Cyber Security for IT Auditors and Assurance Teams Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-007
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

IT auditors and assurance teams are expected to provide defensible conclusions on cyber risk, yet many audits still rely on high-level policy checks, informal interviews and incomplete evidence. This course addresses the gap between understanding security concepts and testing whether controls actually operate. Participants learn to translate threats such as ransomware, credential compromise, cloud misconfiguration and third-party exposure into audit objectives, control tests, evidence requests and findings that risk committees can act on.

The course covers cyber governance, risk assessment, identity and access management, vulnerability management, incident response, cloud security, logging, supplier assurance and security metrics. Participants practise scoping cyber audits using NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022, building risk-and-control matrices, selecting samples, testing control design and operating effectiveness, evaluating technical evidence, and writing findings with clear risk statements, root causes and practical remediation actions. They also learn where assurance work should challenge management claims rather than duplicate operational security testing.

Delivery combines instructor-led explanations with evidence packs, audit working-paper exercises, group challenge sessions and a realistic cyber assurance case. Participants use sample access reviews, vulnerability reports, incident records, cloud configuration extracts and supplier evidence to form audit conclusions. Each participant leaves with a reusable cyber audit planning pack containing a risk assessment, audit programme, control test sheets, evidence checklist, findings template and a 90-day application plan for an upcoming assignment.

The programme suits auditors who already conduct IT, operational, compliance or internal audits and need stronger cyber assurance capability. It is equally relevant to managers responsible for increasing audit coverage of cyber risk without turning their assurance function into a penetration-testing team.

Course objectives

By the end of this course, participants will be able to:

  • Map cyber risks to auditable control objectives using NIST Cybersecurity Framework 2.0 categories and outcomes
  • Build a cyber audit risk-and-control matrix covering governance, identity, vulnerability, incident and supplier controls
  • Define audit scope, materiality criteria and evidence requirements for a risk-based cyber assurance engagement
  • Test the design and operating effectiveness of privileged-access, access-review and joiner-mover-leaver controls
  • Evaluate vulnerability management evidence including scan coverage, remediation ageing, exceptions and risk acceptance
  • Assess incident response capability through timeline analysis, tabletop evidence and post-incident corrective actions
  • Document evidence, sampling rationale and control conclusions in defensible audit working papers
  • Write prioritised cyber audit findings with root cause, risk impact, agreed action owners and target dates

Benefits of attending

For you

  • Gain a repeatable method for converting cyber threats into auditable risks, controls and test procedures
  • Strengthen credibility when challenging security teams on evidence quality, exceptions and remediation claims
  • Produce workpapers and findings that meet internal audit, risk committee and external assurance expectations
  • Broaden eligibility for technology risk, cyber assurance and IT audit assignments
  • Develop the confidence to assess technical reports without needing to operate security tools as an engineer

For your organisation

  • Improve the consistency of cyber audit scopes, control testing and evidence standards across assurance engagements
  • Identify weaknesses in identity, vulnerability, incident and supplier controls before they become material exposures
  • Give audit committees clearer reporting on cyber-control effectiveness, residual risk and overdue remediation
  • Reduce reliance on unstructured policy-based reviews by using risk-and-control matrices and testable criteria
  • Create reusable audit programmes and evidence checklists that shorten preparation time for future cyber audits

Target competencies

Cyber risk scopingControl effectiveness testingTechnical evidence evaluationAccess control assuranceIncident response auditingAudit finding writing

Who should attend

  • IT Auditors — who need to test cyber controls beyond policy and procedure reviews
  • Internal Auditors — who are expanding audit plans to cover technology and cyber risk
  • Technology Risk Auditors — who need consistent methods for evaluating control design and effectiveness
  • Information Security Assurance Analysts — who validate security control operation for governance or compliance reporting
  • Risk and Compliance Managers — who need to challenge cyber-control evidence and track remediation
  • External Audit and Assurance Professionals — who evaluate IT-dependent controls and cyber-related risk exposures

Requirements and prerequisites

Participants should have practical experience of IT audit, internal audit, risk, compliance or information security assurance, including familiarity with audit planning, evidence collection, sampling and reporting. They should understand basic IT concepts such as networks, operating systems, user accounts, cloud services, backups and change management. Familiarity with spreadsheets is expected because exercises use audit workpapers and evidence analysis in Microsoft Excel. Prior use of ServiceNow GRC, vulnerability scanners or security information and event management platforms is helpful but not required. This is not a penetration-testing, digital forensics or security-engineering course; coding, exploit development and command-line administration are not required.

Training methodology

The instructor uses short, focused teaching sessions to establish audit criteria, followed by hands-on review of realistic evidence: access listings, vulnerability dashboards, incident tickets, cloud configuration extracts and supplier assurance reports. Participants work individually and in small audit teams to create test steps, define samples, challenge incomplete evidence and calibrate findings. A running case study links each day’s control domain to one cyber audit file. On the final day, participants assemble their working papers into a practical audit pack and identify how they will apply it to a live or planned engagement.

Course outline

Day 1: Cyber risk, governance and audit scoping

  • Cyber threat scenarios and their impact on audit objectives
  • NIST Cybersecurity Framework 2.0 functions and audit use
  • ISO/IEC 27001:2022 control themes and assurance criteria
  • Cyber governance roles across boards, management and security teams
  • Risk appetite, risk acceptance and escalation evidence
  • Risk-based audit universe and annual cyber audit planning
  • Cyber audit scope statements, objectives and exclusion boundaries

Workshop: Participants build a cyber risk assessment and scoped audit objective set for a fictional organisation facing ransomware and cloud-security exposure.

Day 2: Identity, access and technology control testing

  • Identity lifecycle controls for joiners, movers and leavers
  • Privileged access management control objectives and evidence
  • User access recertification design and operating-effectiveness testing
  • Segregation of duties conflicts and compensating controls
  • Multi-factor authentication coverage and exception governance
  • Logging, monitoring and retention requirements for assurance
  • Sampling methods for access populations and audit trail testing

Workshop: Participants test a privileged-access review using a user population, approval records and exception log, then draft a working-paper conclusion.

Day 3: Vulnerability, configuration and cloud assurance

  • Vulnerability management lifecycle from discovery to remediation
  • Interpreting CVSS scores, asset criticality and remediation ageing
  • Scanner coverage, authenticated scans and asset inventory reconciliation
  • Patch-management exceptions and risk-acceptance evidence
  • Secure configuration baselines and configuration drift testing
  • Cloud shared-responsibility models and audit implications
  • Cloud identity, storage and network configuration evidence

Workshop: Participants analyse a vulnerability report and cloud configuration extract to identify testing gaps, calculate overdue exposure and formulate findings.

Day 4: Incident, resilience and third-party cyber assurance

  • Incident response plans, playbooks and role-accountability testing
  • Incident timeline reconstruction from tickets, logs and communications
  • Tabletop exercise evidence and lessons-learned validation
  • Backup, recovery and ransomware-resilience assurance procedures
  • Security requirements in supplier contracts and service agreements
  • Evaluating SOC 2 reports, ISO certificates and supplier questionnaires
  • Third-party risk monitoring, breach notification and exit controls

Workshop: Audit teams assess an incident file and a critical supplier evidence pack, producing test conclusions and prioritised assurance questions.

Day 5: Reporting defensible cyber assurance conclusions

  • Evaluating control design versus operating effectiveness
  • Triangulating interviews, documents, system extracts and observations
  • Root-cause analysis using the five whys and control failure patterns
  • Risk rating findings using likelihood, impact and compensating controls
  • Writing concise finding statements, causes, effects and recommendations
  • Management action plans, owners, dates and remediation validation
  • Cyber audit dashboards and reporting for audit committees

Workshop: Participants complete a capstone cyber audit pack, present two findings to a mock audit committee and create a 90-day application plan.

Tools & standards covered

NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, ServiceNow GRC, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course is designed for auditors and assurance professionals who need to assess cyber controls, not exploit systems or configure security technology. You should understand core IT concepts and have some experience gathering audit evidence or evaluating controls.

A laptop with Microsoft Excel or equivalent spreadsheet software is recommended for the working-paper exercises. The course uses realistic extracts from tools such as ServiceNow GRC and vulnerability scanners, but participants do not need access to a live corporate environment.

It is best suited to IT auditors, internal auditors, technology risk professionals, compliance managers and security assurance staff. It is particularly useful for people moving from general IT controls into risk-based cyber assurance work.

The focus is on auditability: defining control objectives, obtaining reliable evidence, testing effectiveness and reporting assurance conclusions. Technical security courses teach how to configure or defend systems; this course teaches how to assess whether those activities are governed and operating properly.

Participants receive templates for cyber risk assessment, audit planning, evidence requests, control testing and findings. These can be adapted to an upcoming audit of access management, vulnerability management, incident response, cloud services or third-party security.

You leave with a completed cyber audit planning pack built through the course case study, including a risk-and-control matrix, audit programme, test sheets, evidence checklist and sample findings. You also create a 90-day plan for applying the approach within your own assurance portfolio.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 05 – 09 Oct 2026
    Nairobi · USD 3,000
    Book
  • 12 – 16 Oct 2026
    Nairobi · USD 3,000
    Book
  • 19 – 23 Oct 2026
    Kigali · USD 3,500
    Book
  • 26 – 30 Oct 2026
    Nairobi · USD 3,000
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 02 – 06 Nov 2026
    Nairobi · USD 3,000
    Book
  • 02 – 06 Nov 2026
    Live Online · USD 1,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

PCI DSS v4.0 Payment Card Security Compliance Training Course

Payment card environments are difficult to secure because cardholder data can move across payment applications, e-commerce pages, call-centr…

5 Days Certificate

Advanced Digital Forensics and Malware Analysis Training Course

Security teams need investigators who can move beyond collecting files and alerts to reconstructing an intrusion, establish what executed, i…

5 Days Certificate

OWASP Application Security Verification Standard Implementation Training Course

Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…

5 Days Certificate

Secure Coding and Cyber Security for Software Developers Training Course

Software developers are increasingly expected to prevent security defects before code reaches production, yet many teams still discover inje…