
Discover practical, step-by-step information system audit techniques across a 12-step process—from validating information security policy to reviewing data center, networks, and incident management—in a hands-on beginner-friendly program.
Explore an ideal, customizable audit report format, including objectives, scope, management responsibility, methodology, controls, risk metrics, and drafting audit observations.
Audit step one by examining the information security policy, gathering data, and validating board approval, policy classification, periodic review, and history to identify non-compliances and improve controls.
Learn to audit application controls by validating ownership, categorization, factor of authentication, password complexity, vulnerability testing, source code review, and user access review against the information security policy.
Explore how to audit controls related to databases, gathering name, purpose, owner, categorization of the database operating system, server location, makeup, and other data fields.
Audit database ownership by assigning a dedicated, individual owner with appropriate authority, ensuring accountability and information security policy compliance across databases.
Apply auditing concepts from application categorization to database categorization per the information security policy and clause ten data classification, marking restricted or confidential databases as critical and validating with evidence.
Learn to audit operating systems by validating end-of-support dates and security updates, using official sources to identify risks, and recommending upgrades to maintain compliance.
Assess backup locations against the information security policy for offsite storage. Ensure backup sites are at least 20 miles from the original site to protect continuity.
Learn how privilege identification management (PIM) and BIM software like CyberArk monitor, log, and audit privileged accounts to enforce access control and verify critical databases are covered.
Learn how to obtain and validate secured configuration documentation across databases, operating systems, network devices, and applications. Recognize the document lifecycle: purpose, scope, guidelines, approval, periodic updates, and password encryption.
Audit password encryption as a best practice by distinguishing encryption from hashing and validating encrypted or hashed storage and encrypted transmission per information security policy clause 19.
Audit and validate encryption and hashing algorithms against information security policy requirements. Review evidence from the backend dashboard, identify non-compliant algorithms like DES, and recommend upgrades to approved standards.
Audit and validate restoration tests to determine feasibility of database recovery, align with information security policy, and verify compliance frequencies for critical and noncritical databases.
Audit data center controls by collecting center name, location, hosting type (internal or cloud), and confirming sla availability, latest audit date, and open observations for primary and secondary data centers.
Audit cloud storage SLAs in step 4.1 to verify data confidentiality, data availability, right to audit, and intellectual property rights, ensuring a documented, compliant agreement with external providers.
Explore data center audit practices, including annual in-house and cloud service audits, environmental and fire safety controls, and verifying open observations and compliance certificates.
Audit the controls for network devices, including firewalls, routers, switches, and gateways, by collecting data fields such as device name, purpose, owner, and the date of the latest configuration review.
Audit device ownership as a best practice by assigning a dedicated owner to each device. Individual ownership ensures accountability for risk and controls, rather than grouping by department.
Audit network devices configurations at regular intervals to ensure settings align with the information security policy. Document and cross-check the date on the annual device owner review reports for compliance.
Audit and validate endpoint device controls for desktops, laptops, and mobile phones; cover ownership, operating system, and antivirus checkpoints (steps 6.1–6.3).
Audit and validate device ownership by assigning a dedicated, individual owner responsible for device risk and controls. Enhance accountability through owner-specific governance.
Audit operating systems by validating end-of-support dates for Windows 10 and Windows 7, and verify installations with system information or cmd.
Audit step 6.3 verifies antivirus installation and daily signature updates on user devices, using sample endpoints and system administrators to ensure no more than seven days between updates.
Audit and validate organizational email controls by listing domains, verifying SPF status, ensuring antivirus scanning of attachments, and blocking personal email usage; set up for step 7.1 on policy framework.
Validate SPF implementation as part of email security policy, confirming that only authorized servers can send emails, using SPF record checks to verify domains and prepare for DMARC.
Validate DMARC implementations to ensure domain-based message authentication, reporting and conformance align with SPF, improve email security, and identify audit observations across all domains.
Audit step 7.3 ensures all email attachments are scanned by antivirus software before download, aligning with the information security policy and enabling the email shield dashboard for compliance.
Demonstrate how to validate email restrictions by sending from the official email ID to personal accounts (e.g., Gmail, Yahoo), log any exceptions, and verify monitoring and approvals for such cases.
Audit step eight outsourcing activities by evaluating providers with access to customer data, networks, or continuity-critical services, and collect provider names, agreement dates, audit rights, confidentiality, and information security vetting.
Audit step 8.1 validates the service level agreement, verifies dates and expiry, checks the right to audit, and ensures confidentiality provisions and vetting by the information security team.
Validate step 8.2 by cross-checking annual service provider audits with actual reports and service level agreement compliance. Verify open observations and aging against information security policy remediation timelines.
Audit desktop controls in step nine, covering OS licensing, activation, password deployment, and admin rights restrictions, observed with users and admins and documented with screenshots showing usernames and hostnames.
Audit operating systems by validating the device’s Windows version using four methods: systeminfo, winver, settings about, or searching for system information, then confirm Microsoft support for that version.
Audit os licensed versions by opening the command prompt and running the license-check command to verify the product license terms and the organization name, ensuring compliance.
Audit windows activation by checking activation status in settings and verifying a digital license linked to the Microsoft account, and prepare for step 9.4 on password deployment.
Audit Windows login password settings by cross verifying requirements: min age zero days, max age 90 days, min length eight characters, and password history of five; note noncompliance step 9.4.
Audit step 9.5 validates that end users lack administrative rights using control panel checks and approvals, documenting non-compliance and privilege risk, and previewing the next step clock synchronization.
Audit step 9.6 shows how to validate clock synchronization by using a common time server and date and time settings across devices for incident investigations.
Validate date and time restrictions to prevent users from changing system time; restrict changes to administrator, preserve audit trails, and safeguard investigation procedures, using control panel steps.
Validate the screen saver setting per information security policy, assess whether it is enabled, and identify non-compliant cases where it is not enabled or not protected by the administrator password.
Validate patch updation procedures, verify Windows update status and history, and distinguish feature, quality, and definition updates to guide audit reporting.
Audits verify that the offer to save passwords is disabled across browsers, exemplified in Chrome and Edge, through group policy, documenting evidence and assessing medium risk.
Auditing updated browsers by validating the latest versions of Google Chrome and Microsoft Edge through their about pages, comparing installed versions with current releases, and confirming updates.
Identify approved software by obtaining the approved software list and approvals from CTO or CSO, then compare installed programs to the upload list and report any unapproved items.
Audit step 9.13 validates that only system administrators can install software. The lecture demonstrates testing installation restrictions by downloading and running an executable from a user account, noting compliance.
Audit USB restrictions by validating USB is disabled, using a simple insert-and-check method to verify it is recognized and read, performed by a qualified system administrator to avoid virus spread.
Validate Google Drive restrictions by testing access in a browser to confirm blocking. If allowed for business reasons, obtain written admin approval and check other drives such as Dropbox.
Auditors validate that VBA macros are disabled for RMS Excel and RMS Word to align with information security policy, report non-compliance, and recommend administrative password protection of macro settings.
Auditors validate step 9.7 by confirming PowerShell is disabled to prevent unauthorized script execution, assess medium risk, and document findings with screenshots during laptop hardening.
Learn how to validate that the Windows Run feature is disabled, identify noncompliance, and document evidence to mitigate the medium risk of direct access to registry edit and system32 files.
Validate step 9.19 by auditing that the user attended information security training, confirm attendance or records, ensure at least one training is completed, and note organizational risk exposure.
We assure you that this is not a theory class. Except for this introduction, there will be no other PPTs.
We have designed the course in such as a way that it simulates on-the job kind of training. This course is primarily designed for the beginners/freshers in information system audit and hence we will start from basic aspects of IS audits.
We assure you that after completion of this training program, you will be able to independently handle the IS audits.
For effective and efficient audit program, we have bifurcated Information System audits into 12 step processes. For your easy understanding we have designed exclusive video for each step.
For each step we will guide you about data requirements, audit procedure, evidence to be evaluated and how to write the audit report.
Also, you can download readymade templates from resource section of this course.
Step-wise Audit Program:
Step 1 is about checking the information security policy. In this step, as an auditor you need to check:
o availability of the policy,
o whether policy is approved by appropriate authority?
o whether policy is updated at periodic interval and other aspect with respect to policy?
We will discuss in detail about how to audit and validate these controls in our step 1 video.
Step 2 is about auditing the controls related to applications. In this step, as an auditor you need to check:
o whether application is appropriately categorized?
o Whether each application is owned by dedicated owner?
o How many factors of authentication is applied?
o Whether user access review in conducted for each application at periodic level?
We will discuss in detail about how to audit and validate these controls in our step 2 video.
Step 3 is about auditing the controls related to database. We check
o whether database is appropriately categorized?
o Whether each database is owned by dedicated owner?
o Whether Operating system is updated? Organization should not be using end of life/end of support OS.
o Whether backup arrangement is appropriate?
We will discuss in detail how to audit and validate these controls in our step 3 video.
Step 4 is about auditing the controls related to datacenter. You need to check
o whether datacentre is audited at periodic interval?
o Whether SLA is available for external datacentre?
o Whether secondary datacentre is at offsite location?
Step 5 is about auditing the controls related to network devices. You need to check
o Whether device is owned by dedicated owner?
o Whether device configuration is reviewed at period interval?
Step 6 is about auditing the controls related to endpoint devices like computers, laptops, tablets, mobile etc. You need to check
o Whether asset inventory is maintained and updated?
o Whether end point device is owned by dedicated owner?
o Whether anti-virus is installed for all the devices?
Step 7 is about auditing the controls related to email. You need to check
o whether SPF is enabled? Don’t worry about technical terms. We will simplify the same while discussing the step 7.
o whether DMARC is enabled?
o whether attachments are scanned before downloading?
Step 8 is about auditing the controls related to outsourcing. You need to check
o Whether service level agreement is available for the outsourced services?
o whether service provider is audited at periodic interval?
Step 9 is about auditing the controls related to desktop security You need to check
o Whether operating system is updated and licensed?
o Whether anti-virus is installed and signatures are updated?
o Various user restrictions are implemented?
o Use of latest browsers.
Step 10 is about auditing the controls related to BCP and Incident management. You need to check
o Whether Business Continuity Policy & Incident Management policy is available?
o Whether Business Continuity plan is tested at periodic interval?
Step 11 is about auditing the controls related to users. You need to check
o Whether users are trained at periodic interval on information security?
o whether background verification is conducted for new hires?
These 11 steps cover almost all the important and critical information security requirements. As a step 12, you need to review all other checkpoints as required by the objective of audit.