Certified Information Systems Auditor - CISA

The implementation of the CISA examination hascomplies with standard accounting practices.
resulted in a considerable standardization of skills andThe whole integral concept of IT management
functions among auditors in the IT industry. This wasinvolves the study and control of the different
an extremely necessary step, as this is a fast growingcomponents of the business. This covers not only the
and ever changing industry, an industry in a constantidentification and acquisition of key components, but
change of flux, and rules and guidelines that mightalso their later installation and management. One has to
apply perfectly well today could well turn out to beensure that implementing new strategies actually fits
completely invalid a few months down the line. Theinto the overall company, and does not end by
CISA examinations, by meticulous testing of applicants,disrupting the smooth running of the organization -
holds the industry to the requirements and guidelines ofbecause without this the organization will be unable to
Information Systems Audit and Control Association, ormeet it's goals.
ISACA.There are other aspects that are covered - Systems
By strenuous testing (the examination is 200 questionsand Infrastructure Lifecycle Management was another
long and lasts four whole hours!) the CISA ensuresarea we mentioned. Here, with the aid of potent tools,
that it covers every aspect of an auditors job, fromdata is documented and then secured. These are the
Information Security Processes to Systems andcore integral aspects of the process.
Infrastructure Lifecycle Management.The failure of backups after a catastrophic failure of
Now what exactly is the point of all this? It's verymain systems is unacceptable - so current and regular
simple. An IT auditor's job can be just as strenuous asbackups of all systems is key. It's absolutely essential
the examination. As an example, one of the goals ofto ensure that the core data bank remains secure -
an auditor's mandate is to not only maintain the smoothand it's equally crucial to ensure that any backup
functioning of the organization, but to make sure itsystems also retain their integrity. For this to succeed,
survives - to literally extend it's lifespan. This comesnot only do we need backup systems in place, but we
under the auspices of what we call Informationalso need to ensure that we have a schedule upon
Technology Governance, one of the areas coveredwhich we can work to ensure re-integration of
by the CISA. One learns to assess and managebackups with the main database in case of a
business risks, and to ensure that the organizationcatastrophic failure.