Session 1 - Intro To IS Audit BW PDF
Session 1 - Intro To IS Audit BW PDF
Session 1 - Intro To IS Audit BW PDF
Objective
Software technology
Specific computer application
Sharing experiences in
conducting IS auditing
Page 2
Outline
The need for control and audit of computers
IS auditing definition
Foundation of IS auditing
IS Audit Profession
ISACA
Certified Information System Auditor (CISA)
Page 3
Page 4
Page 5
Page 6
Computer abuse
Threats to business include the following:
Former employees,
Page 7
Page 8
Page 9
Privacy protection
Relates to concentration of
personal data in a centralized
database
Page 10
IS auditing definition
Information systems auditing is defined as any audit that encompasses the review and
evaluation of any aspect of automated information processing systems, including related
non-automated processes, and the interfaces between them.
--ISACA-IS auditing is the process of collecting and evaluating evidence to determine whether a
computer system safeguard assets, maintains data integrity, achieves organizational
goals effectively, and consumes resources efficiently
--Ron Weber-IS auditing is the process of evaluating and reporting the adequacy of system controls,
efficiency, economy, effectiveness, and security practices to assure that computerrelated assets and information resources are safeguarded, that data integrity is
protected, and that the system is complies with applicable policies, procedures,
standards, rules, laws, and regulations.
--S. Rao Valabhaneni--
Page 11
IS auditing definition...
Asset safeguarding objectives
data completeness
data soundness
data purity
data veracity
Page 12
IS auditing definition...
An efficient data processing system uses minimum resources to achieve its required output.
computer time
peripherals
channels
system software
labor
Page 13
Foundation of IS auditing
Traditional
auditing
Information
systems
management
Information
systems
auditing
Computer
Science
Behavioral
science
Page 14
Foundation of IS auditing
Traditional auditing
Controls philosophy
Behavioral science
Computer science
Page 15
IS Audit Profession
MATTERS
FINANCIAL/ INTERNAL
AUDITOR
Standards
Auditee:
IT Division
Professional
Organization
ISACA
AICPA/IIA
Qualification
CISA
Career objectives:
CPA/CIA
Page 16
IS Auditor vs Consultant
Differences
IS Auditor
IT Consultant
No
Yes
Sell product
No
Yes
Yes
No
Review
Yes
No
Independent Entity
Depends on contract
Independence
Page 17
ISACA
Information Systems Audit and Control Association (ISACA) is a
recognized global leader in IT governance, control and assurance. ISACA
sponsors international conferences, administers the globally respected
CISA
Founded in 1969,
Now more than 22,000 members in over 100 countries,
Develops globally-applicable Information Systems (IS) Auditing and
Control Standards, COBIT (Control Objectives for Information Related
Technology)
Certify professionals with CISA (Certified Information Systems Auditor)
Page 18
Page 19
CISA Requirement
1.
2.
3.
4.
5.
Page 20
10
Page 21
11