer needed to perform work duties.

查看IT审计出版物和资源

Gain additional insight and guidance on leveraging the 它的审计 framework to create and maintain the most effective techniques and understanding to manage 它的审计.