Comparison of COSO and COBIT Control Models Used in Computer Audits for Academic Institutions of Secondary Education in Ibarra City
摘要
The risks and threats to technological resources and information security in educational institutions have increased today. However, the evidence of conducting this process in the IT department of educational institutions in Ibarra is limited or non-existent. Therefore, the objective of the research is to determine, through a comparative analysis, which of the COSO and COBIT control models is the most suitable for conducting an internal IT audit in the secondary education institutions of the city of Ibarra. This analysis will be the basis for the development of a set of guidelines that can be used in an auditing process. The comparison was carried out using four metrics: purpose, supervision and monitoring, information security, and adaptability, determining the degree of compliance on a Likert scale. Therefore, COSO and COBIT can be implemented in IT auditing. An auditing guide for secondary education institutions is proposed, using both control models. This guide was evaluated by experts using the Delphi method, with a 95% alignment with the two control models. The degree of compliance is determined with a Likert scale, resulting in an average score of 4 out of 5 for both models. Therefore, COSO and COBIT can be implemented in IT auditing. Furthermore, a guide for IT audits in secondary education institutions is proposed, utilizing both control models. This guide is evaluated by experts using the Delphi method, and they indicate that they agree with the structure of the proposed IT audit guide, which aligns with the two control models by 95%.