1/28/13


Key Tasks of an Info Systems Auditor

  1. Develop and implement risk based audit strategy.
  2. Plan specific audits to ensure the Systems are protected and valuable for the company.
  3. Conduct audits as per standards
  4. Report findings of the audit and make the key stake holders aware of the deficiencies if any
  5. Conduct follow-up to make sure the deficiencies were re-mediated.

1/10/13

Why need IT controls to an organization ?


It is increasingly important to have an IT department with proper internal controls built into its
Operations. Also need information resource planning in order to achieve business objectives of the company. Senior management need to take a closer look at the IT controls in their organizations because of following reasons.

Regulatory Compliance:
New laws like Sarbanes-Oxley (SOX) specify that select senior officers will attest to the state of the internal controls of the company and the reliability of the financial statement released. Since almost all company transactions involve use of a computer system, it is important that there are adequate systems controls in place to assure regulators that the attestation by management is reliable.

IT expenditure:
It is also important that IT expenditure is associated with the company’s business strategy. As the reliance on technology systems to perform and report on transactions increases, technology cost is one significant internal expense. It is important that this cost is aligned with business strategy. There should be a documented IT process that integrates business participation in the creation of an IT strategy plan.

Evacuate from cyber crimes and social engineering attacks:

Organization required evacuating from Common Security Threats in the E-commerce Environment like
 Malicious code,Viruses, Worms, Trojan horses, Bots, botnets, Unwanted programs , Browser parasites, Adware, Spyware, Social engineering, Phishing, Hacking, Cyber vandalism and Data breach..etc

Increase productivity:
By preventing misuse of the information systems and improving the Improve productivity through efficient and responsible staff behavior ... Policy for acceptable use of Internet and email services specifically.



And many more ………….





Why the hell I need help to system review? I am a just a user, not the IT Manager........


Many times system users get annoyed with the slight disturbance of the system auditor. One of a dilemma IS auditor has to face is lack of cooperation from system users. Even though top management has identified the importance of system assurance process, employees in lower level have propensity to avoid revealing required information to the IS auditor.
For this reason it is essential to build client relationship and explicate the importance of the system review to users of the system. Some users lacking of confidence to reveal information because they think this guy will report to the management about the particular loophole and it will lead to lose my job as well. Hence IS auditor need to move out from the traditional Auditor roll and make an impression to client as an IT Advisor or consultant. This would help to carryout system assurance process easily and identify the issues.