<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/feed.rss.xml" type="text/xsl" media="screen"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Alison</title>
    <description/>
    <link>https://speakerdeck.com/alisecure</link>
    <atom:link rel="self" type="application/rss+xml" href="https://speakerdeck.com/alisecure.rss"/>
    <lastBuildDate>2026-04-26 08:40:03 -0400</lastBuildDate>
    <item>
      <title>CISA_Series_-_Audit_Process_Part_2B.pdf</title>
      <description>Part 2B of the CISA Audit Process series explores the governance and foundational concepts that support effective information systems auditing and risk-based assurance activities.

This presentation  covers:
• Governance structures and oversight responsibilities
• The role of the Board, Audit Committee, and Chief Audit Executive
• The Three Lines Model and assurance responsibilities
• Audit authority, independence, and objectivity
• The purpose and importance of the Audit Charter
• Attribute vs Performance Standards
• Audit ethics and professional conduct
• Understanding the organisation and business environment
• How business understanding supports enterprise risk assessment, audit universe development, and strategic audit planning</description>
      <media:content url="https://files.speakerdeck.com/presentations/3e2e114ec8864f77a01f6860f73cbce6/preview_slide_0.jpg?39389330" type="image/jpeg" medium="image"/>
      <content:encoded>Part 2B of the CISA Audit Process series explores the governance and foundational concepts that support effective information systems auditing and risk-based assurance activities.

This presentation  covers:
• Governance structures and oversight responsibilities
• The role of the Board, Audit Committee, and Chief Audit Executive
• The Three Lines Model and assurance responsibilities
• Audit authority, independence, and objectivity
• The purpose and importance of the Audit Charter
• Attribute vs Performance Standards
• Audit ethics and professional conduct
• Understanding the organisation and business environment
• How business understanding supports enterprise risk assessment, audit universe development, and strategic audit planning</content:encoded>
      <pubDate>Wed, 13 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-audit-process-part-2b</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-audit-process-part-2b</guid>
    </item>
    <item>
      <title>CISA Series Introduction - IS Audit Process</title>
      <description>Welcome to Part 1 of the CISA Series — Introduction and the Information Systems Audit Process.

The presentation slides where we explore the foundations of Information Systems auditing and walk through the complete IS audit lifecycle from governance and planning through to fieldwork, reporting, follow-up, and continuous improvement.

This session covers:
• Audit standards and guidelines
• Common audit frameworks and professional practices
• Professional ethics and auditor responsibilities
• Types of audits and audit approaches
• Audit roles and responsibilities
• Governance and audit independence
• Attribute vs Performance Standards
• The complete IS audit lifecycle overview</description>
      <media:content url="https://files.speakerdeck.com/presentations/bc97e59c4ac2459894b2c3bbd1bbdc43/preview_slide_0.jpg?39378774" type="image/jpeg" medium="image"/>
      <content:encoded>Welcome to Part 1 of the CISA Series — Introduction and the Information Systems Audit Process.

The presentation slides where we explore the foundations of Information Systems auditing and walk through the complete IS audit lifecycle from governance and planning through to fieldwork, reporting, follow-up, and continuous improvement.

This session covers:
• Audit standards and guidelines
• Common audit frameworks and professional practices
• Professional ethics and auditor responsibilities
• Types of audits and audit approaches
• Audit roles and responsibilities
• Governance and audit independence
• Attribute vs Performance Standards
• The complete IS audit lifecycle overview</content:encoded>
      <pubDate>Tue, 12 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-introduction-is-audit-process</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-introduction-is-audit-process</guid>
    </item>
    <item>
      <title>CISA Series - Part 7 Exam Preparation</title>
      <description>Master the mindset behind the CISA exam in Part 7 of the CISA Series — Exam Preparation &amp; Strategy: How to Think Like the Exam. This session brings together all five CISA domains into a practical exam-focused review designed to help candidates understand how ISACA structures questions, tests judgement, and evaluates risk-based thinking.

</description>
      <media:content url="https://files.speakerdeck.com/presentations/83ca80a6242e4d99bcdd47c0467fccc2/preview_slide_0.jpg?39336179" type="image/jpeg" medium="image"/>
      <content:encoded>Master the mindset behind the CISA exam in Part 7 of the CISA Series — Exam Preparation &amp; Strategy: How to Think Like the Exam. This session brings together all five CISA domains into a practical exam-focused review designed to help candidates understand how ISACA structures questions, tests judgement, and evaluates risk-based thinking.

</content:encoded>
      <pubDate>Fri, 08 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-part-7-exam-preparation</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-part-7-exam-preparation</guid>
    </item>
    <item>
      <title>CISA Series Introduction - Preparing for the Exam</title>
      <description>These slides ares part of my CISA Exam Preparation Series, where I work through all five domains in a structured and practical way. The focus is not just on theory, but on building real understanding of IT audit, governance, risk, and controls, and how these concepts apply in practice.

In this series, I break down complex topics into manageable sections, link them to real-world scenarios, and reinforce the auditor mindset needed for the exam. The goal is to move beyond memorisation and develop the ability to interpret scenarios and select the best answer — which is critical for CISA success.

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the exam.</description>
      <media:content url="https://files.speakerdeck.com/presentations/7a36935808ad4c65b70a5ad08181394c/preview_slide_0.jpg?39316162" type="image/jpeg" medium="image"/>
      <content:encoded>These slides ares part of my CISA Exam Preparation Series, where I work through all five domains in a structured and practical way. The focus is not just on theory, but on building real understanding of IT audit, governance, risk, and controls, and how these concepts apply in practice.

In this series, I break down complex topics into manageable sections, link them to real-world scenarios, and reinforce the auditor mindset needed for the exam. The goal is to move beyond memorisation and develop the ability to interpret scenarios and select the best answer — which is critical for CISA success.

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the exam.</content:encoded>
      <pubDate>Wed, 06 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-introduction-preparing-for-the-exam</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-introduction-preparing-for-the-exam</guid>
    </item>
    <item>
      <title>CISA Mind Maps Domain 5</title>
      <description>CISA Made Easy – Mind Maps | Domain 5: Protection of Information Assets

In this presentation, I walk through a visual mind map of CISA Domain 5, focusing on one of the most important areas in the exam — protecting information assets.

This domain brings everything together — from access control and encryption through to incident response and forensics. If Domain 4 is about keeping systems running, Domain 5 is about protecting what really matters: the data.</description>
      <media:content url="https://files.speakerdeck.com/presentations/28b2c516f0174d2b8fddb3e4de384fd0/preview_slide_0.jpg?39299784" type="image/jpeg" medium="image"/>
      <content:encoded>CISA Made Easy – Mind Maps | Domain 5: Protection of Information Assets

In this presentation, I walk through a visual mind map of CISA Domain 5, focusing on one of the most important areas in the exam — protecting information assets.

This domain brings everything together — from access control and encryption through to incident response and forensics. If Domain 4 is about keeping systems running, Domain 5 is about protecting what really matters: the data.</content:encoded>
      <pubDate>Mon, 04 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-mind-maps-domain-5</link>
      <guid>https://speakerdeck.com/alisecure/cisa-mind-maps-domain-5</guid>
    </item>
    <item>
      <title>CISA Mind Maps - Domain 4</title>
      <description>omain 4: Operations &amp; Business Resilience

A quick visual breakdown of Domain 4 — showing how IT operations and resilience come together.

This mind map connects the full lifecycle of running and supporting IT environments, including:

IT operations and service delivery
Data management and governance
Change, configuration, and release management
Incident and problem management
Business continuity and disaster recovery</description>
      <media:content url="https://files.speakerdeck.com/presentations/6ccce4dac30847bf9831215841e8327c/preview_slide_0.jpg?39299664" type="image/jpeg" medium="image"/>
      <content:encoded>omain 4: Operations &amp; Business Resilience

A quick visual breakdown of Domain 4 — showing how IT operations and resilience come together.

This mind map connects the full lifecycle of running and supporting IT environments, including:

IT operations and service delivery
Data management and governance
Change, configuration, and release management
Incident and problem management
Business continuity and disaster recovery</content:encoded>
      <pubDate>Mon, 04 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-mind-maps-domain-4</link>
      <guid>https://speakerdeck.com/alisecure/cisa-mind-maps-domain-4</guid>
    </item>
    <item>
      <title>CISA Series Part 6 Domain 5</title>
      <description>CISA Series Part 6: Protection of Information Assets

Welcome to Part 6 of the CISA Made Easy Series, where we take a deep dive into one of the most important domains in the exam:
 Domain 5 – Protection of Information Assets

This part brings everything together — moving from governance and design…
into how organisations actually protect, detect, and respond to threats in real-world environments.

</description>
      <media:content url="https://files.speakerdeck.com/presentations/0217984ee8de40c7a67141ba05f00409/preview_slide_0.jpg?39299502" type="image/jpeg" medium="image"/>
      <content:encoded>CISA Series Part 6: Protection of Information Assets

Welcome to Part 6 of the CISA Made Easy Series, where we take a deep dive into one of the most important domains in the exam:
 Domain 5 – Protection of Information Assets

This part brings everything together — moving from governance and design…
into how organisations actually protect, detect, and respond to threats in real-world environments.

</content:encoded>
      <pubDate>Mon, 04 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-part-6-domain-5</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-part-6-domain-5</guid>
    </item>
    <item>
      <title>CISA_Made_Easy_Domain_3.pdf</title>
      <description>Struggling to connect all the topics in CISA Domain 3?

This deck breaks it down using a clear, visual mind map—helping you see how everything fits together in Information Systems Acquisition, Development, and Implementation.


This visual walkthrough simplifies Domain 3 into one connected view:

✔ Project Governance &amp; Management – how initiatives are structured and controlled
✔ Business Case &amp; Feasibility – why systems are built in the first place
✔ System Development Methodologies (SDLC) – how systems are designed and developed
✔ Acquisition &amp; Development – how solutions are sourced or built
✔ Control Design – ensuring systems are secure and reliable
✔ Testing Methodologies – validating quality and integrity
✔ Implementation &amp; Deployment – moving systems into production
✔ Post-Implementation Review – ensuring value and identifying improvements


</description>
      <media:content url="https://files.speakerdeck.com/presentations/7476782b708f49719b1b04e75ba7c3fc/preview_slide_0.jpg?39299466" type="image/jpeg" medium="image"/>
      <content:encoded>Struggling to connect all the topics in CISA Domain 3?

This deck breaks it down using a clear, visual mind map—helping you see how everything fits together in Information Systems Acquisition, Development, and Implementation.


This visual walkthrough simplifies Domain 3 into one connected view:

✔ Project Governance &amp; Management – how initiatives are structured and controlled
✔ Business Case &amp; Feasibility – why systems are built in the first place
✔ System Development Methodologies (SDLC) – how systems are designed and developed
✔ Acquisition &amp; Development – how solutions are sourced or built
✔ Control Design – ensuring systems are secure and reliable
✔ Testing Methodologies – validating quality and integrity
✔ Implementation &amp; Deployment – moving systems into production
✔ Post-Implementation Review – ensuring value and identifying improvements


</content:encoded>
      <pubDate>Mon, 04 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-made-easy-domain-3</link>
      <guid>https://speakerdeck.com/alisecure/cisa-made-easy-domain-3</guid>
    </item>
    <item>
      <title>CISA Series - Mind Maps - domain 2</title>
      <description>CISA Domain 2 can feel like a lot to take in.

Governance. Risk. Resources. Performance.
And a long list of concepts that don’t always feel connected.

What helped me was stepping back and looking at it as a mind map—
not as separate topics, but as a system.

In this video, I walk through Domain 2 using a visual mind map,
showing how everything fits together—from governance and strategy through to monitoring and improvement.

Then I take it a step further and map it to COBIT.

Because once you see how Domain 2 aligns to:
EDM, APO, BAI, DSS, and MEA…
it becomes much easier to understand how IT is actually governed and managed in practice.

For me, this isn’t about simplifying the content—
it’s about making it easier to see, connect, and remember.

This is part of my CISA Made Easy series—
a personal learning journey, and a way of sharing what I’ve learned along the way.

Key takeaway:
CISA tells you what needs to be done.
COBIT shows you how it’s structured and managed.

Disclaimer:
This is based on my current understanding and experience.
I don’t represent any organisation, and I’m always open to different perspectives.

#CISA #COBIT #ITAudit #Governance #Risk #Learning #MindMap #ISACA</description>
      <media:content url="https://files.speakerdeck.com/presentations/577661388a1a46e59e0a7ab3b59ffa9a/preview_slide_0.jpg?39288337" type="image/jpeg" medium="image"/>
      <content:encoded>CISA Domain 2 can feel like a lot to take in.

Governance. Risk. Resources. Performance.
And a long list of concepts that don’t always feel connected.

What helped me was stepping back and looking at it as a mind map—
not as separate topics, but as a system.

In this video, I walk through Domain 2 using a visual mind map,
showing how everything fits together—from governance and strategy through to monitoring and improvement.

Then I take it a step further and map it to COBIT.

Because once you see how Domain 2 aligns to:
EDM, APO, BAI, DSS, and MEA…
it becomes much easier to understand how IT is actually governed and managed in practice.

For me, this isn’t about simplifying the content—
it’s about making it easier to see, connect, and remember.

This is part of my CISA Made Easy series—
a personal learning journey, and a way of sharing what I’ve learned along the way.

Key takeaway:
CISA tells you what needs to be done.
COBIT shows you how it’s structured and managed.

Disclaimer:
This is based on my current understanding and experience.
I don’t represent any organisation, and I’m always open to different perspectives.

#CISA #COBIT #ITAudit #Governance #Risk #Learning #MindMap #ISACA</content:encoded>
      <pubDate>Sat, 02 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-mind-maps-domain-2</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-mind-maps-domain-2</guid>
    </item>
    <item>
      <title>CISA - Domain 1 Mindmap</title>
      <description>CISA Domain one isn’t about memorising disconnected pieces.

It’s about seeing how the audit process fits together.

Planning. Execution. Evidence. Reporting. Follow-up.

The challenge is remembering it all—and understanding how each part connects.

That’s why I use a mind map approach.

In this video, I walk through the Information Systems Auditing Process as a structured flow—
so you can visualise it, connect it, and actually remember it.

Because once you see the whole picture,
it becomes much easier to work through the detail.

I also touch on how this links to COBIT—
bringing it back to the bigger picture of governance and management.

This is part of my CISA Made Easy series—
sharing what I’ve learned over the years, while continuing to learn myself.</description>
      <media:content url="https://files.speakerdeck.com/presentations/4a32bfd6b20c4f52ae1b8658d7697eb2/preview_slide_0.jpg?39280011" type="image/jpeg" medium="image"/>
      <content:encoded>CISA Domain one isn’t about memorising disconnected pieces.

It’s about seeing how the audit process fits together.

Planning. Execution. Evidence. Reporting. Follow-up.

The challenge is remembering it all—and understanding how each part connects.

That’s why I use a mind map approach.

In this video, I walk through the Information Systems Auditing Process as a structured flow—
so you can visualise it, connect it, and actually remember it.

Because once you see the whole picture,
it becomes much easier to work through the detail.

I also touch on how this links to COBIT—
bringing it back to the bigger picture of governance and management.

This is part of my CISA Made Easy series—
sharing what I’ve learned over the years, while continuing to learn myself.</content:encoded>
      <pubDate>Fri, 01 May 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-domain-1-mindmap</link>
      <guid>https://speakerdeck.com/alisecure/cisa-domain-1-mindmap</guid>
    </item>
    <item>
      <title>CISA Series - Part 5 Domain 4</title>
      <description>Domain 4: Information Systems Operations &amp; Business Resilience

In this part of the series, we move into one of the most practical and heavily tested areas of the CISA exam — day-to-day IT operations and resilience.

This domain brings everything together.

It’s not just about controls on paper — it’s about how systems actually run, how they are monitored, how failures are handled, and how organisations recover when things go wrong.

🔍 What this video covers:

We break Domain 4 into two key areas:

 Part A – Information Systems Operations
IT Asset Management (foundation control)
Job Scheduling &amp; Process Automation
System Interfaces &amp; Data Integrity
End-User Computing (EUC risks &amp; controls)
Data Governance &amp; Data Quality
Systems Performance Management
Incident vs Problem Management
Change, Configuration, Release &amp; Patch Management
Service Level Management (SLAs)
 Focus: Keeping systems stable, controlled, and performing

 Part B – Business Resilience
Business Impact Analysis (BIA)
Backup, Storage &amp; Restoration
Business Continuity Planning (BCP)
Disaster Recovery Planning (DRP)
System Resiliency (hot, warm, cold sites)
Testing &amp; Continuous Assurance

 Focus: Ensuring systems are recoverable and aligned to business priorities

This is one of the most scenario-driven domains in the CISA exam — mastering it will significantly improve your ability to answer real-world questions.
 Disclaimer:
This content is based on my interpretation and experience in IT governance, risk, and assurance, and is intended to support learning and exam preparation.</description>
      <media:content url="https://files.speakerdeck.com/presentations/0ad1d4db7b734a6a917aa0d38df6cfa4/preview_slide_0.jpg?39259117" type="image/jpeg" medium="image"/>
      <content:encoded>Domain 4: Information Systems Operations &amp; Business Resilience

In this part of the series, we move into one of the most practical and heavily tested areas of the CISA exam — day-to-day IT operations and resilience.

This domain brings everything together.

It’s not just about controls on paper — it’s about how systems actually run, how they are monitored, how failures are handled, and how organisations recover when things go wrong.

🔍 What this video covers:

We break Domain 4 into two key areas:

 Part A – Information Systems Operations
IT Asset Management (foundation control)
Job Scheduling &amp; Process Automation
System Interfaces &amp; Data Integrity
End-User Computing (EUC risks &amp; controls)
Data Governance &amp; Data Quality
Systems Performance Management
Incident vs Problem Management
Change, Configuration, Release &amp; Patch Management
Service Level Management (SLAs)
 Focus: Keeping systems stable, controlled, and performing

 Part B – Business Resilience
Business Impact Analysis (BIA)
Backup, Storage &amp; Restoration
Business Continuity Planning (BCP)
Disaster Recovery Planning (DRP)
System Resiliency (hot, warm, cold sites)
Testing &amp; Continuous Assurance

 Focus: Ensuring systems are recoverable and aligned to business priorities

This is one of the most scenario-driven domains in the CISA exam — mastering it will significantly improve your ability to answer real-world questions.
 Disclaimer:
This content is based on my interpretation and experience in IT governance, risk, and assurance, and is intended to support learning and exam preparation.</content:encoded>
      <pubDate>Wed, 29 Apr 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-series-part-5-domain-4</link>
      <guid>https://speakerdeck.com/alisecure/cisa-series-part-5-domain-4</guid>
    </item>
    <item>
      <title>CISA Study Strategy</title>
      <description>Preparing for the Certified Information Systems Auditor (CISA) exam can feel overwhelming — especially if you approach it like a traditional technical exam.

In this presentation, I break down a practical, real-world CISA study strategy based on how the exam is actually structured and how successful candidates prepare.

This is not about memorising definitions — it’s about understanding risk, control, governance, and audit thinking.

How to answer questions using the BEST vs CORRECT technique
Common exam traps and how to avoid them
Key focus areas across all 5 CISA domains</description>
      <media:content url="https://files.speakerdeck.com/presentations/a31dd40e33544f5da907aa3a4bdad0f7/preview_slide_0.jpg?39244177" type="image/jpeg" medium="image"/>
      <content:encoded>Preparing for the Certified Information Systems Auditor (CISA) exam can feel overwhelming — especially if you approach it like a traditional technical exam.

In this presentation, I break down a practical, real-world CISA study strategy based on how the exam is actually structured and how successful candidates prepare.

This is not about memorising definitions — it’s about understanding risk, control, governance, and audit thinking.

How to answer questions using the BEST vs CORRECT technique
Common exam traps and how to avoid them
Key focus areas across all 5 CISA domains</content:encoded>
      <pubDate>Tue, 28 Apr 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-study-strategy</link>
      <guid>https://speakerdeck.com/alisecure/cisa-study-strategy</guid>
    </item>
    <item>
      <title>CISA Exam Preparation – Domain 3 Part 4</title>
      <description>CISA Exam Preparation – Domain 3 Part 4

Information Systems Acquisition, Development &amp; Implementation (Deep Dive)
Based on this slide deck:
This presentation continues my CISA Exam Preparation Series, focusing on Domain 3 — where we move from governance into how systems are actually built, controlled, and implemented in practice.

This is one of the most important domains for the exam, because failures in systems almost always originate early in the lifecycle — especially at the requirements stage.

🔍 What you’ll learn in this video:
📌 System Development Lifecycle (SDLC)
Full lifecycle: Feasibility → Requirements → Design → Build → Test → Implement → Review
Why requirements definition is the most critical phase (exam favourite)
How poor early decisions lead to later failures
 Business Case &amp; Feasibility
Cost vs benefit, alignment to business objectives
Technical, financial, and operational feasibility
Auditor focus: decision quality and risk awareness before approval
⚙️ Development Approaches
Agile, Waterfall, DevOps, RAD
Key insight: Methodology does NOT remove control requirements
Risks: weak documentation, poor change control, inadequate testing
🔐 Control Design &amp; Effectiveness
Input, processing, and output controls
Ensuring accuracy, completeness, and authorisation across data flows
Why controls must be built in early — not added later
🧪 Testing &amp; Implementation
Unit, integration, system, and UAT testing
Configuration and release management
Data migration and cutover strategies (parallel, phased, big bang)
Key risk: uncontrolled changes and data integrity failures
🔄 Post-Implementation Review (PIR)
Validate benefits, performance, and control effectiveness
Capture lessons learned and update risk register
Auditor focus: effectiveness, not just completion
🧠 CISA Exam Insights:
Failures usually start in requirements, not testing
Controls added late = design failure
Skipping review = no improvement
Always trace issues back to the lifecycle stage
Why this matters:

From an audit perspective, this domain is about ensuring that:

Systems meet business objectives
Risks are identified before implementation
Controls are designed and embedded, not retrofitted
Projects deliver real value, not just technical completion</description>
      <media:content url="https://files.speakerdeck.com/presentations/72988b63fcd046c49dbb6e5058176dc3/preview_slide_0.jpg?39224080" type="image/jpeg" medium="image"/>
      <content:encoded>CISA Exam Preparation – Domain 3 Part 4

Information Systems Acquisition, Development &amp; Implementation (Deep Dive)
Based on this slide deck:
This presentation continues my CISA Exam Preparation Series, focusing on Domain 3 — where we move from governance into how systems are actually built, controlled, and implemented in practice.

This is one of the most important domains for the exam, because failures in systems almost always originate early in the lifecycle — especially at the requirements stage.

🔍 What you’ll learn in this video:
📌 System Development Lifecycle (SDLC)
Full lifecycle: Feasibility → Requirements → Design → Build → Test → Implement → Review
Why requirements definition is the most critical phase (exam favourite)
How poor early decisions lead to later failures
 Business Case &amp; Feasibility
Cost vs benefit, alignment to business objectives
Technical, financial, and operational feasibility
Auditor focus: decision quality and risk awareness before approval
⚙️ Development Approaches
Agile, Waterfall, DevOps, RAD
Key insight: Methodology does NOT remove control requirements
Risks: weak documentation, poor change control, inadequate testing
🔐 Control Design &amp; Effectiveness
Input, processing, and output controls
Ensuring accuracy, completeness, and authorisation across data flows
Why controls must be built in early — not added later
🧪 Testing &amp; Implementation
Unit, integration, system, and UAT testing
Configuration and release management
Data migration and cutover strategies (parallel, phased, big bang)
Key risk: uncontrolled changes and data integrity failures
🔄 Post-Implementation Review (PIR)
Validate benefits, performance, and control effectiveness
Capture lessons learned and update risk register
Auditor focus: effectiveness, not just completion
🧠 CISA Exam Insights:
Failures usually start in requirements, not testing
Controls added late = design failure
Skipping review = no improvement
Always trace issues back to the lifecycle stage
Why this matters:

From an audit perspective, this domain is about ensuring that:

Systems meet business objectives
Risks are identified before implementation
Controls are designed and embedded, not retrofitted
Projects deliver real value, not just technical completion</content:encoded>
      <pubDate>Sun, 26 Apr 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-exam-preparation-domain-3-part-4</link>
      <guid>https://speakerdeck.com/alisecure/cisa-exam-preparation-domain-3-part-4</guid>
    </item>
    <item>
      <title>CISA__Preparing_for_the_Exam-_Domain_2_Part_3.pdf</title>
      <description>This Presentation  is part of my CISA Exam Preparation Series, and in this section we continue with Domain 2: Governance and Management of IT, focusing on governance implementation and the control environment.

We explore how governance is translated into practical structures, controls, and accountability mechanisms within an organisation — bridging the gap between strategy and execution.

Key topics covered include:

IT governance structures and roles (board, committees, management)
COBIT governance and management domains in practice
Policies, standards, and procedures hierarchy
Enterprise Architecture and alignment with business strategy
Enterprise Risk Management (ERM) and risk lifecycle
Data governance, privacy, and regulatory compliance (including POPIA/GDPR context)
Vendor management and third-party risk
Performance monitoring, KPIs, KRIs, and reporting
Quality assurance and continuous improvement

We also walk through real-world examples, including a cloud CRM scenario, to demonstrate how governance, risk, and control concepts are applied in practice.

From an audit perspective, the focus is on evaluating whether:

IT is aligned to business objectives
Controls are effective and operating as intended
Governance and management decisions are risk-based and properly evidenced

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the CISA exam.</description>
      <media:content url="https://files.speakerdeck.com/presentations/b15b7e9b477a42c5ae17d3cf9fb89729/preview_slide_0.jpg?39224024" type="image/jpeg" medium="image"/>
      <content:encoded>This Presentation  is part of my CISA Exam Preparation Series, and in this section we continue with Domain 2: Governance and Management of IT, focusing on governance implementation and the control environment.

We explore how governance is translated into practical structures, controls, and accountability mechanisms within an organisation — bridging the gap between strategy and execution.

Key topics covered include:

IT governance structures and roles (board, committees, management)
COBIT governance and management domains in practice
Policies, standards, and procedures hierarchy
Enterprise Architecture and alignment with business strategy
Enterprise Risk Management (ERM) and risk lifecycle
Data governance, privacy, and regulatory compliance (including POPIA/GDPR context)
Vendor management and third-party risk
Performance monitoring, KPIs, KRIs, and reporting
Quality assurance and continuous improvement

We also walk through real-world examples, including a cloud CRM scenario, to demonstrate how governance, risk, and control concepts are applied in practice.

From an audit perspective, the focus is on evaluating whether:

IT is aligned to business objectives
Controls are effective and operating as intended
Governance and management decisions are risk-based and properly evidenced

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the CISA exam.</content:encoded>
      <pubDate>Sun, 26 Apr 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-preparing-for-the-exam-domain-2-part-3</link>
      <guid>https://speakerdeck.com/alisecure/cisa-preparing-for-the-exam-domain-2-part-3</guid>
    </item>
    <item>
      <title>CISA__Preparing_for_the_Exam-_Domain1_Part_2.pdf</title>
      <description>This This presentation is part of my CISA Exam Preparation Series, and in this section we take a deeper dive into Domain 1: Information System Auditing Process — focusing on how audits are actually planned, executed, and evaluated in practice.

We move beyond theory and break down key areas such as the audit lifecycle, risk-based planning, audit risk components, evidence collection, sampling techniques, and reporting. The aim is to build a clear understanding of how an auditor thinks — from identifying risk, to testing controls, to forming defensible conclusions.

This part also emphasises the auditor mindset, including independence, professional scepticism, and the importance of selecting the best answer in exam scenarios — not just a technically correct one.

Throughout the video, I link concepts to practical examples and include CISA-style questions to reinforce how these topics are tested in the exam.

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the CISA exam.</description>
      <media:content url="https://files.speakerdeck.com/presentations/18754edaf03f46dfa6c094169b46cb6b/preview_slide_0.jpg?39223961" type="image/jpeg" medium="image"/>
      <content:encoded>This This presentation is part of my CISA Exam Preparation Series, and in this section we take a deeper dive into Domain 1: Information System Auditing Process — focusing on how audits are actually planned, executed, and evaluated in practice.

We move beyond theory and break down key areas such as the audit lifecycle, risk-based planning, audit risk components, evidence collection, sampling techniques, and reporting. The aim is to build a clear understanding of how an auditor thinks — from identifying risk, to testing controls, to forming defensible conclusions.

This part also emphasises the auditor mindset, including independence, professional scepticism, and the importance of selecting the best answer in exam scenarios — not just a technically correct one.

Throughout the video, I link concepts to practical examples and include CISA-style questions to reinforce how these topics are tested in the exam.

This is part of my personal learning journey, and I’m sharing it in case it helps others preparing for the CISA exam.</content:encoded>
      <pubDate>Sun, 26 Apr 2026 00:00:00 -0400</pubDate>
      <link>https://speakerdeck.com/alisecure/cisa-preparing-for-the-exam-domain1-part-2</link>
      <guid>https://speakerdeck.com/alisecure/cisa-preparing-for-the-exam-domain1-part-2</guid>
    </item>
  </channel>
</rss>
