Control de TI y Confianza Digital: Marco Evolutivo Multidimensional del Auditor de Sistemas hacia el Aseguramiento de Ciberseguridad
IT Control and Digital Trust: A Multidimensional Evolutionary Framework for Systems Auditors toward Cybersecurity Assurance
DOI:
https://doi.org/10.65011/prismaods.v5.i5.342Palabras clave:
auditoría de tecnologías de la información, ciberseguridad, aseguramiento, confianza digital, gobernanza tecnológicaResumen
La creciente interdependencia entre tecnologías digitales, ciberseguridad y gobernanza ha ampliado el alcance del auditor de tecnologías de la información y comunicación (TIC), pero la literatura aún presenta de forma fragmentada las dimensiones mediante las cuales evoluciona su capacidad de aseguramiento. Este estudio tuvo como objetivo analizar esa transformación y desarrollar el IT Auditor Evolution Framework (ITAEF). Se realizó una investigación no experimental, documental, descriptiva y analítica mediante una revisión sistematizada de literatura científica y documentación técnica especializada publicada entre 2010 y 2026. Se consideraron artículos revisados por pares en español e inglés, identificados principalmente en Scopus, Web of Science e IEEE Xplore, junto con marcos institucionales relevantes de NIST, ISACA y The Institute of Internal Auditors. Los hallazgos muestran que la evolución del auditor no responde a una trayectoria lineal ni a la sustitución de funciones tradicionales, sino a una reconfiguración multidimensional de capacidades. El ITAEF organiza esta transformación en ocho dimensiones relacionadas con alcance, riesgo, responsabilidades, competencias, técnicas, evidencia, gobernanza y naturaleza del aseguramiento, y propone cuatro orientaciones potencialmente coexistentes: control de TI, riesgo tecnológico, aseguramiento de ciberseguridad y confianza digital. Se concluye que la sofisticación tecnológica no constituye por sí sola evidencia de una transformación sustantiva; esta depende de la capacidad para sustentar conclusiones independientes, oportunas y confiables sobre riesgos digitales complejos.
Descargas
Referencias
Alzeban, A., Al-Hajaya, K., Sawan, N., Chammaa, H., & Foster, S. (2026). The quality of cybersecurity audits: Do synergies among the chief audit executive, IT governance and internal audit functions matter? Managerial Auditing Journal, 41(2), 322–349. https://doi.org/10.1108/MAJ-05-2025-4825
Axelsen, M., Green, P., & Ridley, G. (2017). Explaining the information systems auditor role in the public sector financial audit. International Journal of Accounting Information Systems, 24, 15–31. https://doi.org/10.1016/j.accinf.2016.12.003
Barr-Pulliam, D., Calvin, C. G., Eulerich, M., & Maghakyan, A. (2024). Audit evidence, technology, and judgement: A review of the literature in response to ED-500. Journal of International Financial Management & Accounting, 35(1), 36–67. https://doi.org/10.1111/jifm.12192
Betti, N., & Sarens, G. (2020). Understanding the internal audit function in a digitalised business environment. Journal of Accounting & Organizational Change, 17(2), 197–216. https://doi.org/10.1108/JAOC-11-2019-0114
Betti, N., Sarens, G., & Poncin, I. (2021). Effects of digitalisation of organisations on internal audit activities and practices. Managerial Auditing Journal, 36(6), 872–888. https://doi.org/10.1108/MAJ-08-2020-2792
Calvin, C. G., Eulerich, M., & Holt, M. (2025). Characteristics of cybersecurity and IT involvement by the IA activity. International Journal of Accounting Information Systems, 56, 100726. https://doi.org/10.1016/j.accinf.2025.100726
Chan, D. Y., & Vasarhelyi, M. A. (2011). Innovation and practice of continuous auditing. International Journal of Accounting Information Systems, 12(2), 152–160. https://doi.org/10.1016/j.accinf.2011.01.001
Föhr, T. L., Reichelt, V., Marten, K.-U., & Eulerich, M. (2025). A framework for the structured implementation of process mining for audit tasks. International Journal of Accounting Information Systems, 56, 100727. https://doi.org/10.1016/j.accinf.2025.100727
The Institute of Internal Auditors. (2024). Global Internal Audit Standards. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
The Institute of Internal Auditors. (2026). Three Lines Model: Assurance and advice in support of effective governance. https://www.theiia.org/en/standards/documents/
ISACA. (2024). Digital Trust Ecosystem Framework (DTEF). https://www.isaca.org/digital-trust
ISACA. (2026). IT Audit Framework (ITAF): A professional practices framework for IT audit (5th ed.). https://www.isaca.org/resources/it-audit
Jans, M., Alles, M., & Vasarhelyi, M. (2013). The case for process mining in auditing: Sources of value added and areas of application. International Journal of Accounting Information Systems, 14(1), 1–20. https://doi.org/10.1016/j.accinf.2012.06.015
Jans, M., & Hosseinpour, M. (2019). How active learning and process mining can act as continuous auditing catalyst. International Journal of Accounting Information Systems, 32, 44–58. https://doi.org/10.1016/j.accinf.2018.11.002
Naciones Unidas. (2015). Transformar nuestro mundo: La Agenda 2030 para el Desarrollo Sostenible (A/RES/70/1). https://sdgs.un.org/es/2030agenda
Omousha, M. M., Al-Zoubi, J. H., Bani Yaseen, O. K., AlNsour, S., Al Ebbini, M., & Al Sardi, A. D. A. (2026). The role of IT audit and management in cybersecurity governance: A bibliometric review. EDPACS. Advance online publication. https://doi.org/10.1080/07366981.2026.2631887
Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
Pizzi, S., Venturelli, A., Variale, M., & Macario, G. P. (2021). Assessing the impacts of digital transformation on internal auditing: A bibliometric analysis. Technology in Society, 67, 101738. https://doi.org/10.1016/j.techsoc.2021.101738
Samiolo, R., Spence, C., & Toh, D. (2024). Auditor judgment in the fourth industrial revolution. Contemporary Accounting Research, 41(1), 498–528. https://doi.org/10.1111/1911-3846.12901
Slapničar, S., Axelsen, M., Bongiovanni, I., & Stockdale, D. (2023). A pathway model to five lines of accountability in cybersecurity governance. International Journal of Accounting Information Systems, 51, 100642. https://doi.org/10.1016/j.accinf.2023.100642
Slapničar, S., Vuko, T., Čular, M., & Drašček, M. (2022). Effectiveness of cybersecurity audit. International Journal of Accounting Information Systems, 44, 100548. https://doi.org/10.1016/j.accinf.2021.100548
Spears, J. L., Barki, H., & Barton, R. R. (2013). Theorizing the concept and role of assurance in information systems security. Information & Management, 50(7), 598–605. https://doi.org/10.1016/j.im.2013.08.004
Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2012). The relationship between internal audit and information security: An exploratory investigation. International Journal of Accounting Information Systems, 13(3), 228–243. https://doi.org/10.1016/j.accinf.2012.06.007
Tharwat, H., Hafez, S. T., Elgohary, I. E., & Hassanein, A. (2025). A decade of cybersecurity research in internal auditing: Bibliometric mapping and future research agenda. Discover Sustainability, 6, 1066. https://doi.org/10.1007/s43621-025-02031-w
Volodina, T., Grossi, G., & Vakulenko, V. (2023). The changing roles of internal auditors in the Ukrainian central government. Journal of Accounting & Organizational Change, 19(6), 1–23. https://doi.org/10.1108/JAOC-04-2021-0057
Vuko, T., Slapničar, S., Čular, M., & Drašček, M. (2025). Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing, 29(1), 188–206. https://doi.org/10.1111/ijau.12365
Wassie, F. A., & Lakatos, L. P. (2024). Artificial intelligence and the future of the internal audit function. Humanities and Social Sciences Communications, 11, 386. https://doi.org/10.1057/s41599-024-02905-w
Werner, M., Wiese, M., & Maas, A. (2021). Embedding process mining into financial statement audits. International Journal of Accounting Information Systems, 41, 100514. https://doi.org/10.1016/j.accinf.2021.100514
Yoon, K., Hoogduin, L., & Zhang, L. (2015). Big data as complementary audit evidence. Accounting Horizons, 29(2), 431–438. https://doi.org/10.2308/acch-51076
Publicado
Número
Sección
Licencia
Derechos de autor 2026 Juan Rigoberto Castillo Serracín, Carlos Bruce, Javier Miguel Gómez, Maricella Corpas Ford, Mauricio Rapón (Autor/a)

Esta obra está bajo una licencia internacional Creative Commons Atribución 4.0.
Todo el contenido de Prisma ODS se publica bajo la Licencia Creative Commons Atribución 4.0 Internacional (CC BY 4.0).
Los autores conservan los derechos de autor y otorgan a la revista el derecho de primera publicación.
Se permite la libre copia, distribución, adaptación y reutilización del contenido para cualquier fin legal,
siempre que se otorgue la atribución adecuada a los autores y a la fuente original.
Más información en: https://creativecommons.org/licenses/by/4.0/
















