1 / 44100%
Students, please view the "Submit a Clickable Rubric Assignment" in the Student
Center.
Instructors, training on how to grade is within the Instructor Center.
Term Paper: Planning an IT Infrastructure Audit for
Compliance
Due Week 10 and worth 200 points
Note:Chapter 5 of the required textbook may be helpful in the completion of the
assignment.
The audit planning process directly affects the quality of the outcome. A proper plan
ensures that resources are focused on the right areas and that potential problems are
identified early. A successful audit first outlines the objectives of the audit, the
procedures that will be followed, and the required resources.
Choose an organization you are familiar with and develop an eight to ten page IT
infrastructure audit for compliance in which you:
1. Define the following items for an organization you are familiar with:
a. Scope
b. Goals and objectives
c. Frequency of the audit
d. Duration of the audit
2. Identify the critical requirements of the audit for your chosen organization and explain why
you consider them to be critical requirements.
3. Choose privacy laws that apply to the organization, and suggest who is responsible for
privacy within the organization.
4. Develop a plan for assessing IT security for your chosen organization by conducting the
following:
a. Risk management
b. Threat analysis
c. Vulnerability analysis
d. Risk assessment analysis
5. Explain how to obtain information, documentation, and resources for the audit.
6. Analyze how each of the seven (7) domains aligns within your chosen organization.
7. Align the appropriate goals and objectives from the audit plan to each domain and provide a
rationale for your alignment.
8. Develop a plan that:
a. Examines the existence of relevant and appropriate security policies and procedures.
b. Verifies the existence of controls supporting the policies.
c. Verifies the effective implementation and ongoing monitoring of the controls.
9. Identify the critical security control points that must be verified throughout the IT
infrastructure, and develop a plan that includes adequate controls to meet high-level
defined control objectives within this organization.
10. Use at least three (3) quality resources in this assignment.: :Wikipedia and similar Note:
Websites do not qualify as quality resources.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on
all sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student's name, the
professor's name, the course title, and the date. The cover page and the reference page are
not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Describe the parameters required to conduct and report on IT infrastructure audit for
organizational compliance.
Describe the components and basic requirements for creating an audit plan to support
business and system considerations
Develop IT compliance audit plans
Use technology and information resources to research issues in security strategy and policy
formation.
Write clearly and concisely about topics related to information technology audit and control
using proper writing mechanics and technical style conventions.
Clickhereto view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 200 Term Paper: Planning an IT Infrastructure Audit for Compliance
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Define the
following items
for an
organization you
are familiar with:
a) Scope;
b)Goals and
objectives;
c)Frequency of
the audit; d)
Duration of the
audit.
Weight: 5%
Did not submit or
incompletelydefined
the following items
for an organization
you are familiar with:
a) Scope; b) Goals
and objectives; c)
Frequency of the
audit; d) Duration of
the audit.
Insufficiently defined
the following items
for an organization
you are familiar with:
a) Scope; b) Goals
and objectives; c)
Frequency of the
audit; d) Duration of
the audit.
Partially defined
the following
items for an
organization you
are familiar with:
a) Scope; b)
Goals and
objectives; c)
Frequency of
the audit; d)
Duration of the
audit.
Satisfactorily defined
the following items
for an organization
you are familiar with:
a) Scope; b) Goals
and objectives; c)
Frequency of the
audit; d) Duration of
the audit.
Thoroughly defined
the following items
for an organization
you are familiar
with: a) Scope; b)
Goals and
objectives; c)
Frequency of the
audit; d) Duration of
the audit.
2. Identify the
critical
requirements of
the audit for
your chosen
organization and
explain why you
consider them to
be critical
requirements.
Weight: 10%
Did not submit or
incompletelyidentifie
d the critical
requirements of the
audit for your
chosen organization
and did not submit
or
incompletelyexplaine
d why you consider
them to be critical
requirements.
Insufficientlyidentifie
d the critical
requirements of the
audit for your
chosen organization
and
insufficientlyexplaine
d why you consider
them to be critical
requirements.
Partiallyidentifie
d the critical
requirements of
the audit for
your chosen
organization and
partiallyexplaine
d why you
consider them to
be critical
requirements.
Satisfactorilyidentifie
d the critical
requirements of the
audit for your chosen
organization and
satisfactorilyexplaine
d why you consider
them to be critical
requirements.
Thoroughlyidentifie
d the critical
requirements of the
audit for your
chosen
organization and
thoroughly
explained why you
consider them to be
critical
requirements.
3. Choose
privacy laws that
apply to the
organization,
and suggest
who is
Did not submit or
incompletelychose
privacy laws that
apply to the
organization, and did
not submit or
Insufficiently chose
privacy laws that
apply to the
organization, and
insufficiently
suggested who is
Partially chose
privacy laws that
apply to the
organization,
and partially
suggested who
Satisfactorily chose
privacy laws that
apply to the
organization, and
satisfactorily
suggested who is
Thoroughly chose
privacy laws that
apply to the
organization, and
thoroughly
suggested who is
responsible for
privacy within
the organization.
Weight: 5%
incompletelysuggest
Students also viewed