Join ITWG e-course "Introduction to Public Sector IT Audit"
In the frame of Research and Training Hub project, EUROSAI IT Working Group has developed a training course "Introduction to Public Sector IT Audit".
The goal of the training course “Introduction to Public Sector IT Audit” is to increase the quality and impact of contemporary audits that frequently include IT components. Therefore, non-IT-auditors and beginner-level IT-auditors would benefit from basic knowledge about IT auditing provided in the training course. The training consists of 7 modules in total.
The course is offered as online course in Moodle environment. There are no time limitations to taking the course - you can take it at your own pace. The exercises in the course material can be taken unlimited number of times. The time required to complete the course is individual, but approximately it is up to 10 hours per module. If you also read additional materials, then accordingly more.
The EUROSAI ITWG Moodle is operated by the EUROSAI ITWG Secretariat / the National Audit Office of Estonia. To take the course, please go to https://training.eurosai-it.org, create your account and start learning.
An overview of modules
The first module IT Audit in a Supreme Audit Institution has five chapters, it starts with an overview of SAI audits with IT components followed by addressing IT components in SAI audits, standards and frameworks relevant to the IT audit, planning of an audit with an IT component, and IT auditing methods.
The second module IT Systems, Software and Data has six chapters - it gives an overview of IT infrastructure, systems, software, and services. In addition, it introduces risks related to data quality, and outlines IT standardization and auditing aspects.
The third module IT Governance has five chapters - it gives an overview of IT governance and related issues, including management. Additionally, it covers IT governance premises and components, frameworks and standards, IT governance in the public sector, as well as auditing aspects of IT governance.
The fourth module Information Security, Protection of Personal Data, and Business Continuity has been developed by colleagues from Bundesrechnungshof (SAI Germany). The study material is available in English, and additionally, German version is also available. It covers topics such as governance in information security management and information security risk management. The study module also gives an overview of operational information security management and business continuity management. Finally, it introduces the design of an information security audit by a supreme audit institution.
The fifth module Procurement and Outsourcing has five chapters. It covers an overview of life cycle, processes and activities of IT procurement and outsourcing. Also, it introduces specific management and technical issues related to IT procurement and outsourcing and related legislation, standards and frameworks. Finally, auditing aspects of IT procurement and outsourcing are presented.
The sixth module IT Development has five chapters. It includes an overview of system and software development processes, life cycles and models, core processes of a representative life cycle model, standards and frameworks relevant from the IT development viewpoint and SAI audits involving components related to IT development.
The seventh module IT Operation and Application Management has five chapters. It opens main concepts of IT operation and application management. and introduces standards and frameworks related to the topic. Also, processes related to IT operation and maintenance are explained and information security aspects, including proper IT administration and change management practices, are covered. Additionally, SAI audits involving components related to IT operation and application management, are being discussed.
In case of any questions or comments, please feel free to contact us at