Information Security and Auditing

Builds security engineers, ethical security testers and IS auditors: foundations, controls, governance, audit, evidence, resilience, ethical testing and reporting.

Build the judgement and skills of a cybersecurity professional, security engineer, ethical security tester and information systems auditor. Lessons teach concepts with a clear objective, worked examples, a short exercise and a self-check. Each topic pairs original notes and labs with a curated video (some are third-party YouTube explainers; the commentary and Uganda examples are mine). Practicals and quizzes sit after the teaching. You cover CIA and risk language, threats, policy and ISO/IEC 27001, access control and cryptography, COBIT governance, IS audit planning, evidence and CAATs, operations and resilience, classification, authorised testing and board reporting. Illustrations draw on Uganda's digital finance and cyber risk patterns. Pearl Horizon Microfinance Ltd (PHML) is a fictional practice case for applied labs and the capstone.

Curriculum Outline

Introduction to Information Security and Auditing

  • Introduction to Information Security (video)
  • Introduction to IT Audit (video)
  • How This Course Fits Together (video)
  • Practical: Organisational urgency and role clarity brief (text)

    Work through this practical here in the course. When you finish, submit the assignment below.

    Practical walkthrough: organisational urgency and role clarity

    Time: 60–90 minutes
    Submit: a 2-page brief (PDF or Markdown)

    Before you start

    1. Read the Introduction to Information Security and Introduction to IT Audit lessons.
    2. Open the Security roles and assurance map handout.
    3. Use fictional names only. Do not paste live employer data.

    Step-by-step

    Step 1 — Pick one service path

    Choose one path you can picture (examples: mobile-money collections, payroll, partner API settlement). Write one sentence naming the service and who depends on it.

    Step 2 — Label three failures

    For that service, write three short scenarios:

    ID Failure type What happened (1–2 sentences) Who is harmed Business consequence
    F1 Disclosure (confidentiality)
    F2 Integrity
    F3 Availability

    Step 3 — Build a RACI

    For one incident (use F1, F2 or F3), complete this RACI. Mark exactly one A (Accountable) per row.

    Activity Security management Control owner Internal IS audit External assurance
    Contain the incident
    Fix the process control
    Independently examine evidence later
    Speak externally under contract

    Use R = Responsible, A = Accountable, C = Consulted, I = Informed.

    Step 4 — One sentence on products vs assurance

    Finish this sentence in your own words:
    “Buying a security product alone does not prove …”

    Step 5 — Self-check before submit

    • Three failures are clearly labelled C / I / A
    • RACI has one Accountable per activity
    • No live personal data
    • Brief is two pages or less

    Done looks like

    A reviewer can read your brief and know which property failed, who owns containment vs examination, and why a purchase is not assurance.

  • Introduction to Information Security and Auditing knowledge check (quiz)
  • Organisational urgency and role clarity brief (assignment)

Principles of Information Security

  • The CIA Triad (video)
  • Authenticity, Accountability and Non-Repudiation (video)
  • Assets, Threats, Vulnerabilities, Controls and Risk (video)
  • Information Security Management Systems (video)
  • Practical: PHML asset register and CIA impact assessment (text)

    Work through this practical here in the course. When you finish, submit the assignment below.

    Practical walkthrough: asset register and CIA impact

    Time: 90–120 minutes
    Case: fictional Pearl Horizon Microfinance Ltd (PHML)
    Submit: completed register (spreadsheet or Markdown table) + ½-page notes

    Before you start

    1. Finish the Principles of Information Security lesson (CIA).
    2. Download the CIA triad revision sheet.
    3. Create a blank spreadsheet with the columns in Step 2.

    Step-by-step

    Step 1 — List 12 assets

    Include a mix: people-facing systems, data stores, keys, devices, and one partner path. Examples you may adapt (fictional):

    1. Collections API
    2. Core loan ledger
    3. Customer KYC file share
    4. Field officer tablets
    5. Agent float reconciliation workbook
    6. Privileged admin VPN accounts
    7. Backup vault
    8. Partner bank callback endpoint
    9. SMS gateway credentials
    10. Board pack folder
    11. Help-desk ticketing system
    12. Signing / encryption keys

    Step 2 — Fill the register

    Complete every column for all 12 rows:

    Asset Owner Dependency C (1–5) + consequence I (1–5) + consequence A (1–5) + consequence One control Evidence idea

    Rating tip: rate Confidentiality, Integrity and Availability separately. A backup vault may score high on A and I, lower on C if poorly encrypted.

    Step 3 — Write three consequence sentences

    Pick your three highest-impact ratings and write one sentence each:
    “If [property] fails on [asset], then [who] suffers [harm].”

    Step 4 — Name evidence for one control

    Choose one control from your table. Write:

    1. How you would test it (sample / observation / reperformance)
    2. What artefact you would keep (log export, ticket, restore test note)
    3. What would make you rate it “not operating”

    Step 5 — Self-check

    • 12 rows complete
    • C, I and A rated separately with consequences
    • Owners named
    • No real customer data

    Done looks like

    A manager can fund or challenge your top risks using the register without asking what “high” means.

  • Principles of Information Security knowledge check (quiz)
  • PHML asset register and CIA impact assessment (assignment)

Threats and Cyber Attacks

  • Threat Actors and Attack Paths (video)
  • Malware and Incident Response (video)
  • Social Engineering and Denial of Service (video)
  • Practical: PHML risk assessment and treatment register (text)

    Work through this practical here in the course. When you finish, submit the assignment below.

    Practical walkthrough: risk assessment and treatment register

    Time: 2–3 hours
    Case: fictional PHML digital collections
    Submit: 10-row risk register + 1-page treatment summary

    Before you start

    1. Finish Threat Actors, Malware, and Social Engineering lessons.
    2. Keep asset / threat / vulnerability / control / risk as separate ideas.
    3. Create a spreadsheet with the columns below.

    Step-by-step

    Step 1 — Set scope in one paragraph

    Write: service in scope, period you are imagining, and what is out of scope (example: only digital collections, not branch cash).

    Step 2 — Draft 10 cause–event–impact scenarios

    Each scenario must be a full sentence, not one word.

    Required mix:

    • At least 2 insider paths
    • At least 2 partner / supplier paths
    • At least 1 malware / ransomware style path
    • At least 1 social engineering / SIM-swap style path
    • At least 1 availability / DoS or dependency outage path

    Step 3 — Complete the register columns

    ID Scenario (because / event / impact) Asset Threat Vulnerability Inherent L (1–5) Inherent I (1–5) Existing controls Residual L Residual I Treatment (Treat / Transfer / Avoid / Accept) Owner Due date Acceptance authority Evidence residual changed

    Step 4 — Apply treatment rules

    1. Treat: name the control that reduces likelihood or impact.
    2. Transfer: insurance or contract may shift financial impact; accountability for customer harm stays.
    3. Avoid: stop the activity.
    4. Accept: name the authority and review date. Blank acceptance is not acceptance.

    Step 5 — Write the one-page summary

    Answer:

    1. Top three residual risks and why they rank first
    2. Two controls you would fund this quarter
    3. One risk you would refuse to accept without escalation

    Step 6 — Self-check

    • No one-word risks
    • Insider and partner paths present
    • Insurance never used to erase accountability
    • Every Accept row has an authority

    Done looks like

    A control owner can act from a row without translating jargon.

  • Threats and Cyber Attacks knowledge check (quiz)
  • PHML risk assessment and treatment register (assignment)

Security Policies and Standards

  • Policies, Standards, Procedures and Guidelines (video)
  • ISO/IEC 27001 Requirements (video)
  • ISO/IEC 27002 Control Themes (video)
  • Practical: Draft and review a PHML security policy (text)

    Work through this practical here in the course. When you finish, submit the assignment below.

    Practical walkthrough: draft and review a security policy

    Time: 90–120 minutes
    Case: fictional PHML
    Submit: policy draft (2–3 pages) + review findings table (5 rows)

    Before you start

    1. Finish Policies / Standards / Procedures and ISO lessons.
    2. Remember force words: policy = direction; standard = measurable must; procedure = steps; guideline = advice.

    Step-by-step

    Step 1 — Choose policy scope

    Write one paragraph: policy title, who it applies to, systems/data in scope, and what is excluded.

    Step 2 — Draft the policy skeleton

    Use these headings and fill each with real sentences (not placeholders):

    1. Purpose
    2. Authority and approval
    3. Scope
    4. Roles and responsibilities
    5. Mandatory statements (8–12 “must” statements)
    6. Exception handling (who approves, expiry, compensating control)
    7. Enforcement and consequences
    8. Related standards and procedures (name them; do not paste them into the policy)
    9. Review cycle
    10. Document control (owner, version, date)

    Step 3 — Separate layers

    Create a small table proving you know the hierarchy:

    Statement Type (Policy / Standard / Procedure / Guideline) Why
    …

    Add at least two of each type. If a statement has a number (e.g. password length), it is usually a standard, not a policy.

    Step 4 — Review like an auditor

    Complete five review findings:

    # Location Issue Risk if left Recommended fix
    1
    2
    3
    4
    5

    Look for: missing owners, no exception expiry, procedures disguised as policy, unenforceable “musts”, missing review date.

    Step 5 — Self-check

    • Policy stays high-level
    • Exceptions have owners and expiry
    • Five review findings are specific
    • No live personal data

    Done looks like

    Leadership can approve the policy without rewriting it into a procedure manual.

  • Security Policies and Standards knowledge check (quiz)
  • Draft and review a PHML security policy (assignment)

Access Control and Cryptography

  • Identification, Authentication, Authorisation and Accountability (video)
  • Access Control Models and Segregation of Duties (video)
  • Cryptography and Defence in Depth (video)
  • Practical: PHML access and control assessment (text)
  • Access Control and Cryptography knowledge check (quiz)
  • PHML access and control assessment (assignment)

IT Governance

  • Governance and Management (video)
  • COBIT 2019 (video)
  • Governance Committees and Capability (video)
  • Practical: PHML COBIT capability assessment (text)
  • IT Governance knowledge check (quiz)
  • PHML COBIT capability assessment (assignment)

Information Systems Audit

  • Information Systems Audit Fundamentals (video)
  • Ethics, Independence and Due Professional Care (video)
  • Risk-Based Audit Planning (video)
  • Practical: Risk-based PHML audit plan (text)
  • Information Systems Audit knowledge check (quiz)
  • Risk-based PHML audit plan (assignment)

Audit Evidence and CAATs

  • Control Types and Test Design (video)
  • Audit Evidence and Sampling (video)
  • Computer-Assisted Audit Techniques (video)
  • Practical: PHML CAAT transaction working paper (text)
  • Data file: PHML practice transactions (CSV) (resource)
  • Audit Evidence and CAATs knowledge check (quiz)
  • PHML CAAT transaction working paper (assignment)

IT Operations and Resilience

  • IT Operations, Incidents and Logging (video)
  • Change and Release Management (video)
  • Business Continuity and Disaster Recovery (video)
  • Practical: PHML change and recovery test (text)
  • IT Operations and Resilience knowledge check (quiz)
  • PHML change and recovery test (assignment)

Information Protection and Security Testing

  • Information Classification and Handling (video)
  • Vulnerability Assessment and Penetration Testing (video)
  • OWASP Top 10 (video)
  • Practical: Authorised PHML lab VAPT report (text)
  • Information Protection and Security Testing knowledge check (quiz)
  • Authorised PHML lab VAPT report (assignment)

Audit Reporting and Communication

  • Audit Working Papers (video)
  • Writing Audit Findings (video)
  • Board Reporting and Disclosure (video)
  • Practical: PHML board audit report (text)
  • Audit Reporting and Communication knowledge check (quiz)
  • PHML board audit report (assignment)

Capstone Project

  • Capstone Brief (video)
  • Practical: PHML capstone engagement (text)
  • Submit the complete PHML engagement (assignment)
  • Final integrative assessment (quiz)