-
CISA for Internal Auditors: When It Is Worth It, What It Tests and How to Pass
Is the CISA worth it for an internal auditor? Five career profiles, the 2024 job practice translated into audit work, ISACA requirements, fees and waivers, a twelve-week study…
Updated
·
21–31 minutes -
How to Audit AWS: A Practical Program for the Dominant Cloud
An AWS-specific audit program for IT auditors: the estate structure, Organizations guardrails and account vending, root user controls including the 2024 to 2025 MFA requirements and centralized root…
Updated
·
19–29 minutes -
How to Audit Cloud Security: A Control-by-Control Program
A provider-agnostic cloud security audit program: the shared-responsibility test map by service model, criteria (CSA CCM v4, ISO/IEC 27017 and 27018, NIST SP 800-210, CIS Foundations Benchmarks, DORA),…
Updated
·
19–28 minutes -
Auditing Cyber Resilience: Can the Organization Actually Recover?
Recovery-side cyber assurance, distinct from prevention-focused audits: resilience versus security, the frameworks that describe recovery (NIST SP 800-160 Vol. 2, CSF 2.0 Recover, DORA Articles 11 and 12,…
Updated
·
19–29 minutes -
DORA for Internal Auditors: ICT Risk, Incident Reporting, and Resilience Testing
The EU Digital Operational Resilience Act as an evergreen structure for internal auditors: scope and proportionality, the five pillars with their articles and delegated regulations, the ICT risk…
Updated
·
19–28 minutes -
How to Audit End-User Computing: Spreadsheet Risk and the EUC Inventory
The end-user computing audit program: why spreadsheets and other user-built tools keep producing wrong numbers, what counts as an EUC, discovery and inventory from six sources when asking…
Updated
·
19–29 minutes -
Manual, Automated, and IT-Dependent Manual Controls: Testing Implications of Each
The three control natures defined by what can fail, their testing implications side by side (design test, operating test, sample sizes, ITGC reliance, evidence, roll-forward), a five-question classification…
Updated
·
20–30 minutes -
How to Audit the SDLC and DevOps Pipeline
How to audit a modern software delivery pipeline: the five change control objectives mapped from traditional ITGCs to pipeline mechanisms, the standards (NIST SSDF, SLSA, ISO/IEC 27001:2022 A.8.25…
Updated
·
21–31 minutes -
Assessing Cybersecurity With NIST CSF 2.0: An Internal Audit Method
An internal audit method for using NIST CSF 2.0 as assessment criteria: how to scope a first-time assessment by depth, turn the 106 subcategories into agreed criteria, apply…
Updated
·
19–29 minutes -
The Cybersecurity Topical Requirement: A Conformance Workbook
The IIA Cybersecurity Topical Requirement turned into a working checklist: the three domains and seventeen requirements with what to assess, example evidence and the common gap for each,…
Updated
·
22–33 minutes -
How to Audit Active Directory and Entra ID: The Identity Backbone
The directory is the control plane of every other control. The method for auditing Active Directory and Entra ID: why it is in scope of everything, the privileged…
Updated
·
20–30 minutes -
How to Audit Data Privacy Compliance: A GDPR-Anchored Program
Privacy programs have excellent policies and unknown practice. The method for auditing one, anchored on the GDPR and portable to the UK GDPR, the CPRA and the twenty…
Updated
·
20–29 minutes -
How to Audit Patch and Vulnerability Management
You cannot patch what you cannot see. The method for auditing vulnerability and patch management as a program: the frameworks from NIST SP 800-40 Rev. 4 to the…
Updated
·
19–29 minutes -
How to Review a SOC 2 Report: Trust Services Criteria for User Entities
The user entity’s method for a SOC 2 report under the AICPA Trust Services Criteria: what the report is and is not, which of the five categories your…
Updated
·
20–29 minutes -
How to Audit Incident Response: Detection to Post-Mortem
The method for auditing incident response as a program rather than a plan: the eight components and their controls under NIST SP 800-61 Rev. 3 and the IIA’s…
Updated
·
20–30 minutes -
Building the IT Audit Plan: From Risk Assessment to Coverage Map
The technology layer of the audit plan, built in six steps: an IT universe reconciled from sources that already exist, a ten-factor risk assessment with evidence behind every…
Updated
·
20–30 minutes -
Testing Automated Controls and System Configurations: A Non-IT Auditor’s Method
How to test the controls a system performs without anyone watching: the seven types of automated control and where their logic lives, why one well-designed test can cover…
Updated
·
21–31 minutes -
How to Review a SOC 1 Report: A User Entity’s Working Method
The user entity’s method for a SOC 1 report under SSAE 18: what the report is and is not, the five sections and what to read in each,…
Updated
·
21–31 minutes -
How to Audit Backups and Recovery: The Restore Test Is the Only Test
Backups are a job that runs; recovery is an outcome that has been proven or has not. The nine controls with their NIST, ISO, CISA and DORA references,…
Updated
·
23–35 minutes -
How to Audit IT Change Management: From Ticket to Production
The working method for auditing IT change management: the ten controls and their COBIT, ITIL, NIST and COSO references, why the population must come from the production system…
Updated
·
26–38 minutes -
How to Run an ERP Segregation of Duties Analysis (Any Platform)
Vendor rulesets flag thousands of conflicts; a few dozen matter. The platform-agnostic method for an ERP segregation of duties analysis: a conflict matrix built from your own risks…
Updated
·
21–31 minutes -
How to Perform a User Access Review That Actually Works
Most user access reviews are signatures, not reviews. How to build one that removes access: scoping by tier with the right reviewers, population completeness reconciled to the system…
Updated
·
19–29 minutes -
SOX ITGC Scoping: Which Systems Are In, and Why
Which systems belong in SOX ITGC scope, and which do not: the six-step chain from significant accounts to applications, layers and third parties, the layer decision defended by…
Updated
·
19–28 minutes -
How to Audit Privileged Access: Admin Rights, Break-Glass, and Vaulting
Privileged access decides how bad everything else can get. The method for auditing it: privilege defined by capability across every layer from the directory to the database and…
Updated
·
19–28 minutes -
ITGC vs Application Controls: The Dependency Everyone Gets Backwards
An application control is only as reliable as the general controls over the system it runs in. The two layers defined precisely, the mechanism by which each ITGC…
Updated
·
21–31 minutes -
How to Audit Identity and Access Management: The Full IAM Program
Identity is the control plane of everything else. The program audit of identity and access management: the seven domains and their frameworks, the joiner-mover-leaver chain with the leaver…
Updated
·
20–29 minutes -
Auditing Cloud Computing: An Internal Audit Guide to Cloud Risks and Controls
A cloud audit guide for internal auditors: shared-responsibility matrix by service model, an eight-domain work program, a 20-check misconfiguration catalog, a SOC 2 reading checklist and a worked…
Updated
·
26–39 minutes -
AI Audit Framework: Auditing AI and Algorithms for Fairness, Transparency, and Control
A lifecycle AI audit framework with 24 rows of risks, controls, tests, and evidence, a fairness test worked with real numbers, an inventory template and tiering rules, and…
Updated
·
29–44 minutes -
IT General Controls (ITGC) Audit: The Complete Primer for Non-IT Auditors
How to scope and test ITGCs without an IT background: a 24-row test matrix with populations, samples and evidence, a PBC list, a 20-question IT interview script, and…
Updated
·
30–46 minutes -
Auditing Cybersecurity Programs: A Complete Guide for Internal Auditors
How to audit a cybersecurity program at program level: a 22-row NIST CSF 2.0 test matrix, the 17 IIA Topical Requirement assessments, a 1–5 maturity rubric, a 90-day…
Updated
·
34–51 minutes