What this book actually covers and how it differs from everything else on your shelf

Most IT auditing guides start with frameworks and spend three chapters explaining why frameworks matter. It Auditing Using Controls To Protect Information Assets 2nd Edition flips that around. It opens by looking at the asset, then works backward to decide which controls are worth the audit effort. That alone makes it useful. The second edition adds coverage on cloud environments and modern supply chain risks that the first one completely glossed over. The core approach treats controls as the primary mechanism for protecting information assets. You identify what data needs protection, map the controls that should safeguard it, and then test whether those controls actually function as designed. The book walks through that process step by step. Not everything in it is practical though, and some of the examples lean heavily toward enterprise environments with mature governance structures. If you work in a smaller organization with limited resources, certain sections will feel theoretical.

It Auditing Using Controls To Protect Information Assets 2nd Edition

The text is structured around real audit scenarios rather than abstract principles. Each chapter builds on a running case study, which helps when you are trying to understand how different control types interact during an actual engagement. The chapters on logical access controls and change management are the most detailed. The sections on monitoring and continuous auditing feel thinner, partly because the field was still evolving when this edition went to print. That said, the authors acknowledge that gap and point readers toward supplementary resources. What works well here is the emphasis on evidence gathering. Too many books treat documentation as an afterthought. This one spends significant time on what constitutes sufficient audit evidence, how to document control testing results, and how to handle situations where the evidence is incomplete or contradictory. Those chapters are worth reading even if you already have a solid grasp of the audit process itself.

How to apply the methodology in practice

Start by defining your scope. Pick one or two critical information assets — customer PII, financial data, intellectual property — and work from there. The book recommends scoping by asset rather than by system, which is a more defensible approach from an audit standpoint. Systems change. Assets stay relevant longer. When you scope by system, you end up auditing outdated infrastructure that no one cares about. Next, identify the controls. The book distinguishes between preventive, detective, and corrective controls. It also introduces compensating controls as a real option rather than just a footnote. A compensating control is acceptable when the primary control cannot be implemented, but you need to document why and show how the alternative achieves equivalent protection. I had a situation where a legacy application could not support multi-factor authentication, and the remediation path was blocked by vendor constraints. The compensating control I documented was network segmentation combined with session monitoring and restricted privileged access. The auditor accepted it because the risk was mitigated to an acceptable level, even though the primary control was absent. After identifying controls, test them. The book covers control testing techniques including inquiry, observation, inspection, and reperformance. Reperformance is the strongest form of evidence and the one most auditors underuse. When you reperform a control, you are not just asking someone to describe how it works. You are executing the control yourself and verifying the result. That takes more time but produces far more credible findings.

Get the Full Details

IT AUDITING USING CONTROLS TO PROTECT INFORMATION ASSETS, 2ND EDITION ...
IT AUDITING USING CONTROLS TO PROTECT INFORMATION ASSETS, 2ND EDITION ...

Document your results with enough detail that another auditor could replicate your work. This sounds obvious. Most audit working papers fail this test. The book provides templates for documenting control tests, and while they are somewhat generic, they are better than starting from scratch.

Common mistakes and where the methodology falls short

One issue I run into frequently is over-auditing. The framework encourages comprehensive control coverage, but that approach breaks down when you have hundreds of controls across dozens of systems. You end up spending weeks on low-risk areas while missing something material. The book touches on risk-based auditing but does not give enough guidance on prioritization. In practice, you need to weight controls by the likelihood and impact of failure, not just by whether they exist on paper. A control that exists but is never tested or monitored is effectively a null control. Another problem is the assumption that controls operate as designed simply because they are documented. Documentation and operation are two different things. I once audited a company that had elaborate change management procedures written in their policy manual. In reality, changes were being pushed to production without any approval workflow. The control existed on paper. It did not exist in practice. The book advises sampling and testing across multiple periods, which helps catch this discrepancy, but the guidance is not strong enough on how to identify controls that are merely cosmetic. The cloud coverage in the second edition is better than the first, but it still leans toward generic cloud scenarios. Specific platforms like AWS, Azure, and GCP each have different control models and shared responsibility boundaries. The book acknowledges shared responsibility without giving enough depth on how to audit it. If your environment is cloud-heavy, supplement this text with platform-specific audit guidance.

Who should use this and who should skip it

This is useful for internal auditors, IT audit managers, and compliance professionals who need a structured approach to evaluating controls. Junior auditors will benefit from the step-by-step methodology, though they may find some sections dense. People already working in mature audit functions might find the content somewhat basic until you get into the later chapters on advanced monitoring techniques. If you are looking for a quick reference, this is not it. The book is thorough, which means it is long. The index and cross-references are adequate but not exceptional. You will spend more time looking things up than you would with a well-organized companion guide.

IT Auditing Using Controls to Protect Information Assets, 2nd Edition ...
IT Auditing Using Controls to Protect Information Assets, 2nd Edition ...

Where to get a copy

You can find It Auditing Using Controls To Protect Information Assets 2nd Edition through major booksellers and academic suppliers. Look for the ISBN on the publisher's website or check academic databases if you have institutional access. The digital version is available through several e-book platforms. Physical copies tend to be more durable for annotation, which is useful since you will want to mark up the sections on evidence documentation and control testing. The book is part of a broader series on IT auditing and information security. If you find the content useful, the companion titles cover related topics like IT governance and cybersecurity risk assessment. They do not repeat the same material, so they add value beyond this single volume.

A final practical note

Reading this book will not make you a better auditor on its own. The methodology needs to be applied repeatedly before it becomes second nature. The first few audits using this framework will feel slow. You will question whether every step is necessary. By the third or fourth engagement, the process becomes faster and the quality of your findings improves noticeably. The real value is in the consistency it brings to your audit work, not in any single technique or tool it provides.