Custom Search

Saturday, May 5, 2007

CISA Audit Process #12

IT Application Audit

The objectives of an IT applicaton audit are to evaluate:

The efficiency of the application in meeting the business processes

The impact of any exposures discovered

The business processes served by the application

The appliction's optimization

However, if a IT auditor is performing a review of an application's controls

It will involves the evaluation of the application's automated controls and an assessment of any

exposures resulting from the control weakness.



Related Tags: , , , , , ,

Thursday, May 3, 2007

CISA 2007 - Audit Process # 11

Auditing Inventory Applicaton

In an audit of an inventory application, the approach which would provide the BEST evidence that purchase orders are valid is testing whether inappropriate personnel can change application parameters.

Tracing purchase orders to a computer listing, comparing receiving reports to purchase order details are after-the fact approaches

Reviewing the application documentation will not give the actual scenario as it is only theory.

Related Tags: , , , , , ,

Tuesday, May 1, 2007

Audit Process #10

Computer Forensic Software

Computer Forensic Software is only utilised if there is a need to collect digital evidence from Information Processing devices such as laptops, computers , PDAs etc. to press charges against fraud, cheat and other computer related crimes.


Computer Forensic Software is most useful for preservation of the chain of custody for electronic evidence

A good Computer Forensic Software should be efficient, effective, time and cost savings.

Another characteristic of a computer forensic software is that it is able to search for violations of intellectual property rights


Related Tags: , , , , ,

Monday, April 30, 2007

CISA 2007 - Audit Process #9

Types of IT Audit Testing

Compliance Testing : In a IT audit , Compliance testing determines whether controls are being applied in compliance with policy. This includes tests to determine whether new accounts were appropriately authorized.

Substantive Testing : In a IT audit , Substantive testing substantiates the integrity of actual processing, such as balances on financial statements. The development of substantive tests is often dependent on the outcome of compliance tests. If compliance tests indicate that there are adequate internal controls, then substantive tests can be minimized.

Variable Sampling : In a IT audit , Variable sampling is used to estimate numerical values, such as dollar values.

Stop-Or-Go Sampling: In a IT audit , Stop-or-go sampling allows a test to be stopped as early as possible and is not appropriate for checking whether procedures have been followed.


Related Tags: , , , , , ,

Friday, April 27, 2007

CISA 2007 - Audit Process #8

IT Audit Process

Not reporting an intrusion is equivalent to an IT auditor hiding a malicious intrusion, which would be a professional mistake. Although notification to the police may be required and the lack of a periodic examination of access rights might be a concern, they do not represent as big a concern as the failure to report the attack. Reporting to the public is not a requirement and is dependent on the organization's desire, or lack thereof, to make the intrusion known.


An organizational chart provides information about the responsibilities and authority of individuals in the organization. This helps the IS auditor to know if there is a proper segregation of functions. A workflow chart would provide information about the roles of different employees. A network diagram will provide information about the usage of various communication channels and will indicate the connection of users to the network.


The audit charter typically sets out the role and responsibility of the internal audit department. It should state management's objectives for and delegation of authority to the audit department. It is rarely changed and does not contain the audit plan or audit process, which is usually part of annual audit planning, nor does it describe a code of professional conduct, since such conduct is set by the profession and not by management.



Related Tags: , , , , ,

Saturday, April 21, 2007

CISA 2007 - Audit Process #7

During a security audit of IT processes, an IT auditor found that there were no documented security procedures.

Since one of the main objectives of an audit is to identify potential risks; therefore, the most proactive approach would be to identify and evaluate the existing security practices being followed by the organization.

IT auditors should not prepare documentation, and doing so could jeopardize their independence. Terminating the audit may prevent achieving one of the basic audit objectives, i.e., identification of potential risks. Since there are no documented procedures, there is no basis against which to test compliance.

Related Tags: , , , , , , ,

CISA 2007 - Audit Process #6

During an IT audit, if the auditee disagrees with the impact of a finding, it is important for the IT auditor to elaborate and clarify the risks and exposures, as the auditee may not fully appreciate the magnitude of the exposure. The goal should be to enlighten the auditee or uncover new information of which the IT auditor may not have been aware. Anything that appears to threaten the auditee will lessen effective communications and set up an adversarial relationship. By the same token, the IT auditor should not automatically agree just because the auditee expresses an alternate point of view at the end of an IT audit

In an IT audit, Attribute sampling is the primary sampling method used for compliance testing. Attribute sampling is a sampling model that is used to estimate the rate of occurrence of a specific quality (attribute) in a population and is used in compliance testing to confirm whether the quality exists. The other choices are used in substantive testing, which involves testing of details or quantity.

Related Tags: , , , ,