From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

IT frameworks

IT frameworks

- [Instructor] One of the roles additionally that senior leadership has is to determine the framework for the organization, the structure and the goals of the organization, how we're going to implement. For instance, if we're talking about IT frameworks, how we're going to implement our information security management program, how we're going to operate. So we want to make sure that we've set up a framework for five key areas to accomplish our business objective. So set up the environment for the control. What controls are implemented, how we determine our control objectives, how we determine whether or not those controls are meeting their objectives? Then how do we conduct risk assessment? We talked about risk assessments in the last section. So are we using the NIST standard? Are there other frameworks that we're going to use? We need clear definition. Control activities, what the controls' functions are, how they're implemented. And really we could include here how we determine the…

Contents