How to perform risk-based IT Audit
Let\’s talk about IT Audit in todays world. What do you know about IT Audit now? Have you ever performed such audits? I have been working for a Auditing company for almost 5 years and all this time I was performing various types of IT Audit. Thus, I think that I have some IT Audit experience.
A lot of of my audits were targeted to financial audits, which is the main operations of my company. However, our department had performed special IT Audits and IT Security Audits for various companies across CIS region.
While performing such small IT audits during work for financial audit, you often face such term as IT Risk Assessment. We need to remember about risks in all our work, thus it is nothing to do – but we need to assess how our customers perform IT risk assessments at their IT environments. That is why we always look at different reports about work performed, talk to different employees from IT department – our target is to ensure that this particular client has dialed with IT risk and no significant impact would arise to the company financial statements. We just need to address any potential risks to our work, as our final report will be very important. It would be not very good, if in future this conclusion will be affected by exploitation of some risk, which we had not seen during our work.
But in order to perform reliable IT Audit we need to use different IT Audit Tools and techniques. Such tools vary for different environments – for example for Windows environment it would be some tools provided by Microsoft company (e.g. MS Security Base Line Analyzer). And for UNIX environment we would use another tools. The same is with databases – one IT Audit tools will be used for Oracle databases and another will be used for MS SQL databases. But always while performing IT Audit work you need to use different IT Audit Tools. This will significantly reduce the amount of manual work you need to accomplish.
Thus, by doing IT Audit assessments, we need to remember about IT Risk Assessment, which can be performed by company, or we may perform such assessment. We need also to use some IT Audit tools and technics, and produce appropriate report for our work. And only after all these tasks are finished, we can start making our IT Audit Report. This is another very challenging task, as you need to consider all issues which you have noticed during the IT Audit work. You need to combine all these issues, sort them, and decide on which of them will be reported. As a rule, this is done through classification of findings based on their criticality and impact to the financial statements of the company. You can sort all isues as having Low, Medium or High impact. Usually we report only Medium and High findings to the executives of the company. And the Low findings are discussed only with local IT management in order to address the risk.