
Learn how cybersecurity relates to audit, with practical assessments, audits, and best practices, tips, tools, and techniques to prepare, conduct, and communicate findings.
Explore the definition of cyber security, the CIA triad, and practical best practices from NIST; learn how to apply cyber hygiene across personal, device, and network levels.
Trace the internet’s history from Arpanet to today’s breach landscape, highlighting key incidents like the Morris worm, the iloveyou virus, Stuxnet, and SolarWinds to extract security lessons.
Discover the human element in cybersecurity, exploring social engineering, phishing variants, the Osint framework, and how auditors defend data and prevent breaches.
Examine common cyber attack types and malware, including phishing, business email compromise, viruses, worms, trojans, ransomware, zero day, backdoors, and rootkits, and cyber hygiene concepts like least privilege.
Explains why cybersecurity standards exist and how they enable comparability and accountability across organizations, covering PCI DSS, NIST CSRC, CIS controls, ISO 27001/27002, and SOC 2.
Navigate the NIST frameworks and standards, including the cybersecurity framework's five functions. Learn the risk management framework and key publications like SP 800 special publications and risk assessments.
Explore ISO/IEC 27001/27002, PCI DSS, HIPAA, NIST, CIS controls, and GDPR, and see how risk management, data lifecycle, encryption, and tokenization shape cybersecurity audits.
Explore how governance, policy, and compliance shape a cybersecurity program, balancing preventive, detective, and corrective controls with independent auditing and executive authority to manage risk.
Evaluate an organization's cybersecurity policy by examining policies, standards, guidelines, and procedures, ensuring clear, accessible governance, enforceable compliance, and proper exception management.
Explore what risk management means in cybersecurity, distinguish risk, threat, and vulnerability, and learn how risk assessments, stakeholders, and cost-benefit guide informed, data-centric security decisions.
Learn to perform threat analysis, identify threat agents and vectors, and build a threat model to assess potential damage using threat intelligence and the Mitre attack framework.
Master the risk management life cycle from asset management to risk response, using qualitative and quantitative analysis, heat maps, and a risk register to balance thresholds, appetite, and controls.
Learn how to identify and inventory hardware, software, and data to support a robust cybersecurity program, guided by NIST and CIS controls and practical network diagrams.
Differentiate and classify internal versus third-party assets, manage ownership across organizational, service provider, and employee roles, and verify third-party security through SOC reports and cloud frameworks.
Learn how to conduct a bia to quantify downtime, costs, and reputational impact, applying mtd, rto, rpo, and service delivery objectives to protect business processes.
Document and manage assets via configuration management and change control, capturing ownership, dependencies, and security baselines in a cmdb to support governance and devsecops.
Defend business assets by inventorying data and mapping layers from data to network. Apply technical, administrative, and physical controls, and align patch, change, and configuration management with CIS guidance.
Explore identity and access management, including identification, authentication, authorization, and auditing; cover access models like mandatory, discretionary, and attribute, role, and rule based approaches, plus ldap, Kerberos, and federated identity.
Learn how authentication and authorization verify identity using something you know, something you have, something you are, and geolocation, then implement multi-factor authentication and just in time access.
Explore vulnerability and patch management, identifying weaknesses, categorizing risks, and applying patches to build security in across apps and networks using automated scans and CVE databases.
Cultivate pervasive security awareness across the organization to ensure compliance, promote cyber hygiene, and reinforce safe behaviors against phishing through ongoing, role-based training, testing, and reminders.
Explore how physical security strengthens cybersecurity by applying the four ds: deny, deter, delay, and detect. Layer defenses, locks, lighting, cameras, and power backups to protect devices and support audits.
Learn how to reduce insider threats by implementing clear personnel security policies, role-based access, and ongoing background checks, while coordinating with hr, management, and audits.
Discover how computer networks transfer data from applications to devices using the OSI seven-layer model, TCP/IP handshakes, IPv4/IPv6 addressing, DHCP, MAC addresses, and port-based protocols for cybersecurity auditing.
Explore how network defenses protect data across routers, switches, proxies, load balancers, and wireless access points, with firewall, VPN concentrator, and gateway protections.
Explore network access control (NAC) with IEEE 802.1x, pre-admission, VLANs, ACLs, NAT, DNS and DNSSEC, and firewall rule ordering.
Explore endpoint and system security configuration using CIS benchmarks and STIGs, covering administrator access, patching, encryption, and centralized policy management via local and group policies across devices and cloud.
Learn how endpoint protection, including antivirus, signatures, and heuristics, safeguards devices; explore data leakage protection, mobile devices, bring your own device policies, cloud services, and audit considerations for secure networks.
Build security in from the start by integrating agile practices, devops, and secure coding techniques. Audit-ready workflows cover environments, change control, and OWASP top ten risks for web applications.
Explore cloud computing security controls and virtualization concepts, including service and deployment models, data retention, encryption, and regulatory considerations for auditors.
Explore encryption and cryptography, revealing how algorithms and keys protect confidentiality, integrity, and availability across networks with transport layer security and digital certificates, and distinguish encoding, obfuscation, and steganography.
Explore cryptographic algorithms, including symmetric and asymmetric encryption, AES and RSA, and key management practices to protect data across networks and at rest for audits.
Explore public key infrastructure (PKI) and digital certificates, including certificate authorities and registration authorities, and learn how asymmetric key management, revocation, and hashing secure websites and digital signatures.
Learn how hashing promotes data integrity and how full disk encryption protects information at rest, with practical audit perspectives on hashing algorithms, FIM, and PKI.
Learn how to assess data privacy controls using a NIST privacy framework, balance privacy and security, manage data lifecycle from capture to disposal, and comply with GDPR and U.S. laws.
Explore how to assess logging, monitoring, and alerting controls, centralize and protect audit trails, and use security incident and event management tools, log correlation, and continuous monitoring to detect incidents.
Learn how to build and test an incident response plan with checklists, roles, and communication strategies, aligning with the NIST respond and recover phases and using tabletop exercises.
Master incident response testing to keep plans current and applicable. Use tabletop exercises, threat analysis, and realistic simulations to train personnel, capture lessons learned, and improve recovery readiness.
Learn how digital forensics preserve evidence, maintain chain of custody, and ensure admissible, reliable data from logs, hashes, and timestamps for civil or criminal investigations.
Design and implement a continuity of operations plan to recover data and systems, ensure redundancy, testing of backups, and cloud and recovery site strategies for resilience.
Compare incident response, business continuity, and disaster recovery plans, and learn to build a business continuity plan with a business impact analysis, recovery objectives (RPO and RTO), and Ready.gov templates.
Explore the auditor's role in cybersecurity, including the three lines model and the distinction between security and audit functions. Emphasize independence, collaboration, and risk-based, value-driven audits with recommendations.
Learn the chief information security officer's role across leadership, governance, risk, and controls. See how CISOs balance business needs with security and compliance, choosing outsourced or virtual options.
Discover how to establish audit scope for cyber security by defining what, when, where, and how, outlining in and out of scope items and data flows across production and cloud.
Define audit goals and scope, secure management support, and build a project plan with sequencing and profiling of current state, policies, and risk-based gaps to drive action.
Learn cybersecurity evaluation methods, including interviews, examinations, and technical tests, and how to define scope and objectives while aligning findings with frameworks like NIST, ISO, and HIPAA.
Learn to conduct vulnerability assessments, scanning, and testing across IT systems with automated tools like Nessus and Nmap, using CIS benchmarks to identify gaps and exploitable weaknesses.
Learn the penetration testing lifecycle from recon and scope to exploitation and reporting, with ethical testing, tools like OWASP ZAP and Burp Suite, and red, blue, and purple team roles.
Use maturity models to assess and improve cybersecurity infrastructure, advancing from ad hoc to optimized processes with the capability maturity model and NIST framework, guided by KPIs and risk management.
Learn to audit with the NIST cybersecurity framework by applying identify, protect, detect, respond, and recover controls, using asset management and risk assessment with open checklists and spreadsheets.
Audit ISO 27001, 27002, and 2705 frameworks to strengthen information security management, risk, supplier management, and incident response through concrete controls and certification insights, mapping to NIST and CIS.
Master PCI DSS requirements and the audit process, covering scope, remediation, vulnerability scans, annual penetration tests, and safeguarding the cardholder data environment with encryption and token-based protections.
Collect, organize, and evaluate cybersecurity evidence across audits by gathering documents, policies, configurations, logs, and risk data, then apply root-cause analysis to support control-based conclusions.
Learn how NIST reporting requirements drive a system security plan with SSP documentation, POA&M, and risk management, using FedRAMP templates and role-based access control.
Learn to prioritize risks and influence decisions by turning audit findings into a focused, quantified risk view tied to business impact, using Nist, Cve, and fair concepts.
Explore how auditors strengthen organizational cybersecurity through governance, policies, and controls, applying threat intelligence and the NIST CSF five functions to identify, protect, detect, respond, and recover.
In an era of increasing cyber threats, auditors must go beyond traditional roles and understand the complexities of cybersecurity. This course equips participants with the knowledge and skills to effectively contribute to their organization's cybersecurity efforts. Attendees will explore the risks associated with cyberattacks, learn how to design and implement robust controls, and understand compliance with industry standards and regulations.
Key topics include effective control frameworks, identifying warning signs of potential incidents, and employing investigative techniques to analyze cybersecurity breaches.
By the end of the course, attendees will be empowered to assess the effectiveness of cybersecurity controls and understand their crucial role as members of their organization’s “Cyber Defense Team.” This comprehensive program is essential for auditors aiming to enhance their contributions to safeguarding organizational data and infrastructure. Join us to build your expertise in cybersecurity and ensure your organization is well-prepared to face evolving threats.
Key Topics:
Cybersecurity Fundamentals: Overview of key concepts, terminology, and frameworks in cybersecurity.
Control Frameworks: Examination of popular cybersecurity frameworks (e.g., NIST, ISO 27001) and their application in organizational contexts.
Positioning Controls: Strategies for determining the most effective placement of cybersecurity controls within organizational processes.
Substantive Testing: Techniques for assessing the effectiveness of cybersecurity controls through substantive testing.