Publication date : 02/23/2024

Course : Audit, indicators and safety control

Synthesis course - 2d - 14h00 - Ref. UDI
Price : 1720 € E.T.

Audit, indicators and safety control




Controlling security has become essential to ensure that investments in this area are commensurate with the stakes. This seminar introduces you to the best methods for auditing and building security indicators and dashboards, for effective implementation in your IS.


INTER
IN-HOUSE
CUSTOM

Synthesis course in person or remote class
Disponible en anglais, à la demande

Ref. UDI
  2d - 14h00
1720 € E.T.




Controlling security has become essential to ensure that investments in this area are commensurate with the stakes. This seminar introduces you to the best methods for auditing and building security indicators and dashboards, for effective implementation in your IS.


Teaching objectives
At the end of the training, the participant will be able to:
Understand the challenges and obligations of safety management
Understand how to create meaningful and effective dashboards
Understand the number and choice of indicators according to the chosen field of application
Safety audit methodology

Intended audience
CISOs or security correspondents, security architects, IT managers, engineers or technicians who need to integrate security requirements.

Prerequisites
Basic knowledge of IT security.

Course schedule

1
Introduction: safety control

  • Reminders. ISO 27000 terminology.
  • Safety control implementation.
  • Short-medium-long-term safety assessment.
  • Safety management: the "manager" view.
  • Safety reviews and input elements.
  • The legibility of its security compared to publishers.
  • Regulatory and standards constraints.

2
Safety audits

  • The safety auditor's job.
  • Identify the context of the mission.
  • Preparing the mission, analyzing the reference framework.
  • Gap classification, determining the risk criteria used.
  • Literature review.
  • Interview preparation.
  • Technical tests.
  • On-site audit: what to do (and what not to do).

3
Indicators and measuring instruments

  • Presentation of indicators and dashboards, examples of formats.
  • A typology of indicators. What is the purpose of my indicator?
  • The number and choice of indicators according to the chosen field of application.
  • ISO 27001 registration. ISMS reviews and re-examinations.
  • The 27004 standard "Information Security Management Measurements": the essentials.
  • Examples of 27001 controls and measures Appendix A.

4
Dashboards and safety management

  • PSSI monitoring, the basis for calculating return on investment.
  • Dashboards: for whom, for what? Monitoring actions and PSSI compliance for CISOs.
  • Monitoring of acceptable risk levels for operational departments.
  • The "Domains - Good practices" reference system as a monitoring tool.
  • The "Type of practice/maturity" benchmark as a target to be achieved.
  • Examples of standard dashboards.

5
Conclusion

  • The choice of indicators.
  • Building my first dashboard.
  • Audit situation.
Case study
Exercises on typical projects "Logical security", "Protection of goods and people", "Communications security", "Application security".


Customer reviews
3,8 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
DOMINIQUE F.
11/12/25
4 / 5

J’attendait plus d’exemples concret d’indicateurs
JEAN-MICHEL L.
11/12/25
4 / 5

Formation intéressante, avec un atelier permettant de concrétiser les concepts.
TANGUY F.
03/07/25
3 / 5

The training gave an impression of a rough draft with:A trainer who seemed to be discovering the presentationA medium that lacked coherence with an aspect of assembly of various presentations, a part with a shaky formatting (bulleted list with different items on the same line, p111 to 219), a repetition of themes (audit p7 to 110, indicators p111 to 219, audit p220 to 264, indicators p 265 to 279).



Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 12 Mar., 2 June, 15 Sep., 17 Dec.

PARIS LA DÉFENSE
2026 : 12 Mar., 2 June, 15 Sep., 17 Dec.