Home > Preparing for auditors: Checklists for before, during and after an IT audit
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

Preparing for auditors: Checklists for before, during and after an IT audit

27 Jun 2006 | Auerbach

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

In this excerpt from Chapter 2, Audit and Review: Its Role in Information Technology, from Information Technology Control and Audit, Second Edition, author Frederick Gallegos offers IT managers checklists to assist in the preparation of an IT audit.

Information Technology Control and Audit

Frederick Gallegos

720 pages; $89.95

Auerbach Publications

"If you build it, they will come" has been a familiar phrase used in reference to the coming of the auditor. An IT manager has a right to receive a quality audit. However, managers can do much to ensure that they receive such a review by asking such questions and making such preparations as given below.

Preaudit checklist:

  1. Who are members of the audit team, and what are their roles and assignments?
  2. What are the credentials and experience of the assigned audit team?
  3. What orientation or training can you provide them to be comfortable within the environment?
  4. Communicate with your managers and staff in the areas to be audited.
  5. If an area was audited before, review the prior report to see the issues raised and recommended made. Get an update of corrections or changes made as a result of prior audit work and give your staff and the audit department credit.

Audit checklist:

  1. Purpose of the audit?
  2. Scope and objectives?
  3. Who are the audit staff assigned? (Ask to be notified if any staff are changed.)
  4. Timeframe for work to be performed?
  5. Use of computer time/access to system/logs/training needed.
  6. Access to IT management and staff?
  7. Communicate (1) and (2) to all IT staff affected.
  8. Set weekly or biweekly meetings with audit manager/audit team to discuss audit progress and issues.
  9. Before the audit is finished, request close-out conference from audit group.
  10. Request a copy of audit report.
More information on IT audits

Learn how to survive a regulatory compliance audit with the resources in our Compliance All-in-One Guide.

Download Chapter 2, Audit and Review: Its Role in Information Technology.

Post-audit checklist:

  1. When the audit report is issued, pull your team together and discuss the report; if you follow the steps above there should be no surprises. If there are, there was a communication breakdown somewhere.
  2. If you disagree with the report or portions of the report, do so in writing with supporting evidence. Remember, the auditor has supporting evidence for their reports, and this exists in their working papers. For those areas you agree, indicate what corrective actions your team plans to take.
  3. Have your team provide a status report to you on a 3- to 6-month cycle with a copy to go to Internal Audit. This shows you value their work.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Audit
PCI version 1.2 clarifications: How to get an early start on compliance audits
Version 1.2 of Payment Card Industry (PCI) Data Security Standard answers questions, raises others
Architect Security and Compliance Programs to Be Complementary
The road to compliance
Hannaford breach illustrates dangerous compliance mentality
Data breach costs soar
IBM to boost security spending, push PCI DSS program
Filtering log data: Looking for the needle in the haystack
Preparing for a network security audit starts with monitoring and remediation
Code Green pitches data protection for SMBs

Passing an audit
Introduction to internal IT audits for regulatory compliance
What I Learned from Audits
PCI Data Security Standard: How to survive an audit

Working with auditors
Passing the blame on regulatory compliance
Surviving an audit
Cheat sheet: 10 ways to prep for auditors

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts