|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/how-to-perform-an-information-security-audit/
课程评论:没有评论
课程名称:如何进行信息安全审计 课程概述: 本课程旨在教授学员如何开展信息安全审计,适合IT和信息安全专业人士、审计师以及其他想要深入了解信息安全审计的评估人员。课程内容涵盖了信息安全审计的各个方面,包括审计的计划、执行和结果报告,让学员掌握必要的知识和工具。主要授课者为Adrian Resag,他是一位经验丰富、获得CISA认证的信息安全审计师,拥有数十年的信息安全、IT和ISO 27001评估经验。 课程内容: 1. 执行信息安全审计:掌握如何规划审计,包括确定目标、标准和范围,学习如何创建工作文件以记录审计过程,并了解审计人员的配置方式。 2. 进行审计:学习信息收集的方法以及如何分析和评估数据,掌握如何监督审计过程。 3. 结果沟通与进展跟踪:学习如何沟通审计结果,以及如何接受风险的过程,掌握内部审计建议的实施进展监控。 4. 信息安全威胁与控制:了解需要评估的主要信息安全威胁,包括数据完整性、保密性和可用性威胁,能够评估隐私风险、智能设备风险、内部威胁、非法软件威胁和网络安全威胁等。同时,掌握评估风险的资产-威胁-脆弱性三角模型。 5. 信息安全控制:了解不同类型的信息安全控制,包括IT一般控制,实施信息安全治理,落实IT管理与治理控制,实施IT职责分离、部门化、信息安全框架以及网络安全治理与政策。学习应用网络安全中的“三道防线”模型,掌握身份访问管理、认证、加密、防火墙、数据隐私与保护控制等技术。 本课程通过实用的案例和丰富的经验分享,帮助学员在信息安全审计领域建立扎实的知识基础和实践能力。
We are glad to bring you a course to learn how to perform information security audits. This course is ideal for:IT and information security professionals who wish to learn techniques on how to assess the security of their information and the vulnerability of their information systems; and Auditors or others performing assessments who wish to learn more about performing information security audits. The course will give you the knowledge and tools necessary to perform information security audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place. It is taught by Adrian Resag, an experienced and CISA certified information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations. The course covers:Performing Information Security AuditsPlanning EngagementsUnderstand how to properly plan engagements by determining their objectives, criteria and scope. Know how to create working papers to document an audit and learn about different ways to staff an audit. Performing EngagementsLearn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements. Communicating Progress and ResultsLearn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations. Information Security Threats and ControlsThreats to information securityKnow about which threats to information security should be assessed, including threats to the integrity of data, confidentiality and the availability of data. Be able to evaluate privacy risks, risks from smart devices, insider threats, illicit software threats and cybersecurity threats amongst others. Be able to evaluate risks by using the Asset-Threat-Vulnerability triangle. Controls over information securityKnow about the different types of information security controls, including IT general controls. Be able to put in place a solid governance over information security, such as by putting in place IT management and governance controls. Be able to implement the segregation of IT duties and IT departmentalization, an information security framework and cybersecurity governance and policies. Be able to apply the Three Lines of Defense Model in cybersecurity. Learn about controls such as identity access management and authentication, encryption and firewalls, data privacy and protection controls. Know about application and access controls, technical IT infrastructure controls, external connections controls and 3rd party information security controls.