Robert E. Davis's Blog, page 6

June 22, 2011

Information security management: First-tier governance development - part 1

Organizationally, governance is the system by which entities are directed and controlled. "Potential stakeholders usually rely upon governance elements prior to investing their time, talent, and/or money." Leadership, stewardship, ethics...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on June 22, 2011 09:31

June 15, 2011

Information security management: Second-tier governance deployment - part 2

Abstraction levels are developed based on perceived usefulness. Second-tier Governance Tree information nodes can be viewed in the context of programs, systems, and processes. Pragmatically, establishment of entity-level governance is a second...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on June 15, 2011 07:53

June 8, 2011

Information security management: Second-tier governance deployment - part 1

Governing an entity mandates management accurately conceptualize organizational development, information criticality, and communication paths. For-profit entities are formulated to generate tangible and intangible wealth for stakeholders while not...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on June 08, 2011 09:50

June 1, 2011

IT audit follow-up: Assessing recommendation resolution - part 3

Control follow-up are activities pursued when an exception condition is identified and reported as presenting a risk to the entity. As a part of the follow-up activities, the IT auditor normally evaluates whether...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on June 01, 2011 09:55

May 25, 2011

IT audit follow-up: Assessing recommendation resolution - part 2

IT auditor follow-up activities has been defined "as a process by which they determine the adequacy, effectiveness and timeliness of actions taken by management on reported engagement observations and recommendations, including those made by...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on May 25, 2011 08:55

May 18, 2011

IT audit follow-up: Assessing recommendation resolution - part 1

While management is responsible for addressing assurance engagement findings and recommendations as well as tracking resolution status; audit is responsible for establishing policies, procedures, standards and rules for follow-up to determine...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on May 18, 2011 10:15

May 11, 2011

IT audit reporting: Communicating results - part 3

The final audit report should clearly identify ‘gaps’ in controls and the source of the vulnerabilities. Of the potential vulnerabilities documented in the audit report, it is importance to identify any significant, or material, risks....

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on May 11, 2011 09:34

May 4, 2011

IT audit reporting: Communicating results - part 2

Through an IT auditor’s efforts, audit findings are facts generated which directly support and evidence conclusions as well as recommendations. Audit findings are also the product of all previously performed audit work related to the audit...

[image error]
 •  0 comments  •  flag
Share on Twitter
Published on May 04, 2011 13:12

April 27, 2011

IT audit reporting: Communicating results - part 1

Robert E. DavisIT audit area reporting conveys an opinion concerning control adequacy based on planning, studying, testing and evaluating material or significant auditable units. Whether an IT auditor is engaged in direct or attest reporting -- after obtaining...April 27, 2011
 •  0 comments  •  flag
Share on Twitter
Published on April 27, 2011 14:39

April 20, 2011

IT audit fieldwork: Generally accepted processes - part 3

Robert E. DavisIT processing of datum has effects on controls and audit trails. Furthermore, IT can induce numerous changes in processing cycles. As a result of these changes, the IT auditor must evaluate the repercussions on the basic characteristics of control...April 20, 2011
[image error]
1 like ·   •  0 comments  •  flag
Share on Twitter
Published on April 20, 2011 11:52