
Learn the foundational principles of IT audit and how controls support effective IT auditing, building a solid understanding of auditing fundamentals.
Define IT audits and controls, explain the hierarchy of controls and the role of key controls in mitigating risks, while noting audits provide reasonable assurance about data completeness and accuracy.
Explore why organizations implement controls for reliable financial reporting, regulatory compliance, operational efficiency, and system security, and learn the elements of an adequate control, including activity, frequency, and evidence.
Identify the three main control types: preventive, detective, and corrective, and see how they prevent, detect, and correct issues with practical examples like access authorization and change management.
Define the IT audit and controls, outline the hierarchy and purposes, identify basic elements and the three main types, and review control examples.
Test controls to determine they fulfill their purpose, distinguishing IT general controls from application controls. Learn about approval limits, authentication, and how these controls support the audit.
Explore the design and operating effectiveness testing of IT general controls, including password controls, testing techniques, and selection sizes, to assess control effectiveness.
Understand how to select representative samples for controls testing, using frequency and risk of failure to determine minimum test items that cover the audit period.
Explore why we test controls, the types of controls and tests, and how to select testing approaches to strengthen IT audit fundamentals.
Finish this course confidently as you confirm the objectives are met and grasp the fundamentals of IT auditing; contact the instructor with any questions.
Explore the ten logical security controls, from policies and procedures to segregation of duties, and learn how to identify, test, and review access across the CIA triad.
This course is for beginners that are interested in a career in IT Audit, Compliance, Governance, Risk and Controls (GRC), or Cybersecurity. This course teaches the foundational principles that are needed for a successful career in the IT Audit and Compliance field.
This is a beginner level course for those that are new to IT Audit. However, the course is also valuable for those looking to refresh their basic knowledge about IT Audits. This course is not for those that do not need a foundational knowledge/refresher of IT Audits. See link in my profile for more information on other courses.
This course teaches the practical aspects of conducting IT audits and is not focused on the CISA certification. CISA aspirants can still benefit from taking this course because they will learn and better understand basic IT Audit concepts in preparation for the exam.
Instructional Goal
Upon completion of this course, students will be able to understand some basic principles around IT Audit and Controls Testing.
Learning Objectives
Upon completion of this course, students should be able to:
1. Understand what an IT Audit is
2. Understand what controls are and their importance
3. Understand the key elements of controls
4. Understand the different types of controls (including IT General Controls and Application Controls)
5. Understand how to select the correct sample size to test controls
Quizzes
Quizzes to reinforce learning objectives are included