defter*
defter / katalog / CTIS 474

CTIS 474 Information Systems Auditing

CTIS 474 teaches you to evaluate IT systems the way an external auditor would: not whether the code works, but whether the controls around it can be trusted by regulators, executives, and risk officers. You'll work through the ISACA CISA domains and standards like ISO 27001, NIST, and GDPR, then apply them in case studies where teams build audit plans, gather evidence, and write findings on real scenarios. It's a useful capstone-level elective if you're aiming for compliance, GRC, or security consulting roles, since it bridges the technical CTIS background with the governance vocabulary those jobs actually run on.

Kredi 3 ECTS 5 Fakülte Uygulamalı Bilimler Fakültesi Bölüm Bilişim Sistemleri ve Teknolojileri Ön koşul CTIS 310 Koordinatör Hamdi Murat Yıldırım

CTIS 474 zor mu?

Son 8 dönemde dersin ortalaması 2,66 (189 öğrencinin notu, 4,00 üzerinden), yani sınıf ortalaması B- civarında. Zorluk hocaya ve şubeye göre değişir; ölçülebilir olan bu sayı. Diğer derslerle karşılaştır →

CTIS 474 dersinde kaç midterm var, ağırlıkları ne?

İzlencede 1 midterm var, ağırlığı %20. Final %30. Kalan %50 dersin öteki kalemlerinde. Tam dağılım aşağıda.

CTIS 474 dersinin ön koşulu var mı?

Evet. Bilkent kataloğuna göre ön koşulu: CTIS 310.

CTIS 474 dersinde hangi kitap okunuyor?

İzlencede önerilen kitap: CISA® Review Manual, ISACA, 28th Edition, ISACA. İzlence toplam 2 kaynak sayıyor.

CTIS 474 kaç kredi?

3 Bilkent kredisi, 5 AKTS.

Haftalık müfredat 14 hafta

Hafta 114–20 Eyl
Information Systems auditing girişi ve standartlar
Definitions of the Information Systems (IS) technologies and auditing process encompasses the standards, principles, methods, guidelines, practices and techniques based on the ISACA CISA domains and ISO 27001/27701 objectives. General roadmap of CTIS-474 course content and studies. Introduction to Information Systems Auditing, the auditor’s mindset, professional ethics, and the global standards and frameworks governing IS audits.
ISACA CISAISO 27001/27701IS auditprofessional ethics
Hafta 221–27 Eyl
IS audit standartları, framework ve sertifikasyonları
Global IS Audit Standards, Frameworks and Certifications. Describe and discuss on IS Audit Global Standards and Frameworks; IS related Professional Certifications; ISACA Frameworks and Certifications; ISO Standards and Certifications; AICPA SOC 1-2-3 Reports; NIST, DORA, NIS2, CMMI, GDPR, Turkish Information and Communication Security (Audit) Guide, etc.
ISACA frameworkISO standartlarıSOC 1-2-3 raporlarıGDPR, DORA, NIS2
Hafta 328 Eyl – 4 Eki
IS audit planlaması ve yürütülmesi
IS Audit Planning and Execution. Planning: IS Audit Standards, Guidelines and Codes of Ethics, Business Processes, Types of Controls, Risk-Based Audit Planning, Types of Audits and Assessments. Execution: Audit Project Management, Sampling Methodology, Audit Evidence Collection Techniques, Data Analytics, AI/ML Effects on Audit, Reporting and Communication Techniques, Quality Assurance and Improvement of the Audit Process
IS audit standardsrisk-based audit planningsampling methodologyaudit evidence
Hafta 45–11 Eki
IT governance ve IT management audit'i
Audit on IT Governance: IT Governance and IT Strategy, IT-Related Frameworks, IT Standards, Policies, and Procedures, Organizational Structure, Enterprise Architecture, Enterprise Risk Management, Maturity Models Laws, Regulations, and Industry Standards Affecting the Organization. Audit on IT Management, IT Resource Management, IT Service Provider Acquisition and Management, IT Performance Monitoring and Reporting, Quality Assurance and Quality Management of IT.
IT governanceenterprise architectureenterprise risk managementIT performance monitoring
Hafta 512–18 Eki
IT management audit'i
Audit on IT Management: IT Resource Management, IT Service Provider Acquisition and Management, IT Performance Monitoring and Reporting, Quality Assurance and Quality Management of IT
IT resource managementIT service provider managementIT performance monitoringquality management
Hafta 619–25 Eki
Sistem edinimi ve geliştirme denetimi
Audit on Information Systems Acquisition and Development: Project Governance and Management, Business Case and Feasibility Analysis, System Development Methodologies, Control Identification and Design
project governancebusiness casefeasibility analysissystem development methodologies
Hafta 726 Eki – 1 Kas
Sistem implementasyonu denetimi ve CAAT
Audit on Information System Implementation: Testing Methodologies, Configuration and Release Management, System Migration, Infrastructure Deployment, and Data Conversion, Post-Implementation Review. Describe the key features of Computer Assisted Audit Techniques (CAAT). Review on the audit objectives of the CAATs and the use of CAATs in the performance of an IS Audit.
CAATconfiguration ve release managementsystem migrationpost-implementation review
Hafta 82–8 Kas
Ara sınav
--MIDTERM--
Hafta 99–15 Kas
Takım Halinde IS Audit Vaka Çalışması
CASE STUDY, 1: As a team of 3 participants, Examine the related IS auditing standards and guidelines; Preparing the audit checklists on the topics, frameworks and methodology previously discussed in class then apply techniques necessary to conduct an IS audit.
IS auditing standardsaudit checklistframeworkmethodology
Hafta 1016–22 Kas
Bilgi güvenliği denetimi ve saldırı yöntemleri
Audit on Information Security: Security Awareness Training and Programs, Information System Attack Methods and Techniques, Vulnerability Analysis and Penetration Testing Methods, Security Testing Tools and Techniques, Security Monitoring Tools and Techniques, Incident Response Management, Evidence Collection and Forensics
security awareness trainingvulnerability analysissecurity monitoringincident response
Hafta 1123–29 Kas
Bilgi varlığı güvenliği ve kontrol audit'i
Audit on Information Asset Security and Control: Privacy Principles, Physical Access and Environmental Controls, Identity and Access Management, Network and End-point Security, Data Classification, Data Encryption and Encryption-related Techniques, Public Key Infrastructure (PKI), Web-based Communication Technologies, Virtualized Environments, Mobile, Wireless, and Internet-of-Things (IOT) Devices
identity and access managementdata encryption ve PKInetwork and endpoint securityvirtualized environments ve IoT
Hafta 1230 Kas – 6 Ara
Bilgi sistemleri operasyonlarının denetimi
Audit on Information System Operations. Computer Hardware Components and Architectures, IT Asset Management, System Interfaces, Systems Performance Management, Problem and Incident Management, Change, Configuration, Release, and Patch Management, IT Service Level Management. Evaluating the opportunities and risks created by disruptive technologies (AI, ML, BigData, etc.) for IS auditing.
IT asset managementpatch managementIT service level managementdisruptive technologies
Hafta 137–13 Ara
Bilgi güvenliği ve privacy denetimi
Audit on Information Security and Privacy: Privacy Principles and Practices, Security Awareness Training and Programs, Information System Attack Methods and Techniques, Vulnerability Analysis and Penetration Testing Methods, Security Testing Tools and Techniques, Security Monitoring Tools and Techniques, Incident Response Management, Evidence Collection and Forensics
privacy principlespenetration testingincident responseevidence collection ve forensics
Hafta 1414–20 Ara
Business resilience audit'i ve vaka çalışması
Audit on Business Resilience: Business Impact Analysis (BIA), System Resiliency, Data Backup, Storage, and Restoration, Business Continuity Plan (BCP), Disaster Recovery Plans (DRPs) Week 15: CASE STUDY, 2: : As a team of 3 participants, Plan and conduct information systems audits on the specific scenarios related to different organizational structures, technological infrastructures and business sectors given by instructor based on topics previously discussed in class.
Business Impact Analysis (BIA)system resiliencyBusiness Continuity Plan (BCP)Disaster Recovery Plan (DRP)

Değerlendirme 100% · 6 adım

18%
20%
18%
30%
10%
4%
Case study Case Study 1, Case Study 2 36%
Midterm Midterm 20%
Final Final 30%
Homework Homework 10%
In-class participation Performance 4%
en büyük tek kalem %30 · sınav ağırlığı %50 · 8 dönem ortalaması 2.66 (189 öğrenci) nasıl hesaplanıyor
Notunu hesapla
KalemAğırlık Notun (100 üzerinden)
Case Study 1%18
Midterm%20
Case Study 2%18
Final%30
Homework%10
Performance%4
Bildiğin notları gir; girmediklerin hesaba katılmaz.

Ağırlıklar CTIS 474 izlencesinden. Hocanın bu dönemki dağılımı farklı olabilir; bağlayıcı olan ders izlencesidir. Harf notu sınırlarını hoca belirliyor, o yüzden hedefi sen giriyorsun. İzlencede FZ şartı var, sayfanın sonundaki kutuda.

Önerilen kaynaklar 2 kitap

📖
Önerilen
CISA® Review Manual, ISACA, 28th Edition, ISACA
📖
Önerilen
CISA® : Certified Information Systems Auditor Study Guide, ISACA, 4th Edition, ISACA

Bu dersi alınca · 10 öğrenme çıktısı

Bilkent'in resmî syllabus'ünden. Sağdaki etiket o çıktının hangi değerlendirmeyle ölçüldüğünü söylüyor.

🤖 GenAI politikası

Students are advised to consult their instructors regarding the use of Generative AI tools and their appropriateness in each course. Responsible use of GenAI is encouraged in accordance with Bilkent University's GenAI Guidelines. Link: https://w3.bilkent.edu.tr/bilkent/generative-artificial-intelligence-genai-guideline/

Ders notları · henüz yok

CTIS 474 için defter ekibi henüz not yazmadı.

İlk dosyayı sen atarsan: not, slayt, geçmiş sınav, çözüm, cheat-sheet, ne varsa. defter ekibi öğrenci paylaşımlarından bu dersin notlarını yazar. Drive linki / PDF / ZIP, hepsi olur.

← katalog

Geçmiş GPA dağılımı 8 dönem · ort. 2.66

DönemDers ort.
2025-2026 Spring 2.78 1 şube · 25 öğr
2024-2025 Spring 2.42 1 şube · 26 öğr
2023-2024 Spring 2.66 1 şube · 24 öğr
2022-2023 Spring 2.79 1 şube · 26 öğr
2022-2023 Fall 2.76 1 şube · 20 öğr
2021-2022 Spring 2.67 1 şube · 23 öğr
2020-2021 Spring 2.91 1 şube · 17 öğr
2020-2021 Fall 2.28 1 şube · 28 öğr

Dersin dönem ortalaması, o dönemin bütün şubeleri birlikte. Kaynak STARS'ın ders değerlendirme raporu. Rapor yalnız kampüs ağından ya da Bilkent VPN ile açılıyor: CTIS 474 raporu · Bilkent VPN bilgisi. Öğrenci anket cevaplarını defter'de tutmuyoruz. Tüm derslerin ortalamaları →

2026-2027 Güz döneminde açılmadı. Ders kaydı geçti, kayıt sisteminde bu dersin şubesi yok. Katalogda duruyor, yani başka bir dönem açılabilir. Son 4 güz döneminin 1 tanesinde açılmış; her yıl açılan bir ders değil. Açık dersler → · kayıt tarihleri

⚠️ FZ engelleyen şartlar

20 out of 70 points from the midterm, homework, participation and the case studies. Do not miss more than 20 hours of lecture without excuse.

Hocalar 0 bu dönem · 1 geçmiş

Geçmişte ders veren (1 kişi)
Volkan Evrin

Bu ders 2 programın seçmeli havuzunda.

Information Systems Elective Bilişim Sistemleri ve Teknolojileri · havuzda 27 ders Restricted Elective Ekonomi · havuzda 1011 ders Unrestricted Elective Ekonomi · havuzda 1369 ders

Havuz listesi bölümün QME müfredatından; en küçük havuzlar önce yazılıyor, çünkü büyük "serbest seçmeli" havuzunda olmak dersi anlatmıyor. Seçmeli havuzunda olmak o dersi alabileceğin anlamına gelmez: ön koşul ve kontenjan ayrıca geçerli.

Aynı koddan diğer dersler · katalogda 42 CTIS dersi · tüm CTIS dersleri →