CYBERSECURITY AUDIT AND CYBERSECURITY FUNDAMENTALS – Non-Technicians
With the continuous increase in cybersecurity threats, including cybersecurity detail in every organization’s audit plans is becoming an increasingly critical factor. This re...
With the continuous increase in cybersecurity threats, including cybersecurity detail in every organization’s audit plans is becoming an increasingly critical factor. This requires auditors to know how to adequately audit cybersecurity processes and policies and to manage the tools to ensure that their organizations implement the appropriate controls. The course program covers the 4 key areas of Cybersecurity Audit: (1) cybersecurity and audit’s role, (2) cybersecurity governance, (3) cybersecurity operations, (4) cybersecurity technology topics. It also provides an in-depth look at how to link COBIT control objectives to the security measures defined according to the NIST Cybersecurity Framework .
The course can also be combined with the 8-hour SUPPLEMENTARY MODULE VA & PENTEST FUNDAMENTALS, in order to gain greater skills in evaluating and interpreting VA and PT activities.
In particular, the overall path provides: – IT AUDITORS with a 360-degree understanding of the key Cybersecurity factors to consider in an Audit Plan, allowing them to understand how to assess and reduce Cybersecurity risks, how to audit Cybersecurity controls, and how to interpret Cybersecurity evidence; – CYBERSECURITY EXPERTS with a clear understanding of Audit processes; – IT RISK MANAGERS with the ability to deepen their understanding of Cybersecurity risks and control measures.
Get Course Details & Pricing
Our advisor will reach out within 24 hours
Enquiry Received!
Thank you! One of our training advisors will contact you within 24 hours with full details and a personalised quote.
IT Auditors, Security Professionals, CISOs, Audit/Assurance professionals, IT Risk professionals, IT Risk Managers. The course is also aimed at Managers, Professionals, and Lawyers who wish to acquire the basic skills needed to understand cybersecurity risk scenarios, vulnerabilities, and threats, as defined by the NIST Cybersecurity Framework, internationally recognized as the cybersecurity reference framework.
A basic understanding of cybersecurity fundamentals is recommended for participation in this course.
If you are completely new to this knowledge, supplementary e-learning sessions are available upon request.
Accredited instructors: Cybersecurity Audit, Cobit2019 Foundation, and Cobit5 Foundation. Senior expert in IT Audit, IT Governance, and Cybersecurity, certified by CISA, CISM, ISO27001 A/LA, and ISO22301 A/LA, Privacy Officer - TUV, Cobit5, and Cobit 2019 Foundation, and Cybersecurity Audit. For the VA-PT Fundamentals module, the instructors will be CEH and CHFI certified, as well as senior experts in VA and PenTest.
The course includes the slides presented during the lectures.
Those who intend to take the exam will also receive the Official ISACA “Cybersecurity Audit Certificate Study Guide” in electronic format by purchasing the exam voucher.
The guide explores the following topics: Cybersecurity and the Audit’s role, Cybersecurity Governance, Cybersecurity Operations, case studies, examples, and insights into specific areas of Cybersecurity technologies.
For those wishing to take the exam, the official ISACA “Cybersecurity Audit Certificate Study Guide” will be provided in electronic format with the purchase of the voucher.
The guide covers the following topics: Cybersecurity and the Audit’s role, Cybersecurity Governance, Cybersecurity Operations, case studies, examples, and insights into specific areas of Cybersecurity technologies.
If you are interested in taking the three-day Cybersecurity Audit course, you can also purchase the additional day with the VA and PENTEST FUNDAMENTALS supplementary modules.
Up to 30 CPEs valid for the purpose of maintaining ISACA certifications
1) Cybersecurity vs Audit’s Role :
Digital Asset Protection; Lines of Defense; Role of Audit; Audit Objectives; Audit Scope
2) Cybersecurity Governance :
Security Organization Goals and Objectives; Cybersecurity Risk Assessment; Service Providers; Performance Measurement
3) Cybersecurity Operations – Cyberattacks :
Threat Assessment; Cybersecurity Measures; Vulnerability Management; Penetration Testing; Red Team/Blue Team/Purple Team Exercises
4) Cybersecurity Operations – Identity and Access Management :
Enterprise Identity and Access Management; Identity Management; Federated Identity Management; Key Objectives of Identity Management; Provisioning and Deprovisioning; Authorization; Privileged User Management and Controls; Third-party Access; Authentication Protocols; Configuration Management; Asset Management; Change Management; Patch Management; Network Security; Security Architecture; Security Perimeter; Network Perimeter; Interdependencies; Network Architecture; Remote Access; System Hardening
5) Cybersecurity Operations – Security Measures :
Incident Management; Digital Forensics; Client Endpoint Protection; Security within SDLC; Data Backup and Recovery
6) Cybersecurity Operations – Compliance and Cryptography :
Security Compliance; Cryptography
7) Security Technologies :
Firewall and Network Security technologies; Security Incident & Event Management (SIEM); Wireless Technology; Cloud Computing; Mobile Security; Internet of Things (IoT)
8) Correlations with COBIT
COBIT control objectives for the Cybersecurity Audit according to the NIST Cybersecurity Framework
Group exercises and practical examples
1) Basic concepts of Vulnerability Management
Main vulnerabilities, how and when to carry out an assessment and with which tools, remediation plan, criticality prioritization, reporting and classification.
2) Basic concepts of Penetration Testing and guidelines:
What is it for, who does it, when it should be done, Definition of the scope, recommendations on the use of tools, Non-Disclosure Agreement, etc.
3) Notes on the main frameworks that can be used (PCI, OSSTMM, etc.)
4) Phases of the PT with a focus on the attack phase
5)Definition, roles and skills of Blue/Red/Purple Team
6) Presentation and reasoned reading of a real Vulnerability Assessment and PenTest report
1) Fundamentals of Vulnerability Assessment for LAN networks
– Main types of host and application vulnerabilities
– The Vulnerability Assessment activity (Phases, standards, subjects involved, the final report)
– Vulnerability research (“Manual” research; General purpose vulnerability scanner (Nessus and OpenVas); Vulnerability scanner for web applications)
2) Fundamentals of Penetration Testing of LAN networks
– Penetration Testing activities
– Differences compared to VA
– Types of PenTest
– Critical issues in carrying out a PenTest
– The final report
– Frameworks that can be used for the Penetration Test of LAN networks
3) Group exercises and practical examples
Course Pricing Options
Choose the package that best fits your learning goals and professional background
Live course + exam
Self Paced E-Learning + Exam
This price variant includes attendance of both the 24-hour Cybersecurity Audit course, also useful for the ISACA certification of the same name, and ALSO of the 8-hour VA and PenTest Fundamentals supplementary module.
Send Course Enquiry
Fill out the form and we will get back to you within 24 hours
Why Choose Profice?
Italy's Leading Training Partner with a Proven Track Record
Official Partner
Authorized Training Partner delivering official certified curriculum
Expert Instructors
Certified professionals with 10+ years of real-world experience
Hands-on Labs
Real-world projects and 24/7 lab environment access
95% Pass Rate
Industry-leading certification exam success rate
Job Assistance
Dedicated placement support with 500+ hiring partners
Lifetime Support
Ongoing mentorship and community access after course completion
Ready to Transform Your Career?
Join thousands of professionals who achieved their certification goals with Profice.