0% found this document useful (0 votes)
12 views4 pages

Advanced Security Audit Training Course

The Advanced Security Course focuses on information security and cybersecurity, equipping auditors with the knowledge to assess and manage risks effectively. Over two days, participants will learn about various security topics, including identity and access management, operating system security, database security, web application security, and incident management. The course also covers current trends in cybersecurity, such as cloud computing and the Internet of Things, along with considerations for auditors.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views4 pages

Advanced Security Audit Training Course

The Advanced Security Course focuses on information security and cybersecurity, equipping auditors with the knowledge to assess and manage risks effectively. Over two days, participants will learn about various security topics, including identity and access management, operating system security, database security, web application security, and incident management. The course also covers current trends in cybersecurity, such as cloud computing and the Internet of Things, along with considerations for auditors.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Advanced Security Course

Information security and cybersecurity are topics that are an integral part
organizations and become a key issue for auditors. The latter
must understand the risks related to information security and the approaches to
audit these risks to ensure that the organization manages them properly.

Through presentations, discussions, and demonstrations, this course will enable...


auditors to develop an audit strategy for multiple security issues
information, especially the new challenges related to cyber security.

Participants will also be able to learn about the different tools used to make a
adequate assessment of the state of information security in organizations.

Course proposal
Duration: Two days
Knowledge: Intermediate
Prerequisites: None
Preparation: None
Delivery format: On-site seminar
Information Security, Advanced Elements

1
Reminder of the basic concepts of security
• Notions of informational assets
• Roles and responsibilities in information security
• Classification of information
• The role of humans in information protection
• Considerations for auditors

Identity and Access Management (IAM)

• The processes of the GIA


• The functional and logical architecture of the GIA
• The available tools
• The management of the GIA program with different models (RBAC, ABAC,
federations)
• Considerations for auditors

Security of operating systems and servers

• Types of operating systems and operation (Unix, Windows, Linux,


Android, etc.
• Vulnerabilities of operating systems
• Configuration
• Virtualization
• Considerations for auditors

Database Security

• Safe installation
• Security configuration
• Database security management
• Considerations for auditors

The security of WEB applications


• Web application architecture and logical separation of services
• Concept of a demilitarized zone
• Bastion concepts
• Classification of networks
• Server and client workstation security
• Main attacks on web applications
• WEB application controls and security and source code management
• Considerations for auditors

2
Security attacks
• Deni of services
• Enumeration
• The man in the middle
• SQL Injection
• Rootkits
• Etc.
• Considerations for auditors

Attack methodologies
• Attack Methods
• Non-destructive techniques and destructive techniques
• Examples of a network attack
• Tools used by hackers
• Vulnerabilities to check and detection by scanning tools
• Considerations for auditors

Network surveillance
• Attack Detection
• Performance tracking
• Management Metrics
• Diagnostic, monitoring, and performance tools
• Considerations for auditors

Incident Management - Advanced Elements

Wireless Networks and VoIP - Advanced Elements

• Protocols and models


• Authentication and encryption
• Ad-hoc and Rogue Networks
• Trojan AP
• Attacks on wireless networks (scanning, probing, active attacks, SSID, etc.)
• Considerations for auditors

Issues related to the Bring Your Own Device (BYOD) theme

Cloud Computing - Security Issues

The Internet of Things and security challenges


• Conceptual architecture of the Internet of Things
• Threats by Industry Type
• Security threat models

3
• The elements of management and protection
• Considerations for auditors

Cybersecurity
• Cyber attacks: examples
• Information security vs Cybersecurity
• Standards in Cybersecurity
ISO 27032
NIST Cybersecurity Framework
Other standards:
. COBIT
. ISO 27000 Family
• Concept of 'Red team', reconnaissance and 'Weaponization' and associated tools
(Directory, Metasploit, ZapProxy, PowerShell, etc)
• The concept of resilience
• After the discovery of an intrusion: improve incident management
• Develop a program that leads to resilience
• Create a digital resilience ecosystem
• Considerations for Auditors

Business continuity and succession plans


• The differences
• The stages of development
• The phases of maintenance
• Considerations for auditors

Current Events

• Evolution of malware (e.g.: Ransomware)


• The wake-up call of WannaCry
• Global threats

You might also like