The process of auditing information systems(must read all directions and use attached outline)
1
Running head: THE PROCESS OF AUDITING INFORMATION SYSTEMS
The process of auditing information systems 2
The process of auditing information systems
Student’s name
Institutional affiliation
THE PROCESS OF AUDITING INFORMATION SYSTEMS
The audit of information systems is the management controls examination inside the infrastructure of Information Technology. The obtained evidence valuation is used to determine if systems of information are protecting assets, upholding integrity of data, and also if they are effectively operating in order to achieve organization’s objectives or goals (Hoelzer, 2009). This process involves;-
Audit Function Management; this process includes assessment which is systematic of policies and methods of management of the organization in management and utilization of resources, improvement of organization and employee, strategic and tactical planning. The main goals are to establish the present effectiveness level, suggesting improvements and putting down standards for performance in future.
Standards of Assurance, IT Audit and Guidelines; these involve the relationships between standards, tools, guidelines and techniques. It also comprises of the assurance framework of Information technology among other standards. They describe a framework of guidance and standards which relates to performance and acceptance of assurance activities and auditing (John, 2007).
Risk Analysis; this involves identifying specific risks that might be faced by the information system of the organization and establish the impacts, occurrence likelihood, severity and priority and recommendations of strategies of mitigation.
Internal Controls; these are actions that the management and other groups take for risk management and increase the possibility that the identified goals and objectives will be attained.
Perform an Information System Audit; this process involves the evaluation of weaknesses and strengths of the audit, testing, sampling, recommendation implementation of the management and communicating the results of the audit, among others (Richard, 2007).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Annotated Bibliography
Hoelzer, D.( 2009). Audit Principles, Risk Assessment & Effective Reporting. SANS Press.
According to Hoelizer David, the author of ‘Audit Principles, Risk Assessment & Effective Reporting’, Information Technology audit is an assessment of the organization controls within an infrastructure of Information Technology (IT). David states in his book that the purpose of financial audits is to assess if an organization is holding to the standard types of accounting performances. He continues to explain that IT auditing is essential while controlling the internal designs as well as examining the company’s effectiveness. In his book, Hoelizer states that the main function of IT auditing is system evaluation in charge of the main company’s information.
Richard, C. (2007). Information system auditing; Auditor's Guide to Information Systems Auditing. High Tower Software
In his book Auditor's Guide to Information Systems Auditing , Richard Carsicarino states the most important points about auditing in the most comprehensive manner. His books have at least something for every auditor no matter their departments of specialization. Richard gives new auditors a platform of being able to study and precisely understand what their roles are while performing the process of auditing. Richard further gives his reads a snick preview of what they should expect in the field of auditing. This book is also educative to the already experienced auditors; because it gives them a detailed focus of how they should too do their job
John, B. (2007). Public Sector Auditing: Is it Value for Money? Creating a culture of compliance
In his book, ‘Public Sector Auditing: Is it Value for Money?’; John Bourns basically gives his personal account on the influence value and role of money auditing in making governments accountable as well as in making public institutions deliver their services appropriately. David, who has an experience of over twenty years as a general auditor and comptroller, in the United Kingdom National Audit Office, has used his experience and his qualifications to come up with this book. Richards book has an in detailed case studies from US, UK, China, Canada, India as well as Australia; thorough analysis of compound areas of expenditure of public for example; education, health, regulation, privatization, defense and Information Technology and finally, the book also shows examples on how auditing promotes positive outcomes.