menu image
AssuranceSecurityGovernanceMembers & LeadersProfessionals & PractitionersStudents & EducatorsExhibitors & Advertisers
menu shadow
Overview & History
What's New
Certification
Education & Conferences
Standards
Research
 Current Projects
 Deliverables
Publications
Chapters
Membership
Bookstore
Downloads
COBIT
Risk IT
Val IT
Career Centre
Languages
spacer image
Print this page
spacer image


Featured Deliverables

Security, Audit and Control Features Oracle Database, 3rd Edition
Security, Audit and Control Features Oracle Database, 3rd Edition

This update of the 2004 edition focuses on the attributes and incremental functionality in the most recent Oracle relational database management system (RDBMS) software releases 10g and 11g (with focus on 11g). The book covers other “soft” topics that an assessor needs to be familiar with, such as developing a strategy to plan the audit, understanding the IT environment, and reviewing policies and standards. It also provides readers with the approach, knowledge and tools to effectively plan and execute an Oracle database security assessment.

Implementing and Continually Improving IT Governance
Implementing and Continually Improving IT Governance

Implementing and Continually Improving IT Governance enhances, expands and improves on the content of the prior ISACA IT Governance Implementation Guide Using COBIT® and Val IT™, 2nd Edition publication. It incorporates valuable references to cutting edge research from the recent ISACA publications The Val IT™ Framework 2.0 and The Risk IT Framework, as well as from the recently issued ISO/IEC 38500 standard on IT governance.

This guide provides an approach for implementing IT governance in such a way that the implementation team can get started in an effective and efficient manner. The objective is to provide a good practice approach for implementing and maintaining effective IT governance based on a continual improvement life cycle that should be tailored to suit the enterprise’s specific needs. Subjects covered in the guide include:

  • Positioning IT governance
  • Taking the first steps towards IT governance
  • Challenges and success factors
  • Enabling change
  • Implementing a continual improvement life cycle
  • Using COBIT, Val IT and Risk IT components

The tool kit zip files for ISACA members now contain 22 supporting documents in various formats. The tool kits include an Excel Process Maturity Tool based on the COBIT maturity model and designed to provide practical support for its use, highlighting the need to address IT governance, perform a gap analysis and identify areas to mature.

The Risk IT Framework

The Risk IT Framework

The Risk IT Framework fills the gap between generic risk management frameworks and detailed (primarily security-related) IT risk management frameworks. It provides an end-to-end, comprehensive view of all risks related to the use of IT and a similarly thorough treatment of risk management, from the tone and culture at the top, to operational issues. In summary, the framework will enable enterprises to understand and manage all significant IT risk types, building upon the existing risk related components within the current ISACA frameworks, i.e., COBIT and Val IT.

The Risk IT Practitioner Guide

The Risk IT Practitioner Guide
The Risk IT Practitioner Guide

The Risk IT Framework describes a detailed process model for the management of IT-related risk. In this model, multiple references are made to risk analysis, scenario analysis, responsibilities, key risk indicators and many other risk-related terms. The Risk IT Practitioner Guide contains practical, detailed guidance on how to accomplish some of the key activities described in the process model.

The Risk IT Framework

Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives
Cloud Computing Whitepaper

Cloud computing is an emerging technology that may help enterprises meet the increased requirements of lower total cost of ownership (TCO), higher return on investment (ROI), increased efficiency, dynamic provisioning and utility-like pay-as-you-go services. However, many IT professionals are citing the increased risks associated with trusting information assets to the cloud as something that must be clearly understood and managed by relevant stakeholders. This page provides resources for more information on what cloud computing and aid in understanding this initiative and how it could align with a business.




Additional Information on Cloud Computing:

Deliverables, in date order of completion

Security, Audit and Control Features Oracle Database, 3rd Edition Dec 2009
Implementing and Continually Improving IT Governance Nov 2009
The Risk IT Framework Nov 2009
The Risk IT Practitioner Guide Nov 2009
Cloud Computing:  Business Benefits With Security, Governance and Assurance Perspectives Oct 2009
Security, Audit and Control Features SAP® ERP, 3rd Edition Aug 2009
Building the Business Case for COBIT® and Val IT™:  Executive Briefing Jun 2009
Val IT™ Mapping: Mapping of Val IT™ 2.0 to MSP™, PRINCE2™ and ITIL® V3 May 2009
COBIT and Application Controls:  A Management Guide May 2009
COBIT User Guide for Service Managers Apr 2009
ITGI™ Enables ISO/IEC 38500:2008 Adoption Feb 2009
An Introduction to the Business Model for Information Security Jan 2009
Change Management Audit/Assurance Program Jan 2009
Generic Application Audit/Assurance Program Jan 2009
Identity Management Audit/Assurance Program Jan 2009
IT Continuity Planning Audit/Assurance Program Jan 2009
Network Perimeter Security Audit/Assurance Program Jan 2009
Outsourced IT Environments Audit/Assurance Program Jan 2009
Security Incident Management Audit/Assurance Program Jan 2009
Systems Development and Project Management Audit/Assurance Program Jan 2009
UNIX/LINUX Operating System Security Audit/Assurance Program Jan 2009
z/OS Security Audit/Assurance Program Jan 2009
ITGI Global Survey Results Jan 2009
ITGI Roundtable Discussions Jan 2009
Defining Information Security Manager Position Requirements: Guidance for Executives and Managers Nov 2008
IT Governance and Process Maturity Nov 2008
Unlocking Value: An Executive Primer on the Critical Role of IT Governance Nov 2008
Aligning COBIT® 4.1, ITIL® V3 and ISO/IEC 27002 for Business Benefit Nov 2008
Understanding How Business Goals Drive IT Goals Oct 2008
Identifying and Aligning Business Goals and IT Goals Oct 2008
COBIT Mapping: Mapping of ITIL V3 With COBIT 4.1 Jul 2008
Top Business/Technology Issues - Survey Results Jul 2008
Enterprise Value: Governance of IT Investments, Getting Started with Value Management Jul 2008
Enterprise Value: Governance of IT Investments, The Val IT Framework 2.0 Jul 2008
Information Security Governance: Guidance for Information Security Managers May 2008
Information Security Career Progression Survey Results May 2008
IT Governance Global Status Report - 2008 May 2008
ITAF: A Professional Practices Framework for IT Assurance Apr 2008
COBIT Mapping: Mapping of NIST SP800-53 Rev 1 With COBIT 4.1 Nov 2007
Stepping Through the InfoSec Program Oct 2007
IT Control Objectives for Basel II: The Importance of Governance and Risk Management for Compliance Oct 2007
COBIT Quickstart, 2nd Edition Sep 2007
COBIT Mapping: Mapping of TOGAF 8.1 With COBIT 4.0 Jun 2007
IT Assurance Guide: Using COBIT May 2007
COBIT 4.1 May 2007
COBIT Control Practices: Guidance to Achieve Control Objective for Successful IT Governance, 2nd Edition Apr 2007
COBIT Mapping: Mapping of CMMI for Development V1.2 With COBIT Feb 2007
COBIT Mapping: Mapping of ITIL With COBIT 4.0 Jan 2007
COBIT Mapping: Mapping PRINCE2 With COBIT Jan 2007
COBIT Mapping: Mapping ISO/IEC 17799:2005 With COBIT 4.0 Dec 2006
Security, Audit and Control Features Oracle® E-Business Suite Oct 2006
IT Control Objectives for Sarbanes-Oxley 2nd Edition Sep 2006
COBIT Mapping: Mapping SEI’s CMM for Software With COBIT 4.0 Sep 2006
COBIT Mapping: Mapping PMBOK with COBIT 4.0 Aug 2006
Security, Audit and Control Features PeopleSoft® 2nd Edition Aug 2006
COBIT Mapping: Mapping ISO/IEC 17799 :2000 With COBIT, 2nd Edition May 2006
COBIT Mapping Overview of International IT Guidance 2nd Edition Apr 2006
Security, Audit and Control Features SAP® R/3®: A Technical and Risk Management Reference Guide 2nd Edition Mar 2006
Information Security Governance Guidance for Boards of Directors and Executive Management 2nd Edition Mar 2006
Managing Risk in the Wireless Environment: Security, Audit and Control Issues Jan 2006
Critical Elements of Information Security Program Success Dec 2005
IT Governance Domains Practices and Competencies: IT Alignment Who Is in Charge? Sep 2005
Security Awareness—Best Practices to Secure Your Enterprise Aug 2005
IT Governance Domains Practices and Competencies: Measuring and Demonstrating the Value of IT Aug 2005
Information Security Governance—Top Actions for Security Managers Aug 2005
IT Governance Domains Practices and Competencies: Governance of Outsourcing Jul 2005
Linux: Security, Audit and Control Features Jul 2005
IT Governance Domains Practices and Competencies: Information Risks-Whose Business are They? Jun 2005
IT Governance Domains Practices and Competencies: Optimising Value Creation from IT Investments Jun 2005
Cybercrime: Incident Response and Digital Forensics Services Project Jun 2005
Information Security Harmonization — Classification of Global Guidance Feb 2005
Governance in the Extended Enterprise Jan 2005
Managing Enterprise Information Integrity Jun 2004
Control Practices for COBIT High-level Objectives Jun 2004
Introduction to Voice-over IP Technology Apr 2004
Security, Audit and Control Features PeopleSoft® Mar 2004
Oracle Database Security, Audit and Control Features, 2nd Edition Mar 2004
Risk and Control of Biometric Technologies: A Security, Audit and Control Primer Jan 2004
Enterprise Identity Management Dec 2003
OS/390-z/OS Security, Audit and Control Features Dec 2003
Peer-to-peer Networking Security and Control Oct 2003
Board Briefing on IT Governance, 2nd Edition Oct 2003
Security, Audit and Control Features Oracle® Applications Oct 2003
Risks of Customer Relationship Management: A Security, Control and Audit Approach Jun 2003
Electronic and Digital Signatures: A Global Status Report Jun 2002
e-Commerce Security: Securing the Network Perimeter Jun 2002
e-Commerce Security: Business Continuity Planning Jun 2002
Security Provisioning: Managing Access in Extended Enterprises Jun 2002
e-Commerce Security - Public Key Infrastructure: Good Practices for Secure Communications Jun 2001
A Guide To Cross-Border Privacy Impact Assessments Jun 2001
e-Commerce Security - A Global Status Report Jun 2000
e-Commerce Security - Trading Partner Identification, Registration and Enrollment Jun 2000
e-Commerce Security - Enterprise Best Practices Jun 2000
Helsinki Finland ISACA Chapter TAKO Project 1997 Jan 1997

nav menu image
spacer image
Assurance | Security | Governance
Members & Leaders | Professionals & Practitioners | Students & Educators | Exhibitors & Advertisers
Info Request | Join | Bookstore | My ISACA | About ISACA
Home | Site Map | Shopping Cart | Logout | Contact Us
spacer image
menu shadow

Terms Of Use | Privacy Policy | IP Guidelines
© 2010 ISACA All rights reserved.
3701 Algonquin Road, Suite 1010, Rolling Meadows, Illinois 60008 USA