Book description
A comprehensive guide to understanding and auditing modern information systems
The increased dependence on information system resources for performing key activities within organizations has made system audits essential for ensuring the confidentiality, integrity, and availability of information system resources. One of the biggest challenges faced by auditors is the lack of a standardized approach and relevant checklist. Understanding and Conducting Information Systems Auditing brings together resources with audit tools and techniques to solve this problem.
Featuring examples that are globally applicable and covering all major standards, the book takes a non-technical approach to the subject and presents information systems as a management tool with practical applications. It explains in detail how to conduct information systems audits and provides all the tools and checklists needed to do so. In addition, it also introduces the concept of information security grading, to help readers to implement practical changes and solutions in their organizations.
Includes everything needed to perform information systems audits
Organized into two sections—the first designed to help readers develop the understanding necessary for conducting information systems audits and the second providing checklists for audits
Features examples designed to appeal to a global audience
Taking a non-technical approach that makes it accessible to readers of all backgrounds, Understanding and Conducting Information Systems Auditing is an essential resource for anyone auditing information systems.
Table of contents
- Cover
- Contents
- Title
- Copyright
- Dedication
- Preface
- Acknowledgments
-
Part One: Conducting an Information Systems Audit
-
Chapter One: Overview of Systems Audit
- Information Systems Audit
- Information Systems Auditor
- Legal Requirements of an Information Systems Audit
- Systems Environment and Information Systems Audit
- Information Systems Assets
- Classification of Controls
- The Impact of Computers on Information
- The Impact of Computers on Auditing
- Information Systems Audit Coverage
- Chapter Two: Hardware Security Issues
- Chapter Three: Software Security Issues
-
Chapter Four: Information Systems Audit Requirements
- Risk Analysis
- Threats, Vulnerability, Exposure, Likelihood, and Attack
- Information Systems Control Objectives
- Information Systems Audit Objectives
- System Effectiveness and Efficiency
- Information Systems Abuse
- Asset Safeguarding Objective and Process
- Evidence Collection and Evaluation
- Logs and Audit Trails as Evidence
-
Chapter Five: Conducting an Information Systems Audit
- Audit Program
- Audit Plan
- Audit Procedures and Approaches
- System Understanding and Review
- Compliance Reviews and Tests
- Substantive Reviews and Tests
- Audit Tools and Techniques
- Sampling Techniques
- Audit Questionnaire
- Audit Documentation
- Audit Report
- Auditing Approaches
- Sample Audit Work-Planning Memo
- Sample Audit Work Process Flow
- Chapter Six: Risk-Based Systems Audit
-
Chapter Seven: Business Continuity and Disaster Recovery Plan
- Business Continuity and Disaster Recovery Process
- Business Impact Analysis
- Incident Response Plan
- Disaster Recovery Plan
- Types of Disaster Recovery Plans
- Emergency Preparedness Audit Checklist
- Business Continuity Strategies
- Business Resumption Plan Audit Checklist
- Recovery Procedures Testing Checklist
- Plan Maintenance Checklist
- Vital Records Retention Checklist
- Forms and Documents
- Chapter Eight: Auditing in the E-Commerce Environment
- Chapter Nine: Security Testing
- Chapter Ten: Case Study: Conducting an Information Systems Audit
-
Chapter One: Overview of Systems Audit
-
Part Two: Information Systems Auditing Checklists
- Chapter Eleven: ISecGrade Auditing Framework
- Chapter Twelve: ISecGrade Checklists
-
Chapter Thirteen: Session Quiz
- Chapter 1: Overview of Systems Audit
- Chapter 2: Hardware Security Issues
- Chapter 3: Software Security Issues
- Chapter 4: Information Systems Audit Requirements
- Chapter 5: Conducting an Information Systems Audit
- Chapter 6: Risk-Based Systems Audit
- Chapter 7: Business Continuity and Disaster Recovery Plan
- Chapter 8: Auditing in the E-Commerce Environment
- Chapter 9: Security Testing
- About the Authors
- About the Website
- Index
Product information
- Title: Understanding and Conducting Information Systems Auditing + Website
- Author(s):
- Release date: March 2013
- Publisher(s): Wiley
- ISBN: 9781118343746
You might also like
book
Auditor’s Guide to Information Systems Auditing
Praise for Auditor's Guide to Information Systems Auditing " Auditor's Guide to Information Systems Auditing is …
book
Auditing Information Systems, Second Edition
Have you been asked to perform an information systems audit and don't know where to start? …
book
Managing Risk in Information Systems, 3rd Edition
Revised and updated with the latest data in the field, the Second Edition of Managing Risk …
book
Internal Audit Quality
Deliver increased value by embedding quality into internal audit activities Internal Audit Quality: Developing a Quality …