IS-audits in gewone taal
IS audits in plain language
Deze training is voor iedereen die wil begrijpen hoe een informatiebeveiligingsaudit in de praktijk verloopt — niet alleen voor mensen die zich voorbereiden op een examen. We doorlopen de volledige auditcyclus: planning, scope, testing en rapportage. De focus ligt op begrip en toepassing, niet op normen uit het hoofd leren.
This training is for anyone who wants to understand how an information security audit works in practice — not only for people preparing for an exam. We walk through the full audit cycle: planning, scope, testing and reporting. The focus is on understanding and application, not on memorising standards.
U hoeft geen diepgaand technisch specialist te zijn. Basiskennis van IT of bedrijfsprocessen is voldoende. Na vier sessies kunt u toegang, wijzigingen, logging en databescherming beoordelen — en bevindingen schrijven die management en teams echt gebruiken.
You do not need to be a deep technical specialist. Basic familiarity with IT or business processes is enough. After four sessions you can assess access, changes, logging and data protection — and write findings that management and teams actually use.
Let op: deze training wordt onafhankelijk verzorgd door OranjeRaksha en is niet verbonden aan ISACA, ISO of een andere certificeringsinstantie. Deelnemers ontvangen een bewijs van deelname van OranjeRaksha. Sessies en materialen zijn volledig Engelstalig.
Note: this training is independently delivered by OranjeRaksha and is not affiliated with ISACA, ISO or any other certification body. Participants receive a certificate of attendance from OranjeRaksha. All sessions and materials are in English.
Voor iedereen die audits beter wil begrijpen of uitvoeren
For anyone who wants to understand or conduct IS audits
U hoeft geen carrière-auditor te zijn om waarde uit deze training te halen. Of u nu security-professional, IT-medewerker, risicomanager, internal auditor of consultant bent — de training maakt het auditproces concreet en toepasbaar voor uw situatie.
You do not have to be a career auditor to benefit. Whether you are a security professional, IT team member, risk manager, internal auditor or consultant — this training makes the audit process concrete and applicable to your situation.
Professionals die willen begrijpen hoe informatiebeveiligingsaudits verlopen en hoe hun dagelijkse werk wordt beoordeeld vanuit een auditperspectief.
Professionals who want a clearer view of how information security audits work and how their day-to-day work is assessed from an audit perspective.
Professionals die meer houvast zoeken bij het testen van toegang, logging en wijzigingen — en sterkere, feitelijkere bevindingen willen schrijven.
Professionals who need structure for testing access, logging and changes — and want to write stronger, more evidence-based findings.
Teams verantwoordelijk voor ISO 27001, NIS2 of andere kaders die willen begrijpen hoe controls in de praktijk worden getoetst — niet alleen op papier staan.
Teams responsible for ISO 27001, NIS2 or other frameworks who want to understand how controls are tested in practice — not just documented on paper.
Professionals die het verschil willen zien tussen "controle in theorie" en "control in de praktijk" en effectiever willen praten met IT- en securitycollega's.
Professionals who want to understand the gap between "control on paper" and "control in real life" and communicate more effectively with IT and security colleagues.
Professionals die klanten begeleiden bij informatiebeveiliging en bevindingen helder moeten uitleggen aan management en technische teams.
Professionals who support clients on information security and need to explain findings clearly to both management and technical teams.
Een eerste stap richting IT-audit, risk of security? Deze training geeft een praktische blik op hoe een echte IS-audit wordt opgezet en uitgevoerd.
A first step into IT audit, risk or security? This training gives a practical view of how a real information security audit is planned and conducted.
Van "wat is een audit?" naar "ik kan dit uitvoeren"
From "what is an audit?" to "I can walk someone through it"
Na de training kun je de volledige cyclus van een informatiebeveiligingsaudit doorlopen — en bevindingen schrijven die management en teams begrijpen, onthouden en kunnen gebruiken.
After the training you can walk through the full cycle of an information security audit — and write findings that management and teams understand, remember and can act on.
Auditdoelen scherp formuleren, scope afbakenen, stakeholders identificeren en een duidelijke auditaanpak opstellen die werkt voor uw organisatie.
Clarify audit objectives, define scope, identify stakeholders and build a clear audit approach that works for your organisation.
Gebruikerslevenscyclus, toegangsrechten, privileged accounts en wijzigingsbeheer stap voor stap beoordelen aan de hand van gerichte auditvragen en praktijkvoorbeelden.
Assess user lifecycle, access rights, privileged accounts and change management step by step using targeted audit questions and real-world examples.
Log-coverage beoordelen, alerting en incident response toetsen — op basis van wat werkelijk is gelogd, niet alleen wat is gedocumenteerd.
Assess log coverage, test alerting and incident response — based on what was actually logged, not only what was documented.
Dataclassificatie, retentie, versleuteling, backup- en herstelprocessen en privacy-gerelateerde controls beoordelen op werking en documentatie.
Assess data classification, retention, encryption, backup and recovery processes and privacy-related controls on both function and documentation.
Wat goede evidence is — en wanneer het ontbreekt. Interviews, systeemrapporten en documentatie combineren tot een onderbouwde auditconclusie.
What good evidence looks like — and when it is missing. Combining interviews, system reports and documentation into a well-supported audit conclusion.
Korte, feitelijke bevindingen met observatie, risico, impact en aanbeveling — gebouwd met voorbeelden uit echte IS-audits, zonder onnodig vakjargon.
Concise, factual findings with observation, risk, impact and recommendation — built with examples from real IS audits, without unnecessary jargon.
Vier sessies: van theorie naar praktijk
Four sessions: from concepts to practice
Elke sessie duurt circa 2 uur. We combineren uitleg met voorbeelden, korte MCQ-vragen en groepsoefeningen zodat je de stof direct toepast op herkenbare situaties. Alle sessies worden in het Engels verzorgd.
Each session is about 2 hours. We combine explanation with examples, short MCQ questions and group exercises so you apply the content immediately to realistic situations. All sessions are delivered in English.
Wat een IS-audit is en waarom organisaties er baat bij hebben. De auditcyclus van planning tot follow-up. Hoe risico's, beleid, processen en controls samenhangen. Auditdoelen, scope en rollen van betrokken partijen helder krijgen.
What an IS audit is and why organisations benefit from it. The audit cycle from planning to follow-up. How risks, policies, processes and controls fit together. Clarifying audit objectives, scope and roles of key stakeholders.
Gebruikerslevenscyclus: aanmaken, wijzigen en de-provisioning. Toegangsrechten, privileged accounts en remote access beoordelen. Wijzigingsaanvragen, testen, goedkeuring en implementatie toetsen — inclusief veelvoorkomende knelpunten en hoe je ze herkent.
User lifecycle: provisioning, changes and de-provisioning. Assessing access rights, privileged accounts and remote access. Reviewing change requests, testing, approval and implementation — including common pitfalls and how to spot them.
Log-coverage, alerting en incident response beoordelen. Backup- en herstelprocessen, dataclassificatie, retentie, versleuteling en privacy-controls kritisch bekijken — op basis van bewijs, niet aannames.
Assessing log coverage, alerting and incident response. Critically reviewing backup and recovery, data classification, retention, encryption and privacy-related controls — based on evidence, not assumptions.
Evidence verzamelen en beoordelen uit interviews, systeemrapporten en documentatie. Bevindingen schrijven met observatie, impact en aanbeveling — zonder onnodig jargon. Groepscase: samen een klein auditprogramma opzetten en bevindingen uitwerken alsof je een echte audit afrondt.
Collecting and evaluating evidence from interviews, system reports and documentation. Writing findings with observation, impact and recommendation — without unnecessary jargon. Group case: build a small audit programme and develop findings as if completing a real audit.
Remote, interactief en direct toepasbaar
Remote, interactive and immediately applicable
Alle sessies zijn live — geen opgenomen video's, geen zelfstudiepakketten. Je kunt vragen stellen, je eigen situaties inbrengen en doorvragen op onderwerpen die relevant zijn voor jouw organisatie of rol. Sessies en materialen zijn volledig Engelstalig.
All sessions are live — no recorded videos, no self-study packages. You can ask questions, bring your own situations and dig deeper into topics relevant to your organisation or role. Sessions and materials are fully in English.
Wil je meer weten over planning, prijs of een in-company variant? Laat je gegevens achter en vermeld kort je rol en context — we nemen gericht contact met je op.
Want details on schedule, pricing or an in-company option? Share your details and briefly describe your role and context — we will reach out with a focused proposal.
Meld je aan voor de trainingRequest enrollmentGeen verplichtingen · Wij reageren doorgaans binnen 1 werkdag.No commitment · We typically respond within 1 business day.
Veelgestelde vragen
Frequently Asked Questions
Nee. Basiskennis van IT of bedrijfsprocessen is voldoende. De training is ontworpen voor security-professionals, IT-medewerkers, risicomanagers, internal auditors, finance- en complianceprofessionals en studenten — ook zonder auditachtergrond.
No. Basic familiarity with IT or business processes is enough. The training is designed for security professionals, IT team members, risk managers, internal auditors, finance and compliance professionals and students — even without an audit background.
Nee. Deze training wordt onafhankelijk verzorgd door OranjeRaksha en is niet verbonden aan ISACA, ISO of een andere certificeringsinstantie. Deelnemers ontvangen een bewijs van deelname van OranjeRaksha. Dit is geen officieel ISACA- of ISO-certificaat.
No. This training is independently delivered by OranjeRaksha and is not affiliated with ISACA, ISO or any other certification body. Participants receive a certificate of attendance from OranjeRaksha. This is not an official ISACA or ISO certificate.
Ja. OranjeRaksha verzorgt in-company versies op maat voor teams. Voorbeelden, cases en oefeningen kunnen worden afgestemd op uw organisatie, sector, systemen en maturityniveau. De training wordt in het Engels gegeven.
Yes. OranjeRaksha delivers in-company versions tailored for teams. Examples, cases and exercises can be aligned to your organisation, sector, systems and maturity level. The training is delivered in English.
Alle sessies, slides, oefeningen en MCQ's worden in het Engels verzorgd. De cursusbeschrijving op deze pagina is ook in het Nederlands beschikbaar zodat u de inhoud kunt beoordelen in uw eigen taal.
All sessions, slides, exercises and MCQs are delivered in English. The course description on this page is also available in Dutch so you can review the content in your own language.
Meer trainingen van OranjeRaksha
More trainings from OranjeRaksha
De Information Security Audit Training is één van meerdere trainingen die we aanbieden voor auditors, IT-professionals, compliance- en riskteams.
The Information Security Audit Training is one of several trainings we offer for auditors, IT professionals, compliance and risk teams.