Course Information
Introduction to IT Auditing
Parking for SAO, Professional Development courses is in Garage B (1511 San Jacinto Blvd.). The Garage signage may read 1511 San Jacinto or Garage B. The elevator in Garage B is not reliable. If you are unable to walk the stairs, please contact the professionaldevelopment@sao.texas.gov for alternate parking arrangements. Handicapped parking is free at the meters around the downtown area.
A course coordinator will email you a parking permit prior to the course start date. A permit must be displayed or you will be ticketed.
Course Description
This comprehensive course is designed for professionals seeking to transition into or advance their career in IT auditing. Whether you're an IT professional, systems administrator, security analyst, compliance specialist, or business professional with technical exposure, this course provides the essential knowledge and practical skills needed to succeed in IT audit roles.
This course serves as your foundation for a rewarding career in IT auditing. Upon completion, you will be prepared to pursue entry-level positions such as:
•IT Auditor / Junior IT Auditor
•IT Compliance Analyst
•Information Security Auditor
•GRC (Governance, Risk & Compliance) Analyst
•Internal Audit Associate (IT focus)
The knowledge gained in this course also provides an excellent foundation for pursuing professional certifications including:
•CISA (Certified Information Systems Auditor)
•CISM (Certified Information Security Manager)
•CIA (Certified Internal Auditor)
•CRISC (Certified in Risk and Information Systems Control)
•CGEIT (Certified in the Governance of Enterprise IT)
Course Objectives
Objectives
Foundational understanding of IT auditing principles and methodologies
Practical skills in risk assessment, control evaluation, and audit execution
Knowledge of industry frameworks and standards (ISO 27001, NIST, COBIT, SOC 2)
Hands-on experience through real-world scenarios and exercises
Confidence to pursue IT audit certifications (CISA, CISM, CIA)
Outline
Module 1: Introduction to IT Auditing
Understand the purpose, scope, and value of IT auditing in modern organizations
Identify the role and responsibilities of IT auditors
Distinguish between internal audits, external audits, and regulatory examinations
Topics Covered:
What is IT auditing and why it matters
Types of IT audits: internal, external, compliance, operational
The IT audit lifecycle: planning, fieldwork, reporting, follow-up
Key stakeholders and the auditor's relationship with management
Professional ethics and independence requirements
Applied Learning Activity: Complete a guided reflection exercise examining common audit scenarios and challenges. Answer short questions about audit scope, stakeholder expectations, and ethical considerations.
Module 2: IT Risk Assessment Fundamentals
Identify and categorize common IT risks across systems and processes
Analyze risk using likelihood and impact assessment techniques
Apply risk assessment methodologies to real-world scenarios
Topics Covered:
Understanding threats, vulnerabilities, and risk exposure
Qualitative vs. quantitative risk assessment approaches
Risk matrices and heat maps
Creating and maintaining risk registers
Documenting risk findings for audit reports
Applied Learning Activity: Analyze a fictional company scenario and identify key IT risks. Use a guided worksheet to assess likelihood and impact, then prioritize risks for audit attention.
Module 3: Internal Controls & Security Frameworks
Understand the concept of internal controls and their role in risk mitigation
Gain familiarity with major IT security and compliance frameworks
Map controls to business objectives and regulatory requirements
Topics Covered:
•Preventive vs. detective controls and their applications
Overview of ISO 27001: Information security management
Overview of NIST Cybersecurity Framework: Risk management
Overview of COBIT: IT governance and management
Overview of SOC 2: Service organization controls
Aligning controls with organizational goals and compliance mandates
Applied Learning Activity: Complete a framework matching exercise. Match real-world control scenarios to the appropriate frameworks (ISO 27001, NIST, COBIT, SOC 2) using an interactive activity.
Module 4: Conducting an IT Audit
Learn the step-by-step process for planning and executing an IT audit
Master evidence collection techniques and documentation best practices
Apply sampling and testing methods to audit scenarios
Topics Covered:
Defining audit scope and objectives
Creating an audit plan and work program
Conducting interviews and walkthrough sessions
Reviewing system documentation and technical configurations
Sampling techniques: judgmental, statistical, and attribute sampling
Testing controls: inquiry, observation, inspection, and re-performance
Applied Learning Activity: Participate in a mini audit simulation. Review sample system documentation for a fictional organization and identify audit evidence, control weaknesses, and information gaps.
Module 5: Audit Tools & Technologies
Explore common tools and technologies used in IT auditing
Understand how automation enhances audit efficiency and effectiveness
Interpret results from vulnerability scans and log analysis tools
Topics Covered:
Audit management and workflow platforms
Log analysis and SIEM (Security Information and Event Management) tools
Vulnerability scanning and penetration testing tools
Configuration review and compliance checking tools
Data analytics and visualization for audit insights
Using spreadsheets and dashboards for audit tracking and reporting
Applied Learning Activity: Watch a recorded demonstration of an audit tool
Instructors
Danny M. Goldberg is a well-known speaker on internal auditing and People-Centric Skills. Danny co-authored People-Centric© Skills: Communication and Interpersonal Skills for Internal Auditors, via Wiley Publications. This is the first book published specifically to address the wide-ranging topic of communication skills for internal auditors. It has been offered through the IIA and ISACA bookstores since July 2015 and has sold over 3,000 copies (through April 2018).
Danny has over 21 years of professional experience, including five years leading/building internal audit functions. Danny was named as one of the Fort Worth Business Press 40 Under 40 for 2014. Danny is also accredited as the Professional Commentator of the Bureau of National Affairs - Internal Audit: Fundamental Principles and Best Practices (Professional Commentator). This book was authored by renowned audit scholars Curtis C. Verschoor and Mort A. Dittenhofer – co-author of Sawyer’s Internal Auditing.