CISA Exam Cram 2: Certified Information Systems Auditor - Softcover

9780789732729: CISA Exam Cram 2: Certified Information Systems Auditor
View all copies of this ISBN edition:
 
 

Want an affordable yet innovative approach to studying for the Certified Information Systems Auditor (CISA) 2005 exam? CISA 2005 Exam Cram 2 is your solution. You will have the essential material for passing the CISA 2005 exam right at your fingertips. All exam objectives are covered and you'll find practice exams, exam alerts, notes, tips and cautions to help guide you through your exam preparation. A CD also provides you with a video introduction to the exam and complete explanations of answers to the practice questions from Certified Tech Trainers (CTT). As a special bonus, you will receive $75 in discounts on CTT products and services. For your smartest, most efficient way to get certified, choose CISA 2005 Exam Cram 2.

"synopsis" may belong to another edition of this title.

About the Author:

Allen Keele has 20 certifications, the CISA, CISM, CISSP, and Security+ among them.  As president and program developer for Certified Tech Trainers, he has over 14 years experience in information security and risk management. He has authored books on security and lectures at leading companies such as Deloitte and Touche, Blue Cross-Blue Shield, and Fujitsu. 

Keith Mortier holds a CISA and CISSP certification and a BS in Computer Information Systems. Within the IT industry, Keith has designed and implemented risk assessment, vulnerability testing and disaster recovery-security plans. Keith is president of LMI solutions providing security services to both commercial and government clients.

Excerpt. © Reprinted by permission. All rights reserved.:
Introduction

Introduction

Welcome to Information Systems Audit and Controls Association's Certified Information Systems Auditor (CISA) Exam Cram 2! Whether this is your first or your fifteenth Exam Cram 2 series book, you will find information here that will help ensure your success as you pursue knowledge, experience, and certification. This introduction explains ISACA certification programs in general and talks about how the Exam Cram 2 series can help you prepare for the CISA exam. This chapter discusses the basics of ISACA certification exams, including a description of the testing environment and a discussion of test-taking strategies. Chapters 1 through 7 are designed to remind you of everything you need to know to take—and pass—the CISA certification exam. The two sample tests at the end of the book should give you a reasonably accurate assessment of your knowledge—and, yes, we've provided the answers and their explanations to the tests. Read the book and understand the material, and you'll stand a very good chance of passing the test.

Exam Cram 2 books help you understand and appreciate the subjects and materials you need to pass ISACA certification exams. Exam Cram 2 books are aimed strictly at test preparation and review. They do not teach you everything you need to know about a topic. Instead, we present and dissect the questions and problems we've found that you're likely to encounter on a test. We've worked to bring together as much information as possible about ISACA certification exams.

Nevertheless, to completely prepare yourself for any ISACA test, we recommend that you begin by taking the Self-Assessment that is included in this book, immediately following this introduction. The Self-Assessment will help you evaluate your knowledge base against the requirements for an ISACA Certified Information Systems Auditor under both ideal and real circumstances.

Based on what you learn from the Self-Assessment, you might decide to begin your studies with some classroom training, some practice with systems auditing, or some background reading. On the other hand, you might decide to read one of the many study guides available from ISACA or third-party vendors on certain topics, including the award-winning certification preparation series from Que Publishing. We also recommend that you supplement your study program with visits to http://www.examcram2.com to receive additional practice questions, get advice, and track the CISA program.

About the CISA Exam and Content Areas

The Information Systems Audit and Control Association (ISACA) developed the Certified Information Systems Auditor (CISA) program in 1978 to accomplish these goals:

  • Develop and maintain a testing instrument that could be used to evaluate an individual's competency in conducting information systems audits

  • Provide a mechanism for motivating information systems auditors to maintain their competencies and monitoring the success of the maintenance programs

  • Aid top management in developing a sound information systems audit function by providing criteria for personnel selection and development

The CISA program is designed to assess and certify individuals in the IS audit, control, or security profession who demonstrate exceptional skill, judgment and proficiency in IS audit, control, and security practices.

More than 35,000 professionals have earned the CISA certification since inception, and the certification is widely respected as a premier information security and information systems auditing accreditation. The certification continues to grow in acceptance and employer desirability; more than 15,000 candidates are expected to register for the 2005 exam (15% growth from 2004).

The CISA exam is offered only once per year, in early June; the exam for 2005 is offered on June 11. You may register as early as February 2, 2005, and the registration deadline is March 30, 2005. You should note that this exam is not computerized and is not provided through conventional testing centers such as Prometric or Vue. You may register online at http://www.isaca.org or take the exam at any ISACA chapter location. The current published exam registration fee is $385 for members and $505 for nonmembers. The best place to learn more about the CISA certification and the CISA exam is http://www.isaca.org.

The Information Systems Audit and Control Association states that the tasks and knowledge required of today's and tomorrow's information systems audit professional serve as the blueprint for the CISA examination. These areas are defined through a Practice Analysis that is conducted at regular intervals and consists of both process and content components in a CISA's job function. Accordingly, exams consist of tasks that are routinely performed by a CISA and the required knowledge to perform these tasks.

How valuable is the CISA certification to employers and individuals? Sometimes the best measure of a certification's value is reflected by how certification holders feel about the certification after having achieved it. In 2001, ISACA surveyed its membership to obtain feedback from CISA certified professionals as to whether obtaining the certification had advanced their careers. Seventy-one percent of members holding the CISA certification affirmed the value of the certification toward career advancement, and 75% of all members, certified and noncertified alike, felt that the CISA certification would be valuable for career advancement in the future.

Another measure of a certification's value can be found by assessing the desirability of the certification to employers. How many employers desire the certification as an employment prerequisite? Looking to popular job boards on the Internet such as Monster.com, TotalJobs.com, and Workthing.com, we can see that the quantity and quality of jobs requiring CISA certification are growing every month.

What is driving the employer demand for the CISA certification? Companies are under growing pressure to improve, document, and test their methods for managing information. As the late Dr. W. E. Deming (1900–1993) was able to prove, the quest for quality of processes and product is achieved through careful measurement of what exists, thorough analysis of defects, and effective remediation and correction. The quest for quality is just that: a quest. This means that quality improvement is an ongoing process that requires continuous reassessment. Assessing the capability of information systems to support business goals while maintaining information confidentiality, integrity, and reliability is exactly what a Certified Information Systems Auditor (CISA) does well.

It is easy enough to create and implement a technology for processing information, which is what the majority of individuals within the information technology (IT) industry are tasked with. However, using IT to facilitate communication and information management is only half the story. Today we need to make sure that IT not only does what it is supposed to do, but also that it will not do what it is not supposed to do. For example, we have created systems to facilitate online commerce and transaction processing. Will those same systems ensure that no transactional errors occur? Will those systems resist accidental or purposeful and malicious modification of data? Do the systems protect the information confidentiality well enough to comply with new privacy laws and standards? We cannot know the answers to these questions unless we have professionally reviewed, measured, and tested the systems. Again, this is what a CISA does.

Although many organizations strive to ensure quality of processes and manufacturing according to ISO standards such as the ISO 9000 series, for competitive reasons, other organizations are forced to invest in quality assurance to comply with the law. Either way, most organizations are spending increasing amounts of money to improve corporate governance. We draw from this example to show the importance of improving IT governance in today's corporate and governmental environment.

In the United States, the healthcare industry is painfully aware of the effects the Health Insurance Portability and Accountability Act (HIPAA) has had on how it does business and manages information. How does an affected healthcare entity prove systems compliance with HIPAA? Why, an audit must be performed! Who directs or assists such a specialized systems audit? Finding someone certified to perform professional systems audits might be a good start. A CISA perhaps?

Likewise, other U.S. legislation, such as the Gramm-Leach-Bliley Act of 1999 (affecting financial institutions) and the Sarbanes-Oxley Act of 2002 (affecting all organizations that are publicly traded on the New York Stock Exchange), are forcing companies to change they way they do business and manage information. Other countries around the world have instituted similar laws or are in the process of creating similar laws. Just look at the United Kingdom's Combined Code, more commonly known as the Turnbull report, and you will see what we mean. Proving compliance with any legislation requires testing and documentation. Testing and documentation of systems controls is what a CISA systems auditor does. The simple fact is that there are new and compelling reasons for companies and government agencies to increase and improve systems auditing, and they need CISA professionals to help them.

The CISA examination is quite broad in scope. The following is a brief description of each topic area. As we move through the chapters, we cover each area in greater detail and provide a map for navigating the CISA exam.

  • Area 1—Management, planning, and organization of IS comprise 11% of the exam. Evaluate strategy, policies, standards, procedures, and related practices for the management, planning, and organization of IS.

  • Area 2—Technical infrastructure and operational practices comprise 13% of the exam. Evaluate the effectiveness and efficiency of the organization's implementation and ongoing management of technical and operational infrastructure to ensure that they adequately support the organization's business objectives.

  • Area 3—Protection of information assets comprises 25% of the exam. Evaluate IT infrastructure security to ensure that it satisfies the organization's business requirements for safeguarding information assets against unauthorized use, disclosure, modification, damage, and loss.

  • Area 4—Disaster recovery and business continuity comprise 10% of the exam. Evaluate the process for developing and maintaining documented, communicated, and tested plans for the continuity of business operations and IS processing in the event of a disruption.

  • Area 5—Business application system development, acquisition, implementation, and maintenance comprise 16% of the exam. Evaluate the methodology and processes by which the business application system development, acquisition, implementation, and maintenance are undertaken to ensure that they meet the organization's business objectives.

  • Area 6—Business process evaluation and risk management comprise 15% of the exam. Evaluate business systems and processes to ensure that risks are managed in accordance with the organization's business objectives.

  • Area 7—The IS audit process comprises 10% of the exam. Conduct IS audits in accordance with generally accepted IS audit standards and guidelines to ensure that the organization's information technology and business systems are adequately controlled, monitored, and assessed.

Reference: http://www.isca.org

How to Prepare for the Exam

The CISA exam is somewhat difficult to prepare for because it is very broad in scope and asks indirect questions requiring strong cognitive skills. The exam is also unusual in its format. The exam is not computerized and is presented as 200 multiple-choice questions in a paper exam booklet. You are required to provide your answers on a familiar "fill-in-the-bubble" answer sheet.

This is not an exam that you can adequately prepare for by simply rote- memorizing terms and definitions. You need to be able to analyze a scenario and answer by combining various knowledge points from various topic areas. Successfully completing this exam requires a great deal of thought and analysis to properly choose the "best" solution from several "viable" solutions. Having successfully passed the CISA, CISSP, Security+, SCNP, CCSE, CCSI, CCNP, CCNA, MCSE, CCEA, and a multitude of other technical and professional certifications, Allen Keele is able to provide valuable exam-taking tips in the audiovisual presentation of the computer-based training available on the accompanying CD-ROM within this book.

Additional Exam-Preparation Resources

Because the scope of the CISA certification is so broad, you could spend months, or even years, reading the myriad of books recommended by ISACA. Unfortunately, there is not much available for the individual seeking a concise distillation of the exam topics only—hence the need for this book! However, other resources are available via additional books and instructor-led training.

  • Information Systems Audit and Controls Association (ISACA)—ISACA sells exam-preparation materials on its website, and we recommend that you seriously consider augmenting your studies with these two:

  • CISA Review Manual —Note that this book is purposed as a review manual. As such, many of my students have found it difficult to prepare for the CISA exam with this book because it tends to focus on strictly review points rather than teaching the supporting concepts. It has been my experience that m...

"About this title" may belong to another edition of this title.

  • PublisherPearson It Certification
  • Publication date2005
  • ISBN 10 0789732726
  • ISBN 13 9780789732729
  • BindingPaperback
  • Number of pages420

Top Search Results from the AbeBooks Marketplace

Stock Image

Keele, Allen; Mortier, Keith
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Paperback Quantity: 1
Seller:
GoldenWavesOfBooks
(Fayetteville, TX, U.S.A.)

Book Description Paperback. Condition: new. New. Fast Shipping and good customer service. Seller Inventory # Holz_New_0789732726

More information about this seller | Contact seller

Buy New
US$ 53.57
Convert currency

Add to Basket

Shipping: US$ 4.00
Within U.S.A.
Destination, rates & speeds
Stock Image

Keele, Allen; Mortier, Keith
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Paperback Quantity: 1
Seller:
Wizard Books
(Long Beach, CA, U.S.A.)

Book Description Paperback. Condition: new. New. Seller Inventory # Wizard0789732726

More information about this seller | Contact seller

Buy New
US$ 56.33
Convert currency

Add to Basket

Shipping: US$ 3.50
Within U.S.A.
Destination, rates & speeds
Stock Image

Keele, Allen; Mortier, Keith
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Softcover Quantity: 1
Seller:
BennettBooksLtd
(North Las Vegas, NV, U.S.A.)

Book Description Condition: New. New. In shrink wrap. Looks like an interesting title! 1.2. Seller Inventory # Q-0789732726

More information about this seller | Contact seller

Buy New
US$ 96.86
Convert currency

Add to Basket

Shipping: US$ 5.02
Within U.S.A.
Destination, rates & speeds
Stock Image

Keele, Allen
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Paperback Quantity: 1
Seller:
Big Bill's Books
(Wimberley, TX, U.S.A.)

Book Description Paperback. Condition: new. Brand New Copy. Seller Inventory # BBB_new0789732726

More information about this seller | Contact seller

Buy New
US$ 101.67
Convert currency

Add to Basket

Shipping: US$ 3.00
Within U.S.A.
Destination, rates & speeds
Stock Image

Keele, Allen
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Paperback Quantity: 1
Seller:
GoldenDragon
(Houston, TX, U.S.A.)

Book Description Paperback. Condition: new. Buy for Great customer experience. Seller Inventory # GoldenDragon0789732726

More information about this seller | Contact seller

Buy New
US$ 101.69
Convert currency

Add to Basket

Shipping: US$ 3.25
Within U.S.A.
Destination, rates & speeds
Stock Image

Keele, Allen
Published by Pearson It Certification (2005)
ISBN 10: 0789732726 ISBN 13: 9780789732729
New Paperback Quantity: 1
Seller:
GoldBooks
(Denver, CO, U.S.A.)

Book Description Paperback. Condition: new. New Copy. Customer Service Guaranteed. Seller Inventory # think0789732726

More information about this seller | Contact seller

Buy New
US$ 101.55
Convert currency

Add to Basket

Shipping: US$ 4.25
Within U.S.A.
Destination, rates & speeds