Home > Preparing for auditors: Checklists for before, during and after an IT audit
Book Chapter:
EMAIL THIS

Preparing for auditors: Checklists for before, during and after an IT audit

27 Jun 2006 | Auerbach

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

In this excerpt from Chapter 2, Audit and Review: Its Role in Information Technology, from Information Technology Control and Audit, Second Edition, author Frederick Gallegos offers IT managers checklists to assist in the preparation of an IT audit.

Information Technology Control and Audit

Frederick Gallegos

720 pages; $89.95

Auerbach Publications

"If you build it, they will come" has been a familiar phrase used in reference to the coming of the auditor. An IT manager has a right to receive a quality audit. However, managers can do much to ensure that they receive such a review by asking such questions and making such preparations as given below.

Preaudit checklist:

  1. Who are members of the audit team, and what are their roles and assignments?
  2. What are the credentials and experience of the assigned audit team?
  3. What orientation or training can you provide them to be comfortable within the environment?
  4. Communicate with your managers and staff in the areas to be audited.
  5. If an area was audited before, review the prior report to see the issues raised and recommended made. Get an update of corrections or changes made as a result of prior audit work and give your staff and the audit department credit.

Audit checklist:

  1. Purpose of the audit?
  2. Scope and objectives?
  3. Who are the audit staff assigned? (Ask to be notified if any staff are changed.)
  4. Timeframe for work to be performed?
  5. Use of computer time/access to system/logs/training needed.
  6. Access to IT management and staff?
  7. Communicate (1) and (2) to all IT staff affected.
  8. Set weekly or biweekly meetings with audit manager/audit team to discuss audit progress and issues.
  9. Before the audit is finished, request close-out conference from audit group.
  10. Request a copy of audit report.
More information on IT audits

Learn how to survive a regulatory compliance audit with the resources in our Compliance All-in-One Guide.

Download Chapter 2, Audit and Review: Its Role in Information Technology.

Post-audit checklist:

  1. When the audit report is issued, pull your team together and discuss the report; if you follow the steps above there should be no surprises. If there are, there was a communication breakdown somewhere.
  2. If you disagree with the report or portions of the report, do so in writing with supporting evidence. Remember, the auditor has supporting evidence for their reports, and this exists in their working papers. For those areas you agree, indicate what corrective actions your team plans to take.
  3. Have your team provide a status report to you on a 3- to 6-month cycle with a copy to go to Internal Audit. This shows you value their work.


BROWSE BY TAG
Security Audit, Compliance and Standards,   IT Security Audits,   Audits,   Passing an audit,   Compliance,   Working with auditors,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
IT Security Audits
Standards compliance does not equal sound information security risk management
Tony Spinelli: Prioritize Information Security over Compliance
How to prepare for a FERPA audit
MasterCard increases PCI compliance requirements for some merchants
How to select a set of network security audit guidelines
How to write a risk methodology that blends business, security needs
PCI compliance requirement 11: Testing
Using IAM tools to improve compliance
Forensic accounting success depends on information security support
HIPAA compliance: New regulations change the game

Passing an audit
Introduction to internal IT audits for regulatory compliance
What I Learned from Audits
PCI Data Security Standard: How to survive an audit

Working with auditors
Passing the blame on regulatory compliance
Surviving an audit
Cheat sheet: 10 ways to prep for auditors

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts