The document discusses essential practices for IT audits, including establishing an audit program and audit resources. It evaluates risk assessment, audit planning, and reporting practices. It also reviews several IT audit methodologies, particularly COBIT which was developed by ISACA and focuses on governance, control, and auditing for IT through processes and control objectives. COBIT is useful for IT audits and implementing IT controls but lacks detailed evaluation methods and control measures.