0% found this document useful (0 votes)
9 views30 pages

Comprehensive Guide to IT Auditing

The document outlines the concepts, objectives, and methodologies of IT auditing, emphasizing the roles and responsibilities of IT auditors. It details various types of audits, including internal, external, and mixed audits, as well as the necessary skills and training for auditors. Additionally, it describes the audit process, from defining objectives to preparing final reports, and highlights tools and standards used in IT audits.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views30 pages

Comprehensive Guide to IT Auditing

The document outlines the concepts, objectives, and methodologies of IT auditing, emphasizing the roles and responsibilities of IT auditors. It details various types of audits, including internal, external, and mixed audits, as well as the necessary skills and training for auditors. Additionally, it describes the audit process, from defining objectives to preparing final reports, and highlights tools and standards used in IT audits.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IT AUDIT

Unit 7: Computer Audit


Concepts of IT auditing. Objectives of the
IT audit. The IT audit during
the development of software engineering. The auditor
computer scientist. The Department of IT auditing.
Types of IT audit. Methodology for the
carrying out a computer audit. Tools,
techniques and standards for IT auditing.

Bibliography
Chapter 9. The IT audit. Management and
Management of Information Systems in the company.
2nd Edition. Pablos Heredero and others.
IT Audit
Definition

The IT audit is the process of collecting, grouping and


evaluate evidence to determine whether a system of
information safeguards the business asset, maintains the
data integrity effectively fulfills the purposes of the
organization, uses resources efficiently, and complies with
the established laws and regulations.
IT Audit
Definition

The computer audit allows to detect in a way


systematic use of resources and information flows
within an organization and determine what information is
criticism for compliance with its mission and objectives,
identifying needs, duplicities, costs, value and
barriers that hinder efficient information flows.
Computer Audit
Causes
The causes that can lead to the creation of an AI can be:
Disorganization/Discoordination
•Ex: Duplication of information
User dissatisfaction
Inadequate IT support
Economic-financial weaknesses
Significant budget deviations
Insecurity of the IS
Lack of physical and logical protection
Compliance with legality
Example: Protection of personal data
Computer Audit
Objectives

The objectives of the IT Audit are:


The control of the IT function.
The analysis and improvement of efficiency, safety, and
profitability of Information Systems.
The verification of compliance with the regulations in this
scope.
IT Audit
The Auditor

Professional person who is engaged in auditing work


habitually with free exercise of a technical occupation.

The IT auditor must ensure the correct use of


the extensive resources that the company puts at stake to
to have an efficient and effective Information System.
IT Audit
The Auditor - Training
The following levels of training are recommended for a
auditor
Academic: Studies at the technical, bachelor's, or
postgraduate studies in administration, information technology, communication.

Complementary: Instruction in the subject, obtained from


length of professional life through diplomas,
seminars, forums and courses, among others.
Empirical: Knowledge resulting from the implementation of
audits in different institutions without having a degree
academic.
IT Audit
The Auditor - Skills and Abilities
An auditor must possess the following characteristics:
Positive attitude. Clarity of verbal and written expression.
Emotional stability. Observation skills.
Objectivity.
Initiative.
Institutional sense.
Discretion.
Know how to listen.
Creativity. Ease of working in a group.
Negotiation skills. Ethical behavior.
Imagination.
Analytical mind.
Respect for the ideas of others.
Awareness of one's own values and those of the environment.
IT Audit
The Auditor - Professional Standards
An auditor must face their commitment with respect and in accordance with standards.

profesionales tales como:


Objectivity. Maintain an independent view of the facts,
avoiding making judgments or falling into omissions that alter in some way
way the results you get.
Responsibility. To observe a professional conduct, fulfilling
with their tasks promptly and efficiently.
•Integridad. Preservar sus valores por encima de las presiones.
Confidentiality. Keep the information secret and do not use it.
for one's own benefit or for the benefit of others.

•Commitment. To be aware of your obligations to yourself and


the organization for which he/she provides services.
IT Audit
The Auditor–Professional Standards
An auditor must face their commitment with respect and adherence to standards.
professionals such as:
Balance. Do not lose the dimension of reality and the meaning of the
facts.
Honesty. Accepting your condition and trying to give your best effort with
their own resources, avoiding accepting compromises or deals of any kind
type.
•Institutionality. Do not forget that your professional ethics obliges you to respect
and obey the organization to which he/she belongs.
Criterion. Use your ability to discern in a balanced way.
Initiative. To adopt an agile and effective attitude and response capability.
Creativity. Being innovative in the development of your work.
IT Audit
The Auditor - Characteristics

What should auditors do What they should not do

Recommend To force or to threaten


Be independent, objective Act in one's own benefit
Be competent in AI Taking on jobs without preparation
Diagnose based on adequate
verifications Diagnose based on
Update on assumptions advancements
Leave your obsolete
knowledge
IT Audit - The Auditor

Vs.

The auditor
The audited
IT Audit
The Audit Department

ADDRESS
GENERAL FINANCIAL

AUDIT Informatics

ORGANIZATIONAL

AREA 1 AREA 2 AREA 3


IT Audit
The Audit Department
The typical organization of the AI must consider the
following principles:
-It must be part of the Management or be very close to it.
she.
It must have its own statute indicating its
dependency, its attributions and its functions or duties.
People should be a mix of those with
training in auditing and organization and those with
computer profile.
The operational organization must be that of a group
independent with full access to the SI and information
Information Technology Audit
Types
Several types of AI can be distinguished according to:
Areas to consider
The director
The scope
-The specificity
IT Audit
Types - According to areas to consider
AI can focus on 4 core areas:
IT Department
Users
Internal
Safety
and four specific areas
Exploitation
Development
Systems
Communications
Security
IT Audit
Types - According to areas to consider

The combination of general areas with specific ones allows for distinction.
up to 19 types of audits.
General Areas
Specific Areas
Internal Management User Security

Exploitation

Development

Systems

Communications

Security
IT Audit
Types - According to the creators
Internal Audit
It is carried out by a functional entity belonging to the structure itself.
organizational structure of the company and in exchange they receive a remuneration
economic.

External Audit
It is carried out by individuals external to the company. The company hires a service.
to audit your information system by individuals external to it.
Sometimes the possibility of auditing an information system is attributed to several
auditors, generally focusing on a specific area.
The contract must specify the duration of the audit and each of the phases.
in which the work is divided, both in total time and partials.

Mixed Audit
It involves the creation of a mixed team of auditors (internal and
externals), to carry out the audit work.
IT Audit
Internal Audit vs. External Audit

There are substantial differences between Internal Audit and Audit.


External, some of which can be detailed as follows:

In Internal Audit there is an employment relationship between the auditor and the
company, while in the External Audit the relationship is of a civil nature.
In the Internal Audit, the auditor's diagnosis is intended for
company; in the case of the External Audit, this report is intended
generally for third parties or those outside the company.
The Internal Audit is prohibited from giving Public Faith, due to its
employment contractual linkage, while the External Audit has the authority
legal to grant Public Faith.
IT Audit
Internal Audit vs. External Audit
A company or institution that has internal audit can and should in
occasions to hire external auditing services. The reasons for doing so
they tend to be:
Need to audit a highly specialized subject, for which
the in-house services are not sufficiently trained.
•Contrast some internal report with the one resulting from the external one, in
those assumptions of internal issuance of serious recommendations that
They clash with the widely held opinion of the company itself.
Serve as a protective mechanism for possible computer audits
externally decreed by the same company.
Although the internal audit is independent of the Department of
Systems, it remains the same company, therefore, it is necessary
that external audits are conducted to have a perspective from
outside the company.
IT Audit
Types - According to the scope of application
1. Audit of figures: It consists of knowing and evaluating the reliability of the
information managed by the system.
Data entry control.
Control of data processing.
Data output control.
2. Audit of procedures: Its objective is the analysis and
evaluation of the adequacy of the methods used, the documentation
used and the regulation applied.
Adjustment of the methods used.
Documentation adjustment.
Adjustment of the applied regulations.
3. Management audit: It aims to analyze whether the model of the structure
the organizational IT of a company is appropriate as well as the
problem that it raises by reviewing the degree of integration of the
information in the company.
IT Audit
Types - According to specificity

On certain occasions, the goals of AI are very specific, to such


a way they can exist for example:
Audit of compliance with transfer controls
applications from the development environment to the production environment.

Compliance audit of current legislation.


Audit on the remuneration of human resources of
Department of IT.
Audit of the procedures of the Information Center.
IT Audit
Methodology for the implementation of an AI

1. Definition of Scope and Objectives.


2. Preliminary Study.
3. Determination of resources.
4. Development of the Plan.
5. Realization.
6. Preparation of the Final Report.
IT Audit
Methodology for the development of an AI
1. Definition of Scope and Objectives.

The field of auditing will set its limits, and it will be


necessary to reach a full agreement between auditors and 'clients' on the
functions, the subjects and the organizations to audit.

AI objectives must be set from the beginning that must be


measurable such as: evaluation of the functioning of the
areas of computing, increase in quality, rise in
security and reliability.

It should be established from the beginning who the interlocutors will be:
IT professionals, users, validators/decision-makers, recipients of
reports.
Computer Audit
Methodology for the development of an AI
2. Preliminary Study.

The general functions and activities of computing will be examined.


how are they:
The organizational environment: The organizational chart of the Department is analyzed.
Computer Science.
The operating environment: The main processes will be reviewed.
IT professionals carried out considering the applications in
exploitation, design methodologies, documentation and
data sources.
The technical environment: Everything related to support will be reviewed.
of the IS considering the architecture and physical and logical support, the
hardware and software inventory, communications.
Computer Audit
Methodology for the development of an AI

3. Determination of resources.

The resources will be:


Humans, establishing the profiles and the necessary personnel,
both for ongoing and occasional participation.
Materials, distinguishing between software and hardware equipment.
IT Audit
Methodology for the creation of an AI

4. Development of the Plan.

The person in charge of the AI establishes the work plan to be followed, with the
tasks to be performed, their interdependence and their estimated time frame,
workload and profiles of the necessary participants.

Once the above is defined, the calendar is established and constructed


the work programs.

The plan must be approved by the management of the audited company and
You must communicate to those involved.
Information Technology Audit
Methodology for the implementation of an AI

5. Execution.

In this phase, the plans and programs created are put into practice,
utilizando las técnicas y herramientas previstas.

The techniques to be used can be: interviews, reviews, tests,


simulations, samplings.
IT Audit
Methodology for the development of an AI
6. Preparation of the Final Report.

The structure of the final AI report will include the following points:

Presentation.
Definition of scope and objectives.
Enumeration of considered topics.
Analysis of the current situation.
Recommendations

The final report is usually accompanied by a summary report for the


Address, where, in no more than 4 pages, the result is summarized
the audit concerning the weaknesses without including the
recommendations.
IT Audit
Tools, techniques, and standards for AI
The interviews.
2. The questionnaires or checklists (of range or binary).
3. The standards.
4. Tracks or traces.
5. Query software.
6. Good control practices related: COBIT
Control Objectives for Information and Related
Technology

You might also like