ITSAC - Module 7 & 8 Flashcards
IT Audit Process & Tools and Techniques Used in IT Auditing (38 cards)
Future Financial Fiascos
- Enron(2001)
- WorldCom (2002)
- is an inventory of all the potential audit areas within an organization
- documents the key business processes and risks of an organization.
audit universe
includes the basic functional audit area, organization objectives, key business processes that support those organization objectives, specific audit objectives, risks of not achieving those objectives, and controls that mitigate the risks.
audit universe
is also an essential building block to a properly risk-based internal audit process.
audit universe
provides a comprehensive list of critical IT processes, which can be used as a starting point.
Control Objectives for Information and Related Technology (COBIT)
COBIT
Control Objectives for Information and Related Technology
is an authoritative, international set of generally accepted IT practices or control objectives that help employees, managers, executives, and auditors
COBIT
supports the need to research, develop, publicize, and promote up-to-date internationally accepted IT control objectives.
COBIT
Where to download COBIT 5
www.isaca.org
—optimizes the use of organizational resources to effectively address risks.
Governance
—plan, build, run, and monitor the activities and processes used by the organization to pursue the objectives established by the board.
management
are considered the foundation of the audit function as they assist in developing the process for planning individual audits.
Risk assessments
assist auditors in automating the necessary audit functions and integrating information gathered as part of the audit process.
Audit productivity tools
Examples of Audit productivity tools
- Audit planning and tracking
- Documentation and presentations Communication
- Data management, electronic working papers, and groupware
- Resource management
Shows the structure of the database by illustrating the different data elements (like customers or transactions) and how they are related.
ENTITY RELATIONSHIP DIAGRAM (ERD)
Shows how data moves through the system—from the point it enters, how it is processed, where it is stored, and where it goes next.
DATA FLOW DIAGRAM (DFD)
Provides a step-by-step visual of the system’s operations, including decisions and actions taken.
FLOWCHART
use symbols to describe transaction processing and the flow of data through a system by specifically showing: inputs and outputs; information activities (processing data); data storage; data flows; and decision steps.
Flowcharts
Manual or electronic document
|’’’’’’’|
|__/’’’
Multiple copies of manual or electronic documents
|_
|’’’’’’’||
|__/’’’
Electronic data entry device (e.g., laptop, mobile device)
|
…………
|……….|
Electronic operation or processing of data by the computer
……
[…..]
Manual operation
_
\_/
Data stored electronically in a database
O
|..|