1 / 25100%
CIS349
Preview: CIS349 Information echnology Audit and Control : T
Course Guide
Prerequisites
Course Description
Instructional Materials
Course Learning Outcomes
This course covers the principles, approaches, and methodologies in auditing information systems to ensure the processes and procedures are in
compliance with pertinent laws and regulatory provisions, especially in the context of information systems security (ISS). Topics include the
processes used to protect and secure business and consumer privacy data, an explanation of compliancy laws, and the process and legal
requirements for conducting IT infrastructure compliance audits.
Required Resources
Martin Weiss. 2016. Auditing IT Infrastructures for Compliance . CIS349 Jones Bartlett Publishers 2nd edition & textbook available at
https://www.strayerbookstore.com
Microsoft. No date. Microsoft 365 Training. http://office.microsoft.com/en-us/support/training-FX101782702.aspx
Note: Microsoft Office, Microsoft Visio, and Microsoft Project or their equivalents such as Open Project, Dia, and OpenOffice are required.
Tutorials for Microsoft Office can 2013 be found on Microsoft’s support site, located at the link provided above.
National Institute of Standards and Technology. 2014. Assessing Security and Privacy Controls in Federal Information Systems and
Organizations. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53Ar4.pdf
Supplemental Resources
Chris Davis. 2011. IT Auditing, Using Controls to Protect Information Assets. CIS349 McGraw-Hill Osborne Media 2nd edition textbook available
at https://www.strayerbookstore.com.
Shon Harris. 2011. CISSP All-in-One Exam Guide . CIS349 McGraw-Hill Osborne Media 5th edition textbook available at
https://www.strayerbookstore.com
Robert R. Moeller. 2010. IT Audit, Control, and Security . CIS349 John Wiley & Sons 2nd edition textbook available at
https://www.strayerbookstore.com
Recommend technical security safeguards to protect private information.
1
Analyze risk appetite with a risk assessment approach.
2
Determine the strengths and weaknesses of MAC, DAC, and RBAC methods of access control.
3
2020 Strayer University. All Rights Reserved. This document contains Strayer University Confidential and Proprietary information and may not be copied, further distributed, or
otherwise disclosed in whole or in part, without the expressed written permission of Strayer University.
NOTE: The links in this document do not function. Please refer to your course to
view/download linked content.
Weekly Course Schedule
Week 1 - To Do List
Learn: Read Chapter from 1 Auditing
IT
Infrastructures
for
Compliance.
Learn: Read this week's PowerPoint and notes.
Discuss: Introduce yourself and complete the discussion, Governance and Compliance.
Assignment: Submit the assignment, Worksheet: Intro to the NIST SP 800-53A.
Week 2 - To Do List
Learn: Read Chapters 2 and 3 from Auditing
IT
Infrastructures
for
Compliance.
Learn: Read this week's PowerPoints and notes.
Students also viewed