| 주제 | 소개 |
|---|
| 주제 1 | - 5. Protection of Information Assets: As the largest portion of the exam, this domain focuses on ensuring the confidentiality, integrity, and availability of information assets. It includes topics such as access control mechanisms, cryptographic practices, network and endpoint security, physical security, and data classification. Candidates must demonstrate the ability to evaluate security policies, perform risk assessments, and ensure compliance with applicable regulations. This domain equips professionals with the knowledge to protect against internal and external threats, enforce security policies, and promote a secure organizational culture.
|
| 주제 2 | - Information Systems Operations and Business Resilience: This section covers the critical activities involved in the day-to-day operations of information systems, including service delivery, performance monitoring, incident management, and problem resolution. It also addresses business continuity and disaster recovery planning to ensure operational resilience. Candidates should be familiar with operational controls, third-party service management, data backup procedures, and disaster recovery testing. This domain ensures professionals are capable of supporting continuous and secure IT operations while preparing the organization to respond to and recover from disruptions effectively.
|
| 주제 3 | - Governance and Management of IT: This domain focuses on the governance and management structures that ensure IT supports the organization’s strategies and objectives. It covers the frameworks, policies, and procedures that drive effective IT governance and the alignment of IT and business goals. Candidates will be tested on IT resource management, performance monitoring, organizational structure, and risk management processes. Understanding this domain is vital for ensuring that IT investments generate business value while maintaining transparency, accountability, and compliance with external requirements and internal policies.
|
| 주제 4 | - Auditing Fundamentals: This section forms the foundation of the CISA exam and focuses on the essential principles and practices of auditing information systems. Candidates are expected to demonstrate a solid understanding of how to plan, conduct, and report on audits following ISACA’s auditing standards and guidelines. It covers key topics such as audit charter development, risk-based audit planning, evidence gathering, audit objectives, and procedures. Additionally, it emphasizes the importance of professional ethics, audit quality assurance, and effective communication of audit findings to stakeholders. Mastery of this domain ensures that professionals can provide independent assurance and consulting services to help organizations maintain robust internal controls and comply with relevant laws and regulations.
|
| 주제 5 | - Information Systems Acquisition, Development, and Implementation: This domain evaluates the candidate's knowledge of best practices for acquiring, developing, and implementing information systems that meet organizational needs. Topics include feasibility studies, business case development, system development life cycle (SDLC), change management, and testing methodologies. Candidates must understand how to assess project governance, system integration, and the use of third-party services. This section also emphasizes the importance of ensuring that new systems are secure, reliable, and aligned with business objectives from the outset of their lifecycle.
|