An internal control framework is a structured guide that organizes and categorizes expected controls or control topics. Some organizations design control frameworks for general purposes, like the COSO internal control framework, while others are more specific, such as the COBIT IT Control framework. Frameworks help the organization design control procedures that create and preserve value while minimizing risk. This session describes the major IT frameworks and their use cases.

This course is a part of IT Audit Bytes series. The other Segments of this series are:

  1. IT Audit Bytes - Access Control
  2. IT Audit Bytes - Backup and Recovery
  3. IT Audit Bytes - Change Management
  4. IT Audit Bytes - Cybersecurity
  5. IT Audit Bytes - Data Loss Prevention
  6. IT Audit Bytes - Disaster Recovery and BCP
  7. IT Audit Bytes - IT Control Frameworks
  8. IT Audit Bytes - Job Monitoring
  9. IT Audit Bytes - Logging and SEIM
  10. IT Audit Bytes - Network Security and Detection
  11. IT Audit Bytes - Password Management
  12. IT Audit Bytes - Physical Security
  13. IT Audit Bytes - Provisioning and Deprovisioning
  14. IT Audit Bytes - SDLC Controls
  15. IT Audit Bytes - Security Awareness Training
  16. IT Audit Bytes - Separation of Duties Controls
  17. IT Audit Bytes - SOC Reports
  18. IT Audit Bytes - Strategy and Governance
  19. IT Audit Bytes - Third-Party IT Risk Management (TPRM)
Learning Objectives
  • Identify and contrast the major IT control frameworks.
  • Describe the use cases for the major IT control framework.
  • Identify and list the steps for auditing with an IT control framework.
Last updated/reviewed: January 31, 2025
Prerequisites
Course Complexity: Foundational
No advanced preparation or prerequisites are required for this course.
Education Provider Information
Company: Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA 95113
Contact: For more information regarding this course, including complaint and cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to .
Instructor for this course
Course Syllabus
INTRODUCTION AND OVERVIEW
  Introduction to IT Control Frameworks0:48
  What is Control Frameworks2:56
  Different Internal Control Frameworks10:27
  Control Testing11:52
CONTINUOUS PLAY
  IT Control Frameworks26:02
SUPPORTING MATERIAL
  Slides: IT Audit Bytes - IT Control FrameworksPDF
  IT Audit Bytes - IT Control Frameworks GlossaryPDF
REVIEW AND TEST
  REVIEW QUESTIONSquiz
 FINAL EXAMexam