The Basics of IT Audit Purposes, Processes, and Practical Information Stephen D. Gantz TECHNICAL EDITOR Steve Maske Table of Contents Cover image Title page Copyright Dedication Acknowledgments About the Author About the Technical Editor Trademarks Introduction Abstract Information in this chapter Introduction to IT auditing Purpose and rationale Structure and content Chapter 1. IT Audit Fundamentals Information in this chapter What is IT auditing? Why audit? Who gets audited? Who does IT auditing? Relevant source material Summary References Chapter 2. Auditing in Context Information in this chapter: IT governance Risk management Compliance and certification Quality management and quality assurance Information security management Relevant source material Summary References Chapter 3.
Internal Auditing Information in this chapter: Internal audit as an organizational capability Benefits of internal IT auditing Internal audit challenges Internal auditors Relevant source material Summary References Chapter 4. External Auditing Information in this chapter: Operational aspects of external audits External IT audit drivers and rationale External audit benefits External audit challenges External auditors Relevant source material Summary References Chapter 5. Types of Audits Information in this chapter: Financial audits Operational audits Certification audits Compliance audits IT-specific audits Relevant source material Summary References Chapter 6. IT Audit Components Information in this chapter Establishing the scope of IT audits Types of controls Auditing different IT assets Auditing procedural controls or processes Relevant source material References Chapter 7.
IT Audit Drivers Information in this chapter: Laws and regulations Certification standards Operational effectiveness Quality assurance and continuous improvement Relevant source material Summary References Chapter 8. IT Audit Processes Information in this chapter: Audit planning Audit performance Reporting findings Process life cycles and methodologies Relevant source material Summary References Chapter 9. Methodologies and Frameworks Information in this chapter Audit-specific methodologies and frameworks IT governance and management frameworks Government-focused audit methodologies Security control assessment frameworks Relevant source material Summary References Chapter 10. Audit-Related Organizations, Standards, and Certifications Information in this chapter National and international perspectives Audit-focused standards and certification organizations Organizations offering standards, guidance, or certifications relevant to IT auditing Relevant source material Summary References References Abstract References Acronyms Abstract Acronyms and abbreviations Index Copyright Acquiring Editor: Steve Elliot Editorial Project Manager: Benjamin Rearick Project Manager: Malathi Samayan Designer: Matthew Limbert Syngress is an imprint of Elsevier 225 Wyman Street, Waltham, MA 02451, USA © 2014 Elsevier Inc.
All rights reserved No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publisher’s permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www. This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein). Notices Knowledge and best practice in this field are constantly changing.
As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described here in. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility. To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.
Library of Congress Cataloging-in-Publication Data Gantz, Stephen D. The basics of IT audit: purposes, processes, and practical information / Stephen D. pages cm Includes bibliographical references and index. Information technology—Auditing.
Computer networks--Security measures.068'1--dc23 2013036148 British Library Cataloguing-in-Publication Data A catalogue record for this book is available from the British Library For information on all Syngress publications, visit our website at store.com/Syngress ISBN: 978-0-12417159-6 Printed and bound in the United States of America 14 15 16 13 12 11 10 9 8 7 6 54321 Dedication Dedicated to my wife Reneé, my son Henry, and my daughters Claire and Gillian, without whose support and forbearance I would not have been able to devote the necessary time and energy into this project. Acknowledgments I would like to acknowledge the very capable support provided by members of the Syngress/Elsevier team in bringing this project to completion, particularly including Steve Elliot and Ben Rearick. Thanks also go to Steven Maske for his helpful feedback, comments, and technical edits on this book. I am also grateful for the guidance and constructive criticism on my writing provided by Dr.
Thomas Mierzwa, who served as my dissertation adviser as I completed my doctorate in management shortly before beginning work on this book. Work in information technology (IT) characterizes my entire career—as a consultant, as a software and security architect, and as an educator and author. I appreciate the many professional opportunities I have received during that time, including my initial exposure to fraud detection and forensic investigation from Malcolm Sparrow more than 15 years ago and subsequent experience in IT auditing and information security since that time. I have been fortunate to work for many managers and executives who have encouraged my continued career development and self-directed projects and writing initiatives.
I am especially grateful for the leadership and support of my current management team, including Michele Kang, Davis Foster, Aaron Daniels, Tom Stepka, and Sean Gallagher, who collectively helped in providing a dynamic and engaging work environment and the opportunity to challenge myself on many types of internal and client-facing projects. About the Author Dr Stephen D. Gantz (CISSP-ISSAP, CEH, CGEIT, CRISC, CIPP/G, C|CISO) is an information security and information technology (IT) consultant with over 20 years of experience in security and privacy management, enterprise architecture, systems development and integration, and strategic planning. He currently holds an executive position with a health information technology services firm primarily serving federal and state government customers.
He is also an associate professor of Information Assurance in the Graduate School at University of Maryland University College (UMUC) and an adjunct lecturer in the Health Information Technology program of the Catholic University of America’s School of Library and Information Science. He maintains a security- focused web site and blog at http://www. His security and privacy expertise spans program management, security architecture, policy development and enforcement, risk assessment, and regulatory compliance with major legislation such as FISMA, HIPAA, and the Privacy Act. His industry experience includes health, financial services, higher education, consumer products, and manufacturing, but since 2000 his work has focused on security and other information resources management functions in state and federal government agencies and in private sector industries responsible for critical infrastructure.
He holds a Doctor of Management degree from UMUC, where his dissertation focused on trust and distrust in inter- organizational networks, alliances, and other cooperative relationships. He also earned a master’s degree in public policy from the Kennedy School of Government at Harvard University and a bachelor’s degree from Harvard. He currently resides in Arlington, Virginia with his wife Reneé and children Henry, Claire, and Gillian. About the Technical Editor Steven Maske (CISA, CISSP) is an information security professional with over 12 years in the information technology (IT) industry.
As the lead security engineer for a Fortune 1000 company he designs, develops, and tests information security solutions and establishes policies, procedures, and controls to ensure regulatory compliance. He is responsible for identifying and managing risks and overseeing IT projects and strategic initiatives. He has previous experience as a consultant where he performed over 150 vulnerability assessments, penetration tests, and IT audits. He is an active member of the security community and can be found on Twitter as @ITSecurity or via his blog, http://SecurityRamblings.
Trademarks Institute of Internal Auditors trademarks: Certified Internal Auditor (CIA®), Certified Government Auditing Professional (CGAP®), Certified Financial Services Auditor (CFSA®), Certification in Control Self-Assessment (CCSA®), Certification in Risk Management Assurance (CRMA®), International Professional Practices Framework (IPPF®) International Council of Electronic Commerce Consultants EC-Council trademarks: Certified Ethical Hacker (C|EHTM), Certified Hacking Forensic Investigator (C|HFITM) International Information Systems Security Certification Consortium certifications: Certified Information Systems Security Professional (CISSP®), Systems Security Certified Professional (SSCP®), Certified Accreditation Professional (CAP®), Certified Secure Software Lifecycle Professional (CSSLP®) ISACA® trademarks: Certified Information Systems Auditor (CISA®), Certified Information Security Manager (CISM®), Certified in Risk and Information Systems Control (CRISC®), Certified in the Governance of Enterprise Information Technology (CGEIT®), Control Objectives for Information and Related Technology (COBIT®) Other trademarks: American Society for Quality (ASQ®) Certified Computer Examiner (CCE®) International Organization for Standardization (ISO®) Information Technology Infrastructure Library (ITIL®) Projects in Controlled Environments, version 2 (PRINCE2®) Project Management Institute (PMI®) Project Management Body of Knowledge (PMBOK®) Introduction Abstract This chapter provides an introduction to the material presented in this book and describes the purpose and intent of the book, its primary intended audiences, likely uses, and why the book was written. It explains the key purposes for and reasons behind IT auditing and highlights the legal, regulatory, compliance, and governance driving auditing in contemporary public and private sector organizations. Finally, the chapter describes the structure and content flow of the subsequent chapters in the book, and offers a brief description of each chapter. Keywords Auditing, information assurance, information technology, risk management, governance Information in this chapter Introduction to IT auditing Purpose and rationale for this book Intended use Key audiences Structure and content of the book Summary descriptions of each chapter Introduction to IT auditing An audit is a systematic, objective examination of one or more aspects of an organization that compares what the organization does to a defined set of criteria or requirements.
Information technology (IT) auditing examines processes, IT assets, and controls at multiple levels within an organization to determine the extent to which the organization adheres to applicable standards or requirements. Virtually, all organizations use IT to support their operations and the achievement of their mission and business objectives. This gives organizations a vested interest in ensuring that their use of IT is effective, that IT systems and processes operate as intended, and that IT assets and other resources are efficiently allocated and appropriately protected. IT auditing helps organizations understand, assess, and improve their use of controls to safeguard IT, measure and correct performance, and achieve objectives and intended outcomes.
IT auditing consists of the use of formal audit methodologies to examine IT- specific processes, capabilities, and assets and their role in enabling an organization’s business processes. IT auditing also addresses IT components or capabilities that support other domains subject to auditing, such as financial management and accounting, operational performance, quality assurance, and governance, risk management, and compliance (GRC). IT audits are performed both by internal auditors working for the organization subject to audit and external auditors hired by the organization. The processes and procedures followed in internal and external auditing are often quite similar, but the roles of the audited organization and its personnel are markedly different.
The audit criteria—the standards or requirements against which an organization is compared during an audit—also vary between internal and external audits and for audits of different types or conducted for different purposes. Organizations often engage in IT audits to satisfy legal or regulatory requirements, assess the operational effectiveness of business processes, achieve certification against specific standards, demonstrate compliance with policies, rules, or standards, and identify opportunities for improvement in the quality of business processes, products, and services. Organizations have different sources of motivation for each type of audit and different goals, objectives, and expected outcomes. This book explains all of these aspects of IT auditing, describes the establishment of organizational audit programs and the process of conducting audits, and identifies the most relevant standards, methodologies, frameworks, and sources of guidance for IT auditing.