Preview

Information Systems Auditing Standards

Good Essays
Open Document
Open Document
9312 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Information Systems Auditing Standards
Chap 8 – INFORMATION SYSTEMS AUDITING STANDARDS, GUIDELINES,
BEST PRACTICES
___________________________________________________________________________
Introduction
BS 7799
CMM - Capability Maturity Model
COBIT – IT Governance Model
CoCo
ITIL (IT Infrastructure Library)
Systrust and Webtrust
HIPAA
SAS 70 – Statement of Auditing Standards for Service Organisations

___________________________________________________________________________
Introduction
Growing business requires computers, networking, video conferencing etc. Consequently, technology has also impacted auditing. Concept of Internal Control has diminished as: o Through computers, a single person performs functions of multiple persons who were earlier part of the internal control system o Batch controls have disappeared

Result: Need to develop new standards of Information Systems. Common feature of such modes of controls or standards are:
1.
2.
3.
4.

Every organization that uses IT uses a set of controls
Controls depends on the business objectives, budget, personality, and context of that organization
Control objectives should be constant across organizations
Each organization could use the same control framework

IS Audit Standards
IS Audit Standards provide audit professionals a clear idea of the minimum level of acceptable performance essential to discharge their responsibilities effectively. Some of the standards by their year of birth are as follows: o 1994
COSO, CoCo o 1996
HIPAA, COBIT o 1998
BS 7799

Standard on Auditing (SA) –



Link to eBook has been given in the Institute study material (ISCA)

SA 315 – “Identifying and Assessing the Risk of Material Misstatement Through Understanding the Entity and its
Environment”
SA 330 - “The Auditor’s Responses to Assessed Risks”

Chap 8 | www.iscanotes.com

1

www.excelnext.in | May 2011

BS 7799
BS 7799 is an International Standard setting out the requirements for an Information

You May Also Find These Documents Helpful

  • Powerful Essays

    Isqc 36 Study Guide

    • 4177 Words
    • 17 Pages

    (m) Partner – Any individual with authority to bind the firm with respect to the performance of a professional services engagement. (n) Personnel – Partners and staff. (o) Professional standards – IAASB Engagement Standards, as defined in the IAASB’s Preface to the International Standards on Quality Control, Auditing, Review, Other Assurance and Related Services, and relevant ethical requirements. (p) Reasonable assurance – In the context of this ISQC, a high, but not absolute, level of assurance. (q) Relevant ethical requirements – Ethical requirements to which the engagement team and engagement quality control reviewer are subject, which ordinarily comprise Parts A and B of the International Ethics Standards Board for Accountants’ Code of Ethics for Professional…

    • 4177 Words
    • 17 Pages
    Powerful Essays
  • Good Essays

    Week 1 Homework Solutions

    • 654 Words
    • 3 Pages

    For the most part, generally accepted auditing standards are general rather than specific. Many practitioners along with critics of the profession believe the standards should provide more clearly defined guidelines as an aid in determining the extent of evidence to be accumulated. This would eliminate some of the difficult audit decisions and provide a source of defense if the CPA is charged with conducting an inadequate audit. On the other hand, highly specific requirements could turn auditing into mechanical evidence gathering, void of professional judgment. From the point of view of both the profession and the users of auditing services, there is probably a greater harm from defining authoritative guidelines too specifically than too broadly.…

    • 654 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    In accordance to AICPA Statement on Auditing Standards, AU 9504.1, after the disclosure of any adjustments made about the interim financial data are noted on the annual report financial statement, the auditor does not have any obligation to audit the interim data. Unless the auditor has been specifically called to do so, he or she does not need to audit the data after auditing the annual financial statements. Thus, Aaron Jones, CPA, does not need to audit the supplementary disclosures made in regards to the major fluctuations in the Low Company’s fourth quarter or the previous year’s financial statement balances.…

    • 326 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    c. What should an audit team consider when seeking to reduce the planned assessed level of control risk below the maximum?…

    • 1065 Words
    • 5 Pages
    Good Essays
  • Better Essays

    The Leslie Fay Companies

    • 1891 Words
    • 8 Pages

    its environment, including its internal control, to assess the risk of material misstatement of the…

    • 1891 Words
    • 8 Pages
    Better Essays
  • Good Essays

    CAS 315: Identifying and assessing the risks of material misstatement through understanding the entity and its environment…

    • 1087 Words
    • 5 Pages
    Good Essays
  • Satisfactory Essays

    Brose Case Study

    • 491 Words
    • 2 Pages

    |Operational, Management and Control |Too many different information systems lead to a lack standardization |…

    • 491 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    PCAOB Standards: AS8, "Audit Risk,” AS9, "Audit Planning,” and AS12, "Identifying and Assessing Risks of Material Misstatement…

    • 272 Words
    • 2 Pages
    Satisfactory Essays
  • Better Essays

    Louwers, T. J. Ramsay, R. J., Sinason, D, Strawser, J. R. (2007) Auditing and Assurance…

    • 2178 Words
    • 9 Pages
    Better Essays
  • Good Essays

    Pcaob Case

    • 705 Words
    • 3 Pages

    * The firm’s failure to identify and thoroughly test controls that are intended to address risks of material misstatements.…

    • 705 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    The major accounting regulatory bodies would include the Securities and Exchange Commission, American Institute of Certified Public, Financial Accounting Standards Board, and Government Accounting Board. Each regulatory body contributes to the ethical over watch of companies by keeping them transparent, follow GAAP, and other ethical practices that should be used by accountants and their companies. The Securities and Exchange Commission regulates companies in how they report their financial statements and to make sure that investors receive all necessary information that involves investment decisions. This commission helps ensure that investors are not deceived and allows them to make better investment decisions. The American Institute of Certified Public Accountants sets guidelines and standards on how companies should be audited, and set standards in accounting practices that certified public accountants should follow. Like the American Institute of Certified Public Accountants, the Financial Accounting Standards Board sets up standards for companies and how they should be reporting their financial reports. Companies that follow the FASB standards can provide more accurate financial information than those who do not. It is important to note that the FASB is for the private sector, the compliment to this regulatory body would be the Government Accounting Standards Board who sets standards for government agencies, programs, and bodies. The GASB is crucial for the federal government because it sets standards on how government agencies report their finances. For example, every state who reports their finances over a certain accounting period would all have the same format in how their balance sheets, financial statements, and other records are presented. This makes the reports easy to understand and compare against other…

    • 271 Words
    • 2 Pages
    Satisfactory Essays
  • Powerful Essays

    Security Audit Policy

    • 1938 Words
    • 8 Pages

    The computer, network and information resources at BPIS, LLC are provided as a means to increase productivity to support the mission of the BPIS, LLC's employees. Usage of computing and networking components by employees of BPIS, LLC should at all times be business related and reflect good judgment in the utilization of shared resources and take heed to the ethical and legal guidelines of society. This document details BPIS, LLC'c acceptable usage of all computing and network resources.…

    • 1938 Words
    • 8 Pages
    Powerful Essays
  • Good Essays

    Hunton, J. A., Bryant, S. M., & Bagranoff, N. A. (2004). Core concepts of information technology auditing. New York: Wiley & Sons.…

    • 696 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    Modern data processing systems pose new, risk-laden challenges to the traditional audit process. Whereas it was once possible to conduct a financial statement audit by assessing and monitoring the controls over paper-based transaction and accounting systems, businesses have increasingly turned to electronic transaction and accounting systems. SAS 94 offers guidance on collecting sufficient, competent evidence in an electronic processing environment. It pays particular attention to identifying circumstances when the system of control over electronic processing must be accessed.…

    • 2188 Words
    • 9 Pages
    Powerful Essays
  • Powerful Essays

    Management designs systems of internal control to accomplish three categories of objectives: financial reporting, operations, and compliance with laws and regulations. The auditor’s focus in both the audit of financial statements and the audit of internal controls is on those controls related to the reliability of financial reporting plus those controls related to operations and to compliance with laws and regulations objectives that could materially affect…

    • 8161 Words
    • 33 Pages
    Powerful Essays