Google

Wednesday, August 01, 2007

IT AUDIT FUNCTION AND ACTIVITIES

IT auditing is a branch of general auditing concerned with governance (control) of information and communications technologies (computers). IT auditor reviews the adequacy and effectiveness of the controls to minimise the IT related risks. Examples of IT risks are unauthorised access, system down, virus threat and loss of data.


Before planning for audit, IT auditor must have an understanding of the environment under review and perform the followings:-

1. Gain an understanding of the business mission, business vision, business purpose, business processes.

2. Identify policies, standards, guidelines, procedures and organisation structure

3. Evaluate risk assessment carried out by the management

4. Perform a risk assessment

1.Gain an understanding of the business mission, business vision, business purpose, business processes

Steps that will be or have been taken to gain an understanding of the business include:

· Tour key organisation facilities

· Reading background materials including annual report

· Reviewing long-term strategic plans

· Interview or meet with key managers to understand business issue

· Reviewing prior audit reports (internal and external)

2.Identify policies, standards, guidelines, procedures and organisation structure

The purpose of this exercise is to determine the governance (control) in place or control that should be in place.

Legal and statutory regulation should also be look into.

3.Evaluate risk assessment carried out by the management

The purpose of this exercise is to determine the areas of management concern. This will be used to identify the auditable areas.

4.Perform a risk assessment

The purpose of this risk assessment is to classify the risk of auditable areas ranging from high, medium and low and determine the priority of the areas that will be audited.

Labels:

technorati tags:

Wednesday, November 01, 2006

Planning of IT Audit

There are many ways to plan for the IT audit:-

  1. ISACA IS Auditing Standard on Planning. There is also an IS Auditing Guidelines on Use of Risk Assessment in Audit Planning
  2. Global Technology Audit Guide (GTAG), Guide 4: Management of IT Auditing
  3. FFIEC IT Examination Handbook section on Audit.
  4. COBIT can also be used for planing an IT audit. One of the example is aailable at this site:-

Whatever way, the most important things are:-

  • to understand how IT support the business
  • what are the IT risks that could occur
  • what is the impact and the likelihood of the IT risks
  • to ensure that all the high risk IT activities are covered, if not all then majority of the highest risk (priority should be gien to the highest risk)

Labels:

technorati tags:

Sunday, October 15, 2006

IT Audit Standards

Almost every professional fields has it practice standards, e.g. accounting standards, IT standards. IT standards can be generic(e.g. COBIT) or specific for certain topics (BS7799 or ISO17799 which covers IT security)

IS Auditing Standards, Guidelines and Procedures are available at the ISACA website.

The IS Auditing standards cover all the aspect of IT audit process from planning, field work, report writing and communication to the management.

Although it is not mandatory, it is a good start to familiarise and learn about the best practices in the IT audit industry.

Labels: ,

technorati tags:

Sunday, October 08, 2006

Timing IT Audits

by: Joshua Feinberg

IT audits should be short and sweet. Typically within about four hours, you should know exactly what is going on within the company's system, what needs to be done next, how you are going to prioritize the to-do list and what additional hardware, software or other products the company needs to buy.

Because you are proposing a lot of follow-up items, there will be plenty of time to come back for more in-depth work later, so you don't want to get too involved right away. IT audits should provide an overview of issues, not immediate solutions or total fixes.

A Checklist Keeps You On Time
Limiting IT audits to four hours is as easy as coming up with about a dozen different areas you will be addressing. Because you can't look at every single PC or item in one four-hour period, keeping it to these twelve most important things can help you stay on target. The following is an example list of items and their time allocations:

1. Half an hour to an hour on the primary server, which maybe another 20 minutes allotted to a secondary (if available).

2. A few minutes (15) on LAN hub infrastructure

3. A search for various routers and hub switches, 10 to 15 minutes at a time while making some notes on what you find or additional observations about LADs or surge protection.

4. Half an hour to 45 minutes on a few “representative PCs.”
What Is A “Representative Pc”?
A representative PC is one attached to the most important PC users in the company. You can find out who these people are by asking your company contact directly. Looking at two to four representative PCs will give you a good idea of what is happening with configurations, drive mappings, network protocols, and what kind of shape they are in.

IT audits should give you plenty of information about what the hot spots are for a company, what can wait a few weeks or a few months to address and also what can go into the to-do list for a long-term plan. But they should be as short as possible while still giving clients a clear idea about how their systems are functioning.

About The Author
Joshua Feinberg helps computer consultant business owners get steady, high-paying clients. Sign-up now for Joshua's free audio training that shows you how to use field-tested, proven Small Biz Tech Talk tools at http://www.SmallBizTechTalk.com/blog.

Labels:

technorati tags:

Wednesday, September 06, 2006

Why perform IT audit?

The objective of an IT audit is to assess the adequacy of the controls in place to safeguard the informational assets.

In other words, to review the level of IT risks, controls and exposure. My simple equation is: -
IT Risk – IT Control = IT Exposure
Therefore, an IT auditor needs to assess the level of IT risks and controls that exist in order to determine whether there is any exposure.

IT Risks
There are many ways to classify the IT risks.

One of the methods is: -
1.Strategic Risk
2.Compliance Risk
3.System Support Risk
4.Operational Risk
5.Security Risk
6.Business Resumption Risk
7.System Support Risk
8.Reputation Risk

Another way is: -
1.Infrastructure Risk
2.Availability Risk
3.Integrity Risk
4.Access Risk
5.Relevance Risk


I will write more about the risks in another post.

Labels:

technorati tags:

Tuesday, September 05, 2006

What is the scope of an IT Audit?

According to FFIEC Information TechnologyExamination Handbook, the typical scope of an IT audit :-
  • Management
  • Operations
  • Development & Acquisition
  • Information Security
  • Business Continuity Planning

As per COBIT, the scope of an IT audit covers the followings:-

  • Plan & Organise (PO)
  • Acquire & Implement (AI)
  • Deliver & Support (DS)
  • Monitor & Evaluate (ME)

Whether you are using FFIEC, COBIT or any other methodology, the most important thing is to understand your IT environment and how its support the organisation business.

Labels:

technorati tags:

Friday, September 01, 2006

What is IT Audit?

IT = Technology (system/process/method) to produce the information required by the users.

Information = Data that has been processed to suit the user requirements

Audit = assurance and consulting activities

IT Audit is just another branch of audit. It is basically an assurance and consulting activities designed to add value and improve the IT operations.

Interesting websites on IT Audit that you can refer to :-

Labels:

technorati tags: