IT audit team reviewing evidence, controls, and risk reporting during an enterprise systems assessment

Internal IT Audit

Develop capabilities in audit planning, risk assessment, audit procedures, evidence collection, reporting findings, and following up corrective actions in IT environments.

Course Contents

1Course Overview

Are the organization’s IT systems secure and available when required? Could corporate data and information be disclosed without authorization? Is information produced by IT systems accurate, reliable, and timely? These critical information security concerns are examined in detail by the IT Internal Auditor. IT auditing evaluates the design and effectiveness of internal IT controls, including security protocols, development processes, monitoring, and IT governance. Implementing IT controls is essential, but controls alone do not guarantee adequate security.

Those responsible for security must periodically review implemented controls to determine whether they are operating effectively and, when a security breach occurs, ensure prompt action is taken to prevent recurrence. These requirements should be independently examined and reported by objective assessors performing the role of IT Internal Auditor.

Infochief’s "Internal IT Audit" course is built around enterprise information security and control assessment standards. The course is designed for auditors, IT managers, project managers, consultants, information security personnel, risk managers, IT procurement professionals, and executives. Participants should have experience working with at least one major IT system in development, operations management, or IT procurement.

Duration3 days / 6 sessions
Delivery FormatPublic / In-house
LevelIT Audit
CertificationInternal IT Audit

2Training Objectives

  1. Apply recognized knowledge and methods for conducting IT audits based on international practices.
  2. Organize and implement internal IT audit activities in line with international best practices.
  3. Understand audit roles, establish an audit team, and propose audit activities within the organization.
  4. Define an appropriate IT audit scope.
  5. Schedule meetings with management to understand IT processes and policies.
  6. Develop effective interview questions for reviewing processes and IT system management controls.
  7. Identify risks to IT assets and recommend remediation steps to mitigate those risks.
  8. Determine audit priorities and the time required to complete each IT audit assignment.
  9. Comply with IT audit standards established by the organization’s audit function.
  10. Ensure previous IT audit recommendations are addressed and implemented.
  11. Develop IT audit reports that present findings and recommendations for risk management.
  12. Maintain clear and complete IT audit documentation.

3Target Participants

i. IT Auditor
ii. Internal Audit / Internal Control Specialist
iii. Senior IT Manager
iv. IT Manager / Deputy IT Manager
v. IT Supervisor
vi. IT Infrastructure Administrator
vii. IT Team Leader
viii. Others seeking to develop a career in IT auditing

4Course Content

PART 01.THE ROLE OF INTERNAL IT AUDIT
  • What is IT Audit?
  • Roles and Responsibilities of an IT Auditor
  • Professional Ethics for IT Auditors
  • The IT Function’s Perspective on Internal IT Audit
  • IT Audit Quality Standards
  • Keys to Successful IT Auditing
PART 02.IT TECHNICAL, MANAGEMENT & GOVERNANCE KNOWLEDGE
  • IT Systems Architecture
  • Audit Process
  • IT Governance
  • IT Investment and Systems Development Lifecycle
  • IT Services, Operations & System Maintenance
  • Information Asset Protection
  • Disaster Recovery & Business Continuity
PART 03.RISK IDENTIFICATION
  • IT Asset Risks
  • IT Workforce Risks
  • Physical and Environmental Risks
  • Operational Process Risks
  • Access Risks
  • IT Incident Risks
  • Continuity and Contingency Risks
PART 04.IT RISK ASSESSMENT PROCESS
  • What are risks in IT systems?
  • What are IT system threats and vulnerabilities?
  • Risk Treatment Measures
  • IT Risk Management Procedures
  • Inventory IT assets and current risk status
  • Determine the impact scope of assets
  • Analyze the likelihood of incidents
  • Calculate IT risk levels
  • Agree on IT risk treatment approaches
  • Assign accountable owners
PART 05.IT AUDIT PROCEDURES
  • Develop an IT Audit Plan
  • Assess IT Risks
  • Conduct the IT Audit
  • IT Review and Assessment Methods
  • Questioning Techniques in IT Audits
  • Data Collection and Sampling Methods
  • Techniques for Identifying Risk Evidence and Analyzing Impact
  • Evidence Classification (poor / good / excellent)
  • Audit Report Writing and Follow-up
  • Presenting IT Audit Results
  • Sample IT Audit Questionnaire
PART 06.IT AUDIT PRACTICE
  • Audit Computers & Peripheral Devices
  • Audit Servers
  • Audit Internal and External Networks
  • Audit Data Storage Operations
  • Audit Database Management
  • Audit Information Security
  • Audit IT Change Management
  • Audit IT Service Level Agreements (SLA)
  • Audit IT Workforce Management

5Training Methodology

30% theory – 70% practice. The instructor presents the knowledge framework concisely, followed by discussions, case studies, self-assessments, scenario-based exercises, and action planning to strengthen workplace application.

6Class Information & Enrollment

Upcoming Public Training Schedule

Expected Start DateScheduleClass HoursLocationTuition FeeEarly-bird FeeEnroll
--/--/----Saturday – Sunday08:30 – 16:30Ho Chi Minh City8.500.000 VND7.500.000 VNDEnroll
--/--/----Monday – Friday18:00 – 21:30Hanoi8.500.000 VND7.500.000 VNDEnroll
Note: The early-bird fee applies when tuition is paid at least 15 days before the course start date. Learners may register to attend the first session on a trial basis; Infochief will confirm the official schedule with registered learners before the course begins.
Total Training Duration: 3 days / 6 sessions.

In-house Training

DurationClass SizeTuition Fee
3 days / 6 sessions.Up to 25 learners per class.VND 58,500,000 per class delivered at the company’s office.

Additional Costs (if applicable): Depending on the training location, instructor travel and accommodation costs may be charged separately.

Post-course Service: Practical Internal IT Audit consulting after the course. 1. Benefits: - Practice auditing IT systems directly within your organization. - Receive detailed guidance and direct consultation from an expert. - Improve audit effectiveness and quality. 2. Duration: 2 days / 4 sessions. 3. Service fee: VND 48,500,000.

Request In-house Consultation →

7Learning Materials & Certification

Infochief Course Materials

Vietnamese course materials for each module, English reference materials, and sample practical exercises.

IT Templates & Toolkits

Forms, Checklists, Templates, Scorecards, Procedures, Flowcharts, Guidance, Samples, Rules, Policies, Questionnaires, Assessments, and Comparison Charts.

Explore the Toolkits →
Sample Internal IT Audit certificate issued by Infochief Academy

Internal IT Audit

Learners who complete the full program and all end-of-course requirements will receive an “Internal IT Audit” certificate from Infochief Academy.

Certification Information →

8Learner Testimonials

Võ Thanh Uy - Infochief Academy learner
Võ Thanh UyIT Manager · PNJ

The course materials combine international standards with the Vietnamese business context; the instructor’s experience and supporting toolkits help improve practical management effectiveness.”

Lê Nguyễn Thanh Hai - Infochief Academy learner
Lê Nguyễn Thanh HaiIT Manager · PV Trans

The systematic management content, together with toolkits, processes, and templates, gives learners a stronger foundation for implementing IT plans professionally.”

Lương Khánh - Infochief Academy learner
Lương KhánhIT Deputy Manager · OCB

The modules closely reflect the needs of IT managers; discussions, real-world scenarios, and the final project strengthen practical application.”

Đỗ Ngọc Minh - Infochief Academy learner
Đỗ Ngọc MinhIT Manager · Bệnh viện Nhiệt Đới

The course helps systematize existing knowledge and adds practical lessons that are useful for day-to-day IT management.”

View More Learner Testimonials →

9Featured Clients