# Information Technology for Auditors Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/information-technology-for-auditors-course-self-paced>

## Overview

This course teaches federal auditors how information technology is organized, developed, and managed, and how IT affects audit responsibilities in a government environment. Updated to reflect the 2024 Revision of Government Auditing Standards (GAO-24-106786), the course covers essential IT concepts, the impact of technology on audit evidence and methodology, protection of information assets, contingency planning, and the systems development life cycle.

You will examine internal control frameworks including COSO, COBIT, and the Federal Information System Controls Audit Manual (FISCAM), and explore IIA Global Technology Audit Guides (GTAGs) addressing cybersecurity risk, application controls, IT governance, and more. The course also addresses how to evaluate general and application controls, classify control types, and apply standards from GAO, IIA, and ISACA to IT audit engagements. Each module includes practical exercises to reinforce learning.

## What you'll learn

- Describe how information technology is organized, developed, and managed.
- Assess how technology affects you in carrying out your audit responsibilities.
- Apply the standards and guidelines governing audits performed under Government Auditing Standards.

## Curriculum

#### Module 1: Basic Computer Concepts, Components, and Terms

- Organization of IT processes, including hardware, software, data, people, and management structures.
- System components for non-networked and networked environments, including servers, clients, and peripherals.
- Software types: operating systems, access control, database management, and application software.
- Data hierarchy, structures, storage media, and data reliability per GAO guidance.

#### Module 2: Impact of Information Technology on the Auditor

- Changes in audit evidence resulting from information technology.
- Changes in audit methodology driven by IT environments.

#### Module 3: Protection of Information Assets

- Types of security protection required for information assets.
- Critical success factors for effective security.
- Security mechanisms including access control software, encryption, and layered security.

#### Module 4: Contingency Planning

- Processes involved in contingency planning, including business impact analysis.
- Critical success factors for effective planning.
- Alternative recovery methods, strategies, and plan testing.

#### Module 5: Systems Development, Acquisition, Implementation, Maintenance, and Review

- Common software problems and the classic system development life cycle.
- Acquisition of vendor packages and systems maintenance methodologies.
- Reviewing the internal control structure designed into systems.

#### Module 6: Internal Controls

- Internal control frameworks: COSO, COBIT, FISCAM, and related standards.
- Classification of controls: preventive, detective, and corrective; general and application.
- Application controls for input, processing, and output.
- Requirements for an effective system of internal controls in the federal environment.

#### Module 7: Auditing Standards and Guidelines

- Government Auditing Standards, 2024 Revision (GAO-24-106786), including audit risk, data reliability, and information systems controls.
- Federal Information System Controls Audit Manual (FISCAM).
- IIA Global Technology Audit Guides (GTAGs) covering cybersecurity, application controls, IT governance, and more.
- ISACA Control Objectives for Information and Related Technology (COBIT).

## Pricing

**Tuition:** $1049
