Loading

Cybersecurity Auditing: Principles, Practices, and Frameworks

Exam Questions: 150
Course Level: Intermediate
Pages: 544 | Content: 518, Supplemental: 26
NASBA Area of Study: Auditing
Not Acceptable for: Enrolled Agents
Version: 8640

This course will help you assess, evaluate, and improve security controls across today’s complex IT environments. It covers cybersecurity operations, governance, and risk management, offering a practical auditing roadmap that spans internal systems, cloud infrastructure, application development, and vendor ecosystems. It offers actionable insights, technical depth, and strategic relevance, plus explores automation, continuous auditing and AI integration. PLEASE NOTE: Not accepted for Enrolled Agents. All course material provided. Prerequisite: Understanding of cybersecurity terminology and auditing techniques. Course level: Intermediate.

Choose Your Format to ADD TO CART:

Go to CART

Course Information

Table of Contents
  • The Role of Audit in Security Governance, Risk, and Compliance
  • Security Standards and Regulations
  • Risk Assessment and Control Design for Modern Systems
  • Evidence, Sampling, and Testing Techniques
  • Auditor Ethics, Independence, and Professional Judgment
  • Identity and Access Management
  • Network and Perimeter Security
  • Application and API Security/CI-CD
  • Cloud and SaaS Security
  • Data Protection
  • Logging, Monitoring, and Detection
  • Incident Response and Crisis Management
  • Vulnerability Management and Pen Test Oversight
  • Third-Party and Supply-Chain Security
  • OT/ICS and Critical Infrastructure Audits
  • Sector Overlays (Financial, Healthcare, Public)
  • Automation, Continuous Auditing, and Advanced Analytics
  • AI Threat Modeling and Attack Surfaces
  • Secure MLOps and Model/Endpoint Controls
  • AI Monitoring and Incident Response
  • Audit Reporting and Executive Communication
  • Annual Audit Planning and Capability Development
Objectives
  • To identify the components of the policy-standards-procedures architecture
  • To recognize the primary purpose of building a common control set across multiple frameworks
  • To identify the minimum traceability chain that connects a risk to its assurance evidence
  • To recall the primary tools for verifying the accuracy of evidence
  • To recall the characteristics and countermeasures of various biases
  • To recognize the three qualities that auditors focus on when evaluating authentication controls
  • To recall the four core indicators that auditors evaluate to assess firewall hygiene maturity
  • To recall the principal purpose of schema validation for an API
  • To recall the most authoritative form of audit evidence in a SaaS environment
  • To recognize the correct sequence for key retirement
  • To identify the five source types that the log coverage model uses to map an organization’s monitoring coverage
  • To recall the characteristics of an effective incident response operating model
  • To recall the cornerstone of credible penetration testing governance
  • To identify the four primary dimensions that determine vendor risk tiering
  • To recall the characteristics of various compensating controls
  • To recall the three documents that form the core of a public-sector authorization package
  • To identify the five categories of artifacts that auditors must preserve for automated assurance evidence
  • To recognize the five dimensions that effective AI control objectives span
  • To identify the correct progression of a dataset’s life cycle for data governance
  • To identify what serves as the backbone of third-party AI incident management
  • To recall what residual risk represents in an audit finding
  • To identify the characteristics of various independence safeguards

PLEASE NOTE: CPE credit measurement is based on NASBA Registry and QAS guidelines of one credit for every 50 minutes. Credit calculation may vary in different states — check with your State Board of Accountancy. Unless otherwise noted in the specific course description, no advanced preparation is required in order to register or complete any PES CPE course. Use of materials or services provided by Professional Education Services, LP ("PES") are governed by the Terms and Conditions stated on PES' website www.mypescpe.com. PES provides these courses with the understanding that it is not providing any accounting, legal, or other professional advice and assumes no liability whatsoever in connection with its use. PES has used diligent efforts to provide quality information and material to its customers, but does not warrant or guarantee the accuracy, timeliness, completeness, or currency of the information contained herein. Ultimately, the responsibility to comply with applicable legal requirements falls solely upon the individual licensee, not PES. PES encourages you to contact your state Board for the latest information and to confirm or clarify any questions or concerns you have regarding your duties or obligations as a licensed professional.