Auditing ISO 27001:2022 Annex A Technical Controls

Udemy Certificate USD 19.99
Enroll now →
Auditing ISO 27001:2022 Annex A Technical Controls

About this course

Unlock the skills to confidently audit ISO/IEC 27001:2022 technical controls.This course provides a complete, step-by-step guide to auditing the 34 Annex A Clause 8 technical controls of ISO/IEC 27001:2022. Covering areas from endpoint security and privileged access to cryptography, network security, and secure software development, it equips you with practical tools, checklists, and methodologies to evaluate compliance and identify risks. This course contains the use of artificial intelligence.Modern organizations face threats ranging from malware infections to misconfigured cloud systems and insecure application development. As an auditor or security professional, your role is not only to confirm compliance but also to highlight risks, evaluate evidence, and recommend improvements. This course bridges the gap between theory and practice, ensuring you can perform robust audits in real-world environments.You’ll learn how to:Audit user endpoints, privileged access rights, and secure authentication.Evaluate controls for capacity, malware, vulnerability, and configuration management.Assess data lifecycle security, including secure deletion, masking, backups, and redundancy.Review logging, monitoring, and privileged utilities to ensure accountability.Verify network and cryptographic security through segregation, filtering, and encryption.Audit secure development practices, including SDLC, coding standards, outsourced development, and change management.Each module includes practical audit checklists, real-world scenarios, and step-by-step examples using a model company (InfoSure Ltd.). You’ll also complete assignments designed to simulate real audits, culminating in a capstone project th

What you'll learn

  • Audit user endpoints and privileged access rights
  • Evaluate controls related to malware and configuration management
  • Assess data lifecycle security
  • Review logging and monitoring practices
  • Verify network security measures including cryptography
  • Audit secure development practices

Course objectives

  • Equip students with the capabilities to conduct robust audits
  • Bridge the gap between theoretical knowledge and practical application

Skills you'll gain

Related courses

Course details are provided by the platform and may change — always confirm on the provider's site. Links may be affiliate links.