NOTE: This course is updated in January 2025.
Business reliance on information technology and the associated risks are restructuring how auditors audit and what auditors assess.
Section 404 of the Sarbanes-Oxley (SOX) Act, requires public companies, and their auditors to annually assess and report on the design and effectiveness of internal control over financial reporting. The reliability of financial reporting is heavily dependent on a well-controlled IT environment.
Today, every auditor must have a good comprehension of information technology basics and the vulnerabilities, threats and risks that face organizations each day to effectively plan and execute any audit engagement.
In this course, we explore the Key Information Technology General Controls areas that must be addressed to ensure the confidentiality, integrity and availability of data and information assets, as well as the reliability of financial reporting.
Course Key Concepts: ITGC, IT Controls, Information Technology General Controls, SOX 404, IT Audit, ICFR, Internal Control over Financial Reporting, Data Confidentiality, Data Integrity, Data Availability.
Prerequisites
No advanced preparation or prerequisites are required for this course.
Additional takeaways from this course will include templates to help develop:
- Basic Data Center controls assessment questionnaire – to assist in audit planning, scoping and risk assessment
- Basic ITGC audit program – to guide the testing of the design and effectiveness of the ITGCs.
Learning Objective
- Identify and describe the key controls over Access to Programs and Data.
- Explore the main Physical Access and Environmental controls over critical IT Infrastructure.
- Recognize the important Change Management controls.
Last updated/reviewed: January 22, 2025
(0) Reviews
(60 rating)Lesson Questions and Answers0 Questions
Progress
INTRODUCTION AND OVERVIEW
- An Overview to Auditing the Key Information Technology General Controls (ITGC) 2:30
- Introduction to IT General Controls 2:50
- Overview of Relevant Control Frameworks 9:12
- Defining the ITGC and The Types of Controls 6:08
- The Importance of Performing General Audits 7:54
- Four Key Areas- Data Center Physical and Environmental Controls 7:20
- Environmental Control Consideration 10:34
- Power Protection 10:06
- Key Area - Identity and Access Management Control 14:30
- Key Area - Change Management Control 10:40
- Key Area - Data Center Operations Control 7:18
- ITGC Audit Common Deficiencies 6:54
- Conclusion 2:24
CONTINUOUS PLAY
SUPPORTING MATERIAL
- Slide: Auditing the Key Information Technology General Controls (ITGC) PDF
- Auditing the Key Information Technology General Controls (ITGC) Glossary/ Index PDF
Additional Resources
REVIEW AND TEST
- REVIEW QUESTIONS quiz
- FINAL EXAM exam
Auditing the Key Information Technology General Controls (ITGC)
Certified Public Accountant
Online
No advanced preparation or prerequisites are required for this course.

NASBA Sponsor Number: 109504
State of New York Sponsor Number: 002746
State of Texas Sponsor Number: 009890
Chartered Accountant (IES8 CPD)
Online
Certified Management Accountant
Online
No advanced preparation or prerequisites are required for this course.
Certified Fraud Examiner
Online
No advanced preparation or prerequisites are required for this course.
Certified Internal Auditor
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Internal Auditor (CIA) CPE program.
Certification in Risk Management Assurance
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Risk Management Assurance (CRMA) CPE program.
Ask the instructor a question about this lesson