REVIEWED
IN PROGRESS
FINDING
Audittraining  ·  Live & Remote  ·  Engels
Audit Training  ·  Live & Remote  ·  English

Information Security
Audit Training.
Vier dagen.
Van vraag tot bevinding.

Information Security
Audit Training.
Four days.
From question to finding.

Niet voor het examen. In vier sessies van twee uur leert u hoe een informatiebeveiligingsaudit echt werkt — van planning en scope tot toegang, wijzigingen, logging en bevindingen die management en teams daadwerkelijk gebruiken.

Not for the exam. In four sessions of two hours each you learn how an information security audit really works — from planning and scope to access, changes, logging and findings that management and teams actually use.

4
dagen
days
8
uur totaal
hours total
4
auditdomeinen
audit domains
100%
live & remote
live & remote
Engelstalige training English-language training Security & ITSecurity & IT Risk & internal auditRisk & internal audit Compliance & GRCCompliance & GRC Finance & taxFinance & tax StudentenStudents
In het kort
At a glance
DuurDuration4 dagen · 2 uur/dag4 days · 2 hrs/day
TotaalTotal8 uur
VormFormatLive · RemoteLive · Remote
VoertaalLanguageEngels / English
OnderwerpenTopics4 auditdomeinen4 audit domains
NiveauLevelInstap tot mediorEntry to intermediate
In-companyIn-companyBeschikbaarAvailable
CertificaatCertificateDeelnamebewijsCertificate of attendance
Meld je aan → Request enrollment →

Geen verplichtingen · Reactie binnen 1 werkdag

No commitment · Response within 1 business day

Over deze training
About this training

IS-audits in gewone taal

IS audits in plain language

Deze training is voor iedereen die wil begrijpen hoe een informatiebeveiligingsaudit in de praktijk verloopt — niet alleen voor mensen die zich voorbereiden op een examen. We doorlopen de volledige auditcyclus: planning, scope, testing en rapportage. De focus ligt op begrip en toepassing, niet op normen uit het hoofd leren.

This training is for anyone who wants to understand how an information security audit works in practice — not only for people preparing for an exam. We walk through the full audit cycle: planning, scope, testing and reporting. The focus is on understanding and application, not on memorising standards.

U hoeft geen diepgaand technisch specialist te zijn. Basiskennis van IT of bedrijfsprocessen is voldoende. Na vier sessies kunt u toegang, wijzigingen, logging en databescherming beoordelen — en bevindingen schrijven die management en teams echt gebruiken.

You do not need to be a deep technical specialist. Basic familiarity with IT or business processes is enough. After four sessions you can assess access, changes, logging and data protection — and write findings that management and teams actually use.

Let op: deze training wordt onafhankelijk verzorgd door OranjeRaksha en is niet verbonden aan ISACA, ISO of een andere certificeringsinstantie. Deelnemers ontvangen een bewijs van deelname van OranjeRaksha. Sessies en materialen zijn volledig Engelstalig.

Note: this training is independently delivered by OranjeRaksha and is not affiliated with ISACA, ISO or any other certification body. Participants receive a certificate of attendance from OranjeRaksha. All sessions and materials are in English.


Voor wie
Who is this for?

Voor iedereen die audits beter wil begrijpen of uitvoeren

For anyone who wants to understand or conduct IS audits

U hoeft geen carrière-auditor te zijn om waarde uit deze training te halen. Of u nu security-professional, IT-medewerker, risicomanager, internal auditor of consultant bent — de training maakt het auditproces concreet en toepasbaar voor uw situatie.

You do not have to be a career auditor to benefit. Whether you are a security professional, IT team member, risk manager, internal auditor or consultant — this training makes the audit process concrete and applicable to your situation.

🔐
Security & IT professionals
Security & IT professionals

Professionals die willen begrijpen hoe informatiebeveiligingsaudits verlopen en hoe hun dagelijkse werk wordt beoordeeld vanuit een auditperspectief.

Professionals who want a clearer view of how information security audits work and how their day-to-day work is assessed from an audit perspective.

📋
Risk & internal audit
Risk & internal audit

Professionals die meer houvast zoeken bij het testen van toegang, logging en wijzigingen — en sterkere, feitelijkere bevindingen willen schrijven.

Professionals who need structure for testing access, logging and changes — and want to write stronger, more evidence-based findings.

⚖️
Compliance & GRC
Compliance & GRC

Teams verantwoordelijk voor ISO 27001, NIS2 of andere kaders die willen begrijpen hoe controls in de praktijk worden getoetst — niet alleen op papier staan.

Teams responsible for ISO 27001, NIS2 or other frameworks who want to understand how controls are tested in practice — not just documented on paper.

💰
Finance, tax & accountancy
Finance, tax & accountancy

Professionals die het verschil willen zien tussen "controle in theorie" en "control in de praktijk" en effectiever willen praten met IT- en securitycollega's.

Professionals who want to understand the gap between "control on paper" and "control in real life" and communicate more effectively with IT and security colleagues.

🧑‍💼
Consultants & adviseurs
Consultants & advisors

Professionals die klanten begeleiden bij informatiebeveiliging en bevindingen helder moeten uitleggen aan management en technische teams.

Professionals who support clients on information security and need to explain findings clearly to both management and technical teams.

🎓
Studenten & starters
Students & starters

Een eerste stap richting IT-audit, risk of security? Deze training geeft een praktische blik op hoe een echte IS-audit wordt opgezet en uitgevoerd.

A first step into IT audit, risk or security? This training gives a practical view of how a real information security audit is planned and conducted.


Wat je leert
What you will achieve

Van "wat is een audit?" naar "ik kan dit uitvoeren"

From "what is an audit?" to "I can walk someone through it"

Na de training kun je de volledige cyclus van een informatiebeveiligingsaudit doorlopen — en bevindingen schrijven die management en teams begrijpen, onthouden en kunnen gebruiken.

After the training you can walk through the full cycle of an information security audit — and write findings that management and teams understand, remember and can act on.

Auditdoelen, scope & rollen begrijpen
Understanding objectives, scope & roles

Auditdoelen scherp formuleren, scope afbakenen, stakeholders identificeren en een duidelijke auditaanpak opstellen die werkt voor uw organisatie.

Clarify audit objectives, define scope, identify stakeholders and build a clear audit approach that works for your organisation.

Toegangsbeheer & wijzigingen toetsen
Testing access management & changes

Gebruikerslevenscyclus, toegangsrechten, privileged accounts en wijzigingsbeheer stap voor stap beoordelen aan de hand van gerichte auditvragen en praktijkvoorbeelden.

Assess user lifecycle, access rights, privileged accounts and change management step by step using targeted audit questions and real-world examples.

Logging & monitoring beoordelen
Reviewing logging & monitoring

Log-coverage beoordelen, alerting en incident response toetsen — op basis van wat werkelijk is gelogd, niet alleen wat is gedocumenteerd.

Assess log coverage, test alerting and incident response — based on what was actually logged, not only what was documented.

Databescherming & backup auditeren
Auditing data protection & backup

Dataclassificatie, retentie, versleuteling, backup- en herstelprocessen en privacy-gerelateerde controls beoordelen op werking en documentatie.

Assess data classification, retention, encryption, backup and recovery processes and privacy-related controls on both function and documentation.

Evidence verzamelen & beoordelen
Collecting & evaluating evidence

Wat goede evidence is — en wanneer het ontbreekt. Interviews, systeemrapporten en documentatie combineren tot een onderbouwde auditconclusie.

What good evidence looks like — and when it is missing. Combining interviews, system reports and documentation into a well-supported audit conclusion.

Bevindingen schrijven die iemand leest
Writing findings people actually read

Korte, feitelijke bevindingen met observatie, risico, impact en aanbeveling — gebouwd met voorbeelden uit echte IS-audits, zonder onnodig vakjargon.

Concise, factual findings with observation, risk, impact and recommendation — built with examples from real IS audits, without unnecessary jargon.


Programma
Program

Vier sessies: van theorie naar praktijk

Four sessions: from concepts to practice

Elke sessie duurt circa 2 uur. We combineren uitleg met voorbeelden, korte MCQ-vragen en groepsoefeningen zodat je de stof direct toepast op herkenbare situaties. Alle sessies worden in het Engels verzorgd.

Each session is about 2 hours. We combine explanation with examples, short MCQ questions and group exercises so you apply the content immediately to realistic situations. All sessions are delivered in English.

1
Dag 1
Day 1
Sessie 1 · 2 uur
Session 1 · 2 hours
Fundamenten van IS-audits
Foundations of IS auditing

Wat een IS-audit is en waarom organisaties er baat bij hebben. De auditcyclus van planning tot follow-up. Hoe risico's, beleid, processen en controls samenhangen. Auditdoelen, scope en rollen van betrokken partijen helder krijgen.

What an IS audit is and why organisations benefit from it. The audit cycle from planning to follow-up. How risks, policies, processes and controls fit together. Clarifying audit objectives, scope and roles of key stakeholders.

AuditcyclusScope & rollenRisico & controlsGroepsoefeningMCQ’sAudit cycleScope & rolesRisk & controlsGroup exerciseMCQs
2
Dag 2
Day 2
Sessie 2 · 2 uur
Session 2 · 2 hours
Toegangsbeheer & wijzigingen in de praktijk
Access management & change handling in practice

Gebruikerslevenscyclus: aanmaken, wijzigen en de-provisioning. Toegangsrechten, privileged accounts en remote access beoordelen. Wijzigingsaanvragen, testen, goedkeuring en implementatie toetsen — inclusief veelvoorkomende knelpunten en hoe je ze herkent.

User lifecycle: provisioning, changes and de-provisioning. Assessing access rights, privileged accounts and remote access. Reviewing change requests, testing, approval and implementation — including common pitfalls and how to spot them.

GebruikerslevenscyclusPrivileged accessWijzigingsbeheerGroepsoefeningMCQ’sUser lifecyclePrivileged accessChange managementGroup exerciseMCQs
3
Dag 3
Day 3
Sessie 3 · 2 uur
Session 3 · 2 hours
Logging, monitoring, backup & databescherming
Logging, monitoring, backup & data protection

Log-coverage, alerting en incident response beoordelen. Backup- en herstelprocessen, dataclassificatie, retentie, versleuteling en privacy-controls kritisch bekijken — op basis van bewijs, niet aannames.

Assessing log coverage, alerting and incident response. Critically reviewing backup and recovery, data classification, retention, encryption and privacy-related controls — based on evidence, not assumptions.

Logging & monitoringBackup & herstelDataclassificatiePrivacy-controlsMCQ’sLogging & monitoringBackup & recoveryData classificationPrivacy controlsMCQs
4
Dag 4
Day 4
Sessie 4 · 2 uur
Session 4 · 2 hours
Evidence, bevindingen & mini-audit
Evidence, findings & mini audit

Evidence verzamelen en beoordelen uit interviews, systeemrapporten en documentatie. Bevindingen schrijven met observatie, impact en aanbeveling — zonder onnodig jargon. Groepscase: samen een klein auditprogramma opzetten en bevindingen uitwerken alsof je een echte audit afrondt.

Collecting and evaluating evidence from interviews, system reports and documentation. Writing findings with observation, impact and recommendation — without unnecessary jargon. Group case: build a small audit programme and develop findings as if completing a real audit.

Evidence-beoordelingBevindingen schrijvenRapportstructuurMini-audit caseMCQ’sEvidence evaluationWriting findingsReport structureMini audit caseMCQs

Vorm & materiaal
Format & materials

Remote, interactief en direct toepasbaar

Remote, interactive and immediately applicable

Alle sessies zijn live — geen opgenomen video's, geen zelfstudiepakketten. Je kunt vragen stellen, je eigen situaties inbrengen en doorvragen op onderwerpen die relevant zijn voor jouw organisatie of rol. Sessies en materialen zijn volledig Engelstalig.

All sessions are live — no recorded videos, no self-study packages. You can ask questions, bring your own situations and dig deeper into topics relevant to your organisation or role. Sessions and materials are fully in English.

🎙️
Live sessies
Live sessions
Vier virtuele sessies van 2 uur. Live uitleg, voorbeelden en ruimte voor vragen vanuit je eigen praktijk.
Four virtual sessions of 2 hours. Live explanation, examples and space for questions from your own work.
📦
Materiaal inbegrepen
Materials included
Slides, MCQ-sets, groepsoefeningen en eenvoudige audittemplates — alles inbegrepen.
Slides, MCQ sets, group exercises and simple audit templates — all included.
🌐
Volledig in het Engels
Fully in English
Training, slides, oefeningen en MCQ's worden in het Engels verzorgd. De cursusbeschrijving is ook in het Nederlands beschikbaar.
Training, slides, exercises and MCQs are delivered in English. The course description is also available in Dutch.
🏢
In-company optie
In-company option
Voor teams op maat, met voorbeelden afgestemd op jouw sector, systemen en maturityniveau.
Tailored for teams, with examples aligned to your sector, systems and maturity level.
👥
Groepscases
Group cases
Groepsoefeningen om de stof direct toe te passen — inclusief een volledige mini-audit op dag 4.
Group exercises to apply the content directly — including a full mini audit on day 4.
📊
MCQ’s om te verankeren
MCQs to reinforce
Korte vragen per sessie — niet als officiële toets, maar om auditlogica en kernbegrippen te verankeren.
Short questions per session — not as an official test, but to reinforce audit logic and key concepts.

Wil je meer weten over planning, prijs of een in-company variant? Laat je gegevens achter en vermeld kort je rol en context — we nemen gericht contact met je op.

Want details on schedule, pricing or an in-company option? Share your details and briefly describe your role and context — we will reach out with a focused proposal.

Meld je aan voor de trainingRequest enrollment

Geen verplichtingen · Wij reageren doorgaans binnen 1 werkdag.No commitment · We typically respond within 1 business day.


Veelgestelde vragen
Frequently Asked Questions

Veelgestelde vragen

Frequently Asked Questions


Andere trainingen
Other trainings

Meer trainingen van OranjeRaksha

More trainings from OranjeRaksha

De Information Security Audit Training is één van meerdere trainingen die we aanbieden voor auditors, IT-professionals, compliance- en riskteams.

The Information Security Audit Training is one of several trainings we offer for auditors, IT professionals, compliance and risk teams.