Information Systems (IS) Audit

IS Audit by an external independent auditor evaluates appropriateness and adequacy of an organisation's IT systems and its operations & management. Like financial audit, which evaluates financial health of the company, the main objective of an IS Audit is to provide assurance that the organisation's information systems are functioning properly and that they are secure against unauthorised access, misuse or damage.

The scope of an IS Audit can vary depending on the organisation's needs and regulatory environment, but it typically includes review of design, implementation, maintenance and security of information systems.

Primary objectives of an IS Audit are as follows:

  • Risk-based Analysis : Identification of high priority / high impact business functions and carry out risk assessment of corresponding Information systems to identify potential threats & vulnerabilities.
  • Assessment of Controls : Verification of existing controls to safeguard against identified threats & vulnerabilities and illegal/ authorised access, modifications, and destructions of computer hardware, software, communications and data. IS Audit provides reasonable assurance to the management on adequacy and effectives of these controls.
  • Conformance and Performance Objectives : Conformance objective of IS Audit focuses on obtaining conclusions on aspects of conformity, namely confidentiality, integrity, availability and compliance with laws & regulations. Performance objective focuses on obtaining conclusions on aspects of performance, namely efficiency, effectiveness, and reliability.
 
     
2111 Times Visited