Information Systems Auditing, Controls and Assurance

I completed Information Systems Auditing, Controls and Assurance from the Hong Kong University of Science and Technology on Coursera in April 2024.

The course covered how auditors connect business risks to IT controls, collect evidence and report findings. Its case studies complemented the control testing I was doing in my audit work.

Category

Information Security

Issued By

The Hong Kong University of Science and Technology

Platform

Coursera

Completion Date

28th April 2024

Verification Link

Curriculum

  • Audit objectives and frameworks, including COBIT, ISO 27001 and ITIL.
  • Business risks and the controls used to address them.
  • Audit planning, fieldwork, evidence and reporting.
  • Controls over access, changes and the system development lifecycle.
  • Risks involving cloud computing, fintech and data.
  • Audit opinions and communication of findings.

What I learned

I reviewed how to evaluate control design and operating effectiveness, document testing and connect findings to business risk. The case studies helped me think through what evidence supports an audit conclusion.

The course was useful for revisiting the reasoning behind ITGC testing, especially the link between a control objective, the test performed and the conclusion reported.