Cybersecurity Audit Evidence for Information Security Auditors Training Course
| Course code | SD-A-059 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Information security auditors are expected to substantiate conclusions about access control, logging, vulnerability management, change control, incident response, and third-party risk with evidence that is reliable, sufficient, and traceable. Weak evidence collection creates audit rework, disputed findings, unsupported control ratings, and delays in closing financial, regulatory, and customer assurance commitments. This course addresses the practical challenge of converting technical records and stakeholder interviews into defensible audit evidence that can withstand management, external auditor, and regulator scrutiny.
Participants learn to plan evidence requests, define audit criteria, map controls to risks, assess evidence quality, test samples, and document results in workpapers. The course uses information-security scenarios involving privileged access reviews, security-event logs, vulnerability scan results, change tickets, backup testing, supplier assessments, and incident records. Participants practise applying ISO/IEC 27001:2022 and NIST SP 800-53 control expectations, distinguishing design effectiveness from operating effectiveness, and writing findings with clear condition, criteria, cause, risk, and recommendation statements.
Delivery combines instructor-led demonstrations, guided evidence-review labs, audit-planning workshops, and case-based group critique. Participants work through a simulated audit of a business system and build a usable audit evidence pack: risk-control matrix, evidence request list, sampling plan, test scripts, annotated workpapers, finding register, and management reporting summary. The completed pack provides a structured template that can be adapted for internal audits, customer assurance reviews, and technology-control audits.
The course is designed for auditors who already understand core information-security controls and need stronger evidence-testing discipline. It also suits assurance professionals working alongside IT, risk, compliance, finance controls, and external audit teams where cyber-control conclusions affect organisational reporting and assurance decisions.
Course objectives
By the end of this course, participants will be able to:
- Develop a risk-based audit evidence plan linking business risks, control objectives, criteria, and required artefacts
- Construct a risk-control matrix for identity, logging, vulnerability, change, incident, and supplier security controls
- Evaluate evidence reliability using source, timeliness, completeness, authenticity, and corroboration criteria
- Design sampling approaches for user access reviews, change records, vulnerability remediation, and security-event evidence
- Test control design and operating effectiveness using documented walkthroughs, reperformance, inspection, and inquiry procedures
- Document audit tests in traceable workpapers with population details, sample rationale, exceptions, and reviewer-ready conclusions
- Write information-security audit findings using condition, criteria, cause, consequence, risk rating, and corrective-action ownership
- Produce a management-ready audit evidence pack containing requests, test scripts, workpapers, findings, and follow-up actions
Benefits of attending
For you
- Build confidence challenging incomplete or unreliable security-control evidence before it reaches audit review
- Create workpapers and test scripts that demonstrate a repeatable information-security audit approach
- Improve credibility with control owners by making evidence requests precise, relevant, and proportionate
- Gain practical language for distinguishing control design gaps from failures in control operation
- Develop a portfolio-quality audit evidence pack that can support progression into IT audit, cyber assurance, or GRC roles
For your organisation
- Reduce audit rework by standardising evidence requests, sampling rationales, workpapers, and review trails
- Improve the quality and consistency of conclusions on critical cybersecurity controls
- Identify evidence gaps before external audits, customer assessments, or regulatory examinations expose them
- Produce clearer remediation actions by linking findings to control criteria, business risk, and accountable owners
- Strengthen coordination between information security, internal audit, IT operations, risk, compliance, and finance assurance teams
Target competencies
Who should attend
- Information Security Auditors — who need to support control conclusions with reliable, reviewable evidence
- IT Internal Auditors — who test technology controls affecting financial reporting, operations, and regulatory assurance
- Cybersecurity Assurance Analysts — who gather and assess evidence for security-control reviews and customer assessments
- GRC Analysts — who maintain control mappings and need to validate that control evidence proves operation
- IT Risk Managers — who challenge control owners and require evidence-based risk treatment decisions
- External Audit Technology Specialists — who evaluate IT-dependent controls and coordinate evidence with internal teams
Requirements and prerequisites
Participants should have practical familiarity with information-security controls such as user access management, logging and monitoring, vulnerability management, change management, incident response, and supplier assurance. They should understand basic audit concepts, including audit criteria, control objectives, evidence, testing, exceptions, and findings, and be comfortable reviewing spreadsheets, tickets, reports, and policy documents. Experience with an audit, risk, compliance, security operations, or IT controls role is expected. Participants do not need to be penetration testers, digital forensics specialists, programmers, or certified ISO auditors. No prior ServiceNow GRC configuration or advanced Excel capability is required.
Training methodology
The instructor uses short technical briefings followed by evidence-review labs built around a simulated business application audit. Participants inspect access listings, ticket exports, vulnerability reports, log extracts, policies, supplier records, and incident documentation; then decide what evidence is sufficient and how to corroborate it. Small groups develop test procedures, select samples, record exceptions, and challenge one another's conclusions in reviewer-style discussions. Each day adds components to an individual audit evidence pack. The final session includes a management-reporting exercise and an application plan for a current or forthcoming audit.
Course outline
Day 1: Audit evidence foundations and planning
- Audit assertions, control objectives, and information-security risk statements
- ISO/IEC 27001:2022 control evidence expectations
- NIST SP 800-53 control assessment concepts
- Risk-based scoping for information-security audits
- Risk-control matrix construction and control ownership mapping
- Evidence request lists and artefact inventories
- Evidence sufficiency, appropriateness, and traceability criteria
Workshop: Participants build a risk-control matrix and prioritised evidence request list for a simulated customer-facing business application.
Day 2: Testing identity, access, and change controls
- Joiner-mover-leaver evidence for user lifecycle controls
- Privileged access review testing and recertification evidence
- Segregation of duties analysis for administrative accounts
- System-generated access listings and population completeness checks
- Change ticket inspection and approval traceability
- Emergency change evidence and retrospective review testing
- Walkthrough, inquiry, inspection, and reperformance procedures
Workshop: Participants test a sample of privileged accounts and production changes, documenting exceptions in reviewer-ready workpapers.
Day 3: Testing monitoring, vulnerability, and incident evidence
- Security logging coverage and log-retention evidence
- SIEM alert triage records and investigation trails
- Vulnerability scan report validation and asset population reconciliation
- Risk-based remediation timelines and exception approvals
- Patch deployment evidence and compensating controls
- Incident response records, lessons learned, and escalation evidence
- Corroborating technical reports with tickets, timestamps, and interviews
Workshop: Participants assess a vulnerability remediation and incident-response evidence set, then prepare a tested-control conclusion.
Day 4: Sampling, workpapers, and audit findings
- Attribute sampling for recurring security controls
- Judgmental sampling for high-risk access and change populations
- Population validation and sample selection documentation
- Microsoft Excel techniques for filtering, reconciling, and exception tracking
- Workpaper indexing, cross-referencing, and audit trail discipline
- Design effectiveness versus operating effectiveness conclusions
- Condition-criteria-cause-consequence finding construction
Workshop: Participants create a documented sampling plan, analyse an evidence export in Excel, and draft two evidence-supported audit findings.
Day 5: Reporting, remediation, and evidence-pack delivery
- Risk rating methods for information-security audit findings
- Root-cause analysis with control owners
- Corrective action design and measurable remediation milestones
- Management action plans and evidence of closure
- ServiceNow GRC issues and remediation workflow concepts
- Executive reporting of control assurance and residual risk
- Quality review checklist for audit evidence packs
Workshop: Participants complete and present an audit evidence pack with findings, remediation actions, and an executive summary for management challenge.
Tools & standards covered
ISO/IEC 27001:2022, NIST SP 800-53, Microsoft Excel, ServiceNow GRC
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
COBIT 2019 Control Assessment for IT Auditors Training Course
IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…
ISACA ITAF Audit Framework Application Training Course
Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…
Advanced Audit Planning and Evidence Evaluation Training Course
Audit teams are increasingly expected to justify why each planned procedure addresses a defined risk, how evidence supports the audit conclu…
Audit Committee Oversight and Assurance Training Course
Audit committee members are expected to challenge financial reporting, internal control, external audit quality and risk information without…