The main risks encountered by an organization when conducting an IT infrastructure audit include hiring a potentially dangerous or unqualified person and difficulties in identifying malicious or harmful code. To control or reduce the impact of such risks, an organization is expected to conduct setting checks for potential workers and installs intrusion discovery system. In addition, they ratify information backup procedures (Moeller, 2010) 

