Cyber Security Audit Certificate

ISACA’s Cybersecurity Audit Certificate Program provides audit/assurance professionals with the knowledge needed to excel in cybersecurity audits. It provides security professionals with an understanding of the audit process, and IT risk professionals with an understanding of cyber-related risk and mitigating controls.

The Cybersecurity Audit Certificate is a comprehensive course designed to help individuals prepare for the Cybersecurity Audit Certificate exam and to understand risk and implement controls to better protect against cyber threats.

The Cybersecurity Audit Certificate exam and manual are organised within four high-level domains:

  • Cybersecurity and Audit’s Role
  • Cybersecurity Governance
  • Cybersecurity Operations
  • Cybersecurity Technology Topics

These domains are the result of extensive research and feedback from subject matter experts from around the world.

Key takeaways

With the increasing number of cyberthreats, it is becoming critical for audit plans to include cybersecurity. ISACA’s Cybersecurity Audit Certificate Program provides audit/assurance professionals with the knowledge needed to excel in cybersecurity audits, and IT risk professionals with an understanding of cyber-related risk and mitigating controls.

  • Understand Security Frameworks to Identify Best Practices
  • Define threat and vulnerability management
  • Assess threats with the help of vulnerability management tools
  • Build and deploy secure authorization processes
  • Explain all aspects of cybersecurity governance
  • Distinguish between firewall and network security technologies
  • Enhance asset, configuration, change and patch management practices
  • Manage enterprise identity and information access
  • Identify application security control
  • Identify cyber and legal regulatory requirements to aid in compliance assessments
  • Identify weaknesses in cloud strategies and controls
  • Perform cybersecurity and third-party risk assessments
  • Identify the benefits and risks of containerization

Prerequisites

You do not need any prerequisites for this accelerated course. However, ISACA recommends that you have a basic understanding of cyber security concepts and previous experience within the industry.

Module 1: Introduction

  • Digital Asset Protection
  • Lines of Defense
  • Role of Audit
  • Audit Objectives
  • Audit Scope

Module 2: Cybersecurity Governance

  • Cybersecurity Roles and Responsibilities
  • Security Frameworks
  • Security Organization Goals & Objectives
  • Cybersecurity Policy and Standards
  • Cyber and Legal/ Regulatory Requirements
  • Information Asset Classification
  • Cybersecurity Insurance
  • Cybersecurity Risk Assessment
  • Cybersecurity Awareness Training & Education
  • Social Media – Risk and Control
  • Third-Party Assessment
  • Service Providers
  • Supply Chain Risk Management
  • Performance Measurement

Module 3: Cybersecurity Operations

  • Concepts and Definitions
  • Threat and Vulnerability Management
  • Enterprise Identity and Access Management
  • Configuration Management / Asset management
  • Change Management
  • Patch Management
  • Network Security
  • Build and Deploy/Secure Authorization Process for Information Technology
  • Incident Management
  • Client Endpoint Protection
  • Application Security
  • Data Backup and Recovery
  • Security Compliance
  • Cryptography

Module 4: Cybersecurity Technology Topics

  • Firewall and Network Security technologies
  • Security Incident & Event Management (SIEM)
  • Wireless Technology
  • Cloud Computing
  • Mobile Security
  • Internet of Things (IoT)
  • Virtualization Security
  • Industrial Control Systems (ICS)

The Cybersecurity Audit Certificate Exam is an online, closed-book, remotely proctored exam. The exam covers four domains and includes a total of 75 questions. The number of questions in each domain is based upon the domain’s assigned weight. The chart on the right displays the domains and the weights assigned to them.

  • Cybersecurity Governance - 20%
  • Cybersecurity Operations - 45%
  • Cybersecurity Technology Topics - 30%
  • Cybersecurity and the audit role - 5%

 

FAQ – Cyber Security Audit Certificate

Hva koster kurset?
Prisen er 17 500 NOK for 2 dager. Kurset inkluderer eksamen til Cyber Security Audit Certificate samt kursmateriell.

Hvor lenge varer kurset?
Kurset går over 2 intensive dager og gjennomføres som virtuelt kurs eller klasseromskurs.

Hvordan gjennomføres kurset?
Kurset er instruktørledet og kombinerer teori med praktiske eksempler og case-basert læring. Deltakerne får innsikt i hvordan revisjon, risikostyring og sikkerhetskontroller brukes i praksis for å evaluere og forbedre cybersikkerhet.

Hvem passer kurset for?
Kurset er utviklet for fagpersoner som arbeider med revisjon, risiko og sikkerhet:

  • Audit- og assurance professionals
  • IT risk professionals
  • Security consultants og rådgivere
  • Compliance- og governance-ansvarlige
  • IT- og sikkerhetsansvarlige

Hva lærer jeg i løpet av kurset?
Du lærer hvordan cybersikkerhet kan revideres og vurderes i en virksomhet. Etter kurset vil du kunne:

  • Forstå revisjonsrollen innen cybersikkerhet
  • Evaluere governance, policyer og sikkerhetsrammeverk
  • Gjennomføre risikovurderinger og kontrollanalyser
  • Analysere trusler, sårbarheter og sikkerhetstiltak
  • Vurdere teknologier som nettverkssikkerhet, sky og IoT
  • Utføre tredjeparts- og leverandørrisikovurderinger

Hvilke temaer dekkes i kurset?
Kurset dekker blant annet:

  • Cybersecurity governance og rammeverk
  • Revisjonsprosesser og kontrollmekanismer
  • Trussel- og sårbarhetsstyring
  • Identitet og tilgangsstyring
  • Incident management og sikkerhetsoperasjoner
  • Teknologier som SIEM, cloud, IoT og nettverkssikkerhet

Får jeg sertifisering etter kurset?
Ja. Kurset inkluderer Cyber Security Audit Certificate-eksamen, som gjennomføres online etter kurset.

Hvilke forkunnskaper anbefales?
Det er ingen formelle krav, men grunnleggende forståelse for cybersikkerhet og erfaring fra IT eller sikkerhet er en fordel.

Hva gjør dette kurset unikt?
Kurset kombinerer revisjon, cybersikkerhet og risikostyring i én helhetlig opplæring. Det gir deg kompetansen til å evaluere sikkerhet på tvers av teknologi, prosesser og organisasjon.

Andre relevante kurs

19. mai
1 dager
Classroom Virtual
20. mai
3 dager
Classroom Virtual