
277
10
inforMation audit
Introduction
is chapter contains three parts. Part 1 discusses the basic definition
of information audit and different dimensions of audit planning, risk
identification, assessment, and details of IT audit, key considerations
for IT audit. Part 2 addresses the audit management. Part 3 discusses
the audit and information security aspects.
Part 1: Denition and Planning
Denition
IEEE Standard 610 definition of audit is as follows:
An independent examination of a work product or set of work products
to assess compliance with specifications, standards, contractual agree-
ments, or other criteria.*
According to Merriam-Webster, an aud ...