Audit and assess information system security
A useful IS audit makes risks and control weaknesses understandable. Structure your investigations, assess evidence and formulate well-supported conclusions. Strengthen your ability to produce recommendations that information system managers can act on.
- Duration
- 2 days 14 hours
- Code
- GSI003FR Code
Presentation
As cyber threats become more complex, implementing safeguards is no longer enough: their effectiveness must be verified. This short course teaches you to structure a rigorous audit approach to assess information system compliance and resilience against standards and framework requirements, including ISO, NIST and ANSSI.
Beyond theory, the programme explores the operational reality of internal control. You will design dashboards to manage security performance and learn to coordinate different audits, from configuration analysis to penetration testing, to identify weaknesses before they are exploited.
By the end of the course, you will be equipped to turn audit findings into practical corrective action plans. You will be able to establish a continuous improvement cycle that supports sustainable, resilient information security governance.
Objectives
By the end of this course, you will be able to:
- define governance issues and obligations relating to information system security;
- develop an audit strategy suited to your organisation's risks and context;
- build relevant dashboards for security management;
- conduct architecture, configuration and organisational audits;
- manage penetration testing campaigns and remediation plans.
Program
Module 1: Understanding information security governance and standards
- Strategic issues and regulatory obligations in security management.
- Defining governance roles and responsibilities.
- Applying key frameworks: ISO 27001, ISO 27005, NIST and ANSSI recommendations.
Case study
- Analyse a fictional company's standards context and identify applicable frameworks.
Module 2: Conducting a security audit
- Overview of audit types: organisational, physical, architecture, configuration and source code.
- Applying proven methodologies and audit best practices.
- Structuring and developing a coherent information security audit plan.
Hands-on exercises
- Simulate planning a security audit for a defined scope.
Module 3: Managing performance through data
- A methodology for developing security indicators, including KPIs and KRIs.
- Designing and using information security decision-support dashboards.
- Using metrics to adjust the management strategy.
Hands-on exercises
- Design a dashboard prototype for a CISO.
Module 4: Coordinating technical controls and tests
- Penetration testing approaches: black-box, grey-box and white-box.
- Analysing vulnerability reports and interpreting technical findings.
- Prioritising risks and defining corrective action plans.
Module 5: Sustaining continuous improvement
- Integrating audit findings into project management and the application lifecycle.
- Communicating findings effectively to stakeholders.
- Monitoring compliance and remediation actions over time.
Hands-on exercises
- Develop a continuous improvement plan following an adverse audit report.
Audience
This course is intended for security and compliance professionals, including:
- CISOs and CIOs responsible for compliance and overall security strategy;
- information security auditors and consultants conducting cybersecurity assurance and advisory assignments;
- compliance and risk managers incorporating security into risk mapping;
- security engineers and administrators participating in technical audits and implementing corrections.
Prerequisites
The following prerequisite applies:
- Theoretical knowledge: a good understanding of cybersecurity fundamentals and ISO 2700x standards is recommended to keep pace with the course.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- Standards-based approach: master key frameworks such as ISO 27001 and NIST to support credible audits.
- 360° perspective: cover the full audit spectrum, from organisational controls to technical penetration testing, without overlooking key areas.
- Management tools: leave with practical methods for building dashboards that communicate effectively with senior management.
- Field expertise: benefit from certified expert instructors with real audit experience.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
#CybersecurityGovernance
fr
en