Chapter 1
Chapter 1
Chapter 1
INFORMATION
TECHNOLOGY
ENVIRONMENT AND
IT AUDIT
Objectives
1. Describe how technology is constantly evolving and shaping today's
information technology (IT) environments.
2. Discuss the auditing profession and define financial auditing.
3. Differentiate between the two types of audit functions that exist today
(internal and external).
4. Explain what IT auditing is and summarize its two broad groupings.
5. Describe current IT auditing trends, and identify the needs to have an IT
audit.
6. Explain the various roles of the IT auditor.
7. Support why IT audit is considered a profession.
8. Describe the profile of an IT auditor in terms of experience and skills
required.
9. Discuss career opportunities available to IT auditors.
Today’s IT Environment
Increased
Organizations more connectivity,
information dependent availability of
systems
High-speed information
Heavy reliance on processing has become
technology to be indispensable
competitive
Big Data
Cloud Computing
Mobile Device
Management
Internal auditor:
Provides assurance to management that policies and
procedures are implemented and working as intended,
through:
monitoring and testing system reliability
detailed test work throughout the year
External auditor:
Independently evaluates the reliability of computer
controls and the validity of the information:
to render an opinion on the F/S
IT Auditors
IT auditors:
Assess the organization’s exposures (risks)
Examine or assist in designing and implementing
procedures (controls) associated with the use of
technology
Are considered part of the business environment
assessment …why?
IT Auditors
Increased
IT’s impact on the
dependence on
business
information
As Management
for decision making purposes
As Investigator
assistscomputer forensics, criminal
investigations
Profession of: IT Audit
Relatively new profession
A profession is supported/characterized
by:
Common Body of Knowledge
ISACA, AICPA, IIA, ISSA, etc.
Certification
Ex. Certified Information Systems Auditor
(CISA) - rigorous exam + 5 years of experience
and education
Profession of: IT Audit
Continuing Education
Important for career growth
Supports CISA certification
To keep up-to-date
Educational curricula
Model Curriculum1 developed to support IT
Auditing
CRISC
CISSP
CFE
CISM
IT Auditor Profile:
Experience and Skills
IT auditors must also possess skills that enable
them to add value to organization and clients.
Combination of
relevant Experience and right Skills -> Success!
Career Opportunities
Application (business/financial) IT audits
Technical/Operational IT audits
(infrastructure, data centers, data
communication)
Compliance IT audits involving national,
international, or regulatory standards
Organizational IT audits (management
control over IT)
Career Opportunities
Public accounting firm
External IT auditors; support financial audits,
compliance, operational
Can advance to Partner / Sr. Management levels
Entry level and experienced auditors
Private industry
Internal IT auditors
Assist with the implementation of IT Governance
Opportunities at the C-suite level (e.g., CIO, CTO)
Entry level and experienced auditors
Career Opportunities
Management consulting
Experienced auditors
Considered experts in the field, subject
matter resources (SMR’s)
Government
Support governmental audits (compliance)
Entry level and experienced auditors
Homework Problems
Chapter 1:
Review Questions: [chosen by Instructor]
Exercises: [chosen by Instructor]