Skip to main content

Introduction to IT Auditing

Back to Course Schedule
Date(s): Dec 01, 2026
Time: 8:00AM - 4:30PM
Registration Fee: $379.00
Cancellation Date: N/A
Location: SAO COMPUTER TRAINING ROOM
City: Austin, TX
Parking Info:

Parking for SAO, Professional Development courses is in Garage B (1511 San Jacinto Blvd.). The Garage signage may read 1511 San Jacinto or Garage B. The elevator in Garage B is not reliable. If you are unable to walk the stairs, please contact the professionaldevelopment@sao.texas.gov for alternate parking arrangements. Handicapped parking is free at the meters around the downtown area.

A course coordinator will email you a parking permit prior to the course start date. A permit must be displayed or you will be ticketed.


Course Description

This comprehensive course is designed for professionals seeking to transition into or advance their career in IT auditing. Whether you're an IT professional, systems administrator, security analyst, compliance specialist, or business professional with technical exposure, this course provides the essential knowledge and practical skills needed to succeed in IT audit roles.

This course serves as your foundation for a rewarding career in IT auditing. Upon completion, you will be prepared to pursue entry-level positions such as:

•IT Auditor / Junior IT Auditor

•IT Compliance Analyst

•Information Security Auditor

•GRC (Governance, Risk & Compliance) Analyst

•Internal Audit Associate (IT focus)

The knowledge gained in this course also provides an excellent foundation for pursuing professional certifications including:

•CISA (Certified Information Systems Auditor)

•CISM (Certified Information Security Manager)

•CIA (Certified Internal Auditor)

•CRISC (Certified in Risk and Information Systems Control)

•CGEIT (Certified in the Governance of Enterprise IT)


Potential CPE Credits: 8.0
Technical Hours: This class meets 8.0 CPE credits of technical training in compliance with Texas Admin. Code Rule 523.102.

Instruction Type: Live
Experience Level:
Category: Auditing

Course Objectives

Objectives

  • Foundational understanding of IT auditing principles and methodologies

  • Practical skills in risk assessment, control evaluation, and audit execution

  • Knowledge of industry frameworks and standards (ISO 27001, NIST, COBIT, SOC 2)

  • Hands-on experience through real-world scenarios and exercises

  • Confidence to pursue IT audit certifications (CISA, CISM, CIA)

Outline

Module 1: Introduction to IT Auditing

  • Understand the purpose, scope, and value of IT auditing in modern organizations

  • Identify the role and responsibilities of IT auditors

  • Distinguish between internal audits, external audits, and regulatory examinations

Topics Covered:

  • What is IT auditing and why it matters

  • Types of IT audits: internal, external, compliance, operational

  • The IT audit lifecycle: planning, fieldwork, reporting, follow-up

  • Key stakeholders and the auditor's relationship with management

  • Professional ethics and independence requirements

Applied Learning Activity: Complete a guided reflection exercise examining common audit scenarios and challenges. Answer short questions about audit scope, stakeholder expectations, and ethical considerations.

Module 2: IT Risk Assessment Fundamentals

  • Identify and categorize common IT risks across systems and processes

  • Analyze risk using likelihood and impact assessment techniques

  • Apply risk assessment methodologies to real-world scenarios

Topics Covered:

  • Understanding threats, vulnerabilities, and risk exposure

  • Qualitative vs. quantitative risk assessment approaches

  • Risk matrices and heat maps

  • Creating and maintaining risk registers

  • Documenting risk findings for audit reports

Applied Learning Activity: Analyze a fictional company scenario and identify key IT risks. Use a guided worksheet to assess likelihood and impact, then prioritize risks for audit attention.

Module 3: Internal Controls & Security Frameworks

  • Understand the concept of internal controls and their role in risk mitigation

  • Gain familiarity with major IT security and compliance frameworks

  • Map controls to business objectives and regulatory requirements

Topics Covered:

  • •Preventive vs. detective controls and their applications

  • Overview of ISO 27001: Information security management

  • Overview of NIST Cybersecurity Framework: Risk management

  • Overview of COBIT: IT governance and management

  • Overview of SOC 2: Service organization controls

  • Aligning controls with organizational goals and compliance mandates

Applied Learning Activity: Complete a framework matching exercise. Match real-world control scenarios to the appropriate frameworks (ISO 27001, NIST, COBIT, SOC 2) using an interactive activity.

Module 4: Conducting an IT Audit

  • Learn the step-by-step process for planning and executing an IT audit

  • Master evidence collection techniques and documentation best practices

  • Apply sampling and testing methods to audit scenarios

Topics Covered:

  • Defining audit scope and objectives

  • Creating an audit plan and work program

  • Conducting interviews and walkthrough sessions

  • Reviewing system documentation and technical configurations

  • Sampling techniques: judgmental, statistical, and attribute sampling

  • Testing controls: inquiry, observation, inspection, and re-performance

Applied Learning Activity: Participate in a mini audit simulation. Review sample system documentation for a fictional organization and identify audit evidence, control weaknesses, and information gaps.

Module 5: Audit Tools & Technologies

  • Explore common tools and technologies used in IT auditing

  • Understand how automation enhances audit efficiency and effectiveness

  • Interpret results from vulnerability scans and log analysis tools

Topics Covered:

  • Audit management and workflow platforms

  • Log analysis and SIEM (Security Information and Event Management) tools

  • Vulnerability scanning and penetration testing tools

  • Configuration review and compliance checking tools

  • Data analytics and visualization for audit insights

  • Using spreadsheets and dashboards for audit tracking and reporting

Applied Learning Activity: Watch a recorded demonstration of an audit tool


Instructors

Danny Goldberg

Danny M. Goldberg is a well-known speaker on internal auditing and People-Centric Skills. Danny co-authored People-Centric© Skills: Communication and Interpersonal Skills for Internal Auditors, via Wiley Publications.  This is the first book published specifically to address the wide-ranging topic of communication skills for internal auditors.  It has been offered through the IIA and ISACA bookstores since July 2015 and has sold over 3,000 copies (through April 2018).

 

Danny has over 21 years of professional experience, including five years leading/building internal audit functions.  Danny was named as one of the Fort Worth Business Press 40 Under 40 for 2014.  Danny is also accredited as the Professional Commentator of the Bureau of National Affairs - Internal Audit: Fundamental Principles and Best Practices (Professional Commentator).  This book was authored by renowned audit scholars Curtis C. Verschoor and Mort A. Dittenhofer – co-author of Sawyer’s Internal Auditing.


Back to Course Schedule