WHY AUDIT INFORMATION SYSTEMS AND SECURITY?WHAT IS THE SCOPE OF THE INFORMATION SECURITY AUDIT?WHO PERFORMS THE INFORMATION SYSTEMS SECURITY AUDITS?WHAT IS THE AUDIT PROCESS?WHAT IS THE MANAGEMENT'S RESPONSE TO THE AUDIT RESULTS?AUDIT OBJECTIVES, AUDIT WORK PROGRAMS, AND AUDIT TOOLS AND TECHNIQUESCONCLUSIONSGLOSSARYAPPENDIX: GOVERNMENT LAWS, DIRECTIVES, AND REGULATIONSCROSS REFERENCESREFERENCESFURTHER READING