Packt
IT & Cloud Audit Masterclass – Fundamentals to Advanced
Packt

IT & Cloud Audit Masterclass – Fundamentals to Advanced

包含在 Coursera Plus

深入了解一个主题并学习基础知识。
中级 等级

推荐体验

3 周 完成
在 10 小时 一周
灵活的计划
自行安排学习进度
深入了解一个主题并学习基础知识。
中级 等级

推荐体验

3 周 完成
在 10 小时 一周
灵活的计划
自行安排学习进度

您将学到什么

  • Conduct IT and cloud security audits, identifying risks and compliance gaps.

  • Apply major cybersecurity frameworks like NIST, ISO 27001, and CIS.

  • Perform technical audits, including access control testing and vulnerability assessments.

  • Implement IT governance, risk management, and compliance best practices.

要了解的详细信息

可分享的证书

添加到您的领英档案

最近已更新!

April 2025

作业

30 项作业

授课语言:英语(English)

了解顶级公司的员工如何掌握热门技能

Petrobras, TATA, Danone, Capgemini, P&G 和 L'Oreal 的徽标

该课程共有29个模块

In this module, we will introduce the fundamental concepts of cybersecurity audits, distinguishing between cybersecurity and information security. We will explore key principles that drive secure data management and examine how cybersecurity integrates within an organization's structure to enhance defense mechanisms.

涵盖的内容

6个视频1篇阅读材料

In this module, we will explore the different types of IT audits and their role in assessing information systems security. We will examine the responsibilities of internal and external auditors, gain insight into cybersecurity audits, and learn how to conduct an effective cybersecurity audit.

涵盖的内容

8个视频1个作业1个插件

In this module, we will introduce IT controls and their role in ensuring system integrity and security. We will explore different types of IT and cybersecurity controls, discuss how to design effective controls, and examine methods for identifying weaknesses and improving security measures.

涵盖的内容

7个视频1个作业1个插件

In this module, we will explore prominent cybersecurity frameworks and standards that guide organizations in mitigating risks. We will examine compliance requirements such as NIST, ISO 27001, HIPAA, and PCI DSS and learn how auditors utilize these frameworks to assess security controls.

涵盖的内容

8个视频1个作业1个插件

In this module, we will provide a structured approach to the cybersecurity audit process, covering the planning, fieldwork, reporting, and follow-up phases. We will explore the key responsibilities of IT audit teams and the methodologies used to assess security risks.

涵盖的内容

6个视频1个作业1个插件

In this module, we will walk through the cybersecurity audit process in detail, covering key testing areas such as access management, vulnerability assessment, patch management, and incident response. We will also discuss best practices for reporting findings and following up on recommendations.

涵盖的内容

29个视频1个作业1个插件

In this module, we will introduce IT auditing fundamentals, including its role in ensuring regulatory compliance. We will discuss the importance of IT audits, the SOX Act, and how IT audit frameworks help organizations maintain security and transparency.

涵盖的内容

5个视频1个作业1个插件

In this module, we will explore essential IT audit frameworks, including COSO and COBIT. We will analyze their role in guiding IT governance, risk management, and control assessments to ensure secure and compliant IT environments.

涵盖的内容

3个视频1个作业1个插件

In this module, we will examine different types of IT audits, including financial statement audits, internal audits, and attestation engagements. We will also compare the responsibilities of internal and external auditors in assessing IT security and compliance.

涵盖的内容

5个视频1个作业1个插件

In this module, we will explore IT controls, focusing on ITGC and ITAC. We will examine access controls, change management, system development life cycle (SDLC) controls, and their impact on maintaining secure IT environments.

涵盖的内容

9个视频1个作业1个插件

In this module, we will review the IT audit process, breaking down the planning, fieldwork, reporting, and follow-up phases. We will discuss best practices for gathering evidence, documenting findings, and ensuring audit compliance.

涵盖的内容

5个视频1个作业1个插件

In this module, we will explore control design and its role in IT security. We will discuss how to identify control weaknesses, differentiate between key and non-key controls, and assess the risk levels of applications. Additionally, we will examine audit documentation, such as workpapers, and define the scope of IT infrastructure testing.

涵盖的内容

6个视频1个作业1个插件

In this module, we will perform an in-depth IT audit, covering key phases such as planning, fieldwork, and reporting. We will test various IT controls, including access management, change management, and system development life cycle (SDLC) controls, while analyzing audit results for deficiencies.

涵盖的内容

11个视频1个作业1个插件

In this module, we will explore SOC audits, focusing on their role in evaluating service organization controls. We will review SOC categories, testing requirements, and reporting formats while learning how to assess SOC reports for compliance and security effectiveness.

涵盖的内容

8个视频1个作业1个插件

In this module, we will introduce cloud auditing and its role in securing cloud environments. We will cover essential cloud computing concepts, review its history and benefits, and differentiate between cloud deployment models and service models such as IaaS, PaaS, and SaaS.

涵盖的内容

16个视频1个作业1个插件

In this module, we will explore cloud governance and its significance in maintaining security and compliance. We will discuss cloudification, risk management, and the shared responsibility model, which defines security roles between cloud providers and customers.

涵盖的内容

4个视频1个作业1个插件

In this module, we will explore audit frameworks used in cloud environments. We will examine cloud governance frameworks, internal controls, and methodologies for identifying and addressing control weaknesses to strengthen cloud security.

涵盖的内容

10个视频1个作业1个插件

In this module, we will cover the cloud audit process, including planning, fieldwork, reporting, and follow-up. We will analyze CSA control domains and leverage frameworks such as the Cloud Controls Matrix (CCM) to assess cloud security effectiveness.

涵盖的内容

7个视频1个作业1个插件

In this module, we will perform cloud security controls testing, covering key areas such as access management, data security, logging, change management, and incident response. We will also review business continuity planning to ensure resilience in cloud-based services.

涵盖的内容

12个视频1个作业1个插件

In this module, we will explore how to assess cloud service provider (CSP) environments for compliance and security risks. We will review SOC reports, analyze different SOC audit categories, and learn how to interpret and validate findings in CSP assessments.

涵盖的内容

5个视频1个作业1个插件

In this module, we will introduce IT audit application walkthroughs, covering the process of gathering information through questionnaires. We will discuss best practices for engaging with audit clients and reviewing system and application configurations for compliance.

涵盖的内容

9个视频1个作业1个插件

In this module, we will focus on walkthrough questionnaires used in IT audits. We will cover critical areas such as system access, password configurations, change management, and data backup, ensuring a structured approach to collecting audit evidence.

涵盖的内容

11个视频1个作业1个插件

In this module, we will perform an application walkthrough to assess security measures. We will review user access provisioning, system configurations, and privilege management while working collaboratively with IT teams and application owners.

涵盖的内容

8个视频1个作业1个插件

In this module, we will review backup and recovery controls as part of IT audits. We will assess data recovery plans, password configurations, and change management processes while documenting findings from walkthrough meetings.

涵盖的内容

4个视频1个作业1个插件

In this module, we will explore best practices for preparing for an IT audit job interview. We will cover resume review, research techniques, punctuality, and post-interview follow-up strategies.

涵盖的内容

9个视频1个作业1个插件

In this module, we will prepare for practical IT audit interviews by discussing common questions and effective response strategies. We will cover key topics such as control testing, IT audit processes, sample size determination, and risk assessments. Additionally, we will explore how to articulate experience with cloud security and audit frameworks.

涵盖的内容

14个视频1个作业1个插件

In this module, we will continue refining responses to IT audit interview questions with a focus on access controls, change management, and backup & recovery testing. We will also discuss common issues encountered during audits and how to approach SOX and SOC audit-related questions.

涵盖的内容

10个视频1个作业1个插件

In this module, we will focus on technical IT audit interview questions. Topics include IT audit frameworks (e.g., COBIT, COSO), IT audit tools, controls testing, risk prioritization, and IT audit report formats. We will also discuss the role of an IT auditor and strategies for handling audit challenges.

涵盖的内容

13个视频1个作业1个插件

In this module, we will prepare for behavioral IT audit interview questions. We will discuss how to handle difficult audit outcomes, manage resistance from stakeholders, and effectively communicate findings to both technical and non-technical teams. Additionally, we will cover common workplace scenarios, such as teamwork, leadership, and personal development.

涵盖的内容

11个视频3个作业

位教师

Packt - Course Instructors
Packt
971 门课程231,340 名学生

提供方

Packt

从 Security 浏览更多内容

人们为什么选择 Coursera 来帮助自己实现职业发展

Felipe M.
自 2018开始学习的学生
''能够按照自己的速度和节奏学习课程是一次很棒的经历。只要符合自己的时间表和心情,我就可以学习。'
Jennifer J.
自 2020开始学习的学生
''我直接将从课程中学到的概念和技能应用到一个令人兴奋的新工作项目中。'
Larry W.
自 2021开始学习的学生
''如果我的大学不提供我需要的主题课程,Coursera 便是最好的去处之一。'
Chaitanya A.
''学习不仅仅是在工作中做的更好:它远不止于此。Coursera 让我无限制地学习。'
Coursera Plus

通过 Coursera Plus 开启新生涯

无限制访问 10,000+ 世界一流的课程、实践项目和就业就绪证书课程 - 所有这些都包含在您的订阅中

通过在线学位推动您的职业生涯

获取世界一流大学的学位 - 100% 在线

加入超过 3400 家选择 Coursera for Business 的全球公司

提升员工的技能,使其在数字经济中脱颖而出

常见问题