An internal control framework is a structured guide that organizes and categorizes expected controls or control topics. Some organizations design control frameworks for general purposes, like the COSO internal control framework, while others are more specific, such as the COBIT IT Control framework. Frameworks help the organization design control procedures that create and preserve value while minimizing risk. This session describes the major IT frameworks and their use cases.
This course is a part of IT Audit Bytes series. The other Segments of this series are:
- IT Audit Bytes - Access Control
- IT Audit Bytes - Backup and Recovery
- IT Audit Bytes - Change Management
- IT Audit Bytes - Cybersecurity
- IT Audit Bytes - Data Loss Prevention
- IT Audit Bytes - Disaster Recovery and BCP
- IT Audit Bytes - IT Control Frameworks
- IT Audit Bytes - Job Monitoring
- IT Audit Bytes - Logging and SEIM
- IT Audit Bytes - Network Security and Detection
- IT Audit Bytes - Password Management
- IT Audit Bytes - Physical Security
- IT Audit Bytes - Provisioning and Deprovisioning
- IT Audit Bytes - SDLC Controls
- IT Audit Bytes - Security Awareness Training
- IT Audit Bytes - Separation of Duties Controls
- IT Audit Bytes - SOC Reports
- IT Audit Bytes - Strategy and Governance
- IT Audit Bytes - Third-Party IT Risk Management (TPRM)
Prerequisites
No advanced preparation or prerequisites are required for this course.Learning Objective
- Identify and contrast the major IT control frameworks.
- Describe the use cases for the major IT control framework.
- Identify and list the steps for auditing with an IT control framework.
Last updated/reviewed: March 16, 2025
(0) Reviews
(0 rating)Lesson Questions and Answers0 Questions
Progress
INTRODUCTION AND OVERVIEW
- Introduction to IT Control Frameworks 0:48
- What is Control Frameworks 2:56
- Different Internal Control Frameworks 10:27
- Control Testing 11:52
CONTINUOUS PLAY
- IT Control Frameworks 26:02
SUPPORTING MATERIAL
- Slides: IT Audit Bytes - IT Control Frameworks PDF
- IT Audit Bytes - IT Control Frameworks Glossary PDF
REVIEW & TEST
- REVIEW QUESTIONS quiz
- FINAL EXAM exam
IT Audit Bytes - IT Control Frameworks
Certified Public Accountant
Online
No advanced preparation or prerequisites are required for this course.

NASBA Sponsor Number: 109504
State of New York Sponsor Number: 002746
State of Texas Sponsor Number: 009890
Chartered Accountant (IES8 CPD)
Online
Certified Management Accountant
Online
No advanced preparation or prerequisites are required for this course.
Certified Fraud Examiner
Online
No advanced preparation or prerequisites are required for this course.
Certified Internal Auditor
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Internal Auditor (CIA) CPE program.
Certification in Risk Management Assurance
Online
No advanced preparation or prerequisites are required for this course.

Recognized CPE provider, authorized by the Institute of Internal Auditors for use in the Certified Risk Management Assurance (CRMA) CPE program.
Certified Information Security Manager
Online
Certified in Risk and Information Systems Control
Online
Certified Identity and Security Technologist
Online
Ask the instructor a question about this lesson