Chapter 7
Chapter 7
Information systems have become an integral part of day-to-day life, and organizations are
adapting to technological changes to survive competition, achieve competitive advantage, and
attain operational excellence
. The application of technology gives rise to risks that may be detrimental to the business,
creating a need for Information System Auditing (ISA)
. The auditor works with management to identify weak controls and risks resulting from the
application of technology and suggests ways to enhance controls to increase IS reliability and
help achieve strategic objectives
--------------------------------------------------------------------------------
Question 1: Define information systems audit. What are the benefits of this audit? What is
CAAT?
2 What are the three primary Confidentiality (disclosure only to authorized users);
objectives (the triad) evaluated Integrity (accurate, reliable, and timely information); and
by an IT audit? Availability (systems available when required)
What are the key It provides assurance that IT systems are adequately protected,
3
benefits of an IS audit? provide reliable information to users, and are properly managed
. It helps reduce risks of data tampering, loss, service disruption, and poor IT management
What is CAAT (Computer An auditing method using computer software tools to query
4
Assisted Audit Techniques)? business data and produce reports that enhance an audit
What are the Time saving (manual tasks done quickly); produces reliable reports
5 benefits of using (auditors create independent reports); and enables a complete review
CAAT in IS audit? of all transactions (100% detail checking) rather than just samples
--------------------------------------------------------------------------------
Question 2: Discuss various issues that are of primary concern for an auditor involved in
information system audit.
Layman Summary: An IS auditor is concerned with the "total systems environment" from the
start of a transaction until it is recorded. They primarily focus on finding controls to ensure
every transaction can be traced (Audit Trail), confirming data integrity, guaranteeing system
changes and overrides are authorized, ensuring adequate security and recovery procedures,
and verifying that all system designs and implementations adhere to policies and
predetermined criteria.
.
What concerns relate to data Controls over the accounting for all data entered into the
2 integrity and accounting system and ensuring the integrity of transactions throughout
controls? the computerized segment of the system
What concerns relate to Control over changes to the computer system to ensure proper
3 system changes and authorization, and establishing authorization procedures for
overrides? system overrides
What concerns relate to Adequate security procedures to protect user data, and
4
infrastructure and security? backup and recovery procedures for system operation
What concerns relate to Testing to determine whether the system performs as stated, and
5 system performance and developing detailed evaluation criteria to determine whether the
evaluation? implemented system has met predetermined specifications
--------------------------------------------------------------------------------
Layman Summary: (Definition covered in Q1). The objectives of IS Auditing fall into two
categories: attesting (focusing on protection and integrity, important for external reports) and
management (focusing on efficiency and effectiveness, important for internal operations).
Overall, the goal is to make sure IT assets are protected, data is accurate, and resources are
used wisely to meet business needs.
What are the two major Attesting objectives (focus on asset safeguarding and data
1 sets of objectives in IS integrity) and Management objectives (focus on
Auditing? effectiveness and efficiency)
2 What is the Data Integrity To maintain the integrity of data at all times, which is fundamental
Objective? for decision-making and competition
What are the System Effectiveness Effectiveness: Auditing system characteristics to ensure
4
and Efficiency Objectives? they meet business and user requirements
. Efficiency: Optimizing the use of IS resources (machine time, software, labor) and minimizing
impact on the computing environment
--------------------------------------------------------------------------------
Question 4: What are the reasons to use risk assessment to determine the areas to be audited.
Layman Summary: Risk assessment is used to strategically manage the audit process. It ensures
the auditor focuses on the most critical threats first, allowing the organization to allocate limited
resources effectively and confirming that the audit work aligns with the overall business
objectives and strategic plans.
Why is risk assessment used Ensures that relevant information is obtained from all levels
2 to determine audit areas? of management, and provides a summary of how the audit
(Relevance & Strategy) subject relates to the overall organization and business plans
Why is risk assessment used to determine Establishes a basis for effectively managing the IT
3
audit areas? (Departmental) audit department/function
.
--------------------------------------------------------------------------------
Question 5: Explain the set of skills that is generally expected of an IS auditor. What is the sole
purpose of audit?
Layman Summary: An IS auditor needs both business acumen (knowing how the company
works) and high technical expertise (understanding IT risks, controls, and best practices). The
entire point of the IS audit is singular: to confirm that automated systems are sufficient to
handle processing needs, that controls are adequate, and that the company’s assets controlled
by IT are protected.
List three key skills Sound knowledge of business operations, requisite professional
1 expected of an IS technical qualification & certifications, and a good understanding
auditor. of Information Risks & Controls
--------------------------------------------------------------------------------
Question 6: What is the scope of IS audit process? Explain major types/ categories of IS Audits in
brief.
Layman Summary: The scope of an IS audit covers everything from the effectiveness of internal
controls to the quality of the system's performance, including how IT is planned and organized.
Audits are categorized based on what they are checking: the specific software application, the
physical data center, the process for developing new systems, the network, or the overall
management structure of the IT department.
. It includes controls for the use and protection of information and resources (data, applications,
facilities, people)
--------------------------------------------------------------------------------
Layman Summary: Auditors classify risks to understand potential failures. Audit Risk means the
auditor misses a significant error. Inherent Risk is the natural weakness of an asset to be
harmed (regardless of controls). Control Risk is the likelihood that the company's internal
controls will fail to catch an error. Detection Risk is the chance that the auditor's testing
procedures will fail to find an error that actually exists.
What is Audit The risk that information contains a material error that may go
1
Risk? undetected during the course of the audit
What is Control The risk that an organization's internal control system will fail to prevent or
3
Risk? detect a material error or gap
What is Detection The risk that the IT auditor’s substantive procedures will not detect an
4
Risk? error which could be material
. (e.g., often high for identifying security breaches because comprehensive logs may not be
unavailable at the time of the audit)
--------------------------------------------------------------------------------
Layman Summary: The audit strategy is the initial high-level blueprint that sets the plan for the
entire audit engagement. It defines the direction, timing, and scope, and outlines how resources
will be allocated. It must be based on known factors like reporting goals and characteristics of
the audit, and it serves as the guide for creating the much more detailed audit plan.
1 What is the purpose of It sets the direction, timing, and scope of an audit, and defines
an IS Audit Strategy? the criteria used to prioritize items in the audit universe and
allocate resources
How does the audit The strategy sets the general guidelines and direction, while the audit
3 strategy relate to the plan is much more detailed, stating the nature, timing, and extent of
audit plan? the specific audit procedures to be conducted
--------------------------------------------------------------------------------
Layman Summary: The IS audit follows a four-step process. 1. Planning (getting permission and
setting the mission via an Audit Charter). 2. Risk Assessment (identifying potential adverse
events to prioritize work). 3. Performance (gathering evidence, testing controls, and
documenting findings). 4. Reporting (communicating the scope, findings, conclusions, and
recommendations to management).
What are the four 1. Audit Planning. 2. Risk Assessment and Business Process
1
phases of IS audit? Analysis. 3. Performance of Audit Work. 4. Reporting
--------------------------------------------------------------------------------
Question 10: What is the basic role of Information System Auditor? What are the ethical issues
associated with information systems?
Layman Summary: (Basic role defined in Q5). Information systems introduce complex ethical
problems because they centralize data and power. Key ethical issues include: who owns the data
(Information Rights), how digital assets are protected (Property Rights), who is responsible
when systems fail (Accountability), what standards of reliability should be demanded (System
Quality), and how technology affects society and culture (Quality of Life).
Ethical Issue: How will traditional intellectual property rights be protected in a digital
3
Property Rights society where tracing ownership and ignoring rights is easy?
.
Ethical Issue: Accountability Who can and will be held accountable and liable for the harm
4
and Control done to information and property rights?
Ethical Issue: System What standards of data and system quality should be demanded to
5 Quality and Quality of protect individual rights? What values and institutions should be
Life preserved in an information society?
--------------------------------------------------------------------------------
Layman Summary: The auditor's role is to ensure that the controls implemented by the
organization are actually effective. This requires the auditor to fully understand all the control
points in the system (from physical access to organizational structure and individual
applications). They test these controls by tracing transactions, using automated software,
interviewing personnel, and inspecting relevant documents and logs.
What is the objective of an MIS To identify all controls that govern individual
1
audit regarding controls? information systems and assess their effectiveness
How does the Interviewing key individuals, examining application controls, tracing the
3 auditor test the flow of sample transactions through the system, and performing tests
controls? using automated audit software
--------------------------------------------------------------------------------
Question 12: Explain the role of information security administrator.
Layman Summary: The Security Administrator is the chief safety officer for the IT environment.
Their job is to set security policies (subject to board approval), classify data to ensure proper
protection, monitor compliance, investigate all security violations, provide training to staff on
security measures, and advise senior management on overall information resource control.
They are responsible for the continuous security program.
How does the Security Responsible for establishing minimal fixed requirements for
2 Administrator manage data classification of information based on physical, procedural,
and access? and logical security elements
--------------------------------------------------------------------------------
What is the Time/Efficiency Manual audit tasks that took many man-hours can be
2
benefit of CAAT? done in a fraction of the time
What is the Reliability Enables the auditor to independently create reports that meet their
3
benefit of CAAT? requirements and are a true reflection of the company’s health
What is the Depth A well-designed CAAT audit reviews 100% of all transactions
4
benefit of CAAT? (complete review) instead of relying on sampling
--------------------------------------------------------------------------------
Layman Summary: (Also covered in Q5 and Q10). The IS auditor’s role is to ensure all aspects of
the system are robust and compliant. This includes verifying IT security, ensuring system
development follows procedures, checking that modifications are authorized, confirming data
processing accuracy, and guaranteeing that identified system issues (bugs) are handled
according to the prescribed process.
.
Role 2: Modifications and To ensure modifications have permissions from the
2
Processing Accuracy. authorities. To ensure data processing is accurate
Role 3: Issue To ensure bugs identified and handled according to the prescribed
3
Handling. process
--------------------------------------------------------------------------------
Layman Summary: This process outlines the specific investigative steps of the audit, which
focuses on where abuse is most likely to happen. The auditor first measures which applications
are most vulnerable, then identifies the potential human sources of threat (e.g., programmers,
users), pinpoints high-risk events where the system could be penetrated (e.g., when data is
altered), and finally conducts the audit check on those vulnerable applications and high-risk
points.
4 Step 4: Check for Conducting the audit of high-risk potential points, considering the
computer abuse. activities of the people who could abuse the IS for the applications that
are highly vulnerable
--------------------------------------------------------------------------------
Question 16: How important is auditing during system development process? Outline some of
the activities of audit or in this regard.
Layman Summary: Auditing is critical during system development because catching and fixing
flaws early is far cheaper and easier than trying to repair a complete, live system. The auditor
works as an assurance provider, ensuring the system meets business objectives, adheres to
standards, and facilitating clear communication among all stakeholders.
--------------------------------------------------------------------------------
Question 17: Describe the role of IS auditor with respect to Physical access controls
Environmental controls.
Layman Summary: The auditor checks controls in two areas. For Physical Access, they ensure
that only authorized personnel can access IT assets by reviewing access logs, procedures, and
touring facilities. For Environmental Controls, they focus on physical safety risks (fire, water,
power) by reviewing policy, checking building plans, inspecting fire equipment, verifying backup
power systems, and observing activities in the Information Processing Facilities (IPF) to confirm
safety practices.
--------------------------------------------------------------------------------
Layman Summary: Concurrent auditing involves running audit tests while the system is
processing live data. Techniques differ in how they interact with live data: ITF uses fake records
alongside real ones; Snapshot records the system state before and after specific transactions
are processed; SCARF and CIS use permanent embedded modules to continuously monitor
transactions based on predefined criteria; and Audit Hooks flag suspicious transactions instantly
for real-time alerts.
--------------------------------------------------------------------------------
Layman Summary: Audits cannot provide 100% assurance due to intrinsic constraints. These
constraints include the need to follow specific financial reporting rules, the inherent limitations
of the audit procedures themselves, and the necessity to complete the audit within a
reasonable timeframe and cost. Due to these limits, audits may not uncover complex issues like
fraud involving senior management, collusion, or events that threaten the company’s future
viability.
List three constraints The nature of financial reporting; the nature of audit
1 that cause audit procedures; and the need for the audit to be conducted within a
limitations. reasonable period of time and at a reasonable cost
What temporal issue is considered Future events or conditions that may cause an entity to
3
an inherent limitation? cease to continue as a going concern
--------------------------------------------------------------------------------
Layman Summary: An audit trail is a log that chronologically records activity at the system,
application, and user level. It serves as an essential detective control. It has two components:
the Accounting Audit Trail (which tracks data source and updates to the database) and the
Operations Audit Trail (which records resource consumption). It is necessary to answer queries,
meet legal requirements, and allow system monitoring.
What is an Logs that record activity at the system, application, and user level. It is an
1
Audit Trail? important detective control to help accomplish security policy objectives
2 What two types of Accounting audit trail (shows the source and nature of data and
trails does it processes that update the database) and Operations audit trail
include? (maintains a record of attempted or actual resource consumption)
What is the purpose To ensure a chronological record of all events is maintained, needed to
3 of audit trail answer queries, fulfill statutory requirements, detect errors, and allow
controls? system monitoring and tuning
--------------------------------------------------------------------------------
Question 21: Explain three major ways by which audit trails can be used to support security
objectives.
Layman Summary: Audit trails help security in three ways. 1. Detection: They can spot
unauthorized access in real-time or after the fact. 2. Reconstruction: They allow analysts to
rebuild the sequence of events leading up to a system failure or security breach, aiding in
recovery. 3. Accountability: They record user activity, which acts as a deterrent (preventive
control) because employees know their actions are logged.
Security Support: Detection can occur in real time (to protect against system
1 Detecting Unauthorized breaches) or after the fact (to determine if unauthorized
Access. access was attempted or accomplished)
--------------------------------------------------------------------------------
Question 22: While doing audit or self-assessment of the BCM program of an enterprise, briefly
describe the matters to be verified.
Layman Summary: When auditing the Business Continuity Management (BCM) program, the
auditor must ensure that the plan is comprehensive, accurate, and practiced. Verification
includes checking that all critical activities are identified, the policies match corporate priorities,
staff competence is adequate, recovery solutions are up-to-date, and there are ongoing
programs for training, maintenance, and handling changes.
BCM Verification: Verify the enterprise’s BCM competence and capability are effective
2 Competence and and fit-for-purpose to manage an incident. Verify the BCM solutions
Solutions. are effective, up-to-date, and appropriate to the level of risk faced
--------------------------------------------------------------------------------
Question 23: What are the steps to be taken by an IS Auditor with respect to IT in the process of
BCP/DRP Audit?
Layman Summary: For an IT-focused BCP/DRP audit, the auditor ensures the plan is realistic and
covers essential technological requirements. This includes checking that the plan matches the
current IT environment, that critical systems are prioritized with reasonable recovery time
requirements, and that backup communication methods are arranged. Most importantly, the
auditor verifies that a robust testing schedule exists (at least annually) and that any weaknesses
found in previous tests have been corrected.
--------------------------------------------------------------------------------
Layman Summary: ISACA provides a framework for IS Audit standards broken into three tiers.
The highest tier, Standards, defines the mandatory, minimum acceptable performance levels.
The second tier, Guidelines, provides advice on how to comply with those mandatory standards.
The lowest tier, Tools and Techniques (like COBIT or audit programs), offers additional useful
guidance but is not mandatory.
1 What is the highest tier Standards: Contain statements of mandatory requirements for IS
of ISACA guidance? audit and assurance. They define the minimum level of
acceptable performance
What is the second Guidelines: Provide guidance and additional information on how to
3 tier of ISACA comply with the mandatory Standards. Professionals should consider
guidance? these when justifying any departure from the standards
--------------------------------------------------------------------------------
Layman Summary: International standards (like COBIT or ISO 27001) are necessary for IT
governance because they provide structured procedures and best practices, which increase the
efficiency, reliability, and security of the IT system
. They help IT managers align technology with business goals, reduce the chances of system
breaks, make rectification easier, and ensure regulatory compliance, ultimately boosting the
company’s performance
What is the primary benefit They provide structured procedures, practices, and steps
1 of adopting IT governance that increase the efficiency, reliability, and effectiveness of
standards? the Information System and its governance
.
They help IT managers bridge the gap between control
How do standards help
requirements, technical issues, and business risks, emphasize
2 with risk and
regulatory compliance, and simplify the implementation of the IT
compliance?
governance framework
What are the practical Reduces the chances of system breaks, makes it easier to identify
3 outcomes of adopting the cause of breaks for rectification, and ensures cost-effective
standards? and secured use of the system
List the six principles that the 1. Responsibility. 2. Strategy. 3. Acquisition. 4. Performance.
4
standard consists of. 5. Conformance. 6. Human behaviour