An IT security audit typically covers various areas, including network security, endpoint security, access controls, identity and access management (IAM), data protection, compliance with regulatory requirements (such as GDPR, HIPAA, PCI DSS), incident response readiness, vendor risk management, and security awareness training.