Domain 1: Information Systems Auditing Process
- Planning: IS audit standards, guidelines and code of professional ethics; types of audits, assessments and reviews
- Risk-based audit planning and types of controls
- Execution: audit project management, testing and sampling methodologies, evidence collection techniques
- Audit data analysis, reporting and communication techniques, quality assurance and improvement of the audit process
Domain 2: Governance and Management of IT
- Laws, regulations and industry standards; organisational structure, IT governance and IT strategy
- IT policies, standards, procedures and practices; enterprise architecture
- Enterprise risk management, privacy programme and principles, data governance and data classification
- IT management: resource and vendor management, performance monitoring and reporting, quality assurance and quality management
Domain 3: Information Systems Acquisition, Development and Implementation
- Project governance and project management; business case and feasibility analysis
- System development methodologies; identification and design of controls
- Implementation: system readiness and implementation testing, configuration and release management
- System migration, infrastructure deployment and data conversion; post-implementation review
Domain 4: Information Systems Operations and Business Resilience
- IT components, IT asset management, job scheduling and automation of production processes, system interfaces
- Shadow IT and end-user computing; availability and capacity management
- Problem and incident management; change, configuration and patch management; management of operational logs
- IT service level management and database management
- Business resilience: business impact analysis, system and operational resilience, data backup, storage and restoration, business continuity and disaster recovery plans
Domain 5: Protection of Information Assets
- Frameworks, standards and guidelines for the security of information assets; physical and environmental controls
- Identity and access management, network and endpoint security, data loss prevention
- Data encryption and Public Key Infrastructure (PKI); cloud and virtualised environments; mobile devices, wireless networks and the Internet of Things
- Security event management: awareness programmes, attack methods and techniques, security testing and monitoring tools
- Security incident response, evidence preservation and forensics