Welcome to cissp CISSP training Certified Information Systems Security Professional
Search
Nickname Password Security Code Security Code Type Security Code  

You are certified but are your qualified?  Become qualified today.

FITSI the certification program for the federal workforce

Rated #1 Training

Surveys

Where do you find the best price for books?

Amazon.Com
Bookpool.Com
The ISC2 webstore
CISSPS.COM
Cheapbooks.com
Ecampus.com
Other (Please leave a comment with name of site)



Results
Polls

Votes: 1436
Comments: 33

Who's Online

There are currently, 76 guest(s) and 13 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

Training Classes Calendar

Test of Widget

 

cissp CISSP training Certified Information Systems Security Professional: CISA

Search on This Topic:   
[ Go to Home | Select a New Topic ]

Auditing information resources
Posted by boss on Monday, 21 July 2008 @ 11:38:58 EDT (1179 reads)
Topic CISA

cdupuis writes "

Dan Swanson’s Security Resources: #11

Auditing information security helps identify key improvement opportunities while studying leading audit guidance provides a better understanding of what the auditors are looking for, helping make audits more productive (a true win/win).

 

Taking the perspective of a board director will help focus your efforts on what the board is concerned about. Board guidance also tends to be very concise (very focused), i.e. they are great reports to study closely. Finally, getting your unplanned work under control will help make your life better, full stop.

 

Enjoy.

 

Good luck and have another great week.

 

Dan Swanson

Dswanson_2005@yahoo.com

 

 

Management Planning Guide for Information Systems Security Auditing

Produced by the National State Auditors Association and the US General Accounting Office.

http://www.gao.gov/special.pubs/mgmtpln.pdf

 

Information Technology and the Board - ”An Insightful Resource”.

http://www.deloitte.com/dtt/article/0%2C1002%2Ccid%25253D152626%2C00.html

 

What the Board Needs to Know About IT: Phase II Findings

Maximizing performance through IT strategy

http://www.deloitte.com/dtt/article/0,1002,sid=36692&cid=151800,00.html


Unplanned Work: The Silent Killer

Find out how unplanned work - those activities not mapped to any project, procedure or change request - is undermining the effectiveness of your IT efforts.

http://www.networkworld.com/whitepapers/nww/pdf/Tripwire_Unplanned_Work_Management_Paper.pdf

20 Questions Directors Should Ask About IT (Revised April 2004)

Information technology is a critical part of an organization’s internal control and management information system. Ensuring its integrity is an important responsibility for board members. ITAC has compiled 20 key questions about IT that should be asked about: strategic planning and technology, performance and personnel issues, internal control issues, risk and security, information privacy, e-business, availability policies, and legal issue.

http://www.cica.ca/index.cfm/ci_id/1000/la_id/1


The Federal Government of Canada (GOC) Internal Audit Guides

Audit of Information Technology Security audit guide
http://www.tbs-sct.gc.ca/Pubs_pol/dcgpubs/tb_h4/01guid01_e.asp
Audit of Security audit guide
http://www.tbs-sct.gc.ca/ia-vi/policies-politiques/gas-gvs/gas-gvs_e.asp
Various other GOC internal audit guides
http://www.tbs-sct.gc.ca/ia-vi/common/guides_e.asp

For more of Dan's great resources visit:  http://blogs.itworldcanada.com/security/category/audit/

"

(Read More... | 3 comments | Score: 0)


AuditNet News for Auditors
Posted by boss on Sunday, 09 December 2007 @ 13:56:49 EST (1776 reads)
Topic CISA

cdupuis writes "

December 2007

AuditNet News is sponsored by Paisley and PricewaterhouseCoopers TeamMate

Paisley - FREE CHECKLIST:

Ten Key Steps to Implement AS5 Key steps and recommended actions to implement the required AS5 standards. Download Today.

http://www.paisley.com/website/pcweb.nsf/fm_Cookie?openForm&r=ANN1107&docID=ARAE-746TUP

PricewaterhouseCoopers TeamMate, a database-driven audit management system that streamlines the audit process by providing integrated tools for documentation, report generation and file sharing. For more information about TeamMate, visit www.pwc.com/teammate

Online Version

http://www.auditnet.org/auditnet-l.htm

 

1. IT Governance Frameworks Help Align Business and IT Interests and Objectives By Przemek Tomczak, Protiviti Associate Director

2. Data Analysis: Establishing a Repeatable Audit Process Using Excel by Mike Blakely

3. Dans Column: Have you assessed your information security program lately?

4. Global Best Practices: What's new: Uncover the gap with a no-cost benchmarking survey

5. Resume Tune-Up by Robbie Miller Kaplan Dig Deep!

6. Recovery Auditing: Detecting Fraud in Health Claims

7. IIA Technology Audit Guide Series Auditing Application Controls AuditNet

8. AuditNet Creates a New Networking Tool Through LinkedIn - Professional Audit Information Networking (PAIN) Group

9. Ask the Auditor: Fixed Asset Inventory Counts

10. AuditNet Information Security Corner Protect Yourself from Hard Drive Leakage by Rey Leclerc

11. Financial Safeguards in Construction Contracts by Gursharan Singh

12. White Collar Crime Fighting News: Read the latest newsletter

New Audit Programs Added This Month

Credit & Collection Financial Controls (Dec 07)
Competency Management Human Resources (Dec 07)
Corporate Performance Management Financial Controls (Dec 07)
Procurement to Payment Cycle Transportation Management-Retail (Dec 07)
Procurement to Payment Inbound Logistics Control (Dec 07)
Procurement to Payment Invoice Reconciliation and Payment Control (Dec 07)
Sales Order to Receipt Cycle-Retail (Dec 07)
Succession Planning Human Resources (Dec 07)
Supply Chain Finance Financial Controls (Dec 07)
Talent Acquisition and Retention Human Resources-Retail (Dec 07)

Training News:

The 6th Annual Summit on Auditing and Governance December 3-4, 2007, New York, NY Optional Workshop(s): December 2 & 5 http://www.misti.com/default.asp?page=65&Return=70&ProductID=7467

All of the above articles are available in the current online newsletter at www.auditnet.org/auditnet-l.htm.

New

AuditNet can now process your credit card payments for premium access by phone or fax.

AuditNet moved to a dedicated server! Please report broken links. Thanks for your patience during the transition.

Renew your subscripton to AuditNet Premium content by December 31, 2007 and receive 13 months for the price of 12!

The opinions, beliefs and viewpoints expressed by the various authors and forum participants on this web site do not necessarily reflect the opinions, beliefs and viewpoints of AuditNet or Jim Kaplan

Jim Kaplan


"

(comments? | Score: 0)


New CISA study guide uploaded to the web site
Posted by boss on Friday, 10 August 2007 @ 21:30:17 EDT (1955 reads)
Topic CISA

cdupuis writes "A new study guide has just been uploaded for the CISA certification.

I would like to thank Julie Baker for this great contribution.

I invite all members to contribute as well.

Click HERE to download the guide
"

(comments? | Score: 0)


Windows Security: What IT auditors don’t check!
Posted by boss on Wednesday, 28 March 2007 @ 19:50:19 EDT (1549 reads)
Topic CISA

vsanker writes "Windows Active Directory environment is a major component of IT infrastructure, in most organizations. There are certain key areas within the Windows environment which are not typically audited, but carry a significant level of risk to the enterprise. An attempt is made in the following article to identify some of those key areas for your next Windows audit!

As an IT auditor who moved from IT Security to IT audit few years back, I was scrambling to identify what needs to be audited in the organization’s various IT systems/applications. While conceptually, IT Security and IT Audit are intended to deliver identical result, (which is to ensure a secure computing environment), the audit approach is quite different from the security approach. While the IT Security practitioner refers to best practice vendor recommendations, the auditor relies on well known control frameworks.

From an auditor’s standpoint, identifying the specific controls to be tested in any environment is the key task and the auditor’s prior knowledge of the environment would be obviously beneficial. While referring to published sources of auditing information for Windows Active Directory environment I was surprised to note that some of the key security configurations/access controls are typically not recommended from an IT Audit perspective. While Group Policies/Active Directory (AD) provisioning environment are almost always audited, certain key areas delineated below are rarely audited.

Click on Read More.... below to see this whole article
"

(Read More... | 7126 bytes more | 4 comments | Score: 4)


EFFECTIVE APPROACH AND PRACTICAL TIPS FOR CISA EXAM
Posted by boss on Saturday, 10 February 2007 @ 23:20:01 EST (3305 reads)
Topic CISA

cdupuis writes "A.Rafeq, FCA, CISA, CQA, CFE, CIA, Past President, ISACA Bangalore Chapter

and

Shirish S. Deshpande, FCA, CISA, Past President, ISACA Pune Chapter

This article consists of two sections. The first section provides a effective approach for CISA exam and second section provides practical tips before, during, at and after the exam.

I. EFFECTIVE APPROACH TO CISA Exam A. Objective of CISA Exam

The CISA Exam Bulletin states that the CISA program is designed to assess and certify individuals in the IS Audit, control, assurance and security professions who demonstrate exceptional skill and judgment. The CISA exam is offered each year in June and December and consists of 200 multiple-choice questions, administered during a four-hour session. The purpose of the exam is to test a candidate’s knowledge, evaluation and application of IS audit principles and practices and six technical content areas covering IS Audit process, IT Governance, Systems and Infrastructure life cycle, protection of information assets and Business continuity and disaster recovery.

Get the document at:

http://www.cccure.org/modules.php?name=Downloads&d_op=viewdownload&cid=75

"

(Read More... | 2 comments | Score: 5)


OSG NEWS: CISA EXAM STUDY TIPS
Posted by boss on Saturday, 10 February 2007 @ 07:47:51 EST (3422 reads)
Topic CISA

cdupuis writes " EFFECTIVE APPROACH AND PRACTICAL TIPS FOR CISA EXAM

 

A.Rafeq, FCA, CISA, CQA, CFE, CIA, Past President, ISACA Bangalore Chapter

and

Shirish S. Deshpande, FCA, CISA, Past President, ISACA Pune Chapter

 

This article consists of two sections. The first section provides a effective approach for CISA exam and second section provides practical tips before, during, at and after the exam.

 

I. EFFECTIVE APPROACH TO CISA Exam A. Objective of CISA Exam

 

The CISA Exam Bulletin states that the CISA program is designed to assess and certify individuals in the IS Audit, control, assurance and security professions who demonstrate exceptional skill and judgment. The CISA exam is offered each year in June and December and consists of 200 multiple-choice questions, administered during a four-hour session. The purpose of the exam is to test a candidate’s knowledge, evaluation and application of IS audit principles and practices and six technical content areas covering IS Audit process, IT Governance, Systems and Infrastructure life cycle, protection of information assets and Business continuity and disaster recovery.

B. Understanding of Information Technology (IT)

 

The CISA exam questions are developed and maintained carefully to ensure they accurately test an individual’s proficiency in IS audit, control and security practices. Hence, CISA Candidates are expected to have working knowledge of IT, auditing, control and security practices. The basic understanding of IT should cover key concepts of various components of Information Technology in their practical deployment. The IT knowledge should encompass overall understanding of IT Infrastructure, IT Facilities, various types of Computer hardware, Systems Software (Operating System, Database, Networking, Multimedia, etc), Business Application software, Office Automation Software and Audit Software. Further, candidates are expected to know concepts and practice of Management as relevant to IT deployment in enterprises.

C. CISA Review Manual (CRM) – Basic reference material

 

CISA Candidates are advised to read the CISA Exam Bulletin of information for understanding details of CISA exam. The Candidates guide to CISA exam must be read to understand broad range of job/process content areas covered including objective, tasks and knowledge statements. The CRM elaborates and covers the topics as per the job/process content areas and including task and knowledge statements. Candidates are advised to use the CRM as the basic guide for learning and supplement additional material as required based on their assessment of gaps and individual competency areas. CRM is not expected to teach fundamental concepts of Information Technology. However, IT components are explained only to the extent required.

D. Conceptual Clarity

 

CISA Candidates need to have conceptual clarity in the following key areas:

  • Risks in deployment of Implementing Information Technology
  • Appropriate risk management strategy for mitigating these risks.
  • Security and controls, which need to be implemented for risk mitigation.
  • Strategy, approach, methodology and techniques for auditing technology.

E. Need for working knowledge of IT

 

Candidates who are not well conversant with IT are advised to do a practical course on IT covering hardware, systems software, office automation, business applications and audit software. This is no substitute for working knowledge but would help familiarize candidates with IT in their practical deployment.

F. Getting CISA Perspective – practical approach

 

The overall understanding of a CISA candidate is expected to cover the related content areas as per the objectives, tasks and knowledge statements given in the Candidates Guide to CISA Exam. Primarily it encompasses three major disciplines - Information Technology, Management, Auditing, control and security practices. The CISA candidates may follow the following approach for getting the perspective of a CISA:

  • Obtain overall understanding of Information Technology – concepts and practice
  • Understand the Risks of deployment of relevant IT Component
  • Know the features and functionalities of security and controls of IT Component
  • Understand how controls could be implemented using the security features and functionalities so as to mitigate the risks in the relevant IT Component
  • Learn how to audit IT components by understanding the risks, review related security, evaluate implemented controls, identify areas of weaknesses and provide appropriate recommendations to mitigate the control weakness.
G. Reference Material for CISA Exam

 

The CISA Review Manual (latest) as relevant to the exam is the best reference material for the exam. This should be supplemented with other material as required. In addition to this, the CISA Questions, Answers and Explanations Manual or CD is an excellent reference point for practicing questions. Please read articles of IS Control Journal of last two years. COBIT Control objectives can be read to understand Controls for various IT processes. Answer the CPE quiz of journal. Sample On-line references are given below:

 

Candidates may read the article published in ISACA Journal 2006-1 titled: “Preparing for the CISA or CISM Examination: A Brief, Hands-on Supplement for Candidates” By Derek J. Oliver, CISA, CISM, CFE, and Max Shanahan, CISA, FCPA

 


II. Practical Tips for CISA Exam A. Before the exam

 

  1. Take a decision early when to take exam. Please remember that early registration reduces fees and also provides you more time for preparation. Make early commitment so that you have more time and save money but don’t postpone your preparation. You need to be regular and consistent in your preparation

 

  1. Read the “CISA Exam Bulletin of Information” and “Candidates guide to CISA exam” to get overall understanding of exam and scope of coverage of the exam.

 

  1. Use the CISA Review Manual as the basic reading material and supplement other material as and when required. If you are from IT, you need to get basic concepts of Auditing right. IT Auditing by Ron Weber could be an excellent book to refer. However, pick up only what is relevant to read. If you are an auditor, then basic book on computers and networking could be referred in addition to doing basic course on computers.

 

  1. Take your family and friends into confidence so that you are able to sacrifice your social commitments and focus on the exam.

 

  1. Motivation is an important aspect of preparation for the exam. Motivation will help you concentrate and be focused on the task on hand. Self Motivation is the best motivation. Remember, you are taking a prestigious and global recognized exam, which will make a significant difference to your career, earnings and your self-esteem. Visualize receiving the Congratulations letter from ISACA and CISA Certification. See yourself being congratulated by your peers and colleagues.

 

  1. The Exam is not Technology or platform specific. Hence, do not get too engrossed with technology details and reading of technology. Focus during your study to get clarity on the fundamentals. Read the IS Auditing standards, guidelines and COBIT Control objectives to get the thinking of an IS Auditor. Put on the cap of the global IS Auditor. Don’t bring in your personal experience and answer questions from your past data unless it is in line with ISACA’s thinking. Please don’t think what is practiced in your technology platform or industry as it may not be applicable or relevant.

 

  1. Make a time plan of what you need to read and prioritize. Deal with unread materials concisely. Formulate a reading strategy in advance with a time table and study plan.

 

  1. The approximate time required for preparing for the exam is subjective and depends on the individual competency, skill-sets and learn-ability. However, it is advisable to study for about 2 hours for 3 to 4 months. The best time to study is as per your regular habit. Follow a regular schedule which is most convenient to you but ensure consistency.

 

  1. Practice the questions and get the reasoning and choice correctly. Remember, the exam is not expected to test your memory but your understanding. Hence, don’t cram any definitions or concepts except the most fundamental ones and that too for understanding.

 

  1. Practice, practice and practice questions available with you. But remember the standard of the questions in the exam is much higher than what you have practiced. Be mentally prepared. If you have conceptual clarity and apply your thinking as an IS Auditor, you should be able to pick up the right answer.

 


  1. Use the CISA Questions, Answer and Explanations Manual for pactising the questions. Answer questions in a block of 100 at a time and then review your performance.
    1. Evaluate your performance both for correct and incorrect answers.
    2. You should have got the correct answers by choice not by chance and for the incorrect answers, analyze why you got it wrong:

i. Is it because your logic was wrong or you did not know the topic of the question.

ii. If you got the answer wrong because the logic was wrong, think, introspect and get your logic right.

iii. If you got the answer wrong because you did not know the topic of the question, read the CRM or additional material as required.

    1. After you have done the above evaluation for the 100 questions, answer the questions again and evaluate, you should have got 100% right. You may not, then repeat the above steps till you get 100% right.
    2. Once you have 100% right, then repeat for next 100 questions and follow the above cycle given above. Keep repeating this till you complete all questions.
    3. After you have completed answering all the questions, then answer the questions in block of 200 questions at a time; evaluate your timing and performance.
    4. After you have practised all the questions, then read the CRM once fully and answer the questions.

 

  1. Consider joining local CISA Review Course. The CISA review courses are conducted by many ISACA chapters. These courses are often taught by current CISAs who present and discuss exam topics and share their secrets of success.

 

  1. Form a small study group or join an e-group for studies and discussions. Review your preparation actively alone and also with group on a regular basis. Review and discuss with group your logic and reasoning and get other perspective also.

 

  1. Focus on ensuring that you get the required knowledge and competency rather than worrying about your prospects of passing the exam. Don’t be too concerned about the percentage of pass or how to apply for certification. Focus on passing the exam first.

 

  1. Don’t sit up late day before the exam trying to read and catch up on lost time. Remember, the principle of farming, you need to sow in time and take care on regular basis so as to reap in time. Last minute preparations may result in lack of concentration in the exam.

 

  1. Prepare yourself emotionally and physically to take the exam. If you have any medical problems, which hinder your sitting for long stretch of time, or you need regular medication, inform the proctor in advance and take necessary precaution.

 

  1. Don’t stress yourself physically before or during the exam. You need to be fully relaxed so as to have maximum concentration. Avoid last minute reading and late night reading before the exam day. It may not really help. Please also take care of your food intake so that you are able to concentrate well during the exam.

 

  1. You may need probably all of four hours to answer 200 questions. Hence, it is essential that you practice sitting at one place and practicing answering the mock tests so that you get practice of sitting for four to five hours at a stretch.

 


B. About the Exam

 

  1. The exam is objective (multiple-choice). The answer is available in the choices. Hence, the approach to studies should not be from the perspective of remembering but more from perspective of understanding.

 

  1. The CISA Exam Questions could be broadly categorized into 2 categories:
    1. Based on Facts – technology, auditing standards. No specific technology related questions. For eg: SAP, Oracle, SQL, etc.
    2. Based on Analysis – context and decision oriented. These questions require you to understand the scenario and formulate your opinion/judgment.

 

  1. In every case, the candidate is required to read the question carefully, eliminate known incorrect answers and then make the best choice possible. Every CISA question has a stem (question) and four options (answer choices). The candidate is asked to choose the correct or best answer from the options. The stem may be in the form of a question or incomplete statement. In some instances, a scenario or description problem may also be included. These questions normally include a description of a situation and require the candidate to answer two/more questions based on the information provided. The candidate has to read each question carefully. Many times a CISA exam question will require the candidate to choose the appropriate answer that is MOST likely or BEST.

 

  1. To assist candidates taking the exam with the translation of technical terminology, a list of the most frequently used technical terms in English along with how they will appear on the exam in other languages offered is available on ISACA’s web site at www.isaca.org/examterm.

 

  1. The Questions and choices are straightforward and simple. They are meant for testing your understanding of concepts and practice of IS Audit. They are not meant to test your grammar or proficiency in English. Hence, do not try to analyze the question and answers too much. Don’t waste time trying to read between the lines and find hidden meaning.

 

  1. The exam consists of one paper, which has all 200 questions. The questions are not in a particular order of domains or chapters but are usually mixed up at random. It is not worthwhile trying to figure out to which domain a question belongs. What is most important is how well you are able to answer the questions in the exam.

 

  1. The exam is based on percentile. The CISA exam consists of 200 items. Candidate scores are reported as a scaled scored. A scaled score is a conversion of a candidate's raw score on an exam to a common scale. ISACA uses and reports scores on a common scale from 200 to 800. A candidate must receive a score of 450 or higher to pass the exam. A score of 450 represents a minimum consistent standard of knowledge as established by ISACA’s CISA Certification Board. It is advisable not to worry too much about the percentile but focus on getting the maximum questions right.

 

  1. Generally, the style of writing in the CISA Exam is based on American English and it follows American Spelling. Hence, please get acquainted by practicing the questions in CISA review manual and CISA Questions, Answers and Explanations manual.

C. Approach to exam

 

  1. As part of preparation, do discuss the questions and answers with an open mind. If you are auditor, get the technology perspective and if you are from IT, get the Audit perspective. Remember as an IS Auditor, you are expected to be auditing Technology as deployed in the organization.

 

  1. Familiarize yourself with the test. Know the tasks, knowledge and scope of the subject, the type of questions and proposed answers. The key ideas to be remembered as an IS Auditor are IS Risks, IS Security, IS Control and IS Audit. You need to be well versed with these concepts. The questions may require you to grade the risks in terms of highest or lowest. In terms of security and controls, you may be required to pick up the best or least effective controls in the context of the question. An IS Audit question may require your judgment in terms of concepts, practical procedures or risk ranking or presenting the findings to the management. There may be few questions, which tests your understanding of core technology. For example, encryption, EDI, Internet Security, Telecommunications control, etc.

 

  1. There are 200 questions to be answered in four hours. This would mean that approx. 70 seconds per question. Some of the questions may be answerable within 30 seconds and some may take more time. Further, in some cases, if you get lost in too much thinking, you may lose track of time and may not have time to answer all questions. Hence, it is essential to manage based on a slot of one hour or for a block of 50 questions. Depending on the progress, you can increase or decrease the pace as required.

 

  1. The questions are not directly picked up from any text book or reading material but are prepared by Practicing CISAs and are aimed to test your understanding of the concepts and practice of IS Audit.

 

  1. Remember that CISA is an objective type exam and just like any exam, it is not necessarily a reflection of your talent, capabilities, competencies or skill-sets. Hence, if you have not been or are not successful, then you should not take it personally. There are times when senior and experienced professionals have failed in the CISA exam not once but two to three times. It does not mean that they were not capable. This only means that they need to learn the knack of passing the exam. It is important to analyze what could have wrong and learn from them. It is quite possible that your current experience itself is becoming a baggage. Think from a new perspective and focus now only on questions and answers and read the topics where you need to.

 

  1. Learn to play the game of CISA. It is not just your knowledge but your ability to answer the questions which is very important. Most candidates who take the exam have most of the knowledge required to pass the CISA exam. You are possibly making the same mistake again and again because you are stuck in your approach. Hence, read the CRM afresh and answer the questions. Interact with other students and get your perspective right. If required, attend a CISA refresher course conducted by a nearby chapter. Identify where you are going wrong else you may commit the same mistakes again.

 


D. At the Exam

 

  1. Do not attempt to read through the question paper fully. You may lose time and may not have time to answer all the questions. The ideal method is to take up one question at a time and answer them one by one.

 

  1. You need to compartmentalize your mind and take one question at a time. Think and decide on the right answer. Once you have answered, forget it and go ahead and tackle the next one and so on. Don’t carry your doubts of the previous question to the next.

 

  1. There may be questions for which you may not be able to strike the right answer straight away. You may skip, but mark it in the questions paper so that it is identifiable and come back to it later. However, the best approach is to take a DECISION and answer it then and there. You may not have time to come back to the question again. Further, there may always be lurking feeling that you have left some questions unanswered. This will be at the back of your mind always. However, if you do have to change, please ensure that you erase the previous answer carefully and fully.

 

  1. Please do not think of coming back to the answers for corrections later on. You may change if and only if you are additional insights or data, which necessitates that your previous answer was incorrect.

 

  1. You may decide on which order you want to answer the questions. Some tend to start from question no. 50 or 100 as it gives them confidence they are progressing and come back. However, the ideal approach is to answer sequentially one at a time.

 

  1. Take one question at a time. Read it fully and carefully. Identify the stem, the key concept that is being tested. Underline the core concept, which is being tested. Read all the choices even if you think you have the right answer in the first or second or third choice.

 

  1. As there is no negative marking, you must answer all questions. Even in case of questions, where you are not sure of right answer, you may guess intelligently.

 

  1. For choosing the right answer, you may be able to identify the right answer straight away. You may also adapt the process of elimination by ruling out the apparently incorrect choices one by one so as to narrow down your choices and pick up the right choice.

 

  1. Every question will have one of the choices framed as a distracter. The distracter may attract those with incomplete knowledge or attempting to answer the question with just common sense. It is essential to be able to eliminate the distracter.

 

  1. You may mark the answers in your question paper and transfer it periodically or mark your answer for every question directly in the answer sheet.

 

  1. If you have to modify your answers for any reason, please ensure that you erase the previous choice properly so that there is no trace of marking else it may be construed as multiple marking and your answer ignored for valuation.

 

  1. Your concentration level may come down after an hour or so. It is important that you have a little break by having a sip of water and looking away from the question paper and get back your concentration before you start answering again. Take a few deep breaths, stretch yourself if required and then get back to the task. Consistent concentration is important.

 

  1. You may encounter some questions, which are familiar to you, which you have answered in the CISA review manual or in the test questions. Don’t be prejudiced by your past answers. Read the question fully, understand it, and look at the choices and then answer. It may be possible that the questions may have been rephrased or re-worded and may have a different answer to what you have seen in the tests or the choices may be re-arranged or rephrased.

 

  1. In the choices, when there are two choices which are similar. Pick the one which is more macro and bigger in nature. Remember the context of the situation as given in the question and the available choices have to be considered to arrive at the best choice.

 

  1. The pass % is normally about 55% globally and varies from centre to centre. However, passing the exam is primarily dependent on your ability to concentrate during your exams and picking up the right choice. Our Analysis reveals that most of the students who fail tend to get around 70% which means that another 5 to 10 questions answered correctly would have got them through. Hence, it is very important that you are able to devote proper time for each of the question and concentrate throughout the exam.

 

  1. Ensure that you are marking the answers exactly. Cross-check regularly to ensure this. You have to be extra careful if have skipped any questions to be answered later. It is important to ensure that you skip marking the answers for that question. You may use a ruler for ensuring you are marking the required choice for the appropriate question.
E. Exam Venue

 

  1. Prepare an exam kit in advance of the exam and carry it to the exam. This kit could include your admission ticket, identity card, pencils, erasers, water bottle, medicines (if required), etc.

 

  1. Visit the venue in advance before the exam and know the route, parking facility and exact place of exam. Reach the exam half an hour before the scheduled time so that you are not running to the venue in a hurry. Do come to the exam to the venue before time and use the time for relaxing.

 

  1. Carry your identification cards, admission tickets, 3-4 pencils sharpened, 2-3 erasers, water bottle. Don’t carry any books. You may not get time to read and it may not be worthwhile trying to read in the last minute. Remember the questions don’t test your memory but are more a test of your judgemental ability as an IS Auditor.

 

  1. The admission ticket is expected to be received by the candidate 2-3 weeks before the exam. It is sent both by email and by post. You can bring printout of email copy to the exam if you don’t receive the hard copy by post. However, if you don’t receive hard copy also, you may contact the chapter office to confirm your name is in the candidates list. The chapter gets a copy of all the candidates writing exam from the test centre. They are authorized to identify candidates who have not received the admission ticket. Hence, please don’t panic if you don’t receive the admission ticket but contact the chapter president or CISA Coordinator of your test centre who would have the complete list of candidates taking the exam from that test centre.

 

  1. The proctor will start reading instructions of the exam 30 minutes before the exam time. You are expected to be in the hall before proctor commences reading the instructions. Proctor may not allow you inside once he starts reading the instructions.

 

  1. The instructions relate to signing of forms and filling up your registration particulars. Clarify your doubts about any procedures you have. Follow the proctor’s instructions carefully and write down the details as per instructions. You can use pen or pencil for writing the registration no. and other details. However, answers are to be marked only in pencil.

 

  1. The proctor will not answer any questions pertaining to the questions or answers.

 

  1. You can go out of the exam hall for answering nature’s call with permission of proctor. You have to hand over your questions and answer paper before going out of the hall and collect it back on arrival.

 

  1. No additional papers or sheets will be provided. You may use the question papers or its back side for making any rough notes. It is advisable not to make any notes or marking on the answer sheet except for marking the circles for the right choice.

 

  1. The CISA Exam is a closed Exam which means neither the question paper or answer papers are released. You are not expected to discuss questions or answers with anyone.

 

  1. After completing the exam, leave the venue silently. Don’t discuss your answers with the other candidates to confirm the answers. You may only get confused.
F. After the Exam

 

  1. You may greatly relieved after writing the exam but begin your preparations for the next exam. Hence, when your memory is fresh, as a first step, walk-through the CRM and Questions manual to identify what went wrong and what went right. This could help you for future exam, if you fail or to become a CISA item write, once you succeed. Yes. You can become a CISA item writer and earn USD 50 per question!

 

  1. Once you have received the score indicating you are successful in the CISA Exam, read the Application for Certification and if eligible apply for certification with all the required documents. Understand the CPE requirements and adhere to them.
G. Summary

 

You may have all the knowledge but remember that CISA is a multi-choice exam. Hence, there is only one correct answer and it is already in front of you. You should learn how to pick up the right answer. Being an experienced professional hard-pressed for time, you need to find time for study and orient your thinking as global IS Auditor. Practice the questions and get perspective right. Remember that passing the exam is only the beginning. Success in CISA exam opens out new windows of opportunity in your professional career. Hence, make learning a life-long experience.

 

Disclaimer:

 

We are glad that you read through these tips. While hoping they would be useful to you in passing the CISA Exam, please note that we do not provide any assurance of your success. We don’t claim that all the tips would be relevant and useful. However, you may pick up whatever you deem useful. Your success in the CISA Exam depends on YOU – your preparation and your performance on the exam day. Your success also depends on the overall performance of all the Candidates. You may consider the above as friendly tips from those who have written and passed the CISA Exam themselves and who have interacted with CISA Exam candidates since last ten years. Wish you Success in the CISA Exam and your professional career.

 

Do email your suggestions for improving or additions to these tips. Rafeq can be reached at rafeq@vsnl.com and Shirish Deshpande can be reached at dshirish99@vsnl.net.

"

(Read More... | 6 comments | OSG NEWS | Score: 4)


Latest newsletter from AuditNet
Posted by boss on Friday, 01 September 2006 @ 17:44:41 EDT (1881 reads)
Topic CISA

cdupuis writes "AuditNet News for Auditors
September 2006

AuditNet News is sponsored by PricewaterhouseCoopers TeamMate, a database-driven audit management system that streamlines the audit process by providing integrated tools for documentation, report generation and file sharing. For more information about TeamMate, visit www.pwc.com/teammate

9th Annual Risk Management and Internal Audit in Telecoms conference - London, UK - 18 – 19th September 2006. For more information go to http://www.riskmanagement-events.com

CONTINUOUS SARBANES OXLEY COMPLIANCE Best Practices for Sustainable SOX Compliance September 12-14, 2006 Digital Sandbox New York, NY Info at http://www.iqpc.com/na-10416-001

Online Version http://www.auditnet.org/auditnet-l.htm for all the following and more!

1. AuditNet Ask the Auditor: Is the External Auditor is responsible for detecting fraud and error, especially after the issuance of the statement 99?
2. AuditNet Heard on the Net– AuditNet® Adds 181 New Programs to the Free Content Area
3. Audit Programs Added This Month – 10 new programs including a Whistleblower Review
4. KnowledgeLeader: Getting Controls Right and Automating Them
5. Get a Free Resume Analysis! Send your resume for a chance for a free critique/analysis
6. Training for Auditors: AuditNet has teamed with the Quality Assurance Institute and the Internal Control Institute to offer online cost-effective audit-related courses.
7. New Exchange Group Formed for Law Firm Internal Auditors
8. Software Compliance: New Monograph on Software Compliance Auditing: Looking for a Career Change?
9. AuditNet Audit Software Corner: No Escaping SOX Requirements Get it done quickly with automation and borrowing from others' experience by Rich Lanza
10. Dan’s Internal Audit Corner – resources from Dan Swanson, a senior security and internal audit professional
11. Internal Audit Manual – a manual for those looking for an online solution.
12. IIA Technology Audit Guide Series – Managing and Auditing Privacy Risks
13. AuditNet Construction Audit Corner Procurement Contracts & Agreements [Detection & Prevention of Fraud] by Gursharan Singh
14. Computer Based Training from Pleier Corporation.
15. Sarbanes-Oxley Corner: Sarbanes Oxley Section 404 Compliance For IT Managers E-book Updated

This month check out Pentana, produces software for audit professionals, including integrated risk and audit management, staff scheduling and information security questionnaires. Support AuditNet® by supporting our sponsors and the audit related products they provide.

AuditNet launches the new Auditor Career Center powered by eFinancialCareers.com If your company has any audit job vacancies that you are looking to fill, have your HR people contact AuditNet® to post the job and search for candidates. Using the AuditNet Career Center helps support AuditNet® as well! For more information go to www.auditnet.jobsinthemoney.com/

AuditNet Adds a New Career Feature: The Resume Tune-Up.
Nationally recognized resume expert and author of How to Say It In Your Job Search, Robbie Miller Kaplan will select one auditor resume each month and suggest ways to transform the resume from passable to powerful. For more information go to www.auditnet.org/auditnet-l.htm

Coming Attractions!

A new monograph on New Auditor Orientation Manual will be available soon. Also new monographs are in the works for Internet related subjects.

The opinions, beliefs and viewpoints expressed by the various authors and forum participants on this web site do not necessarily reflect the opinions, beliefs and viewpoints of AuditNet or Jim Kaplan

AuditNet CPE & Training Conference Corner Check out the AuditNet online newsletter to find out more about these upcoming events:
Continuous Sarbanes Oxley Compliance -Best Practices for Sustainable SOX Compliance, Sep 12-14, 2006 New York, NY
-2006 ACFE Fraud Conferences and Training
-2006 IIA Conferences and Seminar Training Go to the online version for more information about conferences and training!
*****

For all of the above and more, go to www.auditnet.org and click on newsletter!

PUBLICATION FREQUENCY- AuditNet News is published in electronic format monthly. Most of the articles which appear in the newsletter are posted in the Articles Archive section of the AuditNet® website, www.auditnet.org If you no longer wish to receive the AuditNet® News E-mail Newsletter, go to http://www.auditnet.org/subscribe.htm and unsubscribe.

Please forward this newsletter to a friend."

(Read More... | 10 comments | Score: 0)


Online Books: CISA Study Guides
Posted by boss on Tuesday, 08 August 2006 @ 23:23:46 EDT (10746 reads)
Topic CISA

Anonymous writes "

This web page is reserved to advertise future CISA Study guides that will be contributed and created by members of the web site.

If you do have cheat sheet, guides, powerpoint slide show, or other resources you wish to share.

Please do send them to cdupuis@cccure.org and I will be happy to post them for all to use.

Thanks

Clement and Nathalie

"

Online Books: CISA Books
Posted by boss on Tuesday, 08 August 2006 @ 23:05:28 EDT (23951 reads)
Topic CISA

Anonymous writes "

Here is some books that could help you master the CISA Exam:

 

THE CISA ALL IN ONE EXAM GUIDE

NOTE FROM CLEMENT:  This is THE book that you need for your certification exam.  It is written by Peter Gregory who has written about two dozen security books so far.  Peter has a great writing style and the book is very thorough.  It meets all of the 2010 objectives from ISACA.

he CISA Certified Information Systems Auditor All-In-One Exam Guide, published by Osborne McGraw-Hill, is now available in bookstores and from online merchants.

Written by Peter H. Gregory, this book is largest and most complete study guide available for the CISA (Certified Information Systems Auditor) professional certification.  Prior to Osborne McGraw-Hill’s decision to publish this book, the other study guides that were available are shorter and contain less detail. This difference is key for IT professionals who are studying for the CISA certification, which places high demands on the exam taker to be able to recall many details and specifications about information technology, key business processes, and IT auditing.

CoverFront200x

Despite its title, CISA Certified Information Systems Audit All-In-One Exam Guide is structured and designed to also be a desk reference for early- and mid-career security auditors and security specialists who need a reliable, easily-consumed reference guide for key information technologies and IT auditing practices.  The book contains two chapters that go beyond the CISA study material and include lengthy discussions of professional IT auditing and security and governance frameworks.

“The availability of this study guide represents a big step forward for IT professionals who are studying for the CISA exam and those who have IT security and audit responsibilities,” states Peter H. Gregory. “The IT industry has waited a long time for an All-In-One guide for this popular certification,” he adds, citing the enormous popularity of the CISSP All-In-One Study Guide that is written by Shon Harris and considered the best CISSP guide available.

About Peter H. Gregory

Peter Gregory, CISA, CISSP, DRCE is the author of twenty books on security and technology and has been a technical editor for twenty additional books on security and technology. He has over 25 years of experience in virtually every role in Business IT departments, including work in government, banking, non-profit, telecommunications and on-demand financial software businesses.

Gregory is on the board of advisors and the lead instructor for the University of Washington certificate program in information security, and a lecturer at the NSA-certified University of Washington Certificate Program in Information Assurance & Cybersecurity. He is also on the Board of Directors for the Evergreen State Chapter of InfraGard, and the Executive Steering Board for the SecureWorld Expo Conference in Seattle. A founding member of the Pacific CISO Forum, Mr. Gregory is a graduate of the FBI Citizens’ Academy and active in the FBI Citizens’ Academy Alumni Association.

About ISACA®

With more than 86,000 constituents in more than 160 countries, ISACA® (www.isaca.org) is a leading global provider of knowledge, certifications, community, advocacy and education on information systems assurance and security, enterprise governance of IT, and IT-related risk and compliance. Founded in 1969, ISACA sponsors international conferences, publishes the ISACA® Journal, and develops international information systems auditing and control standards. It also administers the globally respected Certified Information Systems Auditor™ (CISA®), Certified Information Security Manager® (CISM®) and Certified in the Governance of Enterprise IT® (CGEIT®) designations.

ISACA developed and continually updates the COBIT®, Val IT™ and Risk IT frameworks, which help IT professionals and enterprise leaders fulfill their IT governance responsibilities and deliver value to the business.

CISA Certified Information Systems Auditor All-In-One Study Guide by Peter H. Gregory; McGraw-Hill; October 2009; Hardback; $79.99; 10: 0071487557; 13: 978-0071487559

“All-in-One is All You Need.”



Click here to peruse more CISA books on the Amazon.com web site

"

New leader for the CISA certification section
Posted by boss on Tuesday, 08 August 2006 @ 22:31:46 EDT (9690 reads)
Topic CISA

Anonymous writes "Good day to all,

Today I am very excited to announce that we have a new leader for the CISA certification area on the web site. As far as leaders are concerned there could not be a better choice. Let me introduce: Jay Ranade (JayRanade@aol.com )

I am very honored to have someone with Jay's caliber and skills to help me expand and father the CISA certification. Here is a short and impressive bio:

Jay is an internationally renowned expert on computers, communications, disaster recovery, IT Security, and IT controls.

He has written and published more than 35 IT related books on various subjects ranging from networks, security, operating systems, languages, and systems.

He also has an imprint with McGraw-Hill with more than 300 books called “Jay Ranade Series”. He has written and published articles for various computer magazines such as Byte, LAN Magazine, and Enterprise Systems Journal.


The New York Times critically acclaimed his book called the “Best of Byte”.

He is currently working on a number of books on various subjects such as IT Audit, IT Security, Business Continuity, and IT Risk Management.

Jay has consulted and worked for Global and Fortune 500 companies in the US and abroad including American International Group, Time Life, Merrill Lynch, Dreyfus/Mellon Bank, Johnson and Johnson, Unisys, McGraw-Hill, Mobiltel Bulgaria, and Credit Suisse.

He is a member of the ISACA International's Publications Committee.

He is four times world champion in Arm Wrestling and two times world champion (2002 and 2003) in martial arts breaking. He has appeared on ESPN and ESPN2 numerous times.


"

(Read More... | 29 comments | Score: 4.2)


CISA and CISM certs receives the ISO 17024 accreditation
Posted by boss on Wednesday, 28 December 2005 @ 20:02:56 EST (1923 reads)
Topic CISA

cdupuis writes "

ISACA is extremely proud to advise you that the American National Standards Institute (ANSI) has awarded accreditation under ISO/IEC 17024 to ISACA's Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) certification programs. ANSI's accreditation:

  • Promotes the unique qualifications and expertise our certifications provide

  • Protects the integrity of our certifications and provides legal defensibility

  • Enhances consumer and public confidence in the certifications and the people who hold them

  • Facilitates the mobility of certified individuals across borders or industries

Accreditation by ANSI signifies that ISACA's procedures meet ANSI's essential requirements for openness, balance, consensus and due process. To maintain ANSI accreditation, certification bodies such as ISACA are required to consistently adhere to a set of requirements or procedures related to quality, openness and due process.

The American National Standards Institute (ANSI) is a private, nonprofit organization that administers and coordinates the US voluntary standardization and conformity assessment system. Its mission is to enhance both the global competitiveness of US business and the US quality of life by promoting and facilitating voluntary consensus standards and conformity assessment systems, and safeguarding their integrity.

This accreditation and adherence to ISO/IEC 17024 are being used as an industry benchmark. For example, the U.S Department of Defense (DoD), to ensure a knowledgeable and skilled workforce, has developed a directive that requires every full- and part-time military service member, defense contractor, civilian and foreign employee with privileged access to a DoD system, regardless of job series or occupational specialty, to obtain a certification credential that has been accredited to the ISO 17024 standard.

With this accreditation, we anticipate that significant opportunities for CISAs and CISMs will continue to open in the US, and we believe it will be a strong motivator for similar recognition by governmental entities outside the US. As such, we encourage those of you inside the US to inform your members, credential holders and state and local governmental entities of this achievement, and outside the US to promote this accreditation to the proper authorities and representatives in your countries to obtain similar recognition and support. Finally, please let us know of the outcome of your efforts so that we can share your experiences with others.

ISACA chapters have long played an important role in the widespread recognition and adoption of CISA and CISM, and there is no question that your support contributed to the ANSI accreditation. Thank you for all you do to promote ISACA and the certifications.

Should you have any questions relating to this new accreditation, please contact Terry Trsar at ttrsar@isaca.org.

Sincerely,
Megan Moritz
Lead Chapter Relations Coordinator
Information Systems Audit and Control Association
Phone: +1.847.590.7487
Fax: +1.847.253.1652
E-mail: mmoritz@isaca.org

"

(Read More... | 5 comments | Score: 0)


Effective Approch in CISA Exam
Posted by boss on Friday, 30 September 2005 @ 16:01:46 EDT (4298 reads)
Topic CISA

NOTE FROM CLEMENT:
First of all I would like to thank A.Rafeq, Past President, ISACA Bangalore Chapter and Shirish Deshpande, FCA,CISA, Past President of ISACA Pune Chapter for this great document and giving me the authorization to report it on www.cccure.org.  Your contribution to the security community is very much appreciated.

Effective Approch in CISA Exam By:
A.Rafeq, President, ISACA Bangalore Chapter and
Shirish S. Deshpande, Past President, ISACA Pune Chapter



Objective of CISA Exam
CISA Exam consists of 200 questions from 7 domains as detailed in the Candidates Guide to the CISA Exam. The CISA Exam tests minimum level of competence for conducting Information Systems Audit.

Understanding of IT
CISA Candidates are expected to have working knowledge of Information Technology. The basic understanding of Information Technology should cover key concepts of various components of Information Technology in their practical deployment. The IT knowledge should encompass overall understanding of IT Infrastructure, IT Facilities, various types of Computer hardware, Systems Software (Operating System, Database, Networking, Multimedia, etc), Business Application software, Office Automation Software and Audit Software. Further, candidates are expected to know concepts and practice of Management as relevant to IT deployment in enterprises.

CRM - only theoretical training
The CISA Review Technical Information Manual (CRM) is not meant for teaching the fundamental concepts of Information Technology. However, IT components are explained only to the extent required. The candidates guide to CISA exam provides the broad range of topics covered and CRM provides the details of concepts of practice of IS Audit as per IS Auditors' Tasks and Knowledge requirements. Candidates are advised to use the CRM as the basic guide for learning and use additional material as required based on their assessment of gaps and individual competency areas.

IT - Practical Training
Candidates who are not well conversant with IT are advised to do a practical course on IT covering hardware, systems software, office automation, business applications and audit software.

Getting CISA Perspective - practical approach
The overall understanding of a CISA candidate is expected to cover the related domains as per the objectives, tasks and knowledge statements given in the Candidates Guide to CISA Exam. Primarily it encompasses three major disciplines - Information Technology, Management and Auditing. The CISA candidates may follow the following approach for getting the perspective of a CISA:
· Obtain overall understanding of Information Technology - concepts and practice
· Understand the Risks of deployment of relevant IT Component
· Know the features and functionalities of Security and controls of IT Component
· Understand how controls could be implemented using the security features and functionalities so as   to mitigate the risks in the relevant IT Component
· Learn how to identify the risks, review the related security, evaluate the implemented controls and identify areas of weaknesses.

Conceptual Clarity
CISA Candidates need to have conceptual clarity in the following key areas:
The inherent risks of Implementing Information Technology
Appropriate risk management strategy for mitigating these risks.
Security and controls, which need to be implanted for, risk mitigation.

Practical Tips for CISA Exam

Click on Read More... below to see 50 tips on the CISA Exam, a must read.

(Read More... | 21787 bytes more | 1 comment | Score: 4.69)


Our Sponsors

Login here

Nickname

Password

Security Code:
Security Code
Type Security Code

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.

CCCure Partners

USA


Security University

Security University


MIDDLE EAST


Dubai, Qatar, Kuwait, Oman

THE OISSG GROUP
The OISSG serving the Middle East security needs


EUROPEAN UNION


Dublin, Ireland
ESPION

Best security training you can get in Ireland


AFRICA


Yaounde-Cameroun
GetSec

The best training one can get in Cameroon

Lagos, Nigeria
Digital Encode


The best security training in Lagos and Nigeria

Most Active Members

· 1: side_winder
Total points: 12209
· 2: Lopezco
Total points: 8506
· 3: cissp_newbie
Total points: 7593
· 4: cdupuis
Total points: 6632
· 5: mikeyoung_fla
Total points: 5490
· 6: Vladimir
Total points: 4611
· 7: MMM
Total points: 2969
· 8: damoose
Total points: 2814
· 9: webplu9
Total points: 2592
· 10: educk
Total points: 2334

Today's Big Story

There isn't a Biggest Story for Today, yet.

Past Articles

There isn't content right now for this block.

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2007 by CCCure.Org, and the site maintainers Clement Dupuis and Nathalie Lambert. Reuse is strictly prohibited without written permission of CCCure.Org or it's maintainers.

This web site is not associated directly or indirectly with ISC2, the SANS Institute, ISACA, or other certification authority. The GCFW, CISSP, SSCP, ISSEP, ISSMP, CISA, and CISM are all the property of their respecful owners. The content of this site is provided to you freely due to the generosity of our sponsors.


  • Career
  • Magazines
  • Conferences
  • Study Books
  • Certifications
  • Training
  • Tutorials
  • Quizzes
  • Forums

  • Page Generation: 1.42 Seconds