Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
How to Perform an IT Audit
Rating: 4.5 out of 5(136 ratings)
944 students

How to Perform an IT Audit

What you need to know to perform IT audits
Last updated 4/2025
English
English [Auto],

What you'll learn

  • Understand how to properly plan engagements by determining their objectives, criteria and scope.
  • Know how to create working papers to document an audit and learn about different ways to staff an audit.
  • Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.
  • Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit
  • Know about the management of IT and the layers model of IT management.
  • Be able to assess systems development methods, including the Systems Development Life Cycle (SDLC), waterfall, spiral, rapid development and agile methods.
  • Learn about application testing methods.
  • Understand and be able to assess relational databases.
  • Know about common application controls you should ensure are in place.
  • Learn about IT governance, IT frameworks and reporting structures.
  • Know IT infrastructure controls and how to test them.
  • Know how to test preparedness Business Continuity Planning and Disaster Recovery Planning (BRP/DRP).
  • Be able to test data backups and controls for recovery.

Course content

3 sections66 lectures7h 48m total length
  • The Layers Model of IT Management3:09

    Discover the layers model of IT management, from IT management and external connections to technical infrastructure, and how these layers support business applications, business continuity, and disaster recovery planning.

  • Systems Development Life Cycle (SDLC) Model5:35

    Explore the systems development life cycle, from planning and analysis to design, programming, testing, and deployment, including in-house development, system selection, or off-the-shelf customization with user-driven refinement.

  • Auditing the Systems Development Life Cycle (SDLC) Model4:31

    Assess project feasibility within the SDLC by involving internal audit in systems analysis, ensure ISO 27,001 information security controls, and verify designs through user acceptance testing and implementation.

  • Types of Systems Development Methods4:10

    Explore systems development methods such as waterfall, spiral, rapid development, and agile, noting phase order, overlapping work, and continuous improvement. Rapid development may waste resources, as the F-35 example shows.

  • Waterfall Method0:19

    Explain how the waterfall method uses stage-by-stage sign-offs to improve control and reduce waste, while highlighting its inflexibility and longer deadlines.

  • Spiral Method0:44

    Apply the spiral method to IT audits by iterating through objectives, risk identification and assessment, and solution development, with regular reviews and re-evaluation.

  • Rapid Development1:28

    Leverage rapid development to speed information technology audit projects by performing steps in parallel, using brainstorming workshops, and building multiple prototypes to shorten development time.

  • Agile Method4:55

    Learn how the agile method promotes continuous iteration, concurrent development and testing, and a customer-centered, collaborative approach that embraces change over fixed plans.

  • Question on Systems Development Methods2:20

    Explain when internal audit should avoid participating in the systems development process: when risk assessment marks the project as low risk, freeing resources for higher-risk areas.

  • Application Testing Methods8:39

    Explore application testing methods across development stages, from alpha and pilot to beta and user acceptance testing, and assess load, throughput, regression, security, sociability, and system testing.

  • Question on Application Testing Methods1:38
  • Databases - Terminology4:04

    Explore database terminology and relational database structure. See how a customer table stores unique identifiers, addresses, and names to avoid redundancy across sales and inventory data.

  • Relational Databases2:38
  • Software and Application Controls5:25

    Understand how software and application controls are embedded in applications and operating systems, from input controls and data validation to processing, integrity, and output controls, and maintain an audit trail.

  • Common Applications3:34

    Explore common business applications, including customer relationship management systems like Salesforce and module-based ERP systems like SAP, which tie inventory, production, and sales, with GRC supporting governance and compliance.

  • IT Reporting Structure6:21

    Explore the information technology reporting structure, from the chief information officer down to operations, technical support, development, data administration, and security, and examine who the CSO reports to.

  • IT Control Framework - COBIT1:35

    Explore the COBIT IT control framework for governance and management of enterprise IT, and learn how ISACA and the CSA certification relate to ISO 27,001 audits.

  • IT Control Framework - COBIT Principles5:28

    Explore COBIT principles that create value for stakeholders and drive governance across the entire organization, aligning with ISO standards and separating governance from management for stronger internal control.

  • IT Infrastructure5:28

    Examine how IT infrastructure and networks support a client-server model, with servers delivering processing power and storage, and data routed through routers, firewalls, VPNs, gateways, and intranet services.

  • Business Continuity and Disaster Recovery Planning (BCP-DRP)5:50

    Explore how business continuity keeps essential services running after a disruption and how disaster recovery focuses on IT, including disaster recovery plans with emergency contacts and initial response steps.

  • Question on Business Continuity and Disaster Recovery Planning (BCP-DRP)0:22

    Managers recognize that no plan foresees every contingency, but a thorough recovery plan improves the ability to resume operations quickly after an interruption in business continuity and disaster recovery planning.

  • Data Backup and Recovery Controls5:05

    Learn data backup and recovery controls, including sun backups and the grandfather-father-son backup model, offsite mirrors, electronic vaulting, cloud backup, and testing for reliable recovery.

Requirements

  • No prior experience or knowledge is required.

Description

We are glad to bring you a course to learn how to perform IT audits.

This course is ideal for:

  1. IT and information security professionals who wish to learn techniques on how to assess their IT systems and the vulnerability of their IT systems; and

  2. Auditors or others performing assessments who wish to learn more about performing IT audits.

The course will give you the knowledge and tools necessary to perform IT audits, starting from how to plan them, how to perform and how to report on the results of the engagement. It will teach you about which threats to assess and which controls should be put in place.

It is taught by Adrian Resag, an experienced and CISA certified IT and information security auditor who has decades of experience evaluating information security, IT and ISO 27001 in many organizations.


The course covers:

Performing IT Audits

Planning Engagements

  • Understand how to properly plan engagements by determining their objectives, criteria and scope.

  • Know how to create working papers to document an audit and learn about different ways to staff an audit.

Performing Engagements

  • Learn how to collect engagement information and then analyze and evaluate it. Learn how to supervise engagements.

Communicating Progress and Results

  • Learn how to communicate engagement results and the process of acceptance of risks. Learn how to monitor progress on the implementation status of internal audit recommendations.

IT Governance, Controls and Frameworks

IT Management

  • Know about the management of IT and the layers model of IT management.

Systems Development

  • Be able to assess systems development methods, including the Systems Development Life Cycle (SDLC) model and how to audit it and the waterfall, spiral, rapid development and agile methods.

  • Learn about  application testing methods.

Databases

  • Understand and be able to assess relational databases.

Software and Application controls

  • Know about common application controls you should ensure are in place.

IT Governance, Frameworks and Reporting

  • Learn about IT governance, IT frameworks and reporting structures.

IT Infrastructure

  • Know IT infrastructure controls and how to test them.

Business Continuity and Disaster Recovery Planning (BRP/DRP)

  • Know how to test preparedness Business Continuity Planning and Disaster Recovery Planning (BRP/DRP).

Data Backup and Recovery Controls

  • Be able to test data backups and controls for recovery.

Who this course is for:

  • Current or future IT and information security professionals who wish to learn techniques on how to assess the security of their information and the vulnerability of their IT systems.
  • Auditors or others performing assessments who wish to learn more about performing IT audits.