INDEPENDENT IT AND
CYBERSECURITY AUDIT
Are your critical technology controls working in practice?
LiajLiajocom Consulting provides independent, risk-based audits of IT governance, cybersecurity, applications, infrastructure, cloud services, databases, operations and resilience.
The objective is to determine whether technology risks are understood, controls are appropriately designed and management can rely on evidence that those controls operate effectively.
Reliable technology
depends on more than documented procedures
Critical business activities rely on interconnected applications, identities, databases, infrastructure, cloud services, external providers and operational processes. A weakness in one layer can undermine controls elsewhere.
Liajocom Consulting evaluates the control environment as an operating system of responsibilities, processes and technologies, rather than as a collection of isolated policy documents.
When an independent
IT audit adds value
Assurance over critical services
Establish whether the technology and controls supporting important business processes are reliable, secure and appropriately governed.
Change or transformation
Assess risks introduced by cloud migration, system implementation, outsourcing, organisational change, security transformation or new operating models.
Independent challenge
Provide management, boards, Internal Audit, Risk or regulated control functions with an objective assessment of a defined technology domain.
Questions the audit can answer
Determine whether decision rights, control ownership, risk acceptance, escalation and management oversight are defined and operate in practice.
Assess identity lifecycle controls, authentication, privileged access, segregation, periodic review, technical accounts and evidence of accountable use.
Evaluate whether changes are authorised, tested, segregated, traceable, deployed safely and supported by effective emergency procedures.
Examine monitoring, incident management, vulnerability handling, configuration, capacity, job execution, backup, recovery and operational responsibilities.
Assess continuity requirements, dependencies, recovery arrangements, testing, restoration evidence and management understanding of residual risk.
Evaluate supplier due diligence, contracts, performance, security, concentration, subcontracting, continuity, information rights and exit arrangements.
IT and cybersecurity audit scope
Engagements may cover one control domain, one system, one business process or a broader technology environment. Scope and test depth are determined by risk and agreed assurance objectives.
IT Governance
Technology strategy, decision structures, policies, accountabilities, risk ownership, management oversight, resource prioritisation, performance information and alignment with business objectives.
IT General Controls
Access management, change management, computer operations, control monitoring and other foundational controls supporting reliable systems and information.
Cybersecurity
Security governance, risk management, protective controls, vulnerability management, monitoring, incident response, configuration, awareness and evidence of operational effectiveness.
Identity and Access
Joiner, mover and leaver controls, authentication, authorisation, privileged access, technical accounts, segregation of duties, recertification and activity traceability.
Infrastructure and Cloud
Architecture, network security, hosts, platforms, cloud governance, configuration, administrative access, monitoring, tenancy, resilience and shared-responsibility arrangements.
Databases and Applications
Application access, configuration, interfaces, processing integrity, database administration, sensitive data, logging, batch controls, errors and technology-dependent business controls.
Change Management
Request, risk assessment, approval, development, testing, segregation, release, emergency change, rollback, documentation and post-implementation review.
Operations and Resilience
Monitoring, incidents, problems, jobs, capacity, availability, backup, restoration, continuity, disaster recovery, crisis arrangements and resilience testing.
ICT Third-Party Risk and DORA
Provider governance, due diligence, contracts, subcontractors, performance, security, incidents, concentration, continuity, testing, information rights, exit and alignment with relevant DORA control requirements.
A scope proportionate
to the assurance need
Targeted IT Control Review
A focused assessment of one area, such as privileged access, vulnerability management, change control, cloud governance, backup or supplier oversight.
Suitable when:
- A specific concern has been identified
- An incident exposed a possible weakness
- A recent change requires assurance
- One control area needs deeper review
Typical output:
Focused conclusions, findings and recommended actions.
System or Process Audit
An end-to-end audit of the technology and controls supporting a particular application, infrastructure service or business process.
Suitable when:
- The system supports a critical activity
- Several controls must work together
- A major change altered the environment
- Internal Audit needs an independent conclusion
Typical output:
Scope-specific audit report and remediation register.
IT Control
Environment Review
A broader assessment of governance, IT general controls, cybersecurity, operations, resilience and external dependencies.
Suitable when:
- No consolidated assurance view exists
- Several control areas need assessment
- Transformation has changed the risk profile
- Management needs clear priorities
Typical output:
Executive assurance report and risk-based roadmap.
Risk-based and evidence-driven
1
Understand
Establish the system’s purpose, stakeholders, architecture, lifecycle stage, decisions, dependencies, operating context and material risks.
2
Determine criteria
Identify applicable internal requirements, contractual obligations, governance expectations, control objectives and agreed assessment criteria.
3
Examine evidence
Review documentation, configurations, records, data flows, validation results, contracts, monitoring information, logs and other relevant evidence.
4
Test and challenge
Evaluate control design and operation, investigate exceptions, challenge assumptions and determine whether evidence supports management’s assertions.
5
Conclude and report
Connect observations to risks, control objectives, causes, consequences and practical remediation priorities.
Evidence, not promises
Evidence is selected according to the system, risk and audit objective. Liajocom Consulting seeks to corroborate statements through records, configurations and samples where access and scope permit.
Governance and lifecycle evidence
- Strategies, policies and standards
- Committee and management records
- Risk and control assessments
- Roles and responsibility matrices
- Procedures and operating records
- Service and performance reports
- Incident and problem records
- Change and release records
- Continuity plans and test results
- Supplier governance records
Technical and operational evidence
- Identity and access extracts
- Privileged-access records
- System and security configurations
- Network and architecture diagrams
- Vulnerability and patch information
- Logs and monitoring results
- Backup and restoration records
- Application and database settings
- Cloud control information
- Technical supplier evidence
Clear conclusions for management and control functions
Deliverable 1: Executive audit summary
Overall conclusion, significant risks, decisions required and management priorities.
Deliverable 2: Detailed control
assessment
Design and operating-effectiveness conclusions for the controls included in scope.
Deliverable 3: Evidence-based
findings
Clear description of condition, criteria, cause, consequence and recommended response, where supported by the engagement evidence.
Deliverable 4: Risk-prioritised
remediation register
Practical actions organised by significance, dependency and agreed responsibility.
Deliverable 5: Scope and evidence
trail
Record of systems, locations, periods, criteria, evidence and tests supporting the audit conclusion.
Deliverable 6:
Closing presentation
Structured communication for management and relevant governance or control functions.
Every material conclusion should be explainable. Every finding should be supported. Every recommendation should be actionable.
IT audit informed by
hands-on technology experience
Independent

The purpose of the engagement is assurance, not the sale of security products, managed services or technology implementation.
Technically grounded

Liajocom Consulting’s
audit capability is built on prior experience across software, databases,
Windows, Unix and enterprise information systems.
Audit-grade

More than ten years
of IT audit experience in Luxembourg supports disciplined scoping, evidence
assessment, professional challenge and reporting.
Founder-led

The professional
responsible for scoping remains directly involved in testing, conclusions and
reporting.
Important clarification
Frequently asked questions
Yes. The engagement may focus on a single area, such as privileged access, cloud governance, database security, resilience or ICT third-party controls.
No. Control auditing and technical penetration testing are different activities. Liajocom Computing does not provide such specialised testing.
Yes. The engagement can be performed as an independent assignment within an approved Internal Audit plan or as a separate assurance review, subject to clearly defined responsibilities.
Yes. Recommendations are designed to address the identified risk and underlying control weakness. Final implementation decisions remain with management.
Yes. A process-oriented audit can examine both technology controls and the technology-dependent business controls required for reliable processing.