Master class

Masterclass Review Framework Information Security

In this master class you will learn more about the 2021 Assessment Framework (SURFaudit NBA model), so that you can properly carry out an assessment, for example in the context of the benchmark. With inspiring in-depth sessions and keynotes you will be well prepared when you start working with the assessment framework.

Close-up student achter laptop met schrijfgerei op tafel
14 — 15 Feb 2023
Feb. 14, 1 p.m. - Feb. 15, 4 p.m.
SURF office, Utrecht


In higher education and mbo, the NBA Maturity Model for Information Security is used as the basis for the assessment framework for the information security benchmark.

Getting started with the Information Security Assessment Framework

The masterclass Information Security Assessment Framework helps you on your way with the transition to this new assessment framework, and is also interesting for FGs, privacy officers and auditors. Under the guidance of expert Ludo Cuijpers you will work hands-on with the statements from the NBA assessment framework. There is plenty of room to exchange experiences and discuss good practices with each other. In addition, there are inspiring keynotes and in-depth sessions planned by various experts. In between there is plenty of opportunity for informal contact.


During the four sessions, we will discuss all fifteen domains of the NBA model. Below is the outline of the program.



General introduction about the NBA model and the Benchmark IB (SURF / MBO Digitaal)


Presentation Governance and HRM (Ludo Cuijpers, VISTA college)
Domains NBA model covered: Governance, Organization, Human Resources, System Development, Identity & Access Management

16.00 Break
17.00 Presentation outsourcing and supply chain security (Niels Dutij, MBO Digitaal)
Domains NBA model covered: Physical Security, Computer Operations, Supply Chain Management
18.00 Presentation architecture (Niels Dutij, MBO Digital)
18.45 Presentation risk management (Maurits Toet, IT auditor Cerrix)
Domain NBA model covered: Risk Management
20.00 Dinner



Keynote on security management (Hub Gerats, Fontys University of Applied Sciences)
Domains NBA model covered: Security Management, Business Continuity Management

12.00 Lunch
13.00 - 16.00

Keynote on configuration management, incident/change management, ITIL processes (Hub Gerats, Fontys University of Applied Sciences)
DomainsNBA model covered: Configuration Management, Incident/Problem Management, Change Management, Data Management

Guide for performing or commissioning an IT audit

Joint closure, exchange of experiences and conclusions


Register for this master class no later than January 16.

Number of participants

The maximum number of participants is 15. If there are less than 10 participants, the master class will not take place.


The costs are 500 euro per participant (excluding VAT). SURF arranges the registration of the masterclasses. The SURF registration system only accepts direct payment (iDeal or credit card). After completing your registration you will receive an e-mail as confirmation with an attached invoice.

Can't make it on this date?

This Master Class will also be given on February 28 as a one-day Master Class. If you want to attend this master class, press the button to register for the one-day master class.

Sign up here