IT Audit Verification Planning: Resolving Technique Selection – Part IV
Posted by: Robert Davis
Auditing IT configurations involves performing compliance and substantive tests on a selected
Auditing IT configurations involves performing compliance and substantive tests on a selected
Auditing electronically encoded programs can also involve compliance and substantive testing. Compliance testing usually involves testing programs for controls. Techniques for auditing programs are primarily oriented toward...
Compliance testing is the primary method employed to verify stated controls are operating effectively, while substantive testing is the primary method utilized to increase audit assurance. For instance, an IT auditor may reperform compliance testing, documented by an entity’s
There are a variety of techniques available to the IT auditor for compliance and substantive testing when performing assurance engagements. ...
Business volatility includes unexpected IT demand, merger and acquisition activities, as well as economic or government events. Whereby, government volatility can reflect a political event. Theoretically, adequate
Business continuity and disaster recovery plans should follow suggested best practices for development to ensure adequate incident handling. Commonly, the primary goals of the incident management...
Organizational resilience imposes proactive preparation for potential incidents in order to avoid suspension of critical operations and services, or if operations and services are disrupted, resuming processing as rapidly as required for those who...
"Attention all personnel! Attention all personnel! We are now experiencing an emergency code red condition. This requires following current crisis management procedures. Please, immediately proceed to your designated evacuation area and await further...
Systems and infrastructure design effects the controls relied on by an entity’s management, therefore, effecting control processes. Because systems and infrastructure are critical to an entity’s success, control processes should be designed...