Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Cybersecurity Audit School
Rating: 4.6 out of 5(20 ratings)
134 students

Cybersecurity Audit School

"Enhancing Auditors' Roles in Cyber Risk Management and Control Assessment"
Last updated 10/2024
English
English [Auto],

What you'll learn

  • Be able to identify and assess cybersecurity risks specific to their organization.
  • Understand how to implement and evaluate cybersecurity controls.
  • Recognize the auditor's role in the cybersecurity landscape and how to collaborate with cybersecurity teams.
  • Gain practical experience through scenarios that reinforce theoretical concepts.

Course content

1 section58 lectures18h 31m total length
  • Overview1:57

    Learn how cybersecurity relates to audit, with practical assessments, audits, and best practices, tips, tools, and techniques to prepare, conduct, and communicate findings.

  • Cybersecurity Key Concepts18:33

    Explore the definition of cyber security, the CIA triad, and practical best practices from NIST; learn how to apply cyber hygiene across personal, device, and network levels.

  • Cybersecurity History and Breaches17:42

    Trace the internet’s history from Arpanet to today’s breach landscape, highlighting key incidents like the Morris worm, the iloveyou virus, Stuxnet, and SolarWinds to extract security lessons.

  • Types of Cyber Attacks - Human17:49

    Discover the human element in cybersecurity, exploring social engineering, phishing variants, the Osint framework, and how auditors defend data and prevent breaches.

  • Types of Cyber Attacks - Technical22:14

    Examine common cyber attack types and malware, including phishing, business email compromise, viruses, worms, trojans, ransomware, zero day, backdoors, and rootkits, and cyber hygiene concepts like least privilege.

  • Cybersecurity Frameworks, Standards19:59

    Explains why cybersecurity standards exist and how they enable comparability and accountability across organizations, covering PCI DSS, NIST CSRC, CIS controls, ISO 27001/27002, and SOC 2.

  • NIST Frameworks and Standards15:29

    Navigate the NIST frameworks and standards, including the cybersecurity framework's five functions. Learn the risk management framework and key publications like SP 800 special publications and risk assessments.

  • Industry Frameworks (PCI, HIPAA, CIS CSC, ISO/IEC)23:35

    Explore ISO/IEC 27001/27002, PCI DSS, HIPAA, NIST, CIS controls, and GDPR, and see how risk management, data lifecycle, encryption, and tokenization shape cybersecurity audits.

  • Cybersecurity Oversight, Governance & Compliance22:12

    Explore how governance, policy, and compliance shape a cybersecurity program, balancing preventive, detective, and corrective controls with independent auditing and executive authority to manage risk.

  • Security Policies22:21

    Evaluate an organization's cybersecurity policy by examining policies, standards, guidelines, and procedures, ensuring clear, accessible governance, enforceable compliance, and proper exception management.

  • Security Risk Management Overview21:24

    Explore what risk management means in cybersecurity, distinguish risk, threat, and vulnerability, and learn how risk assessments, stakeholders, and cost-benefit guide informed, data-centric security decisions.

  • Threat Analysis17:52

    Learn to perform threat analysis, identify threat agents and vectors, and build a threat model to assess potential damage using threat intelligence and the Mitre attack framework.

  • Security Risk Management in Practice21:48

    Master the risk management life cycle from asset management to risk response, using qualitative and quantitative analysis, heat maps, and a risk register to balance thresholds, appetite, and controls.

  • Asset Identification and Inventory20:48

    Learn how to identify and inventory hardware, software, and data to support a robust cybersecurity program, guided by NIST and CIS controls and practical network diagrams.

  • Third-party / Service Provider Management15:09

    Differentiate and classify internal versus third-party assets, manage ownership across organizational, service provider, and employee roles, and verify third-party security through SOC reports and cloud frameworks.

  • Business Impact Assessment14:54

    Learn how to conduct a bia to quantify downtime, costs, and reputational impact, applying mtd, rto, rpo, and service delivery objectives to protect business processes.

  • Configuration Management and Change Control16:10

    Document and manage assets via configuration management and change control, capturing ownership, dependencies, and security baselines in a cmdb to support governance and devsecops.

  • Defending Business Assets Overview19:02

    Defend business assets by inventorying data and mapping layers from data to network. Apply technical, administrative, and physical controls, and align patch, change, and configuration management with CIS guidance.

  • Identity and access management22:14

    Explore identity and access management, including identification, authentication, authorization, and auditing; cover access models like mandatory, discretionary, and attribute, role, and rule based approaches, plus ldap, Kerberos, and federated identity.

  • Authentication and Authorization20:43

    Learn how authentication and authorization verify identity using something you know, something you have, something you are, and geolocation, then implement multi-factor authentication and just in time access.

  • Vulnerability and Patch Management23:06

    Explore vulnerability and patch management, identifying weaknesses, categorizing risks, and applying patches to build security in across apps and networks using automated scans and CVE databases.

  • Security awareness18:53

    Cultivate pervasive security awareness across the organization to ensure compliance, promote cyber hygiene, and reinforce safe behaviors against phishing through ongoing, role-based training, testing, and reminders.

  • Physical Security19:34

    Explore how physical security strengthens cybersecurity by applying the four ds: deny, deter, delay, and detect. Layer defenses, locks, lighting, cameras, and power backups to protect devices and support audits.

  • Personnel Security22:21

    Learn how to reduce insider threats by implementing clear personnel security policies, role-based access, and ongoing background checks, while coordinating with hr, management, and audits.

  • Computer Networking Fundamentals19:36

    Discover how computer networks transfer data from applications to devices using the OSI seven-layer model, TCP/IP handshakes, IPv4/IPv6 addressing, DHCP, MAC addresses, and port-based protocols for cybersecurity auditing.

  • Network Defenses22:19

    Explore how network defenses protect data across routers, switches, proxies, load balancers, and wireless access points, with firewall, VPN concentrator, and gateway protections.

  • Network Security Access Controls20:43

    Explore network access control (NAC) with IEEE 802.1x, pre-admission, VLANs, ACLs, NAT, DNS and DNSSEC, and firewall rule ordering.

  • EndPoint and System Security Configuration15:52

    Explore endpoint and system security configuration using CIS benchmarks and STIGs, covering administrator access, patching, encryption, and centralized policy management via local and group policies across devices and cloud.

  • EndPoint and System Security Protection22:19

    Learn how endpoint protection, including antivirus, signatures, and heuristics, safeguards devices; explore data leakage protection, mobile devices, bring your own device policies, cloud services, and audit considerations for secure networks.

  • Application Security21:48

    Build security in from the start by integrating agile practices, devops, and secure coding techniques. Audit-ready workflows cover environments, change control, and OWASP top ten risks for web applications.

  • Cloud & Virtualization Security22:40

    Explore cloud computing security controls and virtualization concepts, including service and deployment models, data retention, encryption, and regulatory considerations for auditors.

  • Encryption Concepts18:57

    Explore encryption and cryptography, revealing how algorithms and keys protect confidentiality, integrity, and availability across networks with transport layer security and digital certificates, and distinguish encoding, obfuscation, and steganography.

  • Cryptographic Algorithms22:55

    Explore cryptographic algorithms, including symmetric and asymmetric encryption, AES and RSA, and key management practices to protect data across networks and at rest for audits.

  • Encryption - Public Key Infrastructure15:14

    Explore public key infrastructure (PKI) and digital certificates, including certificate authorities and registration authorities, and learn how asymmetric key management, revocation, and hashing secure websites and digital signatures.

  • Data Privacy Controls20:13

    Learn how hashing promotes data integrity and how full disk encryption protects information at rest, with practical audit perspectives on hashing algorithms, FIM, and PKI.

  • Securing Data25:25

    Learn how to assess data privacy controls using a NIST privacy framework, balance privacy and security, manage data lifecycle from capture to disposal, and comply with GDPR and U.S. laws.

  • Logging, monitoring and alerting16:44

    Explore how to assess logging, monitoring, and alerting controls, centralize and protect audit trails, and use security incident and event management tools, log correlation, and continuous monitoring to detect incidents.

  • Incident Response (IR) Planning20:51

    Learn how to build and test an incident response plan with checklists, roles, and communication strategies, aligning with the NIST respond and recover phases and using tabletop exercises.

  • Incident Response (IR) Testing19:53

    Master incident response testing to keep plans current and applicable. Use tabletop exercises, threat analysis, and realistic simulations to train personnel, capture lessons learned, and improve recovery readiness.

  • Digital Forensics14:04

    Learn how digital forensics preserve evidence, maintain chain of custody, and ensure admissible, reliable data from logs, hashes, and timestamps for civil or criminal investigations.

  • Recovering Systems21:22

    Design and implement a continuity of operations plan to recover data and systems, ensure redundancy, testing of backups, and cloud and recovery site strategies for resilience.

  • Business Continuity and Recovery14:54

    Compare incident response, business continuity, and disaster recovery plans, and learn to build a business continuity plan with a business impact analysis, recovery objectives (RPO and RTO), and Ready.gov templates.

  • The Auditor's Role23:06

    Explore the auditor's role in cybersecurity, including the three lines model and the distinction between security and audit functions. Emphasize independence, collaboration, and risk-based, value-driven audits with recommendations.

  • CISO's Role19:25

    Learn the chief information security officer's role across leadership, governance, risk, and controls. See how CISOs balance business needs with security and compliance, choosing outsourced or virtual options.

  • Establishing Audit Scope17:27

    Discover how to establish audit scope for cyber security by defining what, when, where, and how, outlining in and out of scope items and data flows across production and cloud.

  • Building the Audit Plan28:02

    Define audit goals and scope, secure management support, and build a project plan with sequencing and profiling of current state, policies, and risk-based gaps to drive action.

  • Cybersecurity evaluation methods16:27

    Learn cybersecurity evaluation methods, including interviews, examinations, and technical tests, and how to define scope and objectives while aligning findings with frameworks like NIST, ISO, and HIPAA.

  • Vulnerability Assessments, Scanning and Testing20:58

    Learn to conduct vulnerability assessments, scanning, and testing across IT systems with automated tools like Nessus and Nmap, using CIS benchmarks to identify gaps and exploitable weaknesses.

  • Penetration Testing22:48

    Learn the penetration testing lifecycle from recon and scope to exploitation and reporting, with ethical testing, tools like OWASP ZAP and Burp Suite, and red, blue, and purple team roles.

  • Security Maturity Models14:55

    Use maturity models to assess and improve cybersecurity infrastructure, advancing from ad hoc to optimized processes with the capability maturity model and NIST framework, guided by KPIs and risk management.

  • Auditing using NIST frameworks16:58

    Learn to audit with the NIST cybersecurity framework by applying identify, protect, detect, respond, and recover controls, using asset management and risk assessment with open checklists and spreadsheets.

  • Auditing other security frameworks, standards ISO15:32

    Audit ISO 27001, 27002, and 2705 frameworks to strengthen information security management, risk, supplier management, and incident response through concrete controls and certification insights, mapping to NIST and CIS.

  • Auditing PCI DSS19:37

    Master PCI DSS requirements and the audit process, covering scope, remediation, vulnerability scans, annual penetration tests, and safeguarding the cardholder data environment with encryption and token-based protections.

  • Cybersecurity Auditing Examples15:30
  • Collecting and Organizing Cybersecurity Evidence24:26

    Collect, organize, and evaluate cybersecurity evidence across audits by gathering documents, policies, configurations, logs, and risk data, then apply root-cause analysis to support control-based conclusions.

  • NIST Reporting Requirements19:43

    Learn how NIST reporting requirements drive a system security plan with SSP documentation, POA&M, and risk management, using FedRAMP templates and role-based access control.

  • Prioritizing Risks and Influencing decisions18:53

    Learn to prioritize risks and influence decisions by turning audit findings into a focused, quantified risk view tied to business impact, using Nist, Cve, and fair concepts.

  • Course Summary and Conclusion5:51

    Explore how auditors strengthen organizational cybersecurity through governance, policies, and controls, applying threat intelligence and the NIST CSF five functions to identify, protect, detect, respond, and recover.

Requirements

  • Participants are expected to have the following foundational knowledge and skills before enrolling in the course:
  • 1. Basic Understanding of Auditing Principles: Familiarity with auditing concepts, processes, and methodologies is essential.
  • 2. Introductory Knowledge of Cybersecurity: A general understanding of cybersecurity terms, concepts, and common threats is beneficial.
  • 3. Experience with Risk Management: Prior experience or coursework related to risk assessment and management will enhance comprehension of course material.
  • 4. Familiarity with Regulatory Standards: Awareness of industry standards and regulations related to cybersecurity, such as GDPR, HIPAA, or PCI-DSS, is advantageous.
  • While these prerequisites are recommended, a strong desire to learn and engage with cybersecurity topics will also support participants' success in the course.

Description

In an era of increasing cyber threats, auditors must go beyond traditional roles and understand the complexities of cybersecurity. This course equips participants with the knowledge and skills to effectively contribute to their organization's cybersecurity efforts. Attendees will explore the risks associated with cyberattacks, learn how to design and implement robust controls, and understand compliance with industry standards and regulations.

Key topics include effective control frameworks, identifying warning signs of potential incidents, and employing investigative techniques to analyze cybersecurity breaches.

By the end of the course, attendees will be empowered to assess the effectiveness of cybersecurity controls and understand their crucial role as members of their organization’s “Cyber Defense Team.” This comprehensive program is essential for auditors aiming to enhance their contributions to safeguarding organizational data and infrastructure. Join us to build your expertise in cybersecurity and ensure your organization is well-prepared to face evolving threats.

Key Topics:

  • Cybersecurity Fundamentals: Overview of key concepts, terminology, and frameworks in cybersecurity.

  • Control Frameworks: Examination of popular cybersecurity frameworks (e.g., NIST, ISO 27001) and their application in organizational contexts.

  • Positioning Controls: Strategies for determining the most effective placement of cybersecurity controls within organizational processes.

  • Substantive Testing: Techniques for assessing the effectiveness of cybersecurity controls through substantive testing.

Who this course is for:

  • This course is ideal for anyone looking to strengthen their skills in cybersecurity assessment and contribute effectively to their organization’s cyber defense strategy.