{"product_id":"understanding-and-conducting-information-systems-auditing-9781118343746","title":"Understanding and Conducting Information Systems","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eA comprehensive guide to understanding and auditing modern information systems\u003c\/b\u003e  \u003cp\u003eThe increased dependence on information system resources for performing key activities within organizations has made system audits essential for ensuring the confidentiality, integrity, and availability of information system resources. One of the biggest challenges faced by auditors is the lack of a standardized approach and relevant checklist. \u003ci\u003eUnderstanding and Conducting Information Systems Auditing\u003c\/i\u003e brings together resources with audit tools and techniques to solve this problem.\u003c\/p\u003e \u003cp\u003eFeaturing examples that are globally applicable and covering all major standards, the book takes a non-technical approach to the subject and presents information systems as a management tool with practical applications. It explains in detail how to conduct information systems audits and provides all the tools and checklists needed to do so. In addition, it also introduces the concept of information security\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003c\/p\u003e\u003cp\u003ePreface xi\u003c\/p\u003e \u003cp\u003eAcknowledgments xv\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePART ONE: CONDUCTING AN INFORMATION SYSTEMS AUDIT 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1: Overview of Systems Audit 3\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eInformation Systems Audit 3\u003c\/p\u003e \u003cp\u003eInformation Systems Auditor 4\u003c\/p\u003e \u003cp\u003eLegal Requirements of an Information Systems Audit 4\u003c\/p\u003e \u003cp\u003eSystems Environment and Information Systems Audit 7\u003c\/p\u003e \u003cp\u003eInformation System Assets 8\u003c\/p\u003e \u003cp\u003eClassification of Controls 9\u003c\/p\u003e \u003cp\u003eThe Impact of Computers on Information 12\u003c\/p\u003e \u003cp\u003eThe Impact of Computers on Auditing 14\u003c\/p\u003e \u003cp\u003eInformation Systems Audit Coverage 15\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2: Hardware Security Issues 17\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eHardware Security Objective 17\u003c\/p\u003e \u003cp\u003ePeripheral Devices and Storage Media 22\u003c\/p\u003e \u003cp\u003eClient-Server Architecture 23\u003c\/p\u003e \u003cp\u003eAuthentication Devices 24\u003c\/p\u003e \u003cp\u003eHardware Acquisition 24\u003c\/p\u003e \u003cp\u003eHardware Maintenance 26\u003c\/p\u003e \u003cp\u003eManagement of Obsolescence 27\u003c\/p\u003e \u003cp\u003eDisposal of Equipment 28\u003c\/p\u003e \u003cp\u003eProblem Management 29\u003c\/p\u003e \u003cp\u003eChange Management 30\u003c\/p\u003e \u003cp\u003eNetwork and Communication Issues 31\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3: Software Security Issues 41\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eOverview of Types of Software 41\u003c\/p\u003e \u003cp\u003eElements of Software Security 47\u003c\/p\u003e \u003cp\u003eControl Issues during Installation and Maintenance 53\u003c\/p\u003e \u003cp\u003eLicensing Issues 55\u003c\/p\u003e \u003cp\u003eProblem and Change Management 56\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4: Information Systems Audit Requirements 59\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eRisk Analysis 59\u003c\/p\u003e \u003cp\u003eThreats, Vulnerability, Exposure, Likelihood, and Attack 61\u003c\/p\u003e \u003cp\u003eInformation Systems Control Objectives 61\u003c\/p\u003e \u003cp\u003eInformation Systems Audit Objectives 62\u003c\/p\u003e \u003cp\u003eSystem Effectiveness and Effi ciency 63\u003c\/p\u003e \u003cp\u003eInformation Systems Abuse 63\u003c\/p\u003e \u003cp\u003eAsset Safeguarding Objective and Process 64\u003c\/p\u003e \u003cp\u003eEvidence Collection and Evaluation 65\u003c\/p\u003e \u003cp\u003eLogs and Audit Trails as Evidence 67\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5: Conducting an Information Systems Audit 71\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAudit Program 71\u003c\/p\u003e \u003cp\u003eAudit Plan 72\u003c\/p\u003e \u003cp\u003eAudit Procedures and Approaches 75\u003c\/p\u003e \u003cp\u003eSystem Understanding and Review 77\u003c\/p\u003e \u003cp\u003eCompliance Reviews and Tests 77\u003c\/p\u003e \u003cp\u003eSubstantive Reviews and Tests 80\u003c\/p\u003e \u003cp\u003eAudit Tools and Techniques 81\u003c\/p\u003e \u003cp\u003eSampling Techniques 84\u003c\/p\u003e \u003cp\u003eAudit Questionnaire 85\u003c\/p\u003e \u003cp\u003eAudit Documentation 86\u003c\/p\u003e \u003cp\u003eAudit Report 87\u003c\/p\u003e \u003cp\u003eAuditing Approaches 89\u003c\/p\u003e \u003cp\u003eSample Audit Work-Planning Memo 91\u003c\/p\u003e \u003cp\u003eSample Audit Work Process Flow 93\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6: Risk-Based Systems Audit 101\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eConducting a Risk-Based Information Systems Audit 101\u003c\/p\u003e \u003cp\u003eRisk Assessment 104\u003c\/p\u003e \u003cp\u003eRisk Matrix 105\u003c\/p\u003e \u003cp\u003eRisk and Audit Sample Determination 107\u003c\/p\u003e \u003cp\u003eAudit Risk Assessment 109\u003c\/p\u003e \u003cp\u003eRisk Management Strategy 112\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7: Business Continuity and Disaster Recovery Plan 115\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBusiness Continuity and Disaster Recovery Process 115\u003c\/p\u003e \u003cp\u003eBusiness Impact Analysis 116\u003c\/p\u003e \u003cp\u003eIncident Response Plan 118\u003c\/p\u003e \u003cp\u003eDisaster Recovery Plan 119\u003c\/p\u003e \u003cp\u003eTypes of Disaster Recovery Plans 120\u003c\/p\u003e \u003cp\u003eEmergency Preparedness Audit Checklist 121\u003c\/p\u003e \u003cp\u003eBusiness Continuity Strategies 122\u003c\/p\u003e \u003cp\u003eBusiness Resumption Plan Audit Checklist 123\u003c\/p\u003e \u003cp\u003eRecovery Procedures Testing Checklist 126\u003c\/p\u003e \u003cp\u003ePlan Maintenance Checklist 126\u003c\/p\u003e \u003cp\u003eVital Records Retention Checklist 127\u003c\/p\u003e \u003cp\u003eForms and Documents 128\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8: Auditing in the E-Commerce Environment 147\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 147\u003c\/p\u003e \u003cp\u003eObjectives of an Information Systems Audit in the E-Commerce Environment 148\u003c\/p\u003e \u003cp\u003eGeneral Overview 149\u003c\/p\u003e \u003cp\u003eAuditing E-Commerce Functions 150\u003c\/p\u003e \u003cp\u003eE-Commerce Policies and Procedures Review 155\u003c\/p\u003e \u003cp\u003eImpact of E-Commerce on Internal Control 155\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9: Security Testing 159\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCybersecurity 159\u003c\/p\u003e \u003cp\u003eCybercrimes 160\u003c\/p\u003e \u003cp\u003eWhat Is Vulnerable to Attack? 162\u003c\/p\u003e \u003cp\u003eHow Cyberattacks Occur 162\u003c\/p\u003e \u003cp\u003eWhat Is Vulnerability Analysis? 165\u003c\/p\u003e \u003cp\u003eCyberforensics 168\u003c\/p\u003e \u003cp\u003eDigital Evidence 170\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10: Case Study: Conducting an Information Systems Audit 173\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eImportant Security Issues in Banks 174\u003c\/p\u003e \u003cp\u003eImplementing an Information Systems Audit at a Bank Branch 180\u003c\/p\u003e \u003cp\u003eSpecial Considerations in a Core Banking System 185\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePART TWO: INFORMATION SYSTEMS AUDITING CHECKLISTS 197\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11: ISecGrade Auditing Framework 199\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 199\u003c\/p\u003e \u003cp\u003eLicensing and Limitations 200\u003c\/p\u003e \u003cp\u003eMethodology 200\u003c\/p\u003e \u003cp\u003eDomains 200\u003c\/p\u003e \u003cp\u003eGrading Structure 202\u003c\/p\u003e \u003cp\u003eSelection of Checklist 203\u003c\/p\u003e \u003cp\u003eFormat of Audit Report 206\u003c\/p\u003e \u003cp\u003eUsing the Audit Report Format 207\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12: ISecGrade Checklists 209\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eChecklist Structure 209\u003c\/p\u003e \u003cp\u003eInformation Systems Audit Checklists 210\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 13: Session Quiz 281\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eChapter 1: Overview of Systems Audit 281\u003c\/p\u003e \u003cp\u003eChapter 2: Hardware Security Issues 284\u003c\/p\u003e \u003cp\u003eChapter 3: Software Security Issues 286\u003c\/p\u003e \u003cp\u003eChapter 4: Information Systems Audit Requirements 288\u003c\/p\u003e \u003cp\u003eChapter 5: Conducting an Information Systems Audit 290\u003c\/p\u003e \u003cp\u003eChapter 6: Risk-Based Systems Audit 293\u003c\/p\u003e \u003cp\u003eChapter 7: Business Continuity and Disaster Recovery Plan 294\u003c\/p\u003e \u003cp\u003eChapter 8: Auditing in an E-Commerce Environment 296\u003c\/p\u003e \u003cp\u003eChapter 9: Security Testing 297\u003c\/p\u003e \u003cp\u003eAbout the Authors 299\u003c\/p\u003e \u003cp\u003eAbout the Website 301\u003c\/p\u003e \u003cp\u003eIndex 303\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":49406853906775,"sku":"9781118343746","price":72.0,"currency_code":"GBP","in_stock":false}],"url":"https:\/\/bookcurl.com\/products\/understanding-and-conducting-information-systems-auditing-9781118343746","provider":"Book Curl","version":"1.0","type":"link"}