IS 643
Information Security Auditing and Risk Management:ISO Standards
Pace University · UGRD · Fall 2026
Catalog description
This course provides an introduction to security auditing based on the ISO 27000 family of standards. In addition to risk management, the course also resents both nominal security audit based on ISO 27002 and technical security audit based on ISO 27001. Each student is required to conduct a case study where he/she performs security audit for a fictitious or real small-size organization. Security Audit program contains about a dozen security areas of audit focus that are performed but either an external auditor or internal auditor who aims at validating the compliance of the Information Technology and the enterprise to the ISO 27000 Series, Sarbanes-Oxley, HIPAA, and PCI-DSS. Here are the main security audit objectives found in most security audit projects: Corporate Security Management, Systems Development and Maintenance, Information Access Control Management, Compliance Management, Human Resource Security Management, Information Security Incident Management, Communications and Operations Management, Organizational Asset Management, Physical and Environmental Security Management, Security Policy Management and Disaster Recovery Plan and Business Continuity.
Sections
Current meeting, instructor, credit, and enrollment details
001
Availability not recently verified- Days & times
- No scheduled meeting time
- Meeting dates
- —
- Location
- —
- Instructor
- Staff