Name
Strayer University
Conducting an IT Risk Assessment and Compliance Audit
CIS 349 - Information Technology Audit and Control
Task Title: Conducting an IT Risk Assessment and Compliance Audit
Assignment Instructions:
You are assigned to conduct an IT risk assessment and compliance audit for a large healthcare
organization. The organization handles sensitive patient data, and it's crucial to ensure data
security and compliance with healthcare regulations.
Organization Selection: Choose the healthcare organization for your audit. Explain why you
selected this organization and provide a brief overview of its IT infrastructure and healthcare
services.
1. Audit Objectives: Outline the primary objectives of the IT risk assessment and
compliance audit. What are the key goals you aim to achieve with this audit? Consider
factors like data security, compliance with healthcare regulations (e.g., HIPAA), and risk
mitigation.
2. Regulations and Standards: Identify and explain the specific healthcare regulations and
industry standards applicable to the organization. Describe how non-compliance with
these regulations can impact the organization.
3. Audit Scope: Specify the components of the IT infrastructure that will be included in the
audit (e.g., electronic health records systems, network infrastructure, cloud services). Will
the audit cover both physical and virtual infrastructure elements?
4. Audit Team and Resources: Define the roles and responsibilities of the audit team
members. What qualifications and expertise should team members possess? Outline the
resources, tools, and software required for the audit.
5. Risk Assessment Methodology: Explain the methodologies or frameworks you will use to
assess IT risks within the organization. What are the key risks related to data security and
compliance?
6. Audit Procedures: Detail the audit procedures and methodologies that will be employed
to assess compliance and identify potential risks. Describe how you will gather evidence
and documentation during the audit.
7. Data Protection and Privacy Compliance: Describe how the audit will assess the
organization's compliance with data protection and privacy regulations, such as HIPAA.
What specific measures and policies will be evaluated?
8. Storage of Audit Documentation: Outline where and how all audit documentation and
evidence will be securely stored for future reference, including backup copies.
Ensure that your assignment follows the formatting guidelines, including APA or school-
specific format, and includes a cover page with the necessary details. The assignment
should be between eight to ten pages, excluding the cover page and references.
Develop IT compliance audit plans
Use technology and information resources to research issues in security strategy and policy
formation.
Write clearly and concisely about topics related to information technology audit and control
using proper writing mechanics and technical style conventions.
Click;here;to view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 200 Term Paper: Planning an IT Infrastructure Audit for Compliance
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Define
the
following
items for an
organization
you are
familiar
with: a)
Scope;
b)Goals and
objectives;
c)Frequency
of the audit;
d) Duration
of the audit.
Weight: 5%
Did not submit
or
incompletely
defined the
following
items for an
organization
you are
familiar with:
a) Scope; b)
Goals and
objectives; c)
Frequency of
the audit; d)
Duration of the
audit.
Insufficiently
defined the
following
items for an
organization
you are
familiar with:
a) Scope; b)
Goals and
objectives; c)
Frequency of
the audit; d)
Duration of the
audit.
Partially
defined the
following
items for an
organizatio
n you are
familiar
with: a)
Scope; b)
Goals and
objectives;
c)
Frequency
of the audit;
d) Duration
of the audit.
Satisfactorily
defined the
following
items for an
organization
you are
familiar with:
a) Scope; b)
Goals and
objectives; c)
Frequency of
the audit; d)
Duration of the