Skip to main content

Cybersecurity Auditing

Key information

  • Application opening date: July 27, 2026
  • Next application deadline: September 25, 2026
  • Next course starts: October 1, 2026
  • Format: Fully online, asynchronous and synchronous
  • Course duration: 12 weeks
  • Language: English
  • Awarding Institution: German University of Digital Science
  • Delivered by: Vytautas Magnus University, Ataya & Partners
  • Certified by: ASIIN
  • EQF Level: 7
  • ECTS: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
  • Fees: €350

Microcredential Information

The module focuses on auditing, as the third line of defence in cybersecurity-aware deployment. Participants will gain skills related to giving assurance to decision makers in relation to the existence and the efficiency of controls. Students will use auditing to validate the activities already performed by the second line of defence (for example risk managers, CISOs, IT operations) and the first line of defence (Business operations and managers).

Key Details

Auditing is a third line of defence that aims at giving assurance to decision makers in relation to the existence and the efficiency of controls. Auditing involves validating the activities already performed by the second line of defence (for example risk managers, Chief information security officers, IT operations team, Devops teams) and the first line of defence (Business operations and managers).
Building an annual audit programme, developing an audit plan for specific audit assignments, and finally conducting the assignment and producing the resulting report. Auditing produce a statement of findings and recommendations aimed at improving the governance and operations of the cybersecurity activities.

Time commitment

Approximate Total workload: 125 hours

The module is designed to fit around professional and personal commitments. All core content is available asynchronously for self-paced study, complemented by optional live sessions offered throughout the module.

Assessment

  • Evaluation of both business cases in sessions 10 and 12. (20%)
  • Take-home assignments (10%)
  • In-class participation (10%)
  • Proctored exam: Evaluation of a “bad” audit report (60%)
Register your interest

Subjects covered

1. The purpose of audit activities and the need for a third line of defence and relation with Internal auditing (e.g. external/internal auditing for certification), and relation with monitoring activities

2. The business and technical need of an audit assignment.

3. The scoping of the assignment and the selection of suitable criteria and a framework, a method or a baseline. Assess the possible use of automated tools.

4. The development of an audit plan including various phases and a description of various fieldwork activities.

5. The management of audit work includes the validation of the existence of controls, the validation of the effectiveness of controls, substantive testing and conducting interviews.

6. The development of an audit report aligning the findings, the recommendations and the opinion statement to respond to audit request and business needs. The method to produce SMART recommendations that aim at bringing optimal, most suitable and effective mitigations.

7. The presentation of audit findings to the audit requestor highlighting the impact and severity of the findings and the return on investment of proposed recommendations.

8. The development of a yearly audit program based on the understanding of an audit universe, an assessment of business needs from the assurance and audit activity and the best use of available audit resources.

9. Understand of the specificities of cybersecurity auditing with the aim at giving assurance of protection controls, the maturity of the organisation, and the efficiency of the second lines of defence (Risk management; project management Office; Compliance management; CISO office; DPO office) as well as governance practices (Senior management role and involvement in cybersecurity governance; the cybersecurity spending effectiveness and justification).

10. A business case with a real-life audit request to be developed in groups in various environment (Auditing the supply chain, the cybersecurity project implementation; the effectiveness of performance indicators and veracity of management reporting on cybersecurity posture; The effectiveness of intrusion detection activities; the effectiveness of awareness activities, etc.).

11. Presentation of the business case in groups benefiting the whole class.

12. A business case with a real-life need for developing a yearly audit program based on a given risk assessment and a typical audit universe)

Register your interest

Learning objectives

After successful completion of this course, students will be able to:

LO 1. Critically evaluate the scope and distinctive nature of cybersecurity auditing in comparison with technical and compliance assessments.

LO 2. Apply structured techniques (e.g., interviews, observations, sampling, and analytical reasoning) to evaluate the adequacy and effectiveness of security controls.

LO 3. Critically document and justify audit activities, ensuring traceability, evidential integrity, and compliance.

LO 4. Identify and communicate audit findings, validate evidence, and propose corrective actions aligned with audit expectations.

LO 5. Conduct domain-specific audits (e.g., network, cloud, application, and third-party audits), applying defined methodologies and evaluation criteria.

LO 6. Independently execute and critically appraise a complete cybersecurity audit assignment using business cases and recognised frameworks.

LO 7. Critically evaluate the role and strategic importance of cybersecurity audits in the context of risk management, governance, and organizational accountability.

LO 8. Design and appraise audit plans by critically integrating standards, regulatory frameworks, sector-specific requirements, and automated tools.

LO 9. Develop a structured audit plan, incorporating managerial and strategic aspects of risk mapping, assessment reviews, budgeting, stakeholder coordination, and expert input that critically balances resources, risks, and stakeholder expectations.

LO 10. Produce comprehensive audit reports, tailored to different audiences, leveraging modern platforms such as Security Information and Event Management tools (SIEM) and Security orchestration, automation and response (SOAR) for enriched reporting and insights that synthesise technical and strategic insights for diverse stakeholders.

LO 11. Critically align and evaluate audit activities within Governance, Risk, and Compliance (GRC) by incorporating frameworks like the IT Governance framework (COBIT 2019) and EU cybersecurity regulations to ensure organisational impact.

LO 12. Synthesise audit results into actionable business intelligence and evaluate their strategic implications.

Register your interest

Module leaders

Title: Prof.

Name: Georges Ataya

 

 

Register your interest
Prof. Georges Ataya

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle