Cybersecurity Audit Evidence for Information Security Auditors Training Course

5 days Auditing Certificate on completion
Course codeSD-A-059
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Information security auditors are expected to substantiate conclusions about access control, logging, vulnerability management, change control, incident response, and third-party risk with evidence that is reliable, sufficient, and traceable. Weak evidence collection creates audit rework, disputed findings, unsupported control ratings, and delays in closing financial, regulatory, and customer assurance commitments. This course addresses the practical challenge of converting technical records and stakeholder interviews into defensible audit evidence that can withstand management, external auditor, and regulator scrutiny.

Participants learn to plan evidence requests, define audit criteria, map controls to risks, assess evidence quality, test samples, and document results in workpapers. The course uses information-security scenarios involving privileged access reviews, security-event logs, vulnerability scan results, change tickets, backup testing, supplier assessments, and incident records. Participants practise applying ISO/IEC 27001:2022 and NIST SP 800-53 control expectations, distinguishing design effectiveness from operating effectiveness, and writing findings with clear condition, criteria, cause, risk, and recommendation statements.

Delivery combines instructor-led demonstrations, guided evidence-review labs, audit-planning workshops, and case-based group critique. Participants work through a simulated audit of a business system and build a usable audit evidence pack: risk-control matrix, evidence request list, sampling plan, test scripts, annotated workpapers, finding register, and management reporting summary. The completed pack provides a structured template that can be adapted for internal audits, customer assurance reviews, and technology-control audits.

The course is designed for auditors who already understand core information-security controls and need stronger evidence-testing discipline. It also suits assurance professionals working alongside IT, risk, compliance, finance controls, and external audit teams where cyber-control conclusions affect organisational reporting and assurance decisions.

Course objectives

By the end of this course, participants will be able to:

  • Develop a risk-based audit evidence plan linking business risks, control objectives, criteria, and required artefacts
  • Construct a risk-control matrix for identity, logging, vulnerability, change, incident, and supplier security controls
  • Evaluate evidence reliability using source, timeliness, completeness, authenticity, and corroboration criteria
  • Design sampling approaches for user access reviews, change records, vulnerability remediation, and security-event evidence
  • Test control design and operating effectiveness using documented walkthroughs, reperformance, inspection, and inquiry procedures
  • Document audit tests in traceable workpapers with population details, sample rationale, exceptions, and reviewer-ready conclusions
  • Write information-security audit findings using condition, criteria, cause, consequence, risk rating, and corrective-action ownership
  • Produce a management-ready audit evidence pack containing requests, test scripts, workpapers, findings, and follow-up actions

Benefits of attending

For you

  • Build confidence challenging incomplete or unreliable security-control evidence before it reaches audit review
  • Create workpapers and test scripts that demonstrate a repeatable information-security audit approach
  • Improve credibility with control owners by making evidence requests precise, relevant, and proportionate
  • Gain practical language for distinguishing control design gaps from failures in control operation
  • Develop a portfolio-quality audit evidence pack that can support progression into IT audit, cyber assurance, or GRC roles

For your organisation

  • Reduce audit rework by standardising evidence requests, sampling rationales, workpapers, and review trails
  • Improve the quality and consistency of conclusions on critical cybersecurity controls
  • Identify evidence gaps before external audits, customer assessments, or regulatory examinations expose them
  • Produce clearer remediation actions by linking findings to control criteria, business risk, and accountable owners
  • Strengthen coordination between information security, internal audit, IT operations, risk, compliance, and finance assurance teams

Target competencies

Evidence quality assessmentRisk-control mappingAudit sampling designControl effectiveness testingWorkpaper documentationFinding formulation

Who should attend

  • Information Security Auditors — who need to support control conclusions with reliable, reviewable evidence
  • IT Internal Auditors — who test technology controls affecting financial reporting, operations, and regulatory assurance
  • Cybersecurity Assurance Analysts — who gather and assess evidence for security-control reviews and customer assessments
  • GRC Analysts — who maintain control mappings and need to validate that control evidence proves operation
  • IT Risk Managers — who challenge control owners and require evidence-based risk treatment decisions
  • External Audit Technology Specialists — who evaluate IT-dependent controls and coordinate evidence with internal teams

Requirements and prerequisites

Participants should have practical familiarity with information-security controls such as user access management, logging and monitoring, vulnerability management, change management, incident response, and supplier assurance. They should understand basic audit concepts, including audit criteria, control objectives, evidence, testing, exceptions, and findings, and be comfortable reviewing spreadsheets, tickets, reports, and policy documents. Experience with an audit, risk, compliance, security operations, or IT controls role is expected. Participants do not need to be penetration testers, digital forensics specialists, programmers, or certified ISO auditors. No prior ServiceNow GRC configuration or advanced Excel capability is required.

Training methodology

The instructor uses short technical briefings followed by evidence-review labs built around a simulated business application audit. Participants inspect access listings, ticket exports, vulnerability reports, log extracts, policies, supplier records, and incident documentation; then decide what evidence is sufficient and how to corroborate it. Small groups develop test procedures, select samples, record exceptions, and challenge one another's conclusions in reviewer-style discussions. Each day adds components to an individual audit evidence pack. The final session includes a management-reporting exercise and an application plan for a current or forthcoming audit.

Course outline

Day 1: Audit evidence foundations and planning

  • Audit assertions, control objectives, and information-security risk statements
  • ISO/IEC 27001:2022 control evidence expectations
  • NIST SP 800-53 control assessment concepts
  • Risk-based scoping for information-security audits
  • Risk-control matrix construction and control ownership mapping
  • Evidence request lists and artefact inventories
  • Evidence sufficiency, appropriateness, and traceability criteria

Workshop: Participants build a risk-control matrix and prioritised evidence request list for a simulated customer-facing business application.

Day 2: Testing identity, access, and change controls

  • Joiner-mover-leaver evidence for user lifecycle controls
  • Privileged access review testing and recertification evidence
  • Segregation of duties analysis for administrative accounts
  • System-generated access listings and population completeness checks
  • Change ticket inspection and approval traceability
  • Emergency change evidence and retrospective review testing
  • Walkthrough, inquiry, inspection, and reperformance procedures

Workshop: Participants test a sample of privileged accounts and production changes, documenting exceptions in reviewer-ready workpapers.

Day 3: Testing monitoring, vulnerability, and incident evidence

  • Security logging coverage and log-retention evidence
  • SIEM alert triage records and investigation trails
  • Vulnerability scan report validation and asset population reconciliation
  • Risk-based remediation timelines and exception approvals
  • Patch deployment evidence and compensating controls
  • Incident response records, lessons learned, and escalation evidence
  • Corroborating technical reports with tickets, timestamps, and interviews

Workshop: Participants assess a vulnerability remediation and incident-response evidence set, then prepare a tested-control conclusion.

Day 4: Sampling, workpapers, and audit findings

  • Attribute sampling for recurring security controls
  • Judgmental sampling for high-risk access and change populations
  • Population validation and sample selection documentation
  • Microsoft Excel techniques for filtering, reconciling, and exception tracking
  • Workpaper indexing, cross-referencing, and audit trail discipline
  • Design effectiveness versus operating effectiveness conclusions
  • Condition-criteria-cause-consequence finding construction

Workshop: Participants create a documented sampling plan, analyse an evidence export in Excel, and draft two evidence-supported audit findings.

Day 5: Reporting, remediation, and evidence-pack delivery

  • Risk rating methods for information-security audit findings
  • Root-cause analysis with control owners
  • Corrective action design and measurable remediation milestones
  • Management action plans and evidence of closure
  • ServiceNow GRC issues and remediation workflow concepts
  • Executive reporting of control assurance and residual risk
  • Quality review checklist for audit evidence packs

Workshop: Participants complete and present an audit evidence pack with findings, remediation actions, and an executive summary for management challenge.

Tools & standards covered

ISO/IEC 27001:2022, NIST SP 800-53, Microsoft Excel, ServiceNow GRC

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand common security controls and basic audit terminology, and have some exposure to IT audit, cyber assurance, GRC, risk, compliance, or security operations. The course builds evidence-testing capability rather than teaching cybersecurity fundamentals from scratch.

A laptop is recommended for the spreadsheet-based evidence and workpaper exercises. No specialist software licence is required; course materials use representative exports and demonstrate how Excel and ServiceNow GRC-style records support audit evidence.

Yes. It is designed for internal auditors who need to test information-security controls and for security or GRC professionals who provide and assess audit evidence. Discussions focus on the point where technical artefacts must become defensible assurance conclusions.

This course concentrates on the mechanics of audit evidence: requests, population validation, sampling, test scripts, workpapers, exceptions, and findings. It uses ISO/IEC 27001:2022 as an audit criterion but does not focus on running a full certification audit programme.

You can apply the risk-control matrix, evidence request list, sampling template, workpaper structure, and finding format directly to access, logging, vulnerability, change, incident, or supplier control reviews. The methods also help you challenge evidence supplied by control owners before formal testing begins.

You leave with a completed simulated audit evidence pack containing a risk-control matrix, evidence requests, test procedures, sampling rationale, annotated workpapers, findings, and remediation tracking approach. You also receive a certificate of completion.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

COBIT 2019 Control Assessment for IT Auditors Training Course

IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and p…

5 Days Certificate

ISACA ITAF Audit Framework Application Training Course

Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…

5 Days Certificate

Advanced Audit Planning and Evidence Evaluation Training Course

Audit teams are increasingly expected to justify why each planned procedure addresses a defined risk, how evidence supports the audit conclu…

5 Days Certificate

Audit Committee Oversight and Assurance Training Course

Audit committee members are expected to challenge financial reporting, internal control, external audit quality and risk information without…