Batch 3 : General IT Audit Certification Course

Saturday, December 21, 2024

bombay_chambers_years_exp
Batch 3 : General IT Audit Certification Course

Batch 3 : General IT Audit Certification Course

by
81 81 people viewed this event.

Introduction :

Information Technology (IT) is a critical enabler of business. Assuring an organization’s governance, risk management, compliance and control processes requires internal auditors to understand the role of IT within their organizations and to develop adequate knowledge and skills to audit IT systems as the line separating “IT” and “non-IT” audits is beginning to disappear, except in the very technical IT areas.

As technology gets increasingly fused with business processes, business auditors need to be better prepared to provide integrated audit services that encompass process and technology audit areas. This course is specially designed to equip business auditors with skills and knowledge to assess IT risks and related controls, IT governance and management controls.

Learning Outcomes :

  • Ability to identify and evaluate business risks in the IT environment and propose solutions to address the identified risks.
  • Ability to identify IT-related business risks and evaluate IT general controls and IT application controls in a business context.
  • Ability to prepare an audit programme for the audit of an IT system which addresses both IT general control and IT application control objectives
  • Ability to participate effectively in the design, development, testing and implementation of a new IT system, providing appropriate audit advisory and consultancy services from the business context.

Who should attend ?

Security Analysts, IT Security Specialists, Network Security Engineers, Compliance Officers, Risk Analysts, System Administrators, Security Engineers, IT Specialists, Security Architects, Cyber security Analysts, Vulnerability Assessors, Managers

Course Outline :

Day – I

 

• Overview

Definition and scope of IT audit

The CIA Triage (Confidentiality, Integrity and Availability

IT Audit Process

IT audit planning
Conduct of IT audit fieldwork
Reporting of IT audit observations
o IT Audit Risks

o Assessing IT Risk

o Designing IT Controls

o Business Process Controls

IT Governance, Risk Management and Compliance (GRC)

Objectives and scope of GRC
Business and IT Alignment
Third-party risk management
GRC systems – Desired Outcomes
• Standards

o COBIT

o ISO/IEC 27001

o NIST SP-800s

o SANS

o Center for Internet Security (CIS)

• Regulations

o Sarbanes-Oxley

o HIPAA/HITECH

o Privacy & GDPR & CCPA

Day – II

 

Disaster Recovery and Business Continuity

Disaster recovery planning site concepts
Systems and data backup
Systems and data recovery procedures
BCP/DRP planning considerations
Crisis management
Database terms and internet terms
Basic IT infrastructure
Network concepts
o Defining types of networks

o OSI model

o TCP/IP

• Networking Risks & Controls

o Remote access and authentication

o Common vulnerabilities

•Threat models, e.g., social engineering, malware, Advanced Persistent Threat (APT), Denial of Service (DoS)

Network security Tools & resources

Understanding Vulnerability Assessment and Penetration Testing (VAPT)

Web application testing methodology, tools & demos of OWASP top 10

Darknet & deep web

General IT audit checklist

Understanding cyber security framework of RBI, SEBI, IRDAI

Who should attend :

Security Analysts, IT Security Specialists, Network Security Engineers, Compliance Officers, Risk Analysts, System Administrators, Security Engineers, IT Specialists, Security Architects, Cyber security Analysts, Vulnerability Assessors, Managers

Speaker Profile :

Shrikrishna Kulkarni possess more than 26+ years of diverse experience in Banking, Pharma, Manufacturing, Telecom(M&E), and consulting experience in Infrastructure, Cloud, Managed Security Services (MSS), IT Audit, SAP, HANA, technologies supporting infrastructure and applications domain.

• Complex IT projects and issues that encompass a wide range of internal and external systems,

components, and processes

• Cloud – Private, Public & Hybrid

• Application & infrastructure security

• Business continuity

• Project Management

• Pre-Sales

• Audit & Compliance

Experience in BCP, IT DR solutions (Sanovi, Perpuity) and Implementation, Crisis Management. Designing “DRAAS” as Service, BCMS/ ISMS, IT Service Continuity.

Implementation Experience includes BCP/DR Planning, Impact Analysis on Business, Database Replications Solutions, DR automation solutions, Infrastructure and Applications DR for Complex projects in Pharma, Banking, Manufacturing, M&E

Participation Fee :

Members Rs. 9,000 + 18% GST
Non-Members Rs. 10,000 + 18% GST
Bank Details for NEFT
Account No. 10996680930
IFSC CODE SBIN0000300
Bank Name State Bank of India
Branch Address Mumbai Main Branch

Cheque /Demand Draft should be drawn in favor of “BOMBAY CHAMBER OF COMMERCE AND INDUSTRY”

Contact Details :

Revati Khare || Assistant Director – Digitalisation Committee
Email : revati.khare@bombaychamber.com
Tel. (D) + 91 22 6120 0231; (M) + 91 9892029473

Additional Details

Organizer name -

Venue Name -

Event Fees Type

Event or Seminar - Training

To register for this event email your details to infotech@bombaychamber.com

Register using webmail: Gmail / AOL / Yahoo / Outlook

 

Date And Time

December 23, 2024 10:00 AM to
December 24, 2024 05:00 PM
 

Registration End Date

December 24, 2024
 

Location

Online event
 

Event Types

 

Event Category

Share With Friends

instagram default popup image round
Follow Me
502k 100k 3 month ago
Share