302 software Quality assuranCe
Business Process Risks
e IT audit team must be aware of the business process and their
risks, and how the data are being used. Measures to protect printed
information should follow the same principles used to classify and
protect electronic data. At the minimum, the desks should be clean,
and the draws and filing cabinets should be locked. Discretion should
be used in areas open to the public.
Auditors should identify the threats to the organization’s data
through research, benchmarking, and brainstorming and categorize
them according to the likelihood of occurrence and impact.
Vulnerability assessments and penetration test methods are often
cited as assurance methods for network accessible applications and
infr ...