ISSC 471 IT Security Auditing

Discussion Points:

1. What is IT Security Auditing? What does it involve?
2. Why are Governance and Compliance Important?
3. Explain in details the roles and responsibilities in an organization associated with the following:

Risk Manager
Executive Manager

4. Define the Certification and Accreditation (C&A) Process and briefly discuss the phases of C&A.

