
Welcome to the course How to Perform an Information Security Audit.
Define confidentiality as access only for permitted individuals, ensure data integrity through error checking for completeness and accuracy, and maintain data availability with timely, reliable access and possible local mirrors.
Examine IT general controls across governance, operations, and independent assurance, including CSO oversight, BCP/DRP, backup testing, change control, and system development under ISO 27,001.
Enforce segregation of duties to prevent errors and fraud by separating access to assets from changing asset records, and protect production data from developers and third parties.
Explain segregation of duties: users update data through application programs, while application programmers cannot update production data or programs, with changes submitted to the change control unit.
Identify physical security threats, including hazards, unauthorized access, human errors, and service disruptions. Apply controls such as fire alarms, disaster recovery tests, sandbags, biometric access, and uninterruptible power supply.
Assess threats to physical security at a data center and explore biometric controls, concluding that supplementing the system with iris recognition, as part of two-factor authentication, strengthens access without replacement.
Examine the physical design of a data center, covering UPS and surge protection, environment and backup systems, and distinguish physical controls from logical controls like OS access and biometric systems.
Learn to map roles to access rights across ERP, SAP, and Salesforce using a role matrix, assigning read or write permissions for sales, accounting, and auditing.
Explore improving information security audits by implementing roll matrices by job category to standardize system access, reduce over-provisioning, and limit supervisor discretion.
Explore encryption, firewalls, intrusion detection systems, antivirus software, hardware authentication, user behavior analytics, honeypots, data loss prevention, machine learning threat detection, and cloud computing security to safeguard networks.
Explore encryption that turns data into unreadable form via a code to prevent unauthorized access, and how logical access controls and privileged accounts require confidential decryption codes.
Firewalls combine hardware and software to route and restrict unauthorized communications, featuring multi-tiered deployments before web servers and internal networks to block threats and limit data exfiltration.
Audit the data protection framework by evaluating policies, consent (explicit and implicit), and the collection, use, retention, and disclosure of personal data, plus access rights and data security.
Identify why insider risk is the greatest threat to personal data within a data protection framework. Explore how employees colluding and bypassing controls pose the highest breach likelihood.
Explore how bring your own device introduces information security risks across phones and laptops, including physical risks. Address insider risk, privacy concerns, and compliance challenges while emphasizing encryption and backups.
Explore the asset-threat-vulnerability triangle to assess information security risk by evaluating assets, vulnerabilities, and threats, and apply the ISO 27001 context to understand their interplay.
Explore the ecosystem of cybersecurity threats, from viruses and worms to ransomware and insider threats. See how awareness training, phishing, social engineering, and data diddling illustrate threats.
Identify the worm as a malicious, independent program that reproduces itself by copying itself from one system to another over a network, and distinguish it from a virus.
Enforce the principle of least privilege across applications and access controls, manage password standards, monitor privileged access with access management software, and apply timely patching and antivirus protection.
Establish a baseline performance for systems, networks, storage, and resources, and monitor usage for unexpected changes. Maintain change controls, test backups, and inventory IT assets—hardware, networks, and software—to identify vulnerabilities.
Learn how external connection controls secure data by restricting access to malicious sites, defining allowed websites, monitoring remote access, and applying strict internet restrictions for confidential information.
Verify third party information security through service level agreement monitoring and soc reports, enforce assurance clauses, explicit security arrangements, and prompt remediation with ongoing risk monitoring.
The information systems director flags insider threat from fictitious orders at store terminals, and enforces password controls to deter unauthorized entrants and disrupt distribution patterns.
Data classification policies define security levels for different data types to apply controls, align with ISO terminology, inventory personal information, and protect customer data under privacy laws and regulations.
Explores information security frameworks, notably ISO 27001, highlighting governance, risk management, risk assessment, residual risk, action plans, and the path to certification through internal audits and external verification.
Internal audit should focus on detection and reporting systems to provide cyber security assurance, ensuring timely detection, reporting, and remediation of cyber security risks.
Distinguish the extent and nature of audit work, define materiality, set scope limits, and plan engagements using internal control evaluation, tests of control, and substantive procedures.
Define engagement objectives that safeguard assets, support profitability, and ensure reliable reporting, while applying risk assessment and mandatory fraud and data protection considerations in information security audits.
Assess the expenditure cycle to verify goods paid for are received and charged to the correct account, uphold the integrity of financial and operational information, and safeguard assets.
Plan the engagement with a detailed risk assessment to identify significant risks and controls, using risk inventories, heat maps, and a flowchart to uphold due professional care and ethics.
An engagement work program lists objectives and inherent risks, details procedures and tests, supports risk-based audit planning, assigns responsibilities, and ties testing to criteria such as control frameworks and regulations.
Explore generally accepted criteria for assurance engagements, including control frameworks, acts, regulations, and industry best practices, and understand why management objectives are not suitable criteria.
Plan and prepare the engagement from the annual internal audit plan through risk assessment and kickoff; conduct fieldwork with walkthroughs and controls design evaluation; draft and finalize the audit report.
Enhance information gathering through audit techniques, including walkthroughs, observation, interviews, and process mapping, to perform risk-based internal audits and gap analyses against ISO standards.
Learn how to conduct walkthroughs and analyze the walkthrough process to identify root causes and offer practical recommendations. Explore training gaps, control adherence, and handling exceptions within policy and procedure.
Learn how to test the operating effectiveness of internal controls using test of controls, and distinguish design tools from evidence while assessing safeguarding of assets.
Explore interview approaches for information security audits, including structured, behavioral, and situational formats, and master effective skills like active listening, open questions, and creating a relaxed interviewing environment.
Explore process maps and benchmarking to compare current, ideal, and performed paths, identify vulnerabilities, and apply internal, competitive, industrial, and best-in-class benchmarking.
Explore how risk control matrices link objectives to risk assessments within an audit program, focusing on controls, operating effectiveness, and risk-based thinking to assign responsibilities and guide review.
Identify key activities in supervising engagements, from planning and scope confirmation to audit program design, field work, and final report, under multi-level supervision by the chief audit executive.
Implement a performance appraisal system with post engagement evaluations and post audit appraisals to reduce recency bias and tie the annual review to prior internal audits.
Navigate supervision and engagement best practices for internal audits by assigning clear areas of responsibility, enabling full accountability from planning to verification, and addressing blocking points to meet objectives.
Identify appropriate evidence of supervisory review for engagement working papers, including supervisor initials, an engagement review checklist, and a memorandum of supervisory review; avoid relying on performance appraisals as evidence.
Learn to communicate engagement results and monitor the implementation of internal audit recommendations while mastering the confirmation process and risk acceptance.
Learn to communicate interim progress during an information security audit, managing immediate attention items and scope changes, and decide whether resolved issues remain in the final internal audit report.
Describe the risk behind audit findings in information security, identify root causes, and propose actionable recommendations with monitored action plans to remediate risk.
Learn how internal auditors handle risk acceptance, escalate to senior management and the board, determine risk appetite, and evaluate risk responses to audit findings.
Assess engagement outcomes and follow up on the implementation status of internal audit recommendations, ensuring risks are mitigated, evidence supports closure, and management reports to the board.
Examine how to respond when internal control weaknesses are not corrected, evaluate management's risk acceptance, and establish a monitoring process to assess the adequacy, effectiveness, and timeliness of follow-up actions.
Define artificial intelligence and explain machine learning and neural networks, showing how training data and probabilistic parameters yield outputs. Discuss natural language processing, computer vision, and reinforcement learning basics.
Explore the landscape of ai systems, from ai agents and symbolic and subsymbolic ai to learning paradigms—supervised, semi-supervised, unsupervised, and reinforcement learning.
The EU AI Act classifies AI into minimal, limited, high and unacceptable risk, requiring transparency, risk assessments, data quality, intended purpose, human oversight, and robust documentation for high-risk systems.
Explore the ethical principles of AI, including fairness, explainability, accountability, privacy, and security, emphasizing organizational objectives, human oversight, and trusted, reliable systems that protect data and share benefits.
Explore the four AI data analysis types—descriptive, diagnostic, predictive, and prescriptive—and learn how each builds on the last to analyze data, reveal root causes, forecast trends, and support decision making.
Learn how ISO 42,001 frames an artificial intelligence management system that covers planning, do, check, and act, emphasizing risk assessment, leadership commitment, context of the organization, scope, and controls.
Examine the context, scope, and governance of an ISO 42,001 AI management system, covering risk planning, objectives, resources, awareness, operation, and continual improvement.
Explore ISO 42001 annexes: annex a for the statement of applicability, annex b as an implementation guide, and annex c for AI risk objectives to inform your AI risk assessment.
We are glad to bring you a course to learn how to perform information security audits.
This course is ideal for:
IT and information security professionals who wish to learn techniques on how to assess the security of their information and the vulnerability of their information systems; and
Auditors or others performing assessments who wish to learn more about performing information security audits.
The course will give you the knowledge and tools necessary to perform information security audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place.
It is taught by Adrian Resag, an experienced and CISA certified information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations.
The course covers:
Performing Information Security Audits
Planning Engagements
Understand how to properly plan engagements by determining their objectives, criteria and scope.
Know how to create working papers to document an audit and learn about different ways to staff an audit.
Performing Engagements
Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.
Communicating Progress and Results
Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations.
Information Security Threats and Controls
Threats to information security
Know about which threats to information security should be assessed, including threats to the integrity of data, confidentiality and the availability of data.
Be able to evaluate privacy risks, risks from smart devices, insider threats, illicit software threats and cybersecurity threats amongst others.
Be able to evaluate risks by using the Asset-Threat-Vulnerability triangle.
Controls over information security
Know about the different types of information security controls, including IT general controls.
Be able to put in place a solid governance over information security, such as by putting in place IT management and governance controls.
Be able to implement the segregation of IT duties and IT departmentalization, an information security framework and cybersecurity governance and policies.
Be able to apply the Three Lines of Defense Model in cybersecurity.
Learn about controls such as identity access management and authentication, encryption and firewalls, data privacy and protection controls.
Know about application and access controls, technical IT infrastructure controls, external connections controls and 3rd party information security controls.