In today’s the increasing use of digital technologies among companies has emphasized the importance and role of cybersecurity as a new risk management dimension. Internal audit function as third line defence in preventing cyber-attack become important role to provide assurance to the organization’s cybersecurity. The aim of this systematic literature review (SRL) is to identify the relationship between internal audit and cyber security and develop cybersecurity framework to ensure cyber security risk assessment performed well by internal audit. The systematic literature review utilized the ROSES (RepOrting Standards for Systematics Evidence Syntheses) publication standard and encompassed several research methodologies. Scopus, a highly significant scientific database, was utilized for the article selection in this study. The review only considered articles that were published from 2010 to 2024. The focus of the article primarily was on internal audit and cyber security. This review identified four main themes: internal audit characteristics, internal audit role, information technology and management action. An additional twelve sub-themes were derived from the four main themes. This paper systematically reviewed literature related to the internal audit and cyber security. The findings allow the companies to better understand the importance of cyber security that requires the need for internal audit function to assist the organisations in evaluating the effectiveness and adequacy of controls to mitigate the impact of cyber security risks.
Al-matari, O. M. M., Helal, I. M. A., and Mazen, S. A. (2020) ‘Integrated framework for cybersecurity auditing’, Information Security Journal: A Global Perspective, 30(4), pp. 189–204. Available at: https://doi.org/10.1080/19393555.2020.1834649.
Alazzabi, W. Y. E., Mustafa, H., and Karage, A. I. (2023) ‘Risk management , top management support , internal audit activities and fraud mitigation support’, Journal of Financial Crime, 30(2), pp. 569–582. Available at: https://doi.org/10.1108/JFC-11-2019-0147.
Alqudah, H. (2023) ‘The Mediating Role of Digital Competency between Top Management Support and the Electronic Internal Audit Tasks ’ Effectiveness’, Intenational Journal of Academic Accounting, Finance & Management Research, 7(12), pp. 71–80.
Alzeban, A., and Gwilliam, D. (2014) ‘Factors affecting the internal audit effectiveness?: A survey of the Saudi public sector’, Journal of International Accounting, Auditing and Taxation, 23(2), pp. 74–86. Available at: https://doi.org/10.1016/j.intaccaudtax.2014.06.001.
Betti, N., and Sarens, G. (2020) ‘Understanding the internal audit function in a digitalised business environment’, Journal of Accounting and Organizational Change, 17(2), pp. 197–216. Available at: https://doi.org/10.1108/JAOC-11-2019-0114.
Betti, N., Sarens, G., and Poncin, I. (2021) ‘Effects of digitalisation of organisations on internal audit activities and practices’, Managerial Auditing Journal, 36(6), pp. 872–888. Available at: https://doi.org/10.1108/MAJ-08-2020-2792.
Braun, V., and Clarke, V. (2019) ‘Reflecting on reflexive thematic analysis’, Qualitative Research in Sport, Exercise and Health, 11(4), pp. 589–597. Available at: https://doi.org/10.1080/2159676X.2019.1628806.
Burgemeestre, B., Hulstijn, J., and Tan, Y. H. (2013) ‘Value-based argumentation for designing and auditing security measures’, Ethics and Information Technology, 15(3), pp. 153–171. Available at: https://doi.org/10.1007/s10676-013-9325-2.
Curtis, M. B. (2009) ‘Auditors’ training and proficiency in information systems: A research synthesis’, Journal of Information Systems, 23(1), pp. 79–96. Available at: https://doi.org/10.2308/jis.2009.23.1.79.
Delloite. (2017) ‘Cybersecurity and the role of internal audit - An urgent call to action’, p. 10. Available at: https://www2.deloitte.com/content/dam/Deloitte/us/Documents/risk/us-risk-cyber-ia-urgent-call-to-action.pdf.
Drogalas, G., Arampatzis, K., and Anagnostopoulou, E. (2016) ‘The relationship between corporate governance, internal audit and audit committee?: Empirical evidence from Greece’, Corporation Ownership & Control, 14(1), pp. 569–577.
Duncan, B., and Whittington, M. (2014) ‘Compliance with standards, assurance and audit: Does this equal security?’, ACM International Conference Proceeding Series, (April), pp. 77–84. Available at: https://doi.org/10.1145/2659651.2659711.
Elmaasrawy, H. E., and Tawfik, O. I. (2024) ‘Impact of the assertive and advisory role of internal auditing on proactive measures to enhance cybersecurity: evidence from GCC’, Journal of Science and Technology Policy Management [Preprint]. Available at: https://doi.org/10.1108/JSTPM-01-2023-0004.
Gunawan, B. (2023) ‘Cybersecurity effectiveness: The role of internal auditor certification, risk assessment and senior management’, International Journal of Data and Network Science, 7(4), pp. 1805–1814. Available at: https://doi.org/10.5267/j.ijdns.2023.7.011.
Haddaway, N. R. (2018) ‘ROSES Reporting standards for Systematic Evidence Syntheses: Pro forma, flow-diagram and descriptive summary of the plan and conduct of environmental systematic reviews and systematic maps’, Environmental Evidence, 7(1), pp. 4–11. Available at: https://doi.org/10.1186/s13750-018-0121-7.
Hawkey, K., Muldner, K. and Beznosov, K. (2008) ‘Searching for the right fit: Development of applicant person-organization’, IEEE Internet Comput, pp. 22–30.
Héroux, S., and Fortin, A. (2013) ‘The internal audit function in information technology governance: A holistic perspective’, Journal of Information Systems, 27(1), pp. 189–217. Available at: https://doi.org/10.2308/isys-50331.
Hong, Q. N. (2018) ‘The Mixed Methods Appraisal Tool (MMAT) version 2018 for information professionals and researchers’, Education for Information, 34(4), pp. 285–291. Available at: https://doi.org/10.3233/EFI-180221.
Ibrahim, A. (2018) ‘A security review of local government using NIST CSF: a case study’, Journal of Supercomputing, 74(10), pp. 5171–5186. Available at: https://doi.org/10.1007/s11227-018-2479-2.
IIA (2017) ‘International Standards For The Professional Practice Of Internal Auditing (Standards)’, (October 2016), pp. 1–25.
IIA (2020) ‘THE IIA ’ s Three Line s Model An update of the Three Lines of Defense’, Global Headquarters The Institute of Internal Auditors, p. 13.
IIA (2021) Persevering in a pandemic internal auditors are adapting to change and meeting extraordinary challenges head-on.
Islam, M. S., Farah, N., and Stafford, T. F. (2018) ‘Factors associated with security/cybersecurity audit by internal audit function: An international study’, Managerial Auditing Journal, 33(4), pp. 377–409. Available at: https://doi.org/10.1108/MAJ-07-2017-1595.
Jamison, J., Morris, L., and Wilkinson, C. (2018) ‘The future of cybersecurity in internal audit research report by the internal audit foundation and crowe horwath’. Available at: https://graces.community/wp-content/uploads/2022/01/1640227244602.pdf.
Kahyaoglu, S., and Caliyurt, K. (2018) ‘Cyber security assurance process from the internal audit perspective’, Managerial Auditing Journal, 33(4), pp. 360–376. Available at: https://doi.org/10.1108/MAJ-02-2018-1804.
Kannelønning, K., and Katsikas, S. K. (2023) ‘A systematic literature review of how cybersecurity-related behavior has been assessed’, Information and Computer Security, 31(4), pp. 463–477. Available at: https://doi.org/10.1108/ICS-08-2022-0139.
Kiger, M. E., Meyer, H. S., and Varpio, L. (2021) ‘“It is you, me on the team together, and my child”: Attending, resident, and patient family perspectives on patient ownership’, Perspectives on Medical Education, 10(2), pp. 101–109. Available at: https://doi.org/10.1007/s40037-020-00635-8.
Kitchenham, B. (2009) ‘Systematic literature reviews in software engineering - A systematic literature review’, Information and Software Technology, 51(1), pp. 7–15. Available at: https://doi.org/10.1016/j.infsof.2008.09.009.
KPMG. (2019) ‘The role of internal audit in cyber security readiness’.
KPMG. (2024) ‘Technology risk and its impact on internal audit’.
Kraus, S., Breier, M., and Dasí-Rodríguez, S. (2020) ‘The art of crafting a systematic literature review in entrepreneurship research’, International Entrepreneurship and Management Journal, 16, pp. 1023–1042.
Lockwood, C., Munn, Z., and Porritt, K. (2015) ‘Qualitative research synthesis: Methodological guidance for systematic reviewers utilizing meta-aggregation’, International Journal of Evidence-Based Healthcare, 13(3), pp. 179–187. Available at: https://doi.org/10.1097/XEB.0000000000000062.
Lois, P. (2020) ‘Internal audits in the digital era: opportunities risks and challenges’, EuroMed Journal of Business, 15(2), pp. 205–217. Available at: https://doi.org/10.1108/EMJB-07-2019-0097.
Lois, P. (2021) ‘Internal auditing and cyber security: Audit role and procedural contribution’, International Journal of Managerial and Financial Accounting, 13(1), pp. 25–47. Available at: https://doi.org/10.1504/IJMFA.2021.116207.
Okoli, C. (2015) ‘A guide to conducting a standalone systematic literature review’, Communications of the Association for Information Systems, 37(1), pp. 879–910. Available at: https://doi.org/10.17705/1cais.03743.
Patterson, C. M., Nurse, J. R. C., and Franqueira, V. N. L. (2023) ‘Learning from cyber security incidents: A systematic review and future research agenda’, Computers and Security, 132. Available at: https://doi.org/10.1016/j.cose.2023.103309.
Podsakoff, P. M. (2005) ‘The influence of management journals in the 1980s and 1990s’, Strategic Management Journal, 26(5), pp. 473–488. Available at: https://doi.org/10.1002/smj.454.
PWC. (2023) ‘Cybersecurity disclosures and the role of internal audit’, (August), pp. 1–5.
Rahim, N. H. A. (2015) ‘A systematic review of approaches to assessing cybersecurity awareness’, Kybernetes, 44(4), pp. 606–622. Available at: https://doi.org/10.1108/K-12-2014-0283.
Rodgers, W., Alhendi, E., and Xie, F. (2019) ‘The impact of foreignness on the compliance with cybersecurity controls’, Journal of World Business, 54(6), pp. 1–11. Available at: https://doi.org/10.1016/j.jwb.2019.101012.
Rohan, R. (2023) ‘A systematic literature review of cybersecurity scales assessing information security awareness’, Heliyon, 9(3), pp. 1–26. Available at: https://doi.org/10.1016/j.heliyon.2023.e14234.
Shaffril, H. A. M., Samah, A. A., and Samsuddin, S. F. (2021) ‘Guidelines for developing a systematic literature review for studies related to climate change adaptation’, Environmental Science and Pollution Research, 28(18), pp. 22265–22277. Available at: https://doi.org/10.1007/s11356-021-13178-0.
Sinha, V. K., and Arena, M. (2020) ‘Manifold conceptions of the internal auditing of risk culture in the financial sector’, Journal of Business Ethics, 162(1), pp. 81–102. Available at: https://doi.org/10.1007/s10551-018-3969-0.
Slapni?ar, S. (2022) ‘Effectiveness of cybersecurity audit’, International Journal of Accounting Information Systems, 44, pp. 1–21. Available at: https://doi.org/10.1016/j.accinf.2021.100548.
Stafford, T., Deitz, G., and Li, Y. (2018) ‘The role of internal audit and user training in information security policy compliance’, Managerial Auditing Journal, 33(4), pp. 410–424. Available at: https://doi.org/10.1108/MAJ-07-2017-1596.
Steinbart, P. J. (2012) ‘The relationship between internal audit and information security: An exploratory investigation’, International Journal of Accounting Information Systems, 13(3), pp. 228–243. Available at: https://doi.org/10.1016/j.accinf.2012.06.007.
Steinbart, P. J. (2013) ‘Information security professionals’ perceptions about the relationship between the information security and internal audit functions’, Journal of Information Systems, 27(2), pp. 65–86.
Steinbart, P. J. (2016) ‘SECURQUAL: An instrument for evaluating the effectiveness of enterprise information security programs’, Journal of Information Systems, 30(1), pp. 71–92. Available at: https://doi.org/10.2308/isys-51257.
Steinbart, P. J. (2018) ‘The influence of a good relationship between the internal audit and information security functions on information security outcomes’, Accounting, Organizations and Society, 71, pp. 15–29. Available at: https://doi.org/10.1016/j.aos.2018.04.005.
Taylor, P. J. 2020) ‘A systematic literature review of blockchain cyber security’, Digital Communications and Networks, 6(2), pp. 147–156. Available at: https://doi.org/10.1016/j.dcan.2019.01.005.
Tober, M. (2011) ‘PubMed, ScienceDirect, Scopus or Google Scholar - Which is the best search engine for an effective literature research in laser medicine?’, Medical Laser Application, 26(3), pp. 139–144. Available at: https://doi.org/10.1016/j.mla.2011.05.006.
Wallace, L., Lin, H., and Cefaratti, M. A. (2011) ‘Information security and sarbanes-oxley compliance: An exploratory study’, Journal of Information Systems, 25(1), pp. 185–211. Available at: https://doi.org/10.2308/jis.2011.25.1.185.
Wu, T. H. (2017) ‘The effect of competencies, team problem-solving ability, and computer audit activity on internal audit performance’, Information Systems Frontiers, 19(5), pp. 1133–1148. Available at: https://doi.org/10.1007/s10796-015-9620-z.
Wu, T. H. (2024) ‘IT governance and IT controls: Analysis from an internal auditing perspective’, International Journal of Accounting Information Systems, 52, pp. 1–16. Available at: https://doi.org/10.1016/j.accinf.2023.100663.
Tanujaya, K., Ping, T. A., & Mardianto. (2026). Securing the Digital Frontier by Integrating Cybersecurity into Internal Audit Practices: A Systematic Literature Review and Future Research Agenda. International Journal of Academic Research in Business and Social Sciences, 16(7), 1051-1073.
Copyright: © 2026 The Author(s)
Published by Knowledge Words Publications (www.kwpublications.com)
This article is published under the Creative Commons Attribution (CC BY 4.0) license. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this license may be seen at: http://creativecommons.org/licences/by/4.0/legalcode