Een bootcamp, geen droge examentraining
A bootcamp, not a dry exam prep course
CISA is wereldwijd erkend als standaard voor professionals die IT- en informatiesystemen beoordelen. In deze bootcamp gebruiken we de vijf CISA-domeinen als praktische structuur om auditdenken te leren: risico’s begrijpen, controls beoordelen, evidence wegen en bevindingen duidelijk uitleggen.
CISA is globally recognised as a standard for professionals who assess IT and information systems. In this bootcamp we use the five CISA domains as a practical structure for learning audit thinking: understanding risks, assessing controls, evaluating evidence and explaining findings clearly.
De focus ligt op begrip en toepassing. Deelnemers die later het officiële CISA-examen willen afleggen, merken dat de concepten, domeinen en auditlogica al vertrouwd aanvoelen.
The focus is understanding and application. Participants who later decide to sit the official CISA exam will find that the concepts, domains and audit logic already feel familiar.
Let op: deze training wordt onafhankelijk verzorgd door OranjeRaksha en is niet verbonden aan, goedgekeurd door of officieel erkend door ISACA. CISA is een certificering van ISACA.
Note: this training is independently delivered by OranjeRaksha and is not affiliated with, endorsed by or officially recognised by ISACA. CISA is a certification of ISACA.
Voor iedereen die wil begrijpen hoe audits echt werken
For anyone who wants to understand how audits really work
Je hoeft geen auditor te zijn. Je hoeft ook geen concrete CISA-plannen te hebben. Deze bootcamp is bedoeld voor mensen die willen begrijpen hoe organisaties worden getoetst op IT, informatiebeveiliging, governance en continuïteit. De sessies en materialen zijn Engelstalig.
You do not need to be an auditor. You do not need to be planning to sit the CISA exam. This bootcamp is for people who want to understand how organisations are assessed on IT, information security, governance and continuity. Sessions and materials are delivered in English.
Eerste kennismaking met IS-audit. Leer welke vragen auditors stellen, welk bewijs telt en waarom controls belangrijk zijn.
A first step into IS audit. Learn what auditors ask, what evidence matters and why controls are important.
Begrijp hoe je werk wordt getoetst: changes, logging, toegangsbeheer, cloudplatforms, operations en continuïteit.
Understand how your work is assessed: changes, logging, access management, cloud platforms, operations and continuity.
Verdiep je toetsingskader. Formuleer observaties scherper en vertaal technische risico’s naar managementtaal.
Deepen your assessment approach. Write sharper observations and translate technical risks into management language.
Word een betere gesprekspartner richting IT, audit en management over procescontroles, data, bewijs en dossiervorming.
Become a stronger counterpart to IT, audit and management on process controls, data, evidence and working papers.
Spreek audittaal met klanten, regulators en bestuurders. Onderbouw risico’s, verbeteracties en governancekeuzes beter.
Speak audit language with clients, regulators and boards. Support risks, actions and governance choices more clearly.
Bouw een praktijkgerichte basis voordat je gaat studeren. De begrippen en domeinen voelen daarna al vertrouwd.
Build a practical base before you start studying. The concepts and domains will already feel familiar afterwards.
Van “wat is een audit?” naar “ik kan dit uitleggen”
From “what is an audit?” to “I can walk someone through it”
Na de bootcamp kun je auditvragen beter begrijpen, controls beoordelen, evidence kritisch bekijken en bevindingen uitleggen op een manier die bruikbaar is voor technische teams én management.
After the bootcamp you can better understand audit questions, assess controls, review evidence critically and explain findings in a way that is useful for technical teams and management.
Hoe audits worden gepland, uitgevoerd, gedocumenteerd en opgevolgd — en wie welke rol speelt.
How audits are planned, executed, documented and followed up — and who plays what role.
Hoe je processen, risico’s en controls in één verhaal plaatst en uitlegt aan management.
How to link processes, risks and controls in one clear narrative for management.
Wat goede evidence is, wanneer bewijs onvoldoende is en hoe je dit netjes vastlegt in werkdocumentatie.
What good evidence looks like, when evidence is insufficient and how to document it properly in working papers.
Condition, cause, effect, recommendation — opgebouwd met voorbeelden uit echte IS-audits.
Condition, cause, effect, recommendation — built with examples from real IS audits.
Hoe CISA-domeinen zich verhouden tot ISO 27001, SOC-rapportages, NIST, COBIT en NIS2-context.
How CISA domains relate to ISO 27001, SOC reporting, NIST, COBIT and the NIS2 context.
Welke vragen je stelt in interviews en walkthroughs. Doorvragen zonder onnodig confronterend te worden.
What to ask in interviews and walkthroughs. How to probe without becoming unnecessarily confrontational.
Vijf dagen, vijf domeinen
Five days, five domains
Elke dag focussen we op één CISA-domein. Eerst in gewone taal, daarna met praktijkvoorbeelden, mini-cases en korte MCQ-vragen om te checken of de kern is blijven hangen.
Each day focuses on one CISA domain. First in plain language, then through examples, mini cases and short MCQ questions to check whether the key ideas have landed.
Wat is een audit, en waarom vinden organisaties die belangrijk? We doorlopen de auditlevenscyclus van planning tot follow-up, bespreken sleutelrollen en introduceren risico- en governanceframeworks in gewone taal.
What is an audit and why do organisations care? We walk through the audit lifecycle from planning to follow-up, discuss key roles and introduce risk and governance frameworks in plain language.
Van processen naar systemen: applicaties, databases, netwerken, cloud, SaaS en integraties. We bouwen samen een eenvoudige architectuurtekening en auditen die stap voor stap.
From processes to systems: applications, databases, networks, cloud, SaaS and integrations. We build a simple architecture diagram together and audit it step by step.
Hoe changes, incidenten en problemen idealiter verlopen — en wat vaak misgaat. We kijken naar logreviews, monitoring, BCP en disaster recovery via praktijkcases en bouwen samen een kleine controleset.
How changes, incidents and problems should flow — and what often goes wrong. We cover log review, monitoring, BCP and disaster recovery through practical cases and build a small control set together.
SDLC in gewone taal: van idee naar productie. Waar auditors naar kijken bij requirements, testen, go-live, agile werkwijzen en cloudimplementaties. Hoe je evidence verzamelt en vastlegt.
SDLC in plain language: from idea to production. What auditors look at in requirements, testing, go-live, agile ways of working and cloud implementations. How to collect and document evidence.
Wie is eigenaar van data en systemen? Principes rond toegangsbeheer, rollen, functiescheiding, dataclassificatie en de data-levenscyclus. We schrijven samen een observatie over een toegangsprobleem.
Who owns data and systems — and what does that really mean? Access control, roles, segregation of duties, data classification and the data lifecycle. We write an audit observation about an access issue together.
Remote, interactief en direct toepasbaar
Remote, interactive and immediately applicable
Alle sessies zijn live — geen opgenomen video’s, geen zelfstudiepakketten. Je kunt vragen stellen, je eigen cases inbrengen en doorvragen op onderwerpen die relevant zijn voor jouw rol.
All sessions are live — no recorded videos, no self-study packages. You can ask questions, bring your own cases and dig deeper into topics relevant to your role.
Wil je meer weten over planning, prijs of een in-company variant? Laat je gegevens achter en vermeld kort je rol en context — we nemen gericht contact met je op.
Want details on schedule, pricing or an in-company option? Share your details and briefly describe your role and context — we will reach out with a focused proposal.
Meld je aan voor de bootcamp Request enrollmentGeen verplichtingen. Wij reageren doorgaans binnen 1 werkdag. No commitment. We typically respond within 1 business day.
Veelgestelde vragen
Frequently Asked Questions
Niet primair. Deze bootcamp is gericht op praktisch auditdenken en IS-auditprocessen. De vijf CISA-domeinen worden gebruikt als leerstructuur. Deelnemers die later het officiële CISA-examen willen afleggen, merken dat de concepten en domeinen al vertrouwd zijn — maar dit is geen officiële ISACA-examentraining.
Not primarily. This bootcamp focuses on practical audit thinking and IS audit processes. The five CISA domains are used as a learning structure. Participants who later want to sit the official CISA exam find that the concepts and domains already feel familiar — but this is not an official ISACA exam preparation course.
Geen CISA- of auditvoorkennis vereist. De bootcamp start vanaf de basis en bouwt geleidelijk op naar auditgesprekken, risicoanalyse, control testing en evidencebeoordeling. Deelnemers met ervaring in IT, OT, cloud, finance of compliance herkennen veel situaties uit de praktijk.
No CISA or audit knowledge is required. The bootcamp starts from the basics and gradually builds toward audit conversations, risk analysis, control testing and evidence assessment. Participants with IT, OT, cloud, finance or compliance experience will recognise many practical situations.
Ja. We verzorgen in-company versies op maat voor teams. Voorbeelden, cases en discussies kunnen worden afgestemd op uw sector, processen, technologieomgeving en volwassenheidsniveau. De bootcamp wordt in het Engels gegeven.
Yes. We deliver in-company versions tailored for teams. Examples, cases and discussions can be aligned to your sector, processes, technology environment and maturity level. The bootcamp is delivered in English.
Deelnemers ontvangen een bewijs van deelname van OranjeRaksha. Dit is geen officieel ISACA-certificaat. Voor de officiële CISA-certificering moet u het CISA-examen via ISACA afleggen en aan de ISACA-vereisten voldoen.
Participants receive a certificate of attendance from OranjeRaksha. This is not an official ISACA certificate. For official CISA certification, you must sit the CISA exam through ISACA and meet ISACA requirements.
Meer trainingen van OranjeRaksha
More trainings from OranjeRaksha
De CISA Bootcamp is één van meerdere trainingen die we aanbieden voor auditors, IT-professionals, compliance-, risk- en operations-teams.
The CISA Bootcamp is one of several trainings we offer for auditors, IT professionals, compliance, risk and operations teams.