Cyber Security Compliance and Auditing


In this course, participants develop the necessary expertise to perform Information Security Management System (ISMS) audits by applying widely recognized audit principles, procedures, and techniques. The InfoSec auditing body of knowledge is used in the course framework and includes:

  • Fundamental principles and concepts of Information Security Management System
  • Fundamental audit concepts and principles
  • Preparation of an ISO/IEC 27001, NIST 800, SOC 2 Type 2, or ITSG-33 audit
  • Conducting an ISO/IEC 27001, NIST 800, SOC 2 Type 2, or ISTG-33 audit
  • Closing an ISO/IEC 27001, NIST 800, SOC 2 Type 2, or ITSG-33 audit


Learning Outcomes

  • Review the structure of an ISMS
  • Review TRA, PIA, internal, supplier, third party and compliance audit structures
  • Review TRA, PIA, and internal auditing techniques including, project, program, horizontal, vertical, circular etc.
  • Understand how to apply ISO 19011 to prepare for and conduct an audit
  • Conduct audit opening and closing meetings
  • Conduct Audit, TRA, PIA interviews for ISO/IEC 27001, NIST 800, SOC 2 Type 2, or ITSG-33 audits
  • Write an effective audit report



  • Managers and Senior Managers who need to review or assess information security management systems
  • Personnel who are responsible to assessing, analysing, and auditing information security management systems
  • Personnel who deal with information management systems or assess information and cyber risks
  • Personnel looking to enhance their careers in information and cyber security auditing
  • Project Managers with requirements to review and assess information and cyber security systems



12 hours



  • Regular: $1095 (plus tax)


Featured Instructor

Alan McCafferty is a Senior Business Analyst with 25+ years of progressive experience working with public organizations, not-for-profits, start-ups, and multi-national corporations.  Educated in Canada, the USA and Europe in multiple disciplines including Engineering, Business, Risk Management, and Lean 6 Sigma, he is the author of more than 25 white papers and the recipient of the Canada Award for Excellence. During his career, Alan has led the delivery of multi-year $1 billion+, mission critical information technology projects.  As a Cyber Security SME, Alan was key in the developed of the University of Ottawa’s Professional Development Institute cyber security program and teaches several of the courses.  Alan has successfully completed IT, Security, Process, Threat Risk Assessments (TRA), Privacy Impact Assessments (PIA), health and safety projects for federal government departments, provincial healthcare organizations and national not-for-profit organizations.  As a senior consultant, he uses his Lean 6 Sigma skills, along with his risk and security experience to help organizations implement low waste, and effective lean processes in areas such as information security management systems, business continuity, department security plans, quality management systems, health, and safety management systems.

Mark Hearn is a seasoned Business Leader and technical Product Management executive, bringing technology and business together to solve market problems for over 25 years. Mark’s expertise in software security and anti-reverse engineering has helped industry leaders solve critical product security issues with innovation and minimized risk. As a product security evangelist, Mark has spoken at many industry conferences and engaged in panel discussions on the need to protect software products from attack. He is an expert on the business risks associated with reverse engineering and the critical impact that hacking could have for manufacturers, and for their customers. Mark has held executive roles in product management and strategic market development, developing expertise in both the business-critical and technical functions related to business strategy, use/abuse cases, technical requirements, competitive analysis, and security threat-risk analysis.



Event CodeTitleBegin DateEnd DateTermDelivery Method
S00462311ACyber Security Compliance and Auditing11/6/202311/9/2023AutumnOnlineRegister
S00462403ACyber Security Compliance and Auditing3/18/20243/21/2024WinterOnlineRegister
S00462405ACyber Security Compliance and Auditing5/13/20245/16/2024SummerOnlineRegister