Viruses. Worms. Trojans. Denial-of-service attacks. IT security professionals have long wrestled with these and many other external threats, and a bustling industry has sprung up to fend off the pests.

Such risks and others posed by those aiming to compromise corporate IT systems and steal data have garnered nearly all the public attention. And from a compliance perspective, protecting the ramparts against IT security threats is crucial. But it’s only part of a larger story that includes a much less sexy chapter on application controls.

A recent piece of guidance from the Institute of Internal Auditors, “Auditing Application Controls,” may not make ...