Information systems (IS) auditing
"To ensure that IT
and
business systems
are protected and
controlled"
What is IS Auditing?
Information System - IS auditing is the method to examine the effectiveness of the technical and procedural controls to minimize risks towards computer applications, networks and systems.
IT auditing is a branch of general auditing concerned with control of information and communications technologies.
- IT Audit should be conducted regularly (e.g. once per year).
- A audit checklist should be made for each security level/OS, for simplicity.
- The auditor should be independent of the administration and be objective.
- The audit should check: Guidelines, Policies, Users, Management, IT Security managers, Administrators, IT Resources.
IS Audit Procedure
- Audit Planning
- Study & Test Controls
- Audit Report
- Follow UP
Audit Steps:
IS Audit Planning Process
_________________________
Contact us @
_________________________