Is Auditing and Assurance
Is Auditing and Assurance
Information
Systems Auditing and Assurance
Assurance:
professional services that are designed to improve the
quality of information, both financial and nonfinancial, used by decision-makers
includes, but is not limited to attestation
Elements of an Audit
Systematic procedures are used
Evidence is obtained
tests of internal controls
substantive tests
Phases of an IT Audit
Organizational Structure
Internet
& Intranet
Operating
System
Data
Management
Internet
& Intranet
Systems
Development
EDI Trading
Partners
Systems
Maintenance
Personal Computers
Applications
Controls:
access - encryption, user authorization tables,
inference controls and biometric devices are a few
examples
backup - grandfather-father-son and direct access
backup; recovery procedures
Controls:
review organizational & systems documentation,
observe behavior, and review database authority tables
increased supervision
access & security controls
backup controls
systems development and maintenance controls
systems development and acquisition controls
Substantive Testing:
EAM
screen data
statistical sampling methods
foot & balance
format reports
compare files and fields
recalculate data fields
Substantive Testing:
GAS