
Discover the layers model of IT management, from IT management and external connections to technical infrastructure, and how these layers support business applications, business continuity, and disaster recovery planning.
Explore the systems development life cycle, from planning and analysis to design, programming, testing, and deployment, including in-house development, system selection, or off-the-shelf customization with user-driven refinement.
Assess project feasibility within the SDLC by involving internal audit in systems analysis, ensure ISO 27,001 information security controls, and verify designs through user acceptance testing and implementation.
Explore systems development methods such as waterfall, spiral, rapid development, and agile, noting phase order, overlapping work, and continuous improvement. Rapid development may waste resources, as the F-35 example shows.
Explain how the waterfall method uses stage-by-stage sign-offs to improve control and reduce waste, while highlighting its inflexibility and longer deadlines.
Apply the spiral method to IT audits by iterating through objectives, risk identification and assessment, and solution development, with regular reviews and re-evaluation.
Leverage rapid development to speed information technology audit projects by performing steps in parallel, using brainstorming workshops, and building multiple prototypes to shorten development time.
Learn how the agile method promotes continuous iteration, concurrent development and testing, and a customer-centered, collaborative approach that embraces change over fixed plans.
Explain when internal audit should avoid participating in the systems development process: when risk assessment marks the project as low risk, freeing resources for higher-risk areas.
Explore application testing methods across development stages, from alpha and pilot to beta and user acceptance testing, and assess load, throughput, regression, security, sociability, and system testing.
Explore database terminology and relational database structure. See how a customer table stores unique identifiers, addresses, and names to avoid redundancy across sales and inventory data.
Understand how software and application controls are embedded in applications and operating systems, from input controls and data validation to processing, integrity, and output controls, and maintain an audit trail.
Explore common business applications, including customer relationship management systems like Salesforce and module-based ERP systems like SAP, which tie inventory, production, and sales, with GRC supporting governance and compliance.
Explore the information technology reporting structure, from the chief information officer down to operations, technical support, development, data administration, and security, and examine who the CSO reports to.
Explore the COBIT IT control framework for governance and management of enterprise IT, and learn how ISACA and the CSA certification relate to ISO 27,001 audits.
Explore COBIT principles that create value for stakeholders and drive governance across the entire organization, aligning with ISO standards and separating governance from management for stronger internal control.
Examine how IT infrastructure and networks support a client-server model, with servers delivering processing power and storage, and data routed through routers, firewalls, VPNs, gateways, and intranet services.
Explore how business continuity keeps essential services running after a disruption and how disaster recovery focuses on IT, including disaster recovery plans with emergency contacts and initial response steps.
Managers recognize that no plan foresees every contingency, but a thorough recovery plan improves the ability to resume operations quickly after an interruption in business continuity and disaster recovery planning.
Learn data backup and recovery controls, including sun backups and the grandfather-father-son backup model, offsite mirrors, electronic vaulting, cloud backup, and testing for reliable recovery.
Master engagement planning for IT audits by defining objectives, scope, criteria, and procedures, assess risks, and create effective working papers with staffing and standards in mind.
Differentiate extent and nature of audit work using materiality, geographic, department, and time scope; plan engagements with tests of controls, substantive procedures, and analytical methods per standards 2130.
Explore engagement objectives in IT audits, including efficiency and effectiveness of operations, safeguarding assets, profitability, reliable reporting, and compliance, with risk assessment and fraud considerations.
Audit objective of the expenditure cycle focuses on verifying goods paid are received and charged to the correct account, addressing reliability, integrity, compliance, and safeguarding of assets.
In the planning phase, complete and document a detailed risk assessment to identify all significant risks and controls using risk inventories, heat maps, and flowcharts.
Internal auditors assess financial reporting controls, expand scope to cover significant risks, and report findings with due professional care when discoveries affect objectives.
Define engagement work programs and audit programs to map risks and tests in internal audits. Learn how to plan, test, and document controls to cover inherent risks and achieve assurance.
Identify criteria for assurance engagements, including control framework, acts and regulations, and industry best practice, while noting management objectives are not suitable. Explain how engagement objectives validate reporting accuracy.
Map the workflow of an engagement from annual internal audit planning through audit preparation, fieldwork, and report drafting, covering risk assessment, a kickoff meeting, and controls design evaluation.
Internal audit re-evaluates risks and uses fresh eyes through walkthroughs, observations, interviews, process mapping, and benchmarking against ISO standards to perform gap analysis.
Walkthroughs reveal root causes of control deviations, from incomplete understanding to deliberate omissions, and guide training, escalation, or policy redesign to strengthen controls.
Identify how to determine operating effectiveness via a test of controls, not just flowcharts or narratives, with focus on safeguarding assets and background checks.
Examine process maps, workflows, and flowcharts to contrast current, ideal, and actual paths, identify risks, and apply benchmarking across internal, competitive, and best in class standards.
Build a risk-control matrix to create a focused audit program that links objectives, risk, and controls, assesses operating effectiveness, and assigns responsibilities for risk-based IT audits.
Learn to build a risk-control matrix by first understanding objectives and the COSO framework, then identify inherent risks, design and test controls, and report findings.
Identify supervision activities for an internal audit engagement from planning to final report, emphasizing engagement letters, audit program drafts, risk assessment, and adherence to standards by the chief audit executive.
Implement post engagement evaluations and post audit appraisals within internal audit to support a balanced annual performance review, while mitigating recency bias and tracking audits across the year.
Learn supervision best practices for IT audits by coordinating teams, assigning clear areas with responsibility, promoting staff development, and using blocking points to ensure engagement objectives are met.
Discover how high‑quality working papers link risks, objectives, and tests, guiding sign‑off, observations, and recommendations through a structured audit program and quality reviews.
Identify evidence of supervisory review for engagement working papers. Supervisor initials and a memorandum detailing the review provide good evidence; performance appraisals do not, since they occur after engagement.
Learn to communicate engagement results, confirm risk acceptance, and monitor the implementation status of audit recommendations through a structured confirmation meeting.
Communicate audit findings with accuracy, objectivity, and clarity, balancing facts and mitigating circumstances; avoid acronyms, be concise and constructive, and deliver complete, timely reports for all stakeholders.
learn how to communicate interim progress during an it audit, trigger immediate attention for scope changes, and decide whether to include points closed during the audit in the final report.
Communicate audit findings by clearly linking each finding to its risk and root cause, collaborate with action owners to design realistic remediation and follow-up plans that ensure timely reporting.
Discover smart criteria (specific, measurable, achievable, relevant, time-based) for effective IT audit recommendations and build lean reports with clear purpose, scope, findings, action plans, deadlines, and assigned action owners.
Describe engagement opinions and overall opinions, explain positive and negative assurance, and show how risk management maturity and internal control maturity influence qualified opinions and exceptions.
Learn how internal audit reports provide management with actionable recommendations, engage clients for responses, and seek agreement on operating performance criteria before finalizing opinions.
Explore how internal auditors handle acceptance of risk in the it audit process, escalate disputes to senior management and the board, and align risk responses with the organization's risk appetite.
Assess engagement outcomes and follow up on the implementation status of internal audit recommendations, establishing a system to monitor risk mitigation, evidence, and management reporting.
The chief audit executive assesses management's risk acceptance and informs the board. They establish a follow-up process to monitor the adequacy, effectiveness, and timeliness of management's actions.
Cover AI risks, including deepfake fraud, chatbot manipulation, data poisoning, model stealing and model inversion attacks, and guide risk management with the AI use maturity model and ISO 42,001.
Define artificial intelligence and illustrate how neural networks learn from data to output probabilistic results, covering ML, NLP, computer vision, reinforcement learning, AGI and artificial superintelligence concepts.
Explain the EU AI Act's risk-based classification from minimal to unacceptable risk, detailing high-risk controls, transparency, data quality, human oversight, and documentation for responsible AI deployment.
Analyze how AI systems differ by learning methods and cognitive capabilities, from AI agents in environments to symbolic and subsymbolic models, including supervised, semi-supervised, unsupervised, and reinforcement learning.
Describe ethical principles of AI, including fairness, avoidance of bias, transparency, accountability, explainability, privacy, and safety, and emphasize human oversight, reliability, and shared societal benefit.
Explore simple AI use cases for governance, risk management, and compliance (GRC) across organizations. Use AI for anomaly detection, data analytics, and policy management.
Explore descriptive, diagnostic, predictive, and prescriptive AI data analytics, from summarizing data to diagnosing causes, forecasting trends, and recommending decision options.
Explore AI data analytics for compliance, error detection, fraud detection, and anomaly detection, and apply risk analytics and real-time analytics to monitor compliance and detect risks.
Analyze performance, insight, and optimization using advanced data analytics; apply to internal controls, sentiment analysis, network and clustering analysis, and supply chain optimization.
Learn how ISO 42,001 defines an AI management system, guiding planning, doing, checking, and acting through risk assessment, leadership, scope, policies, data, and governance.
Explore the context and scope for implementing ISO 42,001 artificial intelligence management systems, define objectives, assess risks, plan changes, and ensure governance, resources, and awareness.
Explore the annexes of iso 42001 ai management systems, including annex a's statement of applicability, annex b's implementation guidance, and annex c's ai risk assessment guidance.
Explore the diverse roles in an artificial intelligence management system and see how an AI manager coordinates ethics, compliance, data science, risk, operations, and user experience.
We are glad to bring you a course to learn how to perform IT audits.
This course is ideal for:
IT and information security professionals who wish to learn techniques on how to assess their IT systems and the vulnerability of their IT systems; and
Auditors or others performing assessments who wish to learn more about performing IT audits.
The course will give you the knowledge and tools necessary to perform IT audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place.
It is taught by Adrian Resag, an experienced and CISA certified IT and information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations.
The course covers:
Performing IT Audits
Planning Engagements
Understand how to properly plan engagements by determining their objectives, criteria and scope.
Know how to create working papers to document an audit and learn about different ways to staff an audit.
Performing Engagements
Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.
Communicating Progress and Results
Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations.
IT Governance, Controls and Frameworks
IT Management
Know about the management of IT and the layers model of IT management.
Systems Development
Be able to assess systems development methods, including the Systems Development Life Cycle (SDLC) model and how to audit it and the waterfall, spiral, rapid development and agile methods.
Learn about application testing methods.
Databases
Understand and be able to assess relational databases.
Software and Application controls
Know about common application controls you should ensure are in place.
IT Governance, Frameworks and Reporting
Learn about IT governance, IT frameworks and reporting structures.
IT Infrastructure
Know IT infrastructure controls and how to test them.
Business Continuity and Disaster Recovery Planning (BRP/DRP)
Know how to test preparedness Business Continuity Planning and Disaster Recovery Planning (BRP/DRP).
Data Backup and Recovery Controls
Be able to test data backups and controls for recovery.