GRC & IT Audit

GRC & IT Audit

The GRC & IT Audit course is a practical training program designed for professionals who want to understand and apply governance, risk management, and compliance processes in organizations. The course covers GRC fundamentals, IT controls, risk assessment, internal control systems, IT audit methodologies, audit planning, and reporting. Training is based on real business and audit scenarios, helping learners develop a structured and analytical approach to GRC and IT Audit practices.

Duration4 months
Start Date2026-09-30
Schedule2 times per week
FormatHYBRID

Üstünlüklərimiz

Professional Mentors

Guidance and support from experienced specialists

Practical Learning

Not just theory — hands-on experience through real projects

Modern Technologies

Python, AI, web development and other trending fields

Career Support

CV preparation, interview simulations and access to job opportunities

Curriculum

4

M-1

  • 1.* Fundamentals of information security and its key principles * Understanding Governance, Risk & Compliance (GRC) and its key components * The purpose of GRC in information security and its importance for business * Differences between information security, cybersecurity, and privacy * Interrelationship between Governance, Risk, and Compliance functions * Cybersecurity Governance and Board/Senior Management Oversight
8

M-2

  • 1.* Three Lines of Defense * Understanding Governance * COBIT 2019 * Organizational structures, roles, and responsibilities * Information security governance models * Gap Analysis and SWOT Analysis * Information security strategy * Legal, regulatory, and contractual requirements * Protection of sensitive information * Information classification * Human resources security controls * Information security metrics: KPI, KRI, KCI, and KGI * Designing information security control mechanisms * Defence in Depth * Secure by Design * Information security program * Policies, procedures, standards, and guidelines * Information security awareness * Management of external and cloud services * Information security governance committees * AI Governance
12

M-3

  • 1.* Management of information and other related assets * Criticality assessment of information and other related assets * Change management * Access rights management * Identification and authentication * Data leakage protection mechanisms * Network security * Cryptography * E-mail Security * Virtualization * Mobile devices and IoT * Security monitoring and SIEM * Software security * DevSecOps & CI/CD Pipeline * End-user device security * Technical vulnerability management * Configuration management * Data Masking * Backup management * Physical security * Zero Trust Architecture * Security Architecture and Security by Design * Sophos Central Security (Practical Session)
16

M-4

  • 1.* Key concepts and principles of information security risk management * Risk Governance, Risk Ownership, and Risk Management Roles * Identification and assessment of information security risks * Cyber threat and vulnerability analysis * Aligning risk management frameworks with organizational objectives * Risk Appetite, Risk Capacity, and Risk Tolerance * Risk assessment methodologies and tools * Risk and threat models * Risk analysis and risk treatment methods * Understanding Inherent Risk and Residual Risk * Risk response strategies * Risk and control ownership * Risk monitoring and reporting * Quantitative risk analysis (FAIR model and risk monetization) * AI Risk Management * Key Risk Indicators (KRI) and risk thresholds * Third-party and supplier risk management * Risk Assessment Tool (Practical Session)
20

M-5

  • 1.* Concepts, types, and classification of information security incidents * Incident Response Lifecycle — preparation, detection, response, remediation, and recovery * Incident reporting, notification, and escalation mechanisms * Digital Forensics, evidence collection, and Chain of Custody * Cyber Threat Intelligence * Applying the MITRE ATT&CK framework in incident investigations * Root Cause Analysis (RCA), Lessons Learned, and Post-Incident Review * Tabletop and cybersecurity simulation exercises * Assessment of incidents from GRC and IT Audit perspectives
24

M-6

  • 1.* Business Continuity concepts, objectives, and principles * Business Continuity Management System (BCMS) and governance framework * Business Impact Analysis (BIA) — identifying critical processes and services * Developing a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) * Crisis Management and crisis communication plan * Backup and data recovery strategies * Business continuity based on ISO 22301, ISO/IEC 27001, and other relevant standards * Assessing business continuity from GRC and IT Audit perspectives
28

M-7

  • 1.* Введение в стандарты и фреймворки информационной безопасности * ISO/IEC 27001 — ISMS и риск-ориентированное управление * ISO/IEC 27002 — меры и средства контроля информационной безопасности * NIST Cybersecurity Framework (CSF) — Identify, Protect, Detect, Respond, Recover * PCI DSS — безопасность данных платёжных карт и требования соответствия * Cybersecurity Maturity Model и методологии оценки зрелости * GRC Platform (практическое занятие)
32

M-8

  • 1.* Introduction to information security auditing and audit objectives * Audit principles, approaches, and methodology * Audit planning and development of an audit program * Collection and evaluation of audit evidence * Development of audit checklists and testing procedures * Evaluation of the design and effectiveness of controls * Preparation and presentation of audit reports * Audit sampling methodologies

Our Top Graduates

Bu kurs üçün hələ məzun məlumatı əlavə olunmayıb.

Our Teachers

No teachers found in this category.

Market Salaries

1000 AZN

Junior
1 year experience

2500+ AZN

Middle
1–3 years experience

3500+ AZN

Salary Plus Icon
Senior
3+

Frequently Asked Questions

  • idtech is a modern learning ecosystem providing education in technology, programming, and digital skills.

  • You can register by filling out the form in the 'Apply' section on our website.

  • Our courses are suitable for both beginners and those looking to deepen their expertise.

  • Yes, lessons are available both online and in classrooms.

GRC & IT Audit | IT Course & Training — IDTECH