Information Security and Auditing
Builds security engineers, ethical security testers and IS auditors: foundations, controls, governance, audit, evidence, resilience, ethical testing and reporting.
Build the judgement and skills of a cybersecurity professional, security engineer, ethical security tester and information systems auditor. Lessons teach concepts with a clear objective, worked examples, a short exercise and a self-check. Each topic pairs original notes and labs with a curated video (some are third-party YouTube explainers; the commentary and Uganda examples are mine). Practicals and quizzes sit after the teaching. You cover CIA and risk language, threats, policy and ISO/IEC 27001, access control and cryptography, COBIT governance, IS audit planning, evidence and CAATs, operations and resilience, classification, authorised testing and board reporting. Illustrations draw on Uganda's digital finance and cyber risk patterns. Pearl Horizon Microfinance Ltd (PHML) is a fictional practice case for applied labs and the capstone.
Curriculum Outline
Introduction to Information Security and Auditing
- Introduction to Information Security (video)
- Introduction to IT Audit (video)
- How This Course Fits Together (video)
-
Practical: Organisational urgency and role clarity brief (text)
Work through this practical here in the course. When you finish, submit the assignment below.
Practical walkthrough: organisational urgency and role clarity
Time: 60–90 minutes
Submit: a 2-page brief (PDF or Markdown)Before you start
- Read the Introduction to Information Security and Introduction to IT Audit lessons.
- Open the Security roles and assurance map handout.
- Use fictional names only. Do not paste live employer data.
Step-by-step
Step 1 — Pick one service path
Choose one path you can picture (examples: mobile-money collections, payroll, partner API settlement). Write one sentence naming the service and who depends on it.
Step 2 — Label three failures
For that service, write three short scenarios:
ID Failure type What happened (1–2 sentences) Who is harmed Business consequence F1 Disclosure (confidentiality) F2 Integrity F3 Availability Step 3 — Build a RACI
For one incident (use F1, F2 or F3), complete this RACI. Mark exactly one A (Accountable) per row.
Activity Security management Control owner Internal IS audit External assurance Contain the incident Fix the process control Independently examine evidence later Speak externally under contract Use R = Responsible, A = Accountable, C = Consulted, I = Informed.
Step 4 — One sentence on products vs assurance
Finish this sentence in your own words:
“Buying a security product alone does not prove …”Step 5 — Self-check before submit
- Three failures are clearly labelled C / I / A
- RACI has one Accountable per activity
- No live personal data
- Brief is two pages or less
Done looks like
A reviewer can read your brief and know which property failed, who owns containment vs examination, and why a purchase is not assurance.
- Introduction to Information Security and Auditing knowledge check (quiz)
- Organisational urgency and role clarity brief (assignment)
Principles of Information Security
- The CIA Triad (video)
- Authenticity, Accountability and Non-Repudiation (video)
- Assets, Threats, Vulnerabilities, Controls and Risk (video)
- Information Security Management Systems (video)
-
Practical: PHML asset register and CIA impact assessment (text)
Work through this practical here in the course. When you finish, submit the assignment below.
Practical walkthrough: asset register and CIA impact
Time: 90–120 minutes
Case: fictional Pearl Horizon Microfinance Ltd (PHML)
Submit: completed register (spreadsheet or Markdown table) + ½-page notesBefore you start
- Finish the Principles of Information Security lesson (CIA).
- Download the CIA triad revision sheet.
- Create a blank spreadsheet with the columns in Step 2.
Step-by-step
Step 1 — List 12 assets
Include a mix: people-facing systems, data stores, keys, devices, and one partner path. Examples you may adapt (fictional):
- Collections API
- Core loan ledger
- Customer KYC file share
- Field officer tablets
- Agent float reconciliation workbook
- Privileged admin VPN accounts
- Backup vault
- Partner bank callback endpoint
- SMS gateway credentials
- Board pack folder
- Help-desk ticketing system
- Signing / encryption keys
Step 2 — Fill the register
Complete every column for all 12 rows:
Asset Owner Dependency C (1–5) + consequence I (1–5) + consequence A (1–5) + consequence One control Evidence idea Rating tip: rate Confidentiality, Integrity and Availability separately. A backup vault may score high on A and I, lower on C if poorly encrypted.
Step 3 — Write three consequence sentences
Pick your three highest-impact ratings and write one sentence each:
“If [property] fails on [asset], then [who] suffers [harm].”Step 4 — Name evidence for one control
Choose one control from your table. Write:
- How you would test it (sample / observation / reperformance)
- What artefact you would keep (log export, ticket, restore test note)
- What would make you rate it “not operating”
Step 5 — Self-check
- 12 rows complete
- C, I and A rated separately with consequences
- Owners named
- No real customer data
Done looks like
A manager can fund or challenge your top risks using the register without asking what “high” means.
- Principles of Information Security knowledge check (quiz)
- PHML asset register and CIA impact assessment (assignment)
Threats and Cyber Attacks
- Threat Actors and Attack Paths (video)
- Malware and Incident Response (video)
- Social Engineering and Denial of Service (video)
-
Practical: PHML risk assessment and treatment register (text)
Work through this practical here in the course. When you finish, submit the assignment below.
Practical walkthrough: risk assessment and treatment register
Time: 2–3 hours
Case: fictional PHML digital collections
Submit: 10-row risk register + 1-page treatment summaryBefore you start
- Finish Threat Actors, Malware, and Social Engineering lessons.
- Keep asset / threat / vulnerability / control / risk as separate ideas.
- Create a spreadsheet with the columns below.
Step-by-step
Step 1 — Set scope in one paragraph
Write: service in scope, period you are imagining, and what is out of scope (example: only digital collections, not branch cash).
Step 2 — Draft 10 cause–event–impact scenarios
Each scenario must be a full sentence, not one word.
Required mix:
- At least 2 insider paths
- At least 2 partner / supplier paths
- At least 1 malware / ransomware style path
- At least 1 social engineering / SIM-swap style path
- At least 1 availability / DoS or dependency outage path
Step 3 — Complete the register columns
ID Scenario (because / event / impact) Asset Threat Vulnerability Inherent L (1–5) Inherent I (1–5) Existing controls Residual L Residual I Treatment (Treat / Transfer / Avoid / Accept) Owner Due date Acceptance authority Evidence residual changed Step 4 — Apply treatment rules
- Treat: name the control that reduces likelihood or impact.
- Transfer: insurance or contract may shift financial impact; accountability for customer harm stays.
- Avoid: stop the activity.
- Accept: name the authority and review date. Blank acceptance is not acceptance.
Step 5 — Write the one-page summary
Answer:
- Top three residual risks and why they rank first
- Two controls you would fund this quarter
- One risk you would refuse to accept without escalation
Step 6 — Self-check
- No one-word risks
- Insider and partner paths present
- Insurance never used to erase accountability
- Every Accept row has an authority
Done looks like
A control owner can act from a row without translating jargon.
- Threats and Cyber Attacks knowledge check (quiz)
- PHML risk assessment and treatment register (assignment)
Security Policies and Standards
- Policies, Standards, Procedures and Guidelines (video)
- ISO/IEC 27001 Requirements (video)
- ISO/IEC 27002 Control Themes (video)
-
Practical: Draft and review a PHML security policy (text)
Work through this practical here in the course. When you finish, submit the assignment below.
Practical walkthrough: draft and review a security policy
Time: 90–120 minutes
Case: fictional PHML
Submit: policy draft (2–3 pages) + review findings table (5 rows)Before you start
- Finish Policies / Standards / Procedures and ISO lessons.
- Remember force words: policy = direction; standard = measurable must; procedure = steps; guideline = advice.
Step-by-step
Step 1 — Choose policy scope
Write one paragraph: policy title, who it applies to, systems/data in scope, and what is excluded.
Step 2 — Draft the policy skeleton
Use these headings and fill each with real sentences (not placeholders):
- Purpose
- Authority and approval
- Scope
- Roles and responsibilities
- Mandatory statements (8–12 “must” statements)
- Exception handling (who approves, expiry, compensating control)
- Enforcement and consequences
- Related standards and procedures (name them; do not paste them into the policy)
- Review cycle
- Document control (owner, version, date)
Step 3 — Separate layers
Create a small table proving you know the hierarchy:
Statement Type (Policy / Standard / Procedure / Guideline) Why … Add at least two of each type. If a statement has a number (e.g. password length), it is usually a standard, not a policy.
Step 4 — Review like an auditor
Complete five review findings:
# Location Issue Risk if left Recommended fix 1 2 3 4 5 Look for: missing owners, no exception expiry, procedures disguised as policy, unenforceable “musts”, missing review date.
Step 5 — Self-check
- Policy stays high-level
- Exceptions have owners and expiry
- Five review findings are specific
- No live personal data
Done looks like
Leadership can approve the policy without rewriting it into a procedure manual.
- Security Policies and Standards knowledge check (quiz)
- Draft and review a PHML security policy (assignment)
Access Control and Cryptography
- Identification, Authentication, Authorisation and Accountability (video)
- Access Control Models and Segregation of Duties (video)
- Cryptography and Defence in Depth (video)
- Practical: PHML access and control assessment (text)
- Access Control and Cryptography knowledge check (quiz)
- PHML access and control assessment (assignment)
IT Governance
- Governance and Management (video)
- COBIT 2019 (video)
- Governance Committees and Capability (video)
- Practical: PHML COBIT capability assessment (text)
- IT Governance knowledge check (quiz)
- PHML COBIT capability assessment (assignment)
Information Systems Audit
- Information Systems Audit Fundamentals (video)
- Ethics, Independence and Due Professional Care (video)
- Risk-Based Audit Planning (video)
- Practical: Risk-based PHML audit plan (text)
- Information Systems Audit knowledge check (quiz)
- Risk-based PHML audit plan (assignment)
Audit Evidence and CAATs
- Control Types and Test Design (video)
- Audit Evidence and Sampling (video)
- Computer-Assisted Audit Techniques (video)
- Practical: PHML CAAT transaction working paper (text)
- Data file: PHML practice transactions (CSV) (resource)
- Audit Evidence and CAATs knowledge check (quiz)
- PHML CAAT transaction working paper (assignment)
IT Operations and Resilience
- IT Operations, Incidents and Logging (video)
- Change and Release Management (video)
- Business Continuity and Disaster Recovery (video)
- Practical: PHML change and recovery test (text)
- IT Operations and Resilience knowledge check (quiz)
- PHML change and recovery test (assignment)
Information Protection and Security Testing
- Information Classification and Handling (video)
- Vulnerability Assessment and Penetration Testing (video)
- OWASP Top 10 (video)
- Practical: Authorised PHML lab VAPT report (text)
- Information Protection and Security Testing knowledge check (quiz)
- Authorised PHML lab VAPT report (assignment)
Audit Reporting and Communication
- Audit Working Papers (video)
- Writing Audit Findings (video)
- Board Reporting and Disclosure (video)
- Practical: PHML board audit report (text)
- Audit Reporting and Communication knowledge check (quiz)
- PHML board audit report (assignment)
Capstone Project
- Capstone Brief (video)
- Practical: PHML capstone engagement (text)
- Submit the complete PHML engagement (assignment)
- Final integrative assessment (quiz)