Auditing Information Security
Auditing Information Security |
21 – 25 Apr. 2025 | Abu Dhabi | 07 – 11 July 2025 | Dubai | 10 – 14 Nov. 2025 | Abu Dhabi |
Course Objectives:
By the end of this course, participants will:
- Understand the principles, frameworks, and standards for auditing information security systems.
- Gain the skills to evaluate an organization’s information security posture against regulatory requirements and best practices.
- Learn to identify vulnerabilities, gaps, and risks in information security controls and processes.
- Develop proficiency in auditing security policies, access controls, and incident response plans.
- Prepare actionable audit reports to recommend improvements in information security governance.
Course Syllabus:
Day 1: Foundations of Information Security Auditing
- Introduction to Information Security Auditing
- Audit Frameworks and Standards
- Audit Planning and Preparation
- Workshop: Developing an Information Security Audit Plan
Day 2: Assessing Security Controls and Processes
- Evaluating Security Policies and Procedures
- Auditing Access Controls
- Auditing Network and System Security
- Practical Exercise: Conducting an Audit of Access and Network Controls
Day 3: Incident Response, Reporting, and Improvement
- Auditing Incident Response Plans
- Risk Assessment and Mitigation Planning
- Reporting and Presenting Audit Findings
- Capstone Project: Conducting a Mock Information Security Audit