Monday, January 3, 2011

Introduction IS audit process

Audit process means encompasses the entire practice of IS auditing (procedure and methodology) which allows an IT auditor to perform audit in a professional manner.

There are five task within IT / IS Audit process area:
1. Develop and implement risk based IS audit strategy for the organization in compliance with audit standard, guideline and best practices.
2. Plan specific audit to ensure that IT and business system are controlled.
3. Concuct audit in accordance with IS audit standard, guidelines and best practices to meet planned audit objectives.
4. Communicate emerging issues, potential risk and audit result to key stakeholder.
5. Advise on implementation of risk management and control practice within the organization while maintaining independence.

We have to have knowledge in below area:
1. Knowledge of ISACA IS auditing standard, guideline and procedure
2. Knowledge of IS auditing practices and techniques.
3. Knowledge of techniques to gather information and preserve evidence.
4. Knowledge of evidence life cycle
5. Knowledge of control objective and control related
6. Knowledge of risk assessment in an audit context
7. Knowledge of audit planning and management techniques
8. Knowledge of reporting and communication techniques
9. Knowledge of control self assessment
10. Knowledge of continuous audit techniques

In an organization, IS audit function must be established by Audit charter. In addition, It must be approved by highest level of management and audit committee.

After established, IS auditor must be perform his job. First of all, thing that IS auditor must do is planning. It means adequate planning is a necessary first step in performing effective audit. Why planning? Because he needs to understand the general business environment as well as the associated business and control risk. He understands those by assessing operational and control risk and indentify control objectives.

To perform an audit planning, the IS auditor should:
  • Gain an understanding of the business mission, business' objectives, business processes, information and processing requirements such as availability, integrity and security and information architecture requirements. In general terms, process and technology.
  • Perform risk analysis
  • Conduct internal control review
  • Set the audit scope and audit objectives
  • Develop the audit approach or audit strategy
  • Assign resources to audit and address engagement logistics

CISA overview

CISA overview

CISA stands for Certified Information System Auditor. Today, There are many people who pursue international certification especially CISA. Why are they so enthusiast for getting CISA? Below are the answer:

To demonstrate your willingness to improve your technical knowledge and skills

To fulfill a requirement of employment

To advance in your career

To enhance your professional image

To be included with other professionals who have gained worldwide recognition

To demonstrate to management your commitment toward organizational excellence

To obtain credentials that employers seek

Like I did before when I obtain CCNA (one of Cisco certification), I strove hard to study and practiced at my virtual lab in order to get CCNA, because I want to demonstrate my internetworking skill through this.

Now, I am studying IT Audit. Fortunately, I found IS Auditor people who help and teach me about IS Audit. Therefore, I make this blog to summarize materials that I have studied.

There are requirements to get CISA:

Passing score on CISA Exam

At least five years of IS audit, control , assurance and/or security experience (some substitutions available)

Adherence to Code of Professional Ethics

Minimum 120 contact hours of continuing education every three years

Do you want to know what types of question in CISA exam? These are the answer:

Each exam consists of 200 questions administered over a four-hour period

Questions are designed to test practical knowledge and experience

All questions are multiple choice

Questions require the candidate to choose one best answer

Every question or statement has four options (answer choices)

Are you auditor? May be you are interested to take the exam? The exam is held twice annually in June and December. Why do we must know the exam time? In order to take a preparation so we are ready to take the exam.