-
25
pages
-
English
-
Documents
Description
Understanding an IT AuditCraig A. Brye, CISAEide Bailly, LLP701-476-8319‹‹‹‹‹‹BackgroundNetwork AdministrationNetwork SecurityCertified Information Systems Auditor (CISA)‹‹‹‹‹‹‹‹‹‹‹‹Security Vs. AuditDistinct but complementaryMore of a focus on internal issuesProcess oriented– Human elementA comprehensive and successful security solution – Security and PrivacyIncludes the non-technical aspects of reducing IT riskTreat the symptoms or find a cure‹‹‹‹‹‹‹‹‹‹Current Compliance ProgramsSarbanes-Oxley – 404Health Information Portability and Accountability Act (HIPAA)Gramm-Leach-Bliley-–FDIC, FFIECFERC/NERCFTC Safeguards Rule‹‹‹‹‹‹‹‹‹‹‹‹Reasons to Conduct an AuditThe goal of an Information Systems audit is to ascertain the controls in place for all technologies in use and provide an independent opinion on the effectiveness of those controls in regards to containing risk.Regulatory requirementsRequest from a business partnerMarketingEmployee EvaluationPro-active approach to security-‹‹‹‹SAS 70Statement on Auditing Standards (SAS) No. 70, Service Organizations, is an internationally recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA).A SAS 70 audit or service auditor's examination is widely recognized, because it represents that a service organization has been through an in-depth audit of their control activities, which generally ...
-
Publié par
-
Langue
English