Professional Course

Cybersecurity Risks from an Audit Manager’s Perspective

ACI Learning, In Worldwide
Length
2 days
Next course start
Inquire for dates and prices See details
Delivery
On-site
Length
2 days
Next course start
Inquire for dates and prices See details
Delivery
On-site

Course description

Cybersecurity Risks from an Audit Manager's Perspective

New regulations, increasing IT security threats and staff shortages challenge audit management to address the organization's IT risks. This course covers recent security breaches to put into perspective a strategy to help avoid devastating harm to the organization's reputation from these headline-making security breaches. This course provides working knowledge of IT terms and concepts; updates on new and emerging technologies affecting your business, and ways to establish a strategic response.

Do you work at this company and want to update this page?

Is there out-of-date information about your company or courses published here? Fill out this form to get in touch with us.

Upcoming start dates

1 start date available

Inquire for dates and prices

  • On-site
  • Worldwide

Who should attend?

Internal audit seniors, managers and senior managers involved with identifying, assessing and reporting on the technology-related risks for their internal audit projects or for the internal audit risk assessment

Prerequisites

  • Fundamentals of Internal Auditing - OAG101
  • Equivalent Experience

Training content

IT Risks:

  • update on recent security breaches
  • data breach commonalities
  • how hackers are hacking
  • IT risk definitions
  • information security objectives
  • IT audit engagement strategies
  • IT control categories

Basics of Information Technology - Battling the Buzzwords:

  • why learn about technology?
  • defining cyberspace & cybersecurity
  • Operating Systems (OS)
  • mainframe & client/server technology
  • middleware
  • virtualization / virtual servers
  • network environment

Logical Security Risks and Controls:

  • social media and social engineering
  • components of access control
  • user identification and authentication
  • authorization and user access controls
  • log management
  • patch management
  • vulnerability assessments
  • systems administrator / privileged access

Network Risks and Controls:

  • what is a “network”?
  • networking risks
  • LANs & WANs
  • network addressing
  • encryption
  • firewalls
  • Intrusion Detection Systems (IDS / IPS)
  • Virtual Private Networks (VPNs)
  • wireless
  • cloud computing

Database Risks and Controls:

  • Database Management Systems (DBMS)
  • database terminology
  • database risks
  • relational databases
  • database audit procedures

IT General Controls:

  • change management
  • business continuity / disaster recovery
  • physical security
  • environmental exposures

Auditing System Development Projects:

  • business risks
  • getting involved … how, when, who?
  • audit's coverage
  • auditing waterfall and RAD Projects
  • communicating audit's roles and results
  • audit staffing
  • audit resources

Assessing IT Governance:

  • what is IT governance?
  • IT governance risks
  • determining the IT governance audit scope
  • using COBIT® 2019 to assess IT governance

Audit and Control Frameworks and Standards:

  • IIA - Global Technology Audit Guides
  • COBIT®
  • ISO 27002 Security Standard
  • NIST Cybersecurity Framework
  • Center for Internet Security - 20 Critical Security Controls
  • FISMA (NIST 800-53) - Federal Information Security Modernization Act

Course delivery details

Bring this course to your organization at your convenience. ACI Learning can deliver this instructor-led course for your team at a chosen location or virtually. Alternatively, choose the topic(s) you need and ACI will craft a training solution to keep your team future-proof.

Certification / Credits

NASBA Certified CPE: 16 Credits Auditing

Information Security Certificate

What You'll learn

You will learn about a wide range of technologies, the challenges posed by technological change, and ways to provide assurance that IT risks are being adequately addressed.

ACI Learning

ACI Learning

At ACI Learning, we train leaders in Cybersecurity, Audit, and Information Technology. Whether you're starting your IT career, mastering your profession, or developing your team, we're with you every step of the way. We believe that training is not a...

Read more and show all training delivered by this supplier

Ads