This book provides specific information for planning, developing, and enhancing strategies for an IT security audit capability, applying the capability on specific engagements, and measuring and monitoring the performance of IT security audit activities. This volume describes the operational aspects of IT auditing, audit as a function, the development of a strategic plan and mission statement, assessment of IT security audit readiness, criteria for project selection, and the linking of objectives to supporting activities.
Operational Aspects of IS Auditing. Audit as a Function. Audit Approach. Developing a Strategic Plan. Developing a Mission Statement. Objectives for the IS Security Audit Capability. Assessing IS Security Audit Readiness. Devising Criteria for Project Selection. Linking Objectives to the Supporting Activities. Measuring and Monitoring the Audit Capacity Once It Is Established. References.