CYBERSECURITY -3rd line: independent and objective
assurance on governance, risk mgmt., and
-tech, processes, and practices designed to
controls
protect and org’s info assets from
unauthorized access -senior mgmt. and BoD
-controls: IT AUDIT
-strong security frameworks -tech has changed competencies for internal
auditors
-identifying and controlling top risks
-data analytics: how to analyze data and use
-cybersecurity awareness programs
audit software tools
-consideration of internal and
-cybersecurity: key components of info
external threats
security
-strong info security governance
-business continuity and disaster recovery:
-robust response protocol understanding business areas and practices
for recovery
FACTORS AFFECTING IT AUDIT APPROACH
-change mgmt.: knowledge of project mgmt.
1. Proliferation of tech = ^user access
and change processes
2. ^connected devices
-set of controls to mitigate risks
COMMON SOURCES OF CYBER THREATS
during transitions/changes w/in the
1. Nation-states entity
2. Cybercriminals
-newer tech: being tech savvy w/ current
3. Hacktivists
issues one emerging tech and potential
4. Insiders and service providers
impact
5. Developers of substandard services
and products -auditors that work extensively on IT must
have deep IT risk, control and audit expertise
THREE LINES OF DEFENSES FOR IT
-every internal auditor must have a sound
-1st line: mgmt. owns and manages data,
understanding of certain fundamental IT
processes, risks, and controls
concepts
-employees
KEY COMPONENTS OF MODERN UT
-2 line: risk, control, and compliance
nd SYSTEMS
oversight
1. Computer hardware
-by mgmt. -physical components
2. Networks
-ensures that 1st line processes and
-links computers/devices to share
controls are existing and operating
info and workloads
effectively
-client server network: connects 4. Database
client computers with a server -large repository of data contained in
-info processing shared linked files
between client and server -allows data to be easily accessed,
retrieved, and manipulated
-Local area network (LAN): small
-operating database: day-to-day
area (same bldg.)
transaction processing and is
-wide area network (WAN): system continuously updated
of connected LANs -data warehouse: large assemblage
of data stored overtime to support
-intranet: org’s private network
online data analysis and decision
accessible only to org personnel
making
-extranet: accessible to selected 3rd 5. Information
parties (customers/suppliers) -key resource for all enterprises
-information systems: collect, store,
-value-added network (VAN): 3rd
transform data into useful info for
party network that connects org w/
internal and external decision makers
trading partners
6. People
-internet: interconnected networks -chief information officer (CIO):
that is a large and complex system of daily oversight and direction of IT
computer networks -ensures alignment of IT
objectives with overall
3. Computer software
business objectives
-operating system: controls basic
input, processing, and output of the -chief information security officer
computer (CISO): established info security
-manages interconnectivity of polices, procedures, and practices
system hardware devices
-implements monitoring
-utility software: encryption, disk networks and indiv access
space optimization, virus protection control
-database management system -trains indivs on importance of
software: manages data w/in security on corporate access
database, controls access, and and systems
automatically backs-up data
-database administrator: supervises
-application software: used to the design, devt, implementation, and
process transactions maintenance of database, controlling
access, monitoring performance, and
-firewall software: enforces access
upgrade database based on user
controls between networks by
needs
allowing only authorized data
transmissions
-system developers -org cannot effectively and
efficiently implement EDI if
-analysts: survey IT user
trading partners does not have
needs and design new IT
it
systems (what is vs what
should be) -risk: possibility that an event will occur that
will negatively affect the achievement of org
-programmers: construct and
objectives
test software
-power outages,
-information processing personnel:
intercepted/stolen/misused info,
manages centralized IT resources
inaccurate programmed software give
from centralized daily input,
out inaccurate info, infiltrated
processing, and output activities
databases, info risk (invalid info
-end users: managers and employees leading to poor decisions), and
that use the info from the system conceal errors/fraud
IT OPPORTUNITIES AND RISKS IT RISKS
-opportunities: possibility that an event will -not mutually exclusive
occur that will positively affect the
1. Strategic and operational risk
achievement of org objectives
-selection risk: selection of IT
-selling goods online solution is misaligned w/ strategic
objective
-Enterprise Resource Program
-incompatibility of IT solution
(ERP): modular system that integrates
to org system
business processes in one operating
-caused by unqualified
database
decision-makers and
-online real-time processing inadequate info
of transactions, interaction
-development/acquisition and
and sharing of data, improved
deployment risk: problems during
process performance,
devt, acquiring, deploying IT solution
reduction of data redundancy,
timely decision-making -causes delays and cost
overruns
-Electronic Data Interchange (EDI):
computer-to-computer exchange of -caused by insufficient in-
business documents between an org house expertise, inadequate
and trading partners vendor support, untried
software/tech, resistance to
-transaction processing
change
efficiencies and fewer data
processing errors
2. Technical and system risk guest access, lack of strong
-availability risk: unavailability of user access/authentication
system when needed
-fraud and malicious acts risk: theft
-causes delays, business
of IT resources, intentional misuse of
interruptions, lost revenue,
IT resources, intentional distortion of
customer dissatisfaction
info
-caused by hardware/software
malfunctions, unscheduled -caused by disgruntled
maintenance, virus, malicious employees, hackers
acts
IT GOVERNANCE
-hardware/software risk: failure to
-orgs invest in IT since it allows execution of
perform
business strategies
-causes business
-BoD and senior mgmt. owns IT governance
interruptions, temporary or
permanent damage, -governance: IT policies
destruction of data,
-mgmt: standards, organization and mgmt.,
repair/replacement costs
physical and environmental controls
-caused by natural wear and
-technical: system software controls,
tear, natural disasters,
systems devt controls, application-based
viruses, lack of patching
controls
updates, malicious acts
IT RISK MANAGEMENT
-system reliability and information
integrity risk: systematic errors that -identify and mitigate risks
produce irrelevant, inaccurate, and
-identify and exploit opportunities
untimely info
IT CONTROLS
-caused by software
programming errors, weak -general controls: controls on people,
data verification controls, policies, processes, and system components
unauthorized changes
-application controls: controls on
3. Security and compliance risk applications and programs
-access risk: unauthorized
physical/logical access to the system -input controls: correct data is
resulting to theft, misuse, malicious inputted
modifications, or destruction of data -processing controls: data is
-caused by smartphones processed correctly
accessing to company data,
using wireless networks for -output controls: processes release
correct output
IT MANAGEMENT CONTROLS assessment, intrusion testing,
encryption services, change mgmt.
1. IT standards
processes
-support IT policies
-specifically define requirements -system devt and acquisition controls:
-systems devt processes: processes
-documentation of user reqs, process
for designing, developing, testing,
of systems design, structured system
implementing, and maintaining info
devt, testing that ensures operating
systems
effectiveness, and consistent pattern
-systems software configuration:
of control
secure system config
-application controls: all apps that -application-based controls: all input data
support business activities must be is accurate, processed as intended,
controlled completely stored, and accurately outputted
-data structures consistent data
-input controls, processing controls,
definitions ensure that disparate
output controls, integrity controls
systems can access data seamlessly
(monitor data processing and storage
-documentation: specify minimum
for consistent and correct data),
level required
management trail
2. IT organization and mgmt. controls
-provide assurance hat the org is -information security controls: protect an
structured with clearly defined lines info system from unauthorized physical and
of reporting and responsibility w/ logical access
effective control processes
-physical access controls: security
-segregation of duties
over tangible IT resources
-financial controls to ensure
tech yields projected ROI -logical access controls: security
-change mgmt. processes over intangible IT resources (software
3. IT physical and environmental and info)
controls
IMPLICATIONS FOR IT AUDITORS
-protect info system resources
1. IT proficiency and due professional
IT TECHNICAL CONTROLS
care
-form the backbone of mgmt. control -IT auditors must have sufficient
framework knowledge on tech risks and controls
-use tech-based audit techniques
-specific to tech in use
2. Assurance engagement IT
-system software controls: restrict logical responsibilities
access to org systems and apps -assess IT governance supports org
strategies and objectives
-access rights, division of duties,
-evaluate risk exposures
intrusion and vulnerability
3. IT outsourcing
-org still bears the risk and
responsibility for controls
4. Integrated and continuous auditing
-must audit thru the computer (audit
based on outputs and computer
code)
-integrate IT audit into assurance
engagements in increase efficiency
and effectiveness
-continuous auditing
-continuous controls
assessment: focus audit
attention on control
deficiencies
-continuous risk
assessment: highlight
processes/systems with
higher risk lvls