IT Audit process (Reporting) Flashcards
What is reporting?
It’s a document outcome of an audit
When should you implement a Management Action Plan (MAP) or a Corrective Action Plan?
Once a recommendation is sent to auditee, come back with an action plan on how to correct each control gap.
Follow up
Checking whether the audit findings have been corrected.
*Read MAP documented by client to determine if they address/correct audit findings.
What is RIA?
It’s a recommendation requiring immediate attention with in 3 days.
What is RPA?
It’s a recommendation requiring priority action between 60 days and 3 years.
Audit Objective
What is the audit all about?
Audit Scope
What exactly are we checking? (In Scope or out of scope)
Planning
- Logistics (flight ticket, hotel, rental car)
- Meeting invitation
- Desk for 3 people
- Vacation planned
- Kickoff meeting invite
- Create audit program (set of questions we ask during the audit)
- Engagement letter
Engagement letter
To be sent by audit management - Audit manager or director
Kickoff meeting
First meeting with the client or IT Audit department
Fieldwork
- Actual audit
- Testing
- Interview
- Status meetings
Audit report
- Audit objective
- Scope,
- Background,
- Our opinion,
- Issues identified.
Follow-up
Going to check later if they have implemented the solution