Information Systems Audit: The Basics

What should you expect from an IS audit? Jennifer Bayuk spells out the audit process, step by step.

» View Article

READER FEEDBACK
Preview
Anonymous
Tue, 2009-05-19 14:13

Excellent article, covering waaay more than I expected.
Although 'of course' I would have quite some sideline comments like the findings not being required to be in the format listed (rather, C-C-Remainder risk-Cause-Recommendation works better with those responsible (and links to resources like ISACA and others might have helped), I think this is a very worthwhile overview of what audits are about.
Thanks for probably taking away much subconscious fear... The uncertainty and doubt, well, will be brought back in by the auditors ...? ;-)

reply
Anonymous
Wed, 2009-05-20 16:12

You also need to include the work that goes in the beginning, such as defining the Audit universe, the risk & frequency models, determining those areas of greatest risk or concern to the company. These things help define those areas or subjects for auditing, which can then be scoped out.

reply
Jennifer Bayuk
Wed, 2009-06-17 19:34

Though this article does not include a description of the auditor's planning process, that topic is covered in a book I wrote for the Information Systems Audit and Control Association: Stepping Through the IS Audit, A Guide for Information Systems Managers, 2nd Edition. Published in 2005, it is now free online to ISACA members, and also available to non-members at the ISACA online bookstore or Amazon.

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.