IT Governance, Risk, and Compliance

Feb 10 2012   9:36PM GMT

Auditing IT Governance - Part I



Posted by: Robert E. Davis
External Audit, Internal Audit, Certified Internal Auditor, Certified Public Accountant, Certified Information Systems Auditor, Certified Information Technology Professional, Certified Internal Controls Auditor, IT Audit, Performance Measurement, Resource Management, Risk Management, Strategic Alignment, Value Delivery, ITG

Governance supports stakeholder expectations related to management’s fiduciary responsibilities. Governance also reflects how an enterprise achieves its stated mission. Specifically, as presented in the Cadbury Committee Report, “…governance is the system by which companies are directed and controlled.” Leadership, stewardship, ethics, security, vision, direction, influence, and values are prominent components within entity-level governance.

Various respected knowledge leaders, practicing professionals as well as professional organizations consider an entity’s oversight committee, executive management, internal audit, and external audit as governance cornerstones. Consequently, since IT is usually integrated into an entity’s processes, IT audit should be considered IT-level governance as well as entity-level governance cornerstones.

Post Note: Auditing IT Governance is a redacted excerpt from Assuring IT Governance.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Gabrielaela  |   May 7 2012   11:30AM GMT

It’s hard to be a manager with a lot suborniated in your responsibility. I used to have such a job, but I quit because of the money. I agree with the integration of the it-level governance just like entity-level governance cornerstores.
Vacanta in Azuga