The following are some IT audit types in descending from strategic to tactical.
|
|
|
Showing posts with label Ch2. Show all posts
Showing posts with label Ch2. Show all posts
Sunday, January 6, 2013
IT Audit Types
IT Audit Planning
At the highest level IT audit planning would involve the following generic steps.
|
Information System Auditing
The problem with hard and fast rules about information system auditing is that each IT environment itself is unique (the snowflake theory). For example, each system will have the following ingredients.
When deciding what and how to audit the following should be considered
- Centralisation
- Hardware
- Empowerment of users
- Software
- Size
- Customisation
- Operating System
- Managed In House
When deciding what and how to audit the following should be considered
- Security, Effectiveness & Efficiency
- Whether issues are pervasive or system specific
- Whether to plan separately or as part of the overall internal audit plan
Subscribe to:
Posts (Atom)