IT Audit Explained

A resource about IT audit, its guidelines andif computer systems would be available for
applications in an organization. Includes a review ofbusiness when it is required. The confidentiality can
information technology's best practices andbe checked by seeing if the information in the
operations.system can be accessed by unauthorized users.
An IT audit or information technology audit is anThe auditor can satisfy himself regarding the
examination of the working of the informationintegrity by checking if the information provided
technology infrastructure. This seeks to find out ifby the system is accurate, timely and reliable. An
there is proper working in the IT sector and ifIT audit can take two forms it can be either of
proper control is being maintained. These auditsthe form of a "general control review" or an
can be undertaken independently or in association"application control review".
with other forms of company audit such asThere are three broad approaches to carry out
financial audit, inventory audit etc. IT audit wasan audit. They are technological innovation process
formerly called EDP or Electronic Data Processingaudit, innovative comparison audit and
audit. The main purpose of an IT audit is to findtechnological position audit.
out if the information system is workingIn the case of innovation process audit, the
efficiently. It tries to find out if the informationauditor tries to find out the risk profile of its new
system is safeguarding assets, and workingand existing projects by assessing the experience
towards the overall development of theof the company in its chosen field, the industry
organization.and the market.
Although both IT audit and financial audit isComparison audit deals with analysis of the
directed towards the analysis of the working ofcompanies innovative abilities as compared to its
the organization, there are various prominentcompetitors.
ways in which these two differ. In case ofTechnological position audit deals with reviewing
financial audit, the auditor lays a lot of importancethe technologies needed by the business. It also
on internal control. It is primarily of importanceclassifies them in to one of the four categories of
because the auditor has to later extensively placebase, key, pacing and emerging.
reliance on internal control. As a result of this, theThe auditors who perform IT audit hold a very
work of the auditor gets substantially reduced heimportant responsibility and hence it is
does not have to make a detailed study of all therecommended that only people with the required
financial books while conducting the financial audit.skill should be appointed as the auditor. The
On the other hand, the focus of IT audit is to findperson to be given the post of an auditor should
out the risks associated with the informationhave an adequate knowledge of information
assets and checking if there are adequatesystem along with this; he should also have a
measures in force to eliminate or reduce thesegeneral understanding of the accounting principles.
risks. An auditor tries to evaluate the informationApart from this it is always beneficial to appoint
systems availability, its confidentiality and itsan auditor who has received the CISA (Certified
integrity by answering certain questions. ForInformation Systems Auditor) credentials.
example to check the availability, the auditor asks