Khám Phá Những Điều Cơ Bản Về Kiểm Toán CNTT

Tài liệu chỉ dẫn Hướng dẫn cơ bản về kiểm toán CNTT, quy trình cụ thể, mẹo kỹ thuật, tiết kiệm thời gian thực hiện ứng dụng rộng rãi trong thực tiễn

Chuyên ngành

Information Assurance

Người đăng

Ẩn danh

Thể loại

thesis

2014

337
7
0

Phí lưu trữ

75 Point

Mục lục chi tiết

Cover image

Title page

Copyright

Dedication

Acknowledgments

About the Author

About the Technical Editor

Trademarks

Introduction

0.1. Abstract

0.2. Information in this chapter

0.3. Introduction to IT auditing

0.4. Purpose and rationale

0.5. Intended use

0.6. Key audiences

1. CHƯƠNG 1: IT Audit Fundamentals

1.1. Information in this chapter

1.2. What is IT auditing?

1.3. Why audit?

1.4. Who gets audited?

1.5. Who does IT auditing?

1.6. Relevant source material

1.7. Summary

1.8. References

2. CHƯƠNG 2: Auditing in Context

2.1. Information in this chapter

2.2. IT governance

2.3. Risk management

2.4. Compliance and certification

2.5. Quality management and quality assurance

2.6. Information security management

2.7. Relevant source material

2.8. Summary

2.9. References

3. CHƯƠNG 3: Internal Auditing

3.1. Information in this chapter

3.2. Internal audit as an organizational capability

3.3. Benefits of internal IT auditing

3.4. Internal audit challenges

3.5. Internal auditors

3.6. Relevant source material

3.7. Summary

3.8. References

4. CHƯƠNG 4: External Auditing

4.1. Information in this chapter

4.2. Operational aspects of external audits

4.3. External IT audit drivers and rationale

4.4. External audit benefits

4.5. External audit challenges

4.6. External auditors

4.7. Relevant source material

4.8. Summary

4.9. References

5. CHƯƠNG 5: Types of Audits

5.1. Information in this chapter

5.2. Financial audits

5.3. Operational audits

5.4. Certification audits

5.5. Compliance audits

5.6. IT-specific audits

5.7. Relevant source material

5.8. Summary

5.9. References

6. CHƯƠNG 6: IT Audit Components

6.1. Information in this chapter

6.2. Establishing the scope of IT audits

6.3. Types of controls

6.4. Auditing different IT assets

6.5. Auditing procedural controls or processes

6.6. Relevant source material

6.7. References

7. CHƯƠNG 7: IT Audit Drivers

7.1. Information in this chapter

7.2. Laws and regulations

7.3. Certification standards

7.4. Operational effectiveness

7.5. Quality assurance and continuous improvement

7.6. Relevant source material

7.7. Summary

7.8. References

8. CHƯƠNG 8: IT Audit Processes

8.1. Information in this chapter

8.2. Audit planning

8.3. Audit performance

8.4. Reporting findings

8.5. Process life cycles and methodologies

8.6. Relevant source material

8.7. Summary

8.8. References

9. CHƯƠNG 9: Methodologies and Frameworks

9.1. Information in this chapter

9.2. Audit-specific methodologies and frameworks

9.3. IT governance and management frameworks

9.4. Government-focused audit methodologies

9.5. Security control assessment frameworks

9.6. Relevant source material

9.7. Summary

9.8. References

10. CHƯƠNG 10: Audit-Related Organizations, Standards, and Certifications

10.1. Information in this chapter

10.2. National and international perspectives

10.3. Audit-focused standards and certification organizations

10.4. Organizations offering standards, guidance, or certifications relevant to IT auditing

10.5. Relevant source material

10.6. Summary

10.7. References

References

Abstract

Acronyms

Abstract Acronyms and abbreviations

Index

Copyright

Tóm tắt

I. Giới thiệu về kiểm toán CNTT

Kiểm toán công nghệ thông tin (kiểm toán CNTT) là một quy trình hệ thống và khách quan nhằm đánh giá một hoặc nhiều khía cạnh của tổ chức, so sánh hoạt động của tổ chức với một tập hợp tiêu chí hoặc yêu cầu đã định. Mục tiêu chính của kiểm toán CNTT là đảm bảo rằng việc sử dụng công nghệ thông tin trong tổ chức là hiệu quả và các tài sản CNTT được bảo vệ đúng cách. Kiểm toán CNTT không chỉ giúp tổ chức hiểu rõ và cải thiện việc sử dụng các biện pháp kiểm soát mà còn đo lường và điều chỉnh hiệu suất để đạt được các mục tiêu đã đề ra. Theo Gantz, kiểm toán CNTT bao gồm việc sử dụng các phương pháp kiểm toán chính thức để xem xét các quy trình, khả năng và tài sản CNTT cũng như vai trò của chúng trong việc hỗ trợ các quy trình kinh doanh của tổ chức.

1.1. Mục đích và lý do kiểm toán CNTT

Mục đích của kiểm toán CNTT là để đảm bảo rằng các tài sản và thông tin CNTT được bảo vệ hiệu quả trong một tổ chức. Kiểm toán CNTT cũng giúp tổ chức xác định các cơ hội cải tiến trong quy trình và sản phẩm. Theo các quy định pháp lý và tiêu chuẩn, nhiều tổ chức bắt buộc phải thực hiện kiểm toán CNTT để chứng minh sự tuân thủ và hiệu quả trong quản lý rủi ro. Việc kiểm toán không chỉ là một yêu cầu mà còn là một phần thiết yếu trong quản lý và phát triển tổ chức.

II. Quy trình kiểm toán CNTT

Quy trình kiểm toán CNTT bao gồm nhiều bước từ việc lập kế hoạch kiểm toán đến thực hiện và báo cáo kết quả. Đầu tiên, việc lập kế hoạch kiểm toán rất quan trọng để xác định phạm vi và mục tiêu của kiểm toán. Sau đó, các kiểm toán viên tiến hành thu thập thông tin và thực hiện các đánh giá theo tiêu chí đã định. Báo cáo kết quả kiểm toán là một phần không thể thiếu, giúp tổ chức hiểu rõ hơn về tình trạng hiện tại của hệ thống CNTT của mình. Theo Gantz, quy trình này không chỉ giúp phát hiện các vấn đề mà còn cung cấp các khuyến nghị để cải thiện hiệu quả hoạt động.

2.1. Các bước trong quy trình kiểm toán CNTT

Quy trình kiểm toán CNTT thường bao gồm các bước sau: xác định phạm vi kiểm toán, lập kế hoạch chi tiết, thu thập dữ liệu, thực hiện kiểm toán, phân tích kết quả và báo cáo. Mỗi bước đều có vai trò quan trọng trong việc đảm bảo rằng kiểm toán được thực hiện một cách chính xác và hiệu quả. Việc tuân thủ quy trình này giúp tổ chức phát hiện và khắc phục kịp thời các vấn đề liên quan đến an ninh và hiệu suất của hệ thống CNTT.

III. Các phương pháp kiểm toán CNTT

Có nhiều phương pháp khác nhau để thực hiện kiểm toán CNTT, bao gồm kiểm toán nội bộ và kiểm toán bên ngoài. Kiểm toán nội bộ thường được thực hiện bởi các nhân viên trong tổ chức, trong khi kiểm toán bên ngoài được thực hiện bởi các chuyên gia độc lập. Mỗi phương pháp có những ưu điểm và thách thức riêng. Theo Gantz, việc chọn phương pháp phù hợp phụ thuộc vào mục tiêu của kiểm toán và nguồn lực có sẵn trong tổ chức.

3.1. Ưu điểm và nhược điểm của các phương pháp

Kiểm toán nội bộ thường mang lại lợi ích về chi phí và khả năng hiểu biết sâu sắc về tổ chức. Tuy nhiên, nó cũng có thể gặp khó khăn trong việc duy trì tính khách quan. Ngược lại, kiểm toán bên ngoài mang lại cái nhìn khách quan hơn nhưng có thể tốn kém và không hiểu rõ về quy trình nội bộ. Do đó, việc lựa chọn phương pháp kiểm toán cần phải cân nhắc kỹ lưỡng để đạt được kết quả tốt nhất.

IV. Rủi ro trong kiểm toán CNTT

Rủi ro trong kiểm toán CNTT bao gồm nhiều yếu tố như thiếu thông tin, sai sót trong quy trình kiểm toán và khả năng không phát hiện được các vấn đề nghiêm trọng. Việc đánh giá và quản lý rủi ro là rất quan trọng để đảm bảo rằng kiểm toán diễn ra một cách hiệu quả. Theo Gantz, các tổ chức cần phải xây dựng các biện pháp kiểm soát để giảm thiểu rủi ro và đảm bảo rằng các tài sản CNTT được bảo vệ đúng cách.

4.1. Các loại rủi ro phổ biến

Một số loại rủi ro phổ biến trong kiểm toán CNTT bao gồm rủi ro về bảo mật thông tin, rủi ro về tuân thủ quy định và rủi ro về hiệu suất. Các tổ chức cần phải nhận diện và quản lý những rủi ro này để đảm bảo rằng kiểm toán CNTT đạt được mục tiêu đề ra. Việc này không chỉ giúp bảo vệ tài sản CNTT mà còn nâng cao hiệu quả hoạt động của tổ chức.

V. Báo cáo kiểm toán CNTT

Báo cáo kiểm toán CNTT là tài liệu quan trọng cung cấp thông tin về kết quả kiểm toán và các khuyến nghị để cải thiện. Báo cáo này thường bao gồm các phát hiện chính, phân tích và khuyến nghị cụ thể. Theo Gantz, việc trình bày báo cáo một cách rõ ràng và dễ hiểu là rất cần thiết để đảm bảo rằng các bên liên quan có thể dễ dàng hiểu và thực hiện các hành động cần thiết.

5.1. Cấu trúc của báo cáo kiểm toán

Báo cáo kiểm toán thường bao gồm các phần như mục tiêu kiểm toán, phương pháp thực hiện, phát hiện và khuyến nghị. Mỗi phần đều đóng vai trò quan trọng trong việc truyền đạt thông tin một cách hiệu quả. Việc cung cấp thông tin đầy đủ và chính xác trong báo cáo giúp tổ chức có thể thực hiện các cải tiến cần thiết và nâng cao hiệu quả của hệ thống CNTT.

11/01/2025

Trích đoạn nội dung tài liệu

The Basics of IT Audit Purposes, Processes, and Practical Information Stephen D. Gantz TECHNICAL EDITOR Steve Maske Table of Contents Cover image Title page Copyright Dedication Acknowledgments About the Author About the Technical Editor Trademarks Introduction Abstract Information in this chapter Introduction to IT auditing Purpose and rationale Structure and content Chapter 1. IT Audit Fundamentals Information in this chapter What is IT auditing? Why audit? Who gets audited? Who does IT auditing? Relevant source material Summary References Chapter 2. Auditing in Context Information in this chapter: IT governance Risk management Compliance and certification Quality management and quality assurance Information security management Relevant source material Summary References Chapter 3.

Internal Auditing Information in this chapter: Internal audit as an organizational capability Benefits of internal IT auditing Internal audit challenges Internal auditors Relevant source material Summary References Chapter 4. External Auditing Information in this chapter: Operational aspects of external audits External IT audit drivers and rationale External audit benefits External audit challenges External auditors Relevant source material Summary References Chapter 5. Types of Audits Information in this chapter: Financial audits Operational audits Certification audits Compliance audits IT-specific audits Relevant source material Summary References Chapter 6. IT Audit Components Information in this chapter Establishing the scope of IT audits Types of controls Auditing different IT assets Auditing procedural controls or processes Relevant source material References Chapter 7.

IT Audit Drivers Information in this chapter: Laws and regulations Certification standards Operational effectiveness Quality assurance and continuous improvement Relevant source material Summary References Chapter 8. IT Audit Processes Information in this chapter: Audit planning Audit performance Reporting findings Process life cycles and methodologies Relevant source material Summary References Chapter 9. Methodologies and Frameworks Information in this chapter Audit-specific methodologies and frameworks IT governance and management frameworks Government-focused audit methodologies Security control assessment frameworks Relevant source material Summary References Chapter 10. Audit-Related Organizations, Standards, and Certifications Information in this chapter National and international perspectives Audit-focused standards and certification organizations Organizations offering standards, guidance, or certifications relevant to IT auditing Relevant source material Summary References References Abstract References Acronyms Abstract Acronyms and abbreviations Index Copyright Acquiring Editor: Steve Elliot Editorial Project Manager: Benjamin Rearick Project Manager: Malathi Samayan Designer: Matthew Limbert Syngress is an imprint of Elsevier 225 Wyman Street, Waltham, MA 02451, USA © 2014 Elsevier Inc.

All rights reserved No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publisher’s permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www. This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein). Notices Knowledge and best practice in this field are constantly changing.

As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described here in. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility. To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.

Library of Congress Cataloging-in-Publication Data Gantz, Stephen D. The basics of IT audit: purposes, processes, and practical information / Stephen D. pages cm Includes bibliographical references and index. Information technology—Auditing.

Computer networks--Security measures.068'1--dc23 2013036148 British Library Cataloguing-in-Publication Data A catalogue record for this book is available from the British Library For information on all Syngress publications, visit our website at store.com/Syngress ISBN: 978-0-12417159-6 Printed and bound in the United States of America 14 15 16 13 12 11 10 9 8 7 6 54321 Dedication Dedicated to my wife Reneé, my son Henry, and my daughters Claire and Gillian, without whose support and forbearance I would not have been able to devote the necessary time and energy into this project. Acknowledgments I would like to acknowledge the very capable support provided by members of the Syngress/Elsevier team in bringing this project to completion, particularly including Steve Elliot and Ben Rearick. Thanks also go to Steven Maske for his helpful feedback, comments, and technical edits on this book. I am also grateful for the guidance and constructive criticism on my writing provided by Dr.

Thomas Mierzwa, who served as my dissertation adviser as I completed my doctorate in management shortly before beginning work on this book. Work in information technology (IT) characterizes my entire career—as a consultant, as a software and security architect, and as an educator and author. I appreciate the many professional opportunities I have received during that time, including my initial exposure to fraud detection and forensic investigation from Malcolm Sparrow more than 15 years ago and subsequent experience in IT auditing and information security since that time. I have been fortunate to work for many managers and executives who have encouraged my continued career development and self-directed projects and writing initiatives.

I am especially grateful for the leadership and support of my current management team, including Michele Kang, Davis Foster, Aaron Daniels, Tom Stepka, and Sean Gallagher, who collectively helped in providing a dynamic and engaging work environment and the opportunity to challenge myself on many types of internal and client-facing projects. About the Author Dr Stephen D. Gantz (CISSP-ISSAP, CEH, CGEIT, CRISC, CIPP/G, C|CISO) is an information security and information technology (IT) consultant with over 20 years of experience in security and privacy management, enterprise architecture, systems development and integration, and strategic planning. He currently holds an executive position with a health information technology services firm primarily serving federal and state government customers.

He is also an associate professor of Information Assurance in the Graduate School at University of Maryland University College (UMUC) and an adjunct lecturer in the Health Information Technology program of the Catholic University of America’s School of Library and Information Science. He maintains a security- focused web site and blog at http://www. His security and privacy expertise spans program management, security architecture, policy development and enforcement, risk assessment, and regulatory compliance with major legislation such as FISMA, HIPAA, and the Privacy Act. His industry experience includes health, financial services, higher education, consumer products, and manufacturing, but since 2000 his work has focused on security and other information resources management functions in state and federal government agencies and in private sector industries responsible for critical infrastructure.

He holds a Doctor of Management degree from UMUC, where his dissertation focused on trust and distrust in inter- organizational networks, alliances, and other cooperative relationships. He also earned a master’s degree in public policy from the Kennedy School of Government at Harvard University and a bachelor’s degree from Harvard. He currently resides in Arlington, Virginia with his wife Reneé and children Henry, Claire, and Gillian. About the Technical Editor Steven Maske (CISA, CISSP) is an information security professional with over 12 years in the information technology (IT) industry.

As the lead security engineer for a Fortune 1000 company he designs, develops, and tests information security solutions and establishes policies, procedures, and controls to ensure regulatory compliance. He is responsible for identifying and managing risks and overseeing IT projects and strategic initiatives. He has previous experience as a consultant where he performed over 150 vulnerability assessments, penetration tests, and IT audits. He is an active member of the security community and can be found on Twitter as @ITSecurity or via his blog, http://SecurityRamblings.

Trademarks Institute of Internal Auditors trademarks: Certified Internal Auditor (CIA®), Certified Government Auditing Professional (CGAP®), Certified Financial Services Auditor (CFSA®), Certification in Control Self-Assessment (CCSA®), Certification in Risk Management Assurance (CRMA®), International Professional Practices Framework (IPPF®) International Council of Electronic Commerce Consultants EC-Council trademarks: Certified Ethical Hacker (C|EHTM), Certified Hacking Forensic Investigator (C|HFITM) International Information Systems Security Certification Consortium certifications: Certified Information Systems Security Professional (CISSP®), Systems Security Certified Professional (SSCP®), Certified Accreditation Professional (CAP®), Certified Secure Software Lifecycle Professional (CSSLP®) ISACA® trademarks: Certified Information Systems Auditor (CISA®), Certified Information Security Manager (CISM®), Certified in Risk and Information Systems Control (CRISC®), Certified in the Governance of Enterprise Information Technology (CGEIT®), Control Objectives for Information and Related Technology (COBIT®) Other trademarks: American Society for Quality (ASQ®) Certified Computer Examiner (CCE®) International Organization for Standardization (ISO®) Information Technology Infrastructure Library (ITIL®) Projects in Controlled Environments, version 2 (PRINCE2®) Project Management Institute (PMI®) Project Management Body of Knowledge (PMBOK®) Introduction Abstract This chapter provides an introduction to the material presented in this book and describes the purpose and intent of the book, its primary intended audiences, likely uses, and why the book was written. It explains the key purposes for and reasons behind IT auditing and highlights the legal, regulatory, compliance, and governance driving auditing in contemporary public and private sector organizations. Finally, the chapter describes the structure and content flow of the subsequent chapters in the book, and offers a brief description of each chapter. Keywords Auditing, information assurance, information technology, risk management, governance Information in this chapter Introduction to IT auditing Purpose and rationale for this book Intended use Key audiences Structure and content of the book Summary descriptions of each chapter Introduction to IT auditing An audit is a systematic, objective examination of one or more aspects of an organization that compares what the organization does to a defined set of criteria or requirements.

Information technology (IT) auditing examines processes, IT assets, and controls at multiple levels within an organization to determine the extent to which the organization adheres to applicable standards or requirements. Virtually, all organizations use IT to support their operations and the achievement of their mission and business objectives. This gives organizations a vested interest in ensuring that their use of IT is effective, that IT systems and processes operate as intended, and that IT assets and other resources are efficiently allocated and appropriately protected. IT auditing helps organizations understand, assess, and improve their use of controls to safeguard IT, measure and correct performance, and achieve objectives and intended outcomes.

IT auditing consists of the use of formal audit methodologies to examine IT- specific processes, capabilities, and assets and their role in enabling an organization’s business processes. IT auditing also addresses IT components or capabilities that support other domains subject to auditing, such as financial management and accounting, operational performance, quality assurance, and governance, risk management, and compliance (GRC). IT audits are performed both by internal auditors working for the organization subject to audit and external auditors hired by the organization. The processes and procedures followed in internal and external auditing are often quite similar, but the roles of the audited organization and its personnel are markedly different.

The audit criteria—the standards or requirements against which an organization is compared during an audit—also vary between internal and external audits and for audits of different types or conducted for different purposes. Organizations often engage in IT audits to satisfy legal or regulatory requirements, assess the operational effectiveness of business processes, achieve certification against specific standards, demonstrate compliance with policies, rules, or standards, and identify opportunities for improvement in the quality of business processes, products, and services. Organizations have different sources of motivation for each type of audit and different goals, objectives, and expected outcomes. This book explains all of these aspects of IT auditing, describes the establishment of organizational audit programs and the process of conducting audits, and identifies the most relevant standards, methodologies, frameworks, and sources of guidance for IT auditing.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Bài viết "Khám Phá Những Điều Cơ Bản Về Kiểm Toán CNTT" của Stephen D. Gantz, dưới sự hướng dẫn của Dr. Thomas Mierzwa tại Trường Đại học Maryland, cung cấp cái nhìn tổng quan về kiểm toán công nghệ thông tin (CNTT). Nội dung bài viết nhấn mạnh tầm quan trọng của kiểm toán CNTT trong việc đảm bảo an ninh thông tin và bảo vệ dữ liệu trong các tổ chức. Bài viết cũng đề cập đến các phương pháp và công cụ kiểm toán hiệu quả, giúp người đọc hiểu rõ hơn về quy trình và cách thức thực hiện kiểm toán trong lĩnh vực này. Độc giả sẽ nhận được những kiến thức quý giá về cách thức bảo vệ thông tin và nâng cao hiệu quả hoạt động kiểm toán.

Nếu bạn muốn mở rộng kiến thức về kiểm toán nội bộ, có thể tham khảo thêm bài viết "Luận văn về kiểm toán nội bộ hoạt động tín dụng tại ngân hàng thương mại cổ phần Bắc Á". Bài viết này cung cấp thông tin sâu sắc về kiểm toán nội bộ trong lĩnh vực ngân hàng, giúp bạn hiểu rõ hơn về quy trình và tiêu chuẩn kiểm toán.

Ngoài ra, bạn cũng có thể tìm hiểu về "Bài Giảng Kiểm Toán Nội Bộ: Tìm Hiểu Các Khái Niệm Cơ Bản", nơi trình bày các khái niệm cơ bản và vai trò của kiểm toán nội bộ trong các tổ chức, qua đó bổ sung thêm kiến thức cho bạn về lĩnh vực này.

Cuối cùng, bài viết "Luận văn thạc sĩ: Hoàn thiện công tác kế toán doanh thu và chi phí đóng tàu tại Tổng công ty Sông Thu" cũng là một tài liệu hữu ích, liên quan đến kế toán và kiểm toán trong ngành công nghiệp, giúp bạn có thêm cái nhìn tổng quát về các phương pháp kiểm toán trong thực tiễn doanh nghiệp.