Strategic Intelligence for CFOs, Finance Directors, Controllers and Treasurers in Asia  | 
2012, Feb 09

New Audit Guide Addresses IT Risks

New Audit Guide Addresses IT Risks

by CFO Innovation Staff, 02 July 2010
Thumbnail: 

Almost every organisation uses some form of User Developed Applications (UDAs) such as spreadsheets and databases. They can be easily developed, cost effective to produce, and changed with relative ease.  However, risks such as data integrity, availability, and confidentiality can pose threats to an organisation and internal auditors may consider auditing UDAs.

 

To address this growing risk, The Institute of Internal Auditors is releasing two new issues of its ongoing Global Technology Audit Guide (GTAG) series – both aimed at helping internal auditors and their management learn about and assess technology related risks.

 

The New GTAG 14, Auditing User-developed Applications, explores, among other topics, how best to risk rate and scope a UDA audit. The 32-page GTAG also proffers a sample audit program, best practices for implementing controls over UDAs, and advice on how internal auditors can work in a consulting role to help management develop an effective UDA control framework

 

“In most organisations, selected staff members are permitted as a matter of business necessity to extract, manipulate, analyse, and report on enterprise data using spreadsheets, databases, or other user-developed applications (UDAs). This practice gives rise to risks concerning data integrity, availability, and confidentiality,” says IIA Director of Standards and Guidance Lisa Hirtzinger, CIA.

 

Standard 2110.A2 of The IIA’s International Standards for the Professional Practice of Internal Auditing requires the internal audit activity to assess whether the organisation’s information systems sustains and supports agreed-upon strategies and objectives.

 

The New 28-page GTAG 15, Information Security Governance (ISG), explores internal auditing’s roles in and responsibilities for overseeing IT security. It assists organisations in incorporating an audit of ISG into the audit plan, focusing on whether the organisation’s ISG activity delivers the correct behaviors, practices, and execution of information services.

 

“IT failures, especially information security (IS) breaches, can place the organization at risk for reputation damage, diminished competitiveness, noncompliance with laws and regulations, and other adverse consequences,” adds Hirtzinger. “These impacts should not be underestimated.”

 

GTAGs, which address timely issues in IT management, control, and security, are strongly recommended, but not mandatory, guidance under The IIA’s International Professional Practices Framework.

Orignal Author: 
CFO Innovation Staff
Quote Image: 

Related articles

Comment on this article

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

CFO innovation Asia Accounting and Regulation the Asia Pacific resource center for senior finance executives, daily news, analysis, best practice and case studies in Accounting Regulation, IFRS, US GAAP, Tax, investor relations, corporate governance, Corporate Law, Financial Regulators, Internal Audit, Audit, Corporate Law.
CFO innovation Asia, Finance and Banking the Asia Pacific resource center for senior finance executives, daily news, analysis, best practice and case studies in Corporate Finance, trade finance, treasury and risk management, capital expenditure, Banking, mergers and acquisitions
CFO innovation Asia the Asia Pacific resource center for senior finance executives, daily news, analysis, best practice and case studies in Finance Management, Corporate Governance, Human Resource Management, Compensation and Benefits, Mergers and Acquisitions, Professional Development, Corporate Real Estate, Risk Management, Budgeting and Forecasting, Business Process Management, Business Process Reengineering, Outsourcing.
CFO innovation Asia Technology the Asia Pacific resource center for senior finance executives, daily news, analysis, best practice and case studies in Finance Systems, Business Intelligence, EPR, Accounting software, CRM, Cloud Computing, Telecommunications, Business Process Outsourcing, Business Process Management Software.