Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
How to Perform an Information Security Audit
Rating: 4.5 out of 5(55 ratings)
417 students

How to Perform an Information Security Audit

What you need to know to perform information security audits
Last updated 4/2025
English
English [Auto],

What you'll learn

  • Understand how to properly plan engagements by determining their objectives, criteria and scope.
  • Know how to create working papers to document an audit and learn about different ways to staff an audit.
  • Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.
  • Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit
  • Know about which threats to information security should be assessed, including threats to the integrity of data, confidentiality and the availability of data.
  • Be able to evaluate privacy risks, risks from smart devices, insider threats, illicit software threats and cybersecurity threats amongst others.
  • Be able to evaluate risks by using the Asset-Threat-Vulnerability triangle.
  • Know about the different types of information security controls, including IT general controls.
  • Be able to put in place a solid governance over information security, such as by putting in place IT management and governance controls.
  • Be able to implement the segregation of IT duties and IT departmentalization, an information security framework and cybersecurity governance and policies.
  • Be able to apply the Three Lines of Defense Model in cybersecurity.
  • Learn about controls such as identity access management and authentication, encryption and firewalls, data privacy and protection controls.
  • Know about application and access controls, technical IT infrastructure controls, external connections controls and 3rd party information security controls.

Course content

3 sections89 lectures10h 34m total length
  • Information Security5:36

    Welcome to the course How to Perform an Information Security Audit.

  • Data Integrity, Confidentiality and Data Availability2:48

    Define confidentiality as access only for permitted individuals, ensure data integrity through error checking for completeness and accuracy, and maintain data availability with timely, reliable access and possible local mirrors.

  • IT General Controls8:30

    Examine IT general controls across governance, operations, and independent assurance, including CSO oversight, BCP/DRP, backup testing, change control, and system development under ISO 27,001.

  • Segregation of IT Duties5:07

    Enforce segregation of duties to prevent errors and fraud by separating access to assets from changing asset records, and protect production data from developers and third parties.

  • Question on Segregation of IT Duties1:48

    Explain segregation of duties: users update data through application programs, while application programmers cannot update production data or programs, with changes submitted to the change control unit.

  • Threats and Controls to Physical Security7:04

    Identify physical security threats, including hazards, unauthorized access, human errors, and service disruptions. Apply controls such as fire alarms, disaster recovery tests, sandbags, biometric access, and uninterruptible power supply.

  • Question on Threats and Controls to Physical Security1:34

    Assess threats to physical security at a data center and explore biometric controls, concluding that supplementing the system with iris recognition, as part of two-factor authentication, strengthens access without replacement.

  • Question on Threats and Controls to Physical Security2:08

    Examine the physical design of a data center, covering UPS and surge protection, environment and backup systems, and distinguish physical controls from logical controls like OS access and biometric systems.

  • Identity Access Management2:36
  • Access and Authorization Controls - Risks7:02
  • Identity Access Management - Activities6:29
  • Authentication1:04
  • IT Departmentalization6:40

    Learn to map roles to access rights across ERP, SAP, and Salesforce using a role matrix, assigning read or write permissions for sales, accounting, and auditing.

  • Question on IT Departmentalization 1 of 22:30

    Explore improving information security audits by implementing roll matrices by job category to standardize system access, reduce over-provisioning, and limit supervisor discretion.

  • Question on IT Departmentalization 2 of 22:51
  • Types of Information Security Controls11:41

    Explore encryption, firewalls, intrusion detection systems, antivirus software, hardware authentication, user behavior analytics, honeypots, data loss prevention, machine learning threat detection, and cloud computing security to safeguard networks.

  • Encryption1:59

    Explore encryption that turns data into unreadable form via a code to prevent unauthorized access, and how logical access controls and privileged accounts require confidential decryption codes.

  • Firewalls4:35

    Firewalls combine hardware and software to route and restrict unauthorized communications, featuring multi-tiered deployments before web servers and internal networks to block threats and limit data exfiltration.

  • Data Privacy and Protection6:59
  • Data Protection Framework12:25

    Audit the data protection framework by evaluating policies, consent (explicit and implicit), and the collection, use, retention, and disclosure of personal data, plus access rights and data security.

  • Question on Data Protection Framework2:00

    Identify why insider risk is the greatest threat to personal data within a data protection framework. Explore how employees colluding and bypassing controls pose the highest breach likelihood.

  • Smart Devices and Their Risks7:57

    Explore how bring your own device introduces information security risks across phones and laptops, including physical risks. Address insider risk, privacy concerns, and compliance challenges while emphasizing encryption and backups.

  • Question on Smart Devices and Their Risks3:31
  • Question on Data Protection Framework4:59
  • Asset-Threat-Vulnerability Triangle8:05

    Explore the asset-threat-vulnerability triangle to assess information security risk by evaluating assets, vulnerabilities, and threats, and apply the ISO 27001 context to understand their interplay.

  • Cybersecurity Risks2:17
  • Cybersecurity Threats33:41

    Explore the ecosystem of cybersecurity threats, from viruses and worms to ransomware and insider threats. See how awareness training, phishing, social engineering, and data diddling illustrate threats.

  • Question on Cybersecurity Threats 10:26

    Identify the worm as a malicious, independent program that reproduces itself by copying itself from one system to another over a network, and distinguish it from a virus.

  • Question on Cybersecurity Threats 20:59
  • Question on Cybersecurity Threats 31:01
  • Question on Cybersecurity Threats 40:35
  • IT Management and Governance Controls Against Cybersecurity Threats7:12
  • Application and Access Controls7:05

    Enforce the principle of least privilege across applications and access controls, manage password standards, monitor privileged access with access management software, and apply timely patching and antivirus protection.

  • Technical IT Infrastructure Controls2:31

    Establish a baseline performance for systems, networks, storage, and resources, and monitor usage for unexpected changes. Maintain change controls, test backups, and inventory IT assets—hardware, networks, and software—to identify vulnerabilities.

  • External Connections Controls3:54

    Learn how external connection controls secure data by restricting access to malicious sites, defining allowed websites, monitoring remote access, and applying strict internet restrictions for confidential information.

  • Verifying 3rd Party Information Security6:54

    Verify third party information security through service level agreement monitoring and soc reports, enforce assurance clauses, explicit security arrangements, and prompt remediation with ongoing risk monitoring.

  • Illicit Software Use7:49
  • Insider Threat9:09
  • Question on Insider Threat0:28

    The information systems director flags insider threat from fictitious orders at store terminals, and enforces password controls to deter unauthorized entrants and disrupt distribution patterns.

  • Question on Data Privacy and Protection2:06

    Data classification policies define security levels for different data types to apply controls, align with ISO terminology, inventory personal information, and protect customer data under privacy laws and regulations.

  • Cybersecurity Governance and Policies5:51
  • Information Security Framework5:23

    Explores information security frameworks, notably ISO 27001, highlighting governance, risk management, risk assessment, residual risk, action plans, and the path to certification through internal audits and external verification.

  • The Three Lines of Defense Model in Cybersecurity3:37
  • Question on Cybersecurity Governance and Policies2:28

    Internal audit should focus on detection and reporting systems to provide cyber security assurance, ensuring timely detection, reporting, and remediation of cyber security risks.

Requirements

  • No prior experience or knowledge is required.

Description

We are glad to bring you a course to learn how to perform information security audits.

This course is ideal for:

  1. IT and information security professionals who wish to learn techniques on how to assess the security of their information and the vulnerability of their information systems; and

  2. Auditors or others performing assessments who wish to learn more about performing information security audits.

The course will give you the knowledge and tools necessary to perform information security audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place.

It is taught by Adrian Resag, an experienced and CISA certified information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations.


The course covers:

Performing Information Security Audits

Planning Engagements

  • Understand how to properly plan engagements by determining their objectives, criteria and scope.

  • Know how to create working papers to document an audit and learn about different ways to staff an audit.

Performing Engagements

  • Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.

Communicating Progress and Results

  • Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations.

Information Security Threats and Controls

Threats to information security

  • Know about which threats to information security should be assessed, including threats to the integrity of data, confidentiality and the availability of data.

  • Be able to evaluate privacy risks, risks from smart devices, insider threats, illicit software threats and cybersecurity threats amongst others.

  • Be able to evaluate risks by using the Asset-Threat-Vulnerability triangle.

Controls over information security

  • Know about the different types of information security controls, including IT general controls.

  • Be able to put in place a solid governance over information security, such as by putting in place IT management and governance controls.

  • Be able to implement the segregation of IT duties and IT departmentalization, an information security framework and cybersecurity governance and policies.

  • Be able to apply the Three Lines of Defense Model in cybersecurity.

  • Learn about controls such as identity access management and authentication, encryption and firewalls, data privacy and protection controls.

  • Know about application and access controls, technical IT infrastructure controls, external connections controls and 3rd party information security controls.

Who this course is for:

  • Current or future IT and information security professionals who wish to learn techniques on how to assess the security of their information and the vulnerability of their information systems.
  • Auditors or others performing assessments who wish to learn more about performing information security audits.