Welcome to your ultimate accounting resource


IT Audit Explained

A resource about IT audit, itsquestions. For example to check the
guidelines and applications in anavailability, the auditor asks if
organization. Includes a review ofcomputer systems would be available for
information technology's best practicesbusiness when it is required. The
and operations.confidentiality can be checked by seeing
An IT audit or information technologyif the information in the system can be
audit is an examination of the workingaccessed by unauthorized users. The
of the information technologyauditor can satisfy himself regarding
infrastructure. This seeks to find outthe integrity by checking if the
if there is proper working in the ITinformation provided by the system is
sector and if proper control is beingaccurate, timely and reliable. An IT
maintained. These audits can beaudit can take two forms it can be
undertaken independently or ineither of the form of a "general control
association with other forms of companyreview" or an "application control
audit such as financial audit, inventoryreview".
audit etc. IT audit was formerly calledThere are three broad approaches to
EDP or Electronic Data Processing audit.carry out an audit. They are
The main purpose of an IT audit is totechnological innovation process audit,
find out if the information system isinnovative comparison audit and
working efficiently. It tries to findtechnological position audit.
out if the information system isIn the case of innovation process audit,
safeguarding assets, and working towardsthe auditor tries to find out the risk
the overall development of theprofile of its new and existing projects
organization.by assessing the experience of the
Although both IT audit and financialcompany in its chosen field, the
audit is directed towards the analysisindustry and the market.
of the working of the organization,Comparison audit deals with analysis of
there are various prominent ways inthe companies innovative abilities as
which these two differ. In case ofcompared to its competitors.
financial audit, the auditor lays a lotTechnological position audit deals with
of importance on internal control. It isreviewing the technologies needed by the
primarily of importance because thebusiness. It also classifies them in to
auditor has to later extensively placeone of the four categories of base, key,
reliance on internal control. As apacing and emerging.
result of this, the work of the auditorThe auditors who perform IT audit hold a
gets substantially reduced he does notvery important responsibility and hence
have to make a detailed study of all theit is recommended that only people with
financial books while conducting thethe required skill should be appointed
financial audit. On the other hand, theas the auditor. The person to be given
focus of IT audit is to find out thethe post of an auditor should have an
risks associated with the informationadequate knowledge of information system
assets and checking if there arealong with this; he should also have a
adequate measures in force to eliminategeneral understanding of the accounting
or reduce these risks. An auditor triesprinciples. Apart from this it is always
to evaluate the information systemsbeneficial to appoint an auditor who has
availability, its confidentiality andreceived the CISA (Certified Information
its integrity by answering certainSystems Auditor) credentials.



1 A B C D E 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133