Information Security Audit and Compliance
Auditing and governing information security: risk assessment, control frameworks, ISO 27001, the audit process, compliance regimes, and remediation.
- 60hours
- 30topics
- 10modules
Foundations of information security
The CIA triad, threats, and the language of security governance.
Start module- The CIA Triad and Security FundamentalsIntroduces confidentiality, integrity, and availability as the three pillars of information security and explains how each property is threatened and protected. Establishes the vocabulary used throughout security governance, audit, and compliance work.13 min
- The Threat Landscape and Threat ActorsSurveys the categories of threats facing modern organisations, from nation-state attackers and organised crime to insider risk and accidental disclosure. Examines how threat intelligence informs audit scope and control selection.13 min
- Security Governance Frameworks OverviewExplains the role of governance in information security, including accountability structures, policy hierarchies, and the relationship between boards, executives, and security teams. Provides context for understanding how audit and compliance programmes are authorised and overseen.13 min
Risk management and assessment
Identifying, assessing and treating information-security risk.
Start module- Risk Identification and Asset ClassificationCovers the first stage of risk management: cataloguing information assets, classifying them by sensitivity and criticality, and identifying threats and vulnerabilities that bear on each asset. Introduces asset inventories as a foundational audit artefact.13 min
- Risk Assessment MethodologiesCompares qualitative and quantitative risk assessment approaches, including likelihood-impact matrices, FAIR (Factor Analysis of Information Risk), and annualised loss expectancy calculations. Explains how each method supports different organisational contexts and audit objectives.13 min
- Risk Treatment and the Risk RegisterDescribes the four risk treatment options: accept, avoid, mitigate, and transfer, and explains how decisions are documented in a risk register. Covers risk ownership, residual risk, and the ongoing risk review cycle that feeds compliance programmes.13 min
Security controls and frameworks
NIST CSF, CIS Controls and how control catalogues are used.
Start module- The NIST Cybersecurity FrameworkExplains the structure of the NIST CSF, its five core functions (Identify, Protect, Detect, Respond, Recover), and how organisations use implementation tiers and profiles to tailor the framework. Covers the transition from CSF 1.1 to CSF 2.0 and the addition of the Govern function.13 min
- CIS Controls and Implementation GroupsSurveys the CIS Critical Security Controls, their prioritisation into Implementation Groups (IG1, IG2, IG3), and the supporting CIS Benchmarks for specific technologies. Explains how auditors use the Controls as a measurement baseline and gap-analysis tool.13 min
- Mapping Controls Across FrameworksDemonstrates how control catalogues such as NIST SP 800-53, ISO 27002, CIS Controls, and PCI-DSS requirements overlap and can be cross-mapped. Explains how a unified control mapping reduces audit duplication when an organisation must satisfy multiple compliance regimes simultaneously.13 min
ISO/IEC 27001 and the ISMS
The information security management system and certification.
Start module- ISO/IEC 27001: Standard Structure and RequirementsExplains the clause structure of ISO/IEC 27001:2022, covering the mandatory requirements from context of the organisation through management commitment, risk treatment, and continual improvement. Distinguishes normative requirements from the guidance in the companion standard ISO 27002.13 min
- Designing and Implementing an ISMSCovers the practical steps in establishing an Information Security Management System: defining scope, selecting and applying controls from Annex A, producing the Statement of Applicability, and aligning documentation to audit expectations. Addresses common implementation pitfalls and readiness indicators.13 min
- ISO/IEC 27001 Certification and Surveillance AuditsDescribes the three-year certification cycle, including Stage 1 (documentation review), Stage 2 (on-site certification audit), and the annual surveillance audits that maintain certification. Explains the role of accredited certification bodies and how nonconformities are classified and resolved.13 min
The security audit process
Planning, fieldwork, testing and evidence in a security audit.
Start module- Audit Planning and Scope DefinitionCovers the pre-engagement activities of a security audit: defining objectives and scope, understanding the audited environment, identifying key controls to test, and producing an audit plan. Explains how scope decisions shape resource requirements and the reliability of conclusions.13 min
- Fieldwork, Evidence Collection, and Control TestingExamines the fieldwork phase of a security audit, including interviews, document review, configuration inspection, and observation of processes. Explains standards for evidence sufficiency, chain of custody in an audit context, and how control effectiveness is evaluated against criteria.13 min
- Audit Sampling Techniques and Working PapersIntroduces statistical and judgement-based sampling methods used in security audits to draw conclusions about large populations of controls or transactions. Covers the structure and retention of working papers as the documented basis for audit opinions.13 min
Compliance regimes
GDPR, the Digital Personal Data Protection Act 2023, HIPAA and PCI-DSS.
Start module- GDPR: Core Principles and Audit ObligationsExplains the seven data-protection principles of the General Data Protection Regulation, the accountability requirement, and the documentation obligations that auditors examine. Covers lawful bases for processing, data subject rights, and the consequences of supervisory-authority enforcement actions.13 min
- India's Digital Personal Data Protection Act 2023Surveys the structure of India's DPDP Act 2023, including the rights of data principals, obligations of data fiduciaries, Significant Data Fiduciary designation, and the role of the Data Protection Board. Positions the Act within the global landscape of data-protection law and highlights audit implications.13 min
- HIPAA and PCI-DSS Compliance RequirementsCovers the HIPAA Security Rule's administrative, physical, and technical safeguard categories for protected health information, and the PCI-DSS twelve requirements for organisations that handle payment card data. Explains how auditors assess compliance with each regime and the distinct roles of qualified assessors.13 min
Governance, policy and assurance reports
Policy, governance structures and SOC 2 / assurance reporting.
Start module- Information Security Policy HierarchyDescribes the three-tier policy architecture of standards, policies, and procedures, and explains how each tier is authored, approved, and reviewed. Covers the audit tests used to verify that policies are current, communicated, and enforced in practice.13 min
- Security Governance Structures and RolesExamines the organisational structures that support security governance, including boards, audit committees, CISOs, and dedicated security steering groups. Explains three-lines-of-defence model and how responsibility for security oversight is allocated and evidenced in audit.13 min
- SOC Reports and Third-Party AssuranceExplains the AICPA SOC framework, distinguishing SOC 1 (financial-reporting controls) from SOC 2 (trust service criteria) and SOC 3 (public-facing summary). Covers Type I versus Type II reports, the criteria categories (Security, Availability, Confidentiality, Processing Integrity, Privacy), and how relying parties use these reports in their own compliance programmes.13 min
Technical assessment interface
How vulnerability assessment and testing feed the audit.
Start module- Vulnerability Assessment as Audit EvidenceExplains how the outputs of vulnerability scanning and assessment programmes feed into security audits as objective evidence of control effectiveness. Covers CVSS scoring, remediation prioritisation, and the auditor's role in interpreting scan results rather than replicating the scanner's work.13 min
- Penetration Testing Scope and Audit InterfaceDescribes the relationship between penetration testing engagements and the audit function, including how to commission, scope, and interpret a penetration test report without duplicating forensic or incident-response activities. References the /topics/cyber-forensics subject for technical mechanics and focuses on governance and evidence use.13 min
- Security Metrics and Continuous MonitoringCovers the design of key risk indicators (KRIs) and key performance indicators (KPIs) for security controls, and explains how continuous monitoring programmes provide ongoing assurance between point-in-time audits. Examines how SIEM outputs and automated compliance dashboards are evaluated by auditors.13 min
Third-party and supply-chain risk
Assessing vendors and managing supply-chain exposure.
Start module- Third-Party Risk Management ProgrammeExplains the lifecycle of third-party risk management, from initial due diligence and onboarding through periodic reassessment and offboarding, and the contractual and operational controls used at each stage. Covers vendor tiering by criticality and the documentation an auditor expects to find.13 min
- Vendor Security Questionnaires and AssessmentsSurveys the principal vendor assessment instruments, including standardised questionnaires (SIG, CAIQ) and on-site assessments, and explains their strengths and limitations as evidence of supplier controls. Discusses how organisations validate questionnaire responses and escalate unacceptable findings.13 min
- Supply-Chain Risk and Software DependenciesAddresses the security risks introduced by software supply chains, including open-source dependencies, SBOMs (Software Bills of Materials), and the audit controls that detect compromised or outdated components. Connects to the broader third-party risk programme and references incident-response preparedness at /topics/incident-response-and-management.13 min
Reporting, remediation and improvement
Findings, remediation tracking and continuous improvement.
Start module- Audit Report Structure and Communicating FindingsDescribes the standard components of a security audit report, from executive summary through detailed findings, risk ratings, and management responses. Explains how auditors communicate findings to different audiences and the principles of clear, evidence-backed reporting.13 min
- Remediation Tracking and Management Action PlansCovers the post-audit remediation cycle: issuing management action plans, assigning owners and deadlines, tracking closure evidence, and performing follow-up verification. Explains how unresolved findings are escalated and how recurring findings signal systemic control weaknesses.13 min
- Continuous Improvement and Audit Programme MaturityExplains how audit programmes evolve over time through lessons-learned reviews, maturity model assessments (such as CMMC tiers), and integration with enterprise risk management. Covers the metrics used to measure audit programme effectiveness and the role of internal audit in driving a culture of security improvement.13 min