Skip to main content
GMI-TECHNOLOGIES: A GMI-INVESTMENTS Company
F1 Β· 2 days

Multi-Framework Security Auditor

This 2-day course gives you the method and reflexes to run an audit covering several frameworks at once, without starting from scratch every time the standard changes. It relies on realistic case studies and a field workshop on a dedicated virtual network lab.

What this course covers

Multi-framework audit methodology and the crosswalk logic between standards
The structure and requirements of ISO/IEC 27001:2022, and the 93 Annex A controls of ISO/IEC 27002:2022
The specifics of PCI-DSS 4.0.1, CIS Controls v8.1 and NIST CSF 2.0
Running a full audit, from document review to writing the finding, on a test environment

Detailed program

Day 1 β€” Audit fundamentals and ISO 27001/27002

1Audit principles (ISO 19011) and multi-framework methodology
2ISO/IEC 27001:2022 structure: clauses 4 to 10, the PDCA cycle
3ISO/IEC 27002:2022: the 93 Annex A controls, focus on the 11 controls new in 2022
4Workshop: mapping a single control to several frameworks
5Case study #1: a known compliance gap that was never treated

Day 2 β€” PCI-DSS, CIS Controls, NIST CSF, and closing

1PCI-DSS 4.0.1: the 12 requirements, the CDE environment, network segmentation, SAQ vs QSA
2CIS Controls v8.1: 18 controls, implementation groups IG1/IG2/IG3
3NIST CSF 2.0: the 6 functions (Govern, Identify, Protect, Detect, Respond, Recover)
4Field workshop: a multi-framework mini-audit on the virtual network lab
5Case studies #2 and #3, closing module "AI and anomaly detection in auditing" (2h)
6Certification advice (Lead Auditor / Lead Implementer) and final quiz
Flagship product

AuditForge

Automated orchestration of security audits and multi-framework compliance

AuditForge orchestrates your open-source technical tools (network, application, cloud scans) while guaranteeing rigorous traceability between detected vulnerabilities and business risks. The solution serves consulting firms as well as internal security leaders, on a secure and sovereign architecture, with progressive feature rollout.

  • 8 business modules: mapping, compliance, vulnerabilities, risks & SoA, GDPR, reporting, client portal
  • 6 integrated frameworks: ISO 27001/27002, PCI-DSS 4.0.1, GDPR, CIS Controls v8.1, NIST CSF 2.0
  • Technical scan orchestration (Nmap, Nuclei, testssl.sh, Prowler)
  • Sovereign architecture, strict data isolation per firm
Discover AuditForge

Materials provided to participants

Detailed program, course deck, case studies and workshop guide are provided to every registered participant, ahead of and during the course.

Detailed program (PDF)
Course deck (PPTX)
Case studies (PDF)
Virtual network lab procedure (PDF)
Full participant handbook (PDF)

A question about this course?