Advanced Security Audit Training Course
Advanced Security Audit Training Course
Information security and cybersecurity are topics that are an integral part
organizations and become a key issue for auditors. The latter
must understand the risks related to information security and the approaches to
audit these risks to ensure that the organization manages them properly.
Participants will also be able to learn about the different tools used to make a
adequate assessment of the state of information security in organizations.
Course proposal
Duration: Two days
Knowledge: Intermediate
Prerequisites: None
Preparation: None
Delivery format: On-site seminar
Information Security, Advanced Elements
1
Reminder of the basic concepts of security
• Notions of informational assets
• Roles and responsibilities in information security
• Classification of information
• The role of humans in information protection
• Considerations for auditors
Database Security
• Safe installation
• Security configuration
• Database security management
• Considerations for auditors
2
Security attacks
• Deni of services
• Enumeration
• The man in the middle
• SQL Injection
• Rootkits
• Etc.
• Considerations for auditors
Attack methodologies
• Attack Methods
• Non-destructive techniques and destructive techniques
• Examples of a network attack
• Tools used by hackers
• Vulnerabilities to check and detection by scanning tools
• Considerations for auditors
Network surveillance
• Attack Detection
• Performance tracking
• Management Metrics
• Diagnostic, monitoring, and performance tools
• Considerations for auditors
3
• The elements of management and protection
• Considerations for auditors
Cybersecurity
• Cyber attacks: examples
• Information security vs Cybersecurity
• Standards in Cybersecurity
ISO 27032
NIST Cybersecurity Framework
Other standards:
. COBIT
. ISO 27000 Family
• Concept of 'Red team', reconnaissance and 'Weaponization' and associated tools
(Directory, Metasploit, ZapProxy, PowerShell, etc)
• The concept of resilience
• After the discovery of an intrusion: improve incident management
• Develop a program that leads to resilience
• Create a digital resilience ecosystem
• Considerations for Auditors
Current Events