ISACA CISA®, Certified Information Systems Auditor® incl QAE (CISAU)

Kurskode CISAU
Varighet 4
Leverandør ISACA
Neste kurs

Om kurset

Prepare for CISA® — Certified Information Systems Auditor cerification

 

This 4-day CISA training course is the preparation for the newest CISA certification. During this course, you will learn about the IT audit process.

CISA® — Certified Information Systems Auditor is the globally recognized gold standard for IS audit,control, and assurance, in demand and valued by leading global brands.

 It’s often a mandatory qualification for employment as an IT auditor. CISA professionals offer the credibility to leverage standards, manage vulnerabilities, ensure compliance, offer solutions, institute controls and deliver value to organizations.

  • Continuing Professional Education (CPE) : 31
  • Practice questions (QAE = Questions, Answers and Explanations) : 6 month access included

 

Updated 4/2026

Dette lærer du

Domain 1 - Information System Auditing Process

  • • Plan an audit to determine whether information systems are protected, controlled, and provide value to the enterprise.
  • • Conduct an audit following IS audit standards and a risk-based IS audit strategy.
  • • Communicate audit progress, findings, results, and recommendations to stakeholders.
  • • Conduct audit follow-up to evaluate whether risks have been sufficiently addressed.
  • • Evaluate IT management and monitoring of controls.
  • • Utilize data analytics tools to streamline audit processes.
  • • Provide consulting services and guidance to the enterprise to improve the quality and control of information systems.
  • • Identify opportunities for process improvement in the enterprise's IT policies and practices.

Domain 2 – Governance and Management of IT

  • • Evaluate the IT strategy for alignment with the enterprise’s strategies and objectives.
  • • Evaluate the effectiveness of IT governance structure and IT organizational structure.
  • • Evaluate the enterprise’s management of IT policies and practices.
  • • Evaluate the enterprise’s IT policies and practices for compliance with regulatory and legal requirements.
  • • Evaluate IT resource and portfolio management for alignment with the enterprise’s strategies and objectives.
  • • Evaluate the enterprise’s risk management policies and practices.
  • • Evaluate IT management and monitoring of controls.
  • • Evaluate the monitoring and reporting of IT key performance indicators (KPIs).
  • • Evaluate whether IT supplier selection and contract management processes align with business requirements.
  • • Evaluate whether IT service management practices align with business requirements.
  • • Conduct periodic review of information systems and enterprise architecture. Evaluate data governance policies and practices.
  • • Evaluate the information security program to determine its effectiveness and alignment with the enterprise’s strategies and objectives.
  • • Evaluate potential opportunities and threats associated with emerging technologies, regulations, and industry practices.

Domain 3 – Information Systems Acquisition, Development, and Implementation

  • • Evaluate whether the business case for proposed changes to information systems meet business objectives.
  • • Evaluate the enterprise's project management policies and practices.
  • • Evaluate controls at all stages of the information systems development lifecycle.
  • • Evaluate the readiness of information systems for implementation and migration into production.
  • • Conduct post-implementation review of systems to determine whether project deliverables, controls, and requirements are met.
  • • Evaluate change, configuration, release, and patch management policies and practices.

Domain 4 – Information Systems Operations and Business Resilience

  • • Evaluate the enterprise’s ability to continue business operations.
  • • Evaluate whether IT service management practices align with business requirements.
  • • Conduct periodic review of information systems and enterprise architecture.
  • • Evaluate IT operations to determine whether they are controlled effectively and continue to support the enterprise’s objectives.
  • • Evaluate IT maintenance practices to determine whether they are controlled effectively and continue to support the enterprise’s objectives.
  • • Evaluate database management practices.
  • • Evaluate data governance policies and practices.
  • • Evaluate problem and incident management policies and practices.
  • • Evaluate change, configuration, release, and patch management policies and practices.
  • • Evaluate end-user computing to determine whether the processes are effectively controlled.
  • • Evaluate policies and practices related to asset lifecycle management.

Domain 5 – Protection of Information Assets

  • • Conduct audit in accordance with IS audit standards and a risk-based IS audit strategy.
  • • Evaluate problem and incident management policies and practices.
  • • Evaluate the enterprise's information security and privacy policies and practices.
  • • Evaluate physical and environmental controls to determine whether information assets are adequately safeguarded.
  • • Evaluate logical security controls to verify the confidentiality, integrity, and availability of information.
  • • Evaluate data classification practices for alignment with the enterprise’s policies and applicable external requirements.
  • • Evaluate policies and practices related to asset lifecycle management.
  • • Evaluate the information security program to determine its effectiveness and alignment with the enterprise’s strategies and objectives.
  • • Perform technical security testing to identify potential threats and vulnerabilities.
  • • Evaluate potential opportunities and threats associated with emerging technologies, regulations, and industry practices.

Kursinnhold

Kurset dekker blant annet følgende temaer:

  • Domain 1 - Information System Auditing Process
  • Domain 2 – Governance and Management of IT
  • Domain 3 – Information Systems Acquisition, Development, and Implementation
  • Domain 4 – Information Systems Operations and Business Resilience
  • Domain 5 – Protection of Information Assets
  • CISA Exam Preparation

Forkunnskaper

There are no specific entry requirements to participate in this CISAU training. We nevertheless recommend a good understanding of security requirements and audit processes.

Hvem passer kurset for?

Designed for mid-career IS audit, control and assurance professionals looking to leverage career growth including:

- IT Audit Directors/Managers/Consultants

- IT Auditors

- Compliance/Risk/Privacy Directors

- IT Directors/Managers/Consultants

Videre kurs

We may suggest the following certification courses:

  • CISSP (Certified Information Systems Security Professional): Expands your audit foundation into hands-on security engineering, architecture, and technical operations.
  • CISM (Certified Information Systems Manager): Focuses on security program management, strategy, and governance rather than only audit.
  • CRISC (Certified in Risk and Information Systems Control): Deepens your expertise in enterprise IT risk identification, mitigation, and control monitoring. 
  • CCSP (Certified Cloud Security Professional): Adds specialized cloud infrastructure governance, data, and operations security knowledge.
  • Kommende kurs

    Kursdatoer

    Viser 4 av 4
    NOK 35.000
    NOK 35.000
    NOK 35.000
    NOK 35.000
    SG Partner

    Hvorfor velge SG Partner?

    Vi gjør det enkelt å finne riktig kurs og riktig gjennomføring for deg og din virksomhet.

    Offisielle kurs

    Kursinnhold fra anerkjente teknologileverandører og fagmiljøer.

    Erfarne instruktører

    Praktisk og faglig undervisning med fokus på kompetanse du kan bruke.

    Fleksibel gjennomføring

    Velg mellom tilgjengelige virtuelle, fysiske og bedriftsinterne kurs.

    Personlig rådgivning

    Vi hjelper deg med å finne kurs og kompetanseløp som passer behovet ditt.

    FAQ

    Ofte stilte spørsmål

    Hvor lenge varer kurset?

    Kursets oppgitte varighet er 4.

    Kan jeg ta en sertifisering?

    Kurset kan være relevant som forberedelse til sertifisering. Se kursbeskrivelsen for informasjon om aktuell sertifisering og eksamen.

    Hvilke forkunnskaper trenger jeg?

    There are no specific entry requirements to participate in this CISAU training. We nevertheless recommend a good understanding of security requirements and audit processes.

    Hvem passer kurset for?

    Designed for mid-career IS audit, control and assurance professionals looking to leverage career growth including:- IT Audit Directors/Managers/Consultants- IT Auditors- Compliance/Risk/Privacy Directors - IT Directors/Managers/Consultants

    Kan kurset leveres som bedriftsinternt kurs?

    Ja.

    Hvor kan kurset leveres?

    Kurset kan leveres over hele Norge, blant annet i Oslo, Kristiansand, Stavanger, Bergen, Trondheim og Tromsø.