Course Information
Auditing Cybersecurity Governance and IT Controls in Government Environments
Parking for SAO, Professional Development courses is in Garage B (1511 San Jacinto Blvd.). The Garage signage may read 1511 San Jacinto or Garage B. The elevator in Garage B is not reliable. If you are unable to walk the stairs, please contact the professionaldevelopment@sao.texas.gov for alternate parking arrangements. Handicapped parking is free at the meters around the downtown area.
A course coordinator will email you a parking permit prior to the course start date. A permit must be displayed or you will be ticketed.
Course Description
This course equips government auditors with advanced techniques for auditing and evaluating cybersecurity governance and IT control environments. Participants will evaluate controls using NIST, COBIT, and ISO 27001 frameworks, aligned with Government Auditing Standards and IIA guidance.
The course emphasizes risk-based IT auditing, enabling participants to assess identity management, cloud environments, third-party risks, and IT general controls (ITGCs). Through hands-on audit simulations, participants will strengthen their ability to identify control weaknesses, test controls, and communicate technology risks effectively
Through practical frameworks aligned with NIST, COBIT, and ISO standards, participants will learn how to assess technology governance structures, evaluate the effectiveness of IT general controls, and identify emerging cybersecurity risks that impact operational and regulatory compliance.
Real-world case studies and audit simulations will provide hands-on experience in designing and executing technology audit procedures, documenting findings, and communicating technology risk to leadership.
Course Objectives
Objectives
Upon completion of this course, participants will be able to:
Apply risk-based IT audit methodologies.
Evaluate ITGCs across infrastructure, applications, and cloud systems.
Map cybersecurity frameworks (NIST, COBIT) to audit procedures.
Identify control gaps in identity, access, and data protection.
Design and execute technology audit programs.
Develop defensible audit findings aligned with government standards.
Outline
*Technology Risk and Governance Foundations
1. Overview of Technology Risk in Government Environments
Emerging cybersecurity threats
Technology risk categories
Governance and oversight structures
2. Cybersecurity Governance Frameworks
NIST Cybersecurity Framework
COBIT governance model
ISO 27001 control framework
Mapping frameworks to audit procedures
3. IT General Controls (ITGC) Fundamentals
Identity and access management
Change management controls
System logging and monitoring
Data protection and encryption
4. Third-Party and Cloud Risk Oversight
Shared responsibility models
Vendor risk management
Cloud configuration risk
*Audit Execution and Reporting
1. Designing Technology Audit Programs
Defining audit scope
Risk-based audit planning
Control testing techniques
2. Evaluating Secure Software Development
Secure SDLC principles
Code integrity and testing processes
Application control evaluation
3. Data-Driven Audit Techniques
Leveraging audit analytics
Identifying anomalies in technology environments
4. Audit Documentation and Reporting
Writing defensible findings
Linking evidence to control weaknesses
Communicating cybersecurity risk to leadership
*Case Study: Simulated Cybersecurity Audit Engagement
Participants will conduct a mock technology audit scenario to practice identifying risks, evaluating controls, and developing audit findings.
Prerequisites
Participants should have a basic understanding of auditing principles and internal control concepts. Prior exposure to technology environments or IT auditing is helpful but not required.
Instructors
Evelyn Nkechi Omozeje, MBA, CISA, CISM, is an experienced technology audit and cybersecurity governance leader with extensive expertise in enterprise risk management, technology control oversight, and large-scale audit execution across complex technology environments. She currently serves as an Enterprise Technology Audit Manager (Vice President), leading enterprise-wide technology risk and control assurance engagements across infrastructure, cloud platforms, application security, and automated business controls.
Her work focuses on strengthening organizational governance and regulatory compliance through structured audit programs aligned with internationally recognized frameworks including NIST, ISO 27001, COBIT, SOC 2, HIPAA, and PCI-DSS. Evelyn has led high-impact technology audits evaluating identity and access management, secure system development practices, third-party vendor risk management, cloud security architecture, and enterprise data protection controls.
Throughout her career she has delivered complex integrated audit engagements that assess both business processes and the technology environments that support them. She has worked closely with executive leadership, engineering teams, and risk management functions to identify control weaknesses, design effective remediation strategies, and enhance operational resilience.
Her professional experience includes leadership roles in technology audit, cybersecurity risk management, and enterprise program oversight across major global organizations including financial services and technology environments. She has also led audit initiatives supporting major transformation programs such as large-scale cloud migrations, core banking modernization efforts, and enterprise platform integrations.
Evelyn holds a Master of Business Administration (MBA) and a Bachelor of Science in Accounting. She is a Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) through ISACA, and holds Microsoft cloud certifications including AZ-900 and AZ-305.
Her professional focus is on enabling organizations to strengthen governance, reduce technology risk exposure, and build resilient control environments capable of addressing evolving cybersecurity threats.