Hafta 114–20 Eyl
Information Systems auditing girişi ve standartlar
Definitions of the Information Systems (IS) technologies and auditing process encompasses the standards, principles, methods, guidelines, practices and techniques based on the ISACA CISA domains and ISO 27001/27701 objectives. General roadmap of CTIS-474 course content and studies. Introduction to Information Systems Auditing, the auditor’s mindset, professional ethics, and the global standards and frameworks governing IS audits.
ISACA CISAISO 27001/27701IS auditprofessional ethics
Hafta 221–27 Eyl
IS audit standartları, framework ve sertifikasyonları
Global IS Audit Standards, Frameworks and Certifications. Describe and discuss on IS Audit Global Standards and Frameworks; IS related Professional Certifications; ISACA Frameworks and Certifications; ISO Standards and Certifications; AICPA SOC 1-2-3 Reports; NIST, DORA, NIS2, CMMI, GDPR, Turkish Information and Communication Security (Audit) Guide, etc.
ISACA frameworkISO standartlarıSOC 1-2-3 raporlarıGDPR, DORA, NIS2
Hafta 328 Eyl – 4 Eki
IS audit planlaması ve yürütülmesi
IS Audit Planning and Execution. Planning: IS Audit Standards, Guidelines and Codes of Ethics, Business Processes, Types of Controls, Risk-Based Audit Planning, Types of Audits and Assessments. Execution: Audit Project Management, Sampling Methodology, Audit Evidence Collection Techniques, Data Analytics, AI/ML Effects on Audit, Reporting and Communication Techniques, Quality Assurance and Improvement of the Audit Process
IS audit standardsrisk-based audit planningsampling methodologyaudit evidence
Hafta 45–11 Eki
IT governance ve IT management audit'i
Audit on IT Governance: IT Governance and IT Strategy, IT-Related Frameworks, IT Standards, Policies, and Procedures, Organizational Structure, Enterprise Architecture, Enterprise Risk Management, Maturity Models Laws, Regulations, and Industry Standards Affecting the Organization. Audit on IT Management, IT Resource Management, IT Service Provider Acquisition and Management, IT Performance Monitoring and Reporting, Quality Assurance and Quality Management of IT.
IT governanceenterprise architectureenterprise risk managementIT performance monitoring
Hafta 512–18 Eki
IT management audit'i
Audit on IT Management: IT Resource Management, IT Service Provider Acquisition and Management, IT Performance Monitoring and Reporting, Quality Assurance and Quality Management of IT
IT resource managementIT service provider managementIT performance monitoringquality management
Hafta 619–25 Eki
Sistem edinimi ve geliştirme denetimi
Audit on Information Systems Acquisition and Development: Project Governance and Management, Business Case and Feasibility Analysis, System Development Methodologies, Control Identification and Design
project governancebusiness casefeasibility analysissystem development methodologies
Hafta 726 Eki – 1 Kas
Sistem implementasyonu denetimi ve CAAT
Audit on Information System Implementation: Testing Methodologies, Configuration and Release Management, System Migration, Infrastructure Deployment, and Data Conversion, Post-Implementation Review. Describe the key features of Computer Assisted Audit Techniques (CAAT). Review on the audit objectives of the CAATs and the use of CAATs in the performance of an IS Audit.
CAATconfiguration ve release managementsystem migrationpost-implementation review
Hafta 82–8 Kas
Ara sınav
--MIDTERM--
Hafta 99–15 Kas
Takım Halinde IS Audit Vaka Çalışması
CASE STUDY, 1: As a team of 3 participants, Examine the related IS auditing standards and guidelines; Preparing the audit checklists on the topics, frameworks and methodology previously discussed in class then apply techniques necessary to conduct an IS audit.
IS auditing standardsaudit checklistframeworkmethodology
Hafta 1016–22 Kas
Bilgi güvenliği denetimi ve saldırı yöntemleri
Audit on Information Security: Security Awareness Training and Programs, Information System Attack Methods and Techniques, Vulnerability Analysis and Penetration Testing Methods, Security Testing Tools and Techniques, Security Monitoring Tools and Techniques, Incident Response Management, Evidence Collection and Forensics
security awareness trainingvulnerability analysissecurity monitoringincident response
Hafta 1123–29 Kas
Bilgi varlığı güvenliği ve kontrol audit'i
Audit on Information Asset Security and Control: Privacy Principles, Physical Access and Environmental Controls, Identity and Access Management, Network and End-point Security, Data Classification, Data Encryption and Encryption-related Techniques, Public Key Infrastructure (PKI), Web-based Communication Technologies, Virtualized Environments, Mobile, Wireless, and Internet-of-Things (IOT) Devices
identity and access managementdata encryption ve PKInetwork and endpoint securityvirtualized environments ve IoT
Hafta 1230 Kas – 6 Ara
Bilgi sistemleri operasyonlarının denetimi
Audit on Information System Operations. Computer Hardware Components and Architectures, IT Asset Management, System Interfaces, Systems Performance Management, Problem and Incident Management, Change, Configuration, Release, and Patch Management, IT Service Level Management. Evaluating the opportunities and risks created by disruptive technologies (AI, ML, BigData, etc.) for IS auditing.
IT asset managementpatch managementIT service level managementdisruptive technologies
Hafta 137–13 Ara
Bilgi güvenliği ve privacy denetimi
Audit on Information Security and Privacy: Privacy Principles and Practices, Security Awareness Training and Programs, Information System Attack Methods and Techniques, Vulnerability Analysis and Penetration Testing Methods, Security Testing Tools and Techniques, Security Monitoring Tools and Techniques, Incident Response Management, Evidence Collection and Forensics
privacy principlespenetration testingincident responseevidence collection ve forensics
Hafta 1414–20 Ara
Business resilience audit'i ve vaka çalışması
Audit on Business Resilience: Business Impact Analysis (BIA), System Resiliency, Data Backup, Storage, and Restoration, Business Continuity Plan (BCP), Disaster Recovery Plans (DRPs) Week 15: CASE STUDY, 2: : As a team of 3 participants, Plan and conduct information systems audits on the specific scenarios related to different organizational structures, technological infrastructures and business sectors given by instructor based on topics previously discussed in class.
Business Impact Analysis (BIA)system resiliencyBusiness Continuity Plan (BCP)Disaster Recovery Plan (DRP)