Skip to main content

Auditing Cybersecurity Governance and IT Controls in Government Environments

Back to Course Schedule
Date(s): May 24, 2027
Time: 8:00AM - 4:30PM
Registration Fee: $329.00
Cancellation Date: N/A
Location: JOHN M. KEEL LEARNING CENTER
City: Austin, TX
Parking Info:

Parking for SAO, Professional Development courses is in Garage B (1511 San Jacinto Blvd.). The Garage signage may read 1511 San Jacinto or Garage B. The elevator in Garage B is not reliable. If you are unable to walk the stairs, please contact the professionaldevelopment@sao.texas.gov for alternate parking arrangements. Handicapped parking is free at the meters around the downtown area.

A course coordinator will email you a parking permit prior to the course start date. A permit must be displayed or you will be ticketed.


Course Description

This course equips government auditors with advanced techniques for auditing and evaluating cybersecurity governance and IT control environments. Participants will evaluate controls using NIST, COBIT, and ISO 27001 frameworks, aligned with Government Auditing Standards and IIA guidance.

The course emphasizes risk-based IT auditing, enabling participants to assess identity management, cloud environments, third-party risks, and IT general controls (ITGCs). Through hands-on audit simulations, participants will strengthen their ability to identify control weaknesses, test controls, and communicate technology risks effectively

Through practical frameworks aligned with NIST, COBIT, and ISO standards, participants will learn how to assess technology governance structures, evaluate the effectiveness of IT general controls, and identify emerging cybersecurity risks that impact operational and regulatory compliance.

Real-world case studies and audit simulations will provide hands-on experience in designing and executing technology audit procedures, documenting findings, and communicating technology risk to leadership.


Potential CPE Credits: 8.0
Govt Hours: This class meets 8.0 hours of the 24-hour requirement for governmental CPE under Government Auditing Standards (yellow book), in most cases.
Technical Hours: This class meets 8.0 CPE credits of technical training in compliance with Texas Admin. Code Rule 523.102.

Instruction Type: Live
Experience Level: ALL
Category: Auditing

Course Objectives

Objectives

Upon completion of this course, participants will be able to:

  • Apply risk-based IT audit methodologies.

  • Evaluate ITGCs across infrastructure, applications, and cloud systems.

  • Map cybersecurity frameworks (NIST, COBIT) to audit procedures.

  • Identify control gaps in identity, access, and data protection.

  • Design and execute technology audit programs.

  • Develop defensible audit findings aligned with government standards.

Outline

*Technology Risk and Governance Foundations

1. Overview of Technology Risk in Government Environments

  • Emerging cybersecurity threats

  • Technology risk categories

  • Governance and oversight structures

2. Cybersecurity Governance Frameworks

  • NIST Cybersecurity Framework

  • COBIT governance model

  • ISO 27001 control framework

  • Mapping frameworks to audit procedures

3. IT General Controls (ITGC) Fundamentals

  • Identity and access management

  • Change management controls

  • System logging and monitoring

  • Data protection and encryption

4. Third-Party and Cloud Risk Oversight

  • Shared responsibility models

  • Vendor risk management

  • Cloud configuration risk

*Audit Execution and Reporting

1. Designing Technology Audit Programs

  • Defining audit scope

  • Risk-based audit planning

  • Control testing techniques

2. Evaluating Secure Software Development

  • Secure SDLC principles

  • Code integrity and testing processes

  • Application control evaluation

3. Data-Driven Audit Techniques

  • Leveraging audit analytics

  • Identifying anomalies in technology environments

4. Audit Documentation and Reporting

  • Writing defensible findings

  • Linking evidence to control weaknesses

  • Communicating cybersecurity risk to leadership

*Case Study: Simulated Cybersecurity Audit Engagement

  • Participants will conduct a mock technology audit scenario to practice identifying risks, evaluating controls, and developing audit findings.


Prerequisites

Participants should have a basic understanding of auditing principles and internal control concepts. Prior exposure to technology environments or IT auditing is helpful but not required.


Instructors

Evelyn Nkechi Omozeje

Evelyn Nkechi Omozeje, MBA, CISA, CISM, is an experienced technology audit and cybersecurity governance leader with extensive expertise in enterprise risk management, technology control oversight, and large-scale audit execution across complex technology environments. She currently serves as an Enterprise Technology Audit Manager (Vice President), leading enterprise-wide technology risk and control assurance engagements across infrastructure, cloud platforms, application security, and automated business controls.

Her work focuses on strengthening organizational governance and regulatory compliance through structured audit programs aligned with internationally recognized frameworks including NIST, ISO 27001, COBIT, SOC 2, HIPAA, and PCI-DSS. Evelyn has led high-impact technology audits evaluating identity and access management, secure system development practices, third-party vendor risk management, cloud security architecture, and enterprise data protection controls.

Throughout her career she has delivered complex integrated audit engagements that assess both business processes and the technology environments that support them. She has worked closely with executive leadership, engineering teams, and risk management functions to identify control weaknesses, design effective remediation strategies, and enhance operational resilience.

Her professional experience includes leadership roles in technology audit, cybersecurity risk management, and enterprise program oversight across major global organizations including financial services and technology environments. She has also led audit initiatives supporting major transformation programs such as large-scale cloud migrations, core banking modernization efforts, and enterprise platform integrations.

Evelyn holds a Master of Business Administration (MBA) and a Bachelor of Science in Accounting. She is a Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) through ISACA, and holds Microsoft cloud certifications including AZ-900 and AZ-305.

Her professional focus is on enabling organizations to strengthen governance, reduce technology risk exposure, and build resilient control environments capable of addressing evolving cybersecurity threats.


Back to Course Schedule