• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Ekonomi och Ledarskap
    2. Ledarskapsböcker

    Understanding and Conducting Information Systems Auditing

    AvVeena Hingarh,Arif Ahmed

    Inbunden, Engelska, 2013

    Del 618 i serien Wiley Corporate F&A

    1 145 kr

    Beställningsvara. Skickas inom 11-20 vardagar. Fri frakt över 249 kr.

    Beskrivning

    A comprehensive guide to understanding and auditing modern information systems The increased dependence on information system resources for performing key activities within organizations has made system audits essential for ensuring the confidentiality, integrity, and availability of information system resources. One of the biggest challenges faced by auditors is the lack of a standardized approach and relevant checklist. Understanding and Conducting Information Systems Auditing brings together resources with audit tools and techniques to solve this problem.Featuring examples that are globally applicable and covering all major standards, the book takes a non-technical approach to the subject and presents information systems as a management tool with practical applications. It explains in detail how to conduct information systems audits and provides all the tools and checklists needed to do so. In addition, it also introduces the concept of information security grading, to help readers to implement practical changes and solutions in their organizations. Includes everything needed to perform information systems auditsOrganized into two sections—the first designed to help readers develop the understanding necessary for conducting information systems audits and the second providing checklists for auditsFeatures examples designed to appeal to a global audienceTaking a non-technical approach that makes it accessible to readers of all backgrounds, Understanding and Conducting Information Systems Auditing is an essential resource for anyone auditing information systems.

    Produktinformation

    • Utgivningsdatum:2013-03-15
    • Mått:183 x 257 x 25 mm
    • Vikt:816 g
    • Format:Inbunden
    • Språk:Engelska
    • Serie:Wiley Corporate F&A
    • Antal sidor:304
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781118343746

    Utforska kategorier

    • Ledarskapsböcker inom Ekonomi och Ledarskap
    • Redovisning inom Ekonomi och Ledarskap

    Mer om författaren

    VEENA HINGARH is Joint Director of the South Asian Management Technologies Foundation, a center for research, training, and application in the areas of finance and risk management, which provides training in areas including IS auditing, enterprise risk management, and risk modeling. Winner of numerous merit-based awards during her career, Hingarh’s major areas of focus are IFRS and IS. She speaks frequently at conferences and platforms throughout Asia and the Middle East. Hingarh is a Chartered Accountant from the Institute of Chartered Accountants of India (ICAI), Certified Company Secretary of the Institute of Company Secretaries of India (ICSI), and Certified Information System Auditor (CISA) from ISACA (USA).ARIF AHMED is a professor at and Director of the South Asian Management Technologies Foundation as well as a Chartered Accountant from the Institute of Chartered Accountants of India (ICAI). He is an Information Security Management System Lead Auditor for the British Standards Institution. Ahmed’s areas of focus are finance and risk management, and he has over two decades of postqualification experience in training and strategic consulting. He has been interviewed and quoted throughout the media and has spoken at various seminars and institutions, including the Institute of Chartered Accountants of India, XLRI, and the Institute of Company Secretaries of India.

    Innehållsförteckning

    • Preface xiAcknowledgments xvPART ONE: CONDUCTING AN INFORMATION SYSTEMS AUDIT 1Chapter 1: Overview of Systems Audit 3Information Systems Audit 3Information Systems Auditor 4Legal Requirements of an Information Systems Audit 4Systems Environment and Information Systems Audit 7Information System Assets 8Classification of Controls 9The Impact of Computers on Information 12The Impact of Computers on Auditing 14Information Systems Audit Coverage 15Chapter 2: Hardware Security Issues 17Hardware Security Objective 17Peripheral Devices and Storage Media 22Client-Server Architecture 23Authentication Devices 24Hardware Acquisition 24Hardware Maintenance 26Management of Obsolescence 27Disposal of Equipment 28Problem Management 29Change Management 30Network and Communication Issues 31Chapter 3: Software Security Issues 41Overview of Types of Software 41Elements of Software Security 47Control Issues during Installation and Maintenance 53Licensing Issues 55Problem and Change Management 56Chapter 4: Information Systems Audit Requirements 59Risk Analysis 59Threats, Vulnerability, Exposure, Likelihood, and Attack 61Information Systems Control Objectives 61Information Systems Audit Objectives 62System Effectiveness and Effi ciency 63Information Systems Abuse 63Asset Safeguarding Objective and Process 64Evidence Collection and Evaluation 65Logs and Audit Trails as Evidence 67Chapter 5: Conducting an Information Systems Audit 71Audit Program 71Audit Plan 72Audit Procedures and Approaches 75System Understanding and Review 77Compliance Reviews and Tests 77Substantive Reviews and Tests 80Audit Tools and Techniques 81Sampling Techniques 84Audit Questionnaire 85Audit Documentation 86Audit Report 87Auditing Approaches 89Sample Audit Work-Planning Memo 91Sample Audit Work Process Flow 93Chapter 6: Risk-Based Systems Audit 101Conducting a Risk-Based Information Systems Audit 101Risk Assessment 104Risk Matrix 105Risk and Audit Sample Determination 107Audit Risk Assessment 109Risk Management Strategy 112Chapter 7: Business Continuity and Disaster Recovery Plan 115Business Continuity and Disaster Recovery Process 115Business Impact Analysis 116Incident Response Plan 118Disaster Recovery Plan 119Types of Disaster Recovery Plans 120Emergency Preparedness Audit Checklist 121Business Continuity Strategies 122Business Resumption Plan Audit Checklist 123Recovery Procedures Testing Checklist 126Plan Maintenance Checklist 126Vital Records Retention Checklist 127Forms and Documents 128Chapter 8: Auditing in the E-Commerce Environment 147Introduction 147Objectives of an Information Systems Audit in the E-Commerce Environment 148General Overview 149Auditing E-Commerce Functions 150E-Commerce Policies and Procedures Review 155Impact of E-Commerce on Internal Control 155Chapter 9: Security Testing 159Cybersecurity 159Cybercrimes 160What Is Vulnerable to Attack? 162How Cyberattacks Occur 162What Is Vulnerability Analysis? 165Cyberforensics 168Digital Evidence 170Chapter 10: Case Study: Conducting an Information Systems Audit 173Important Security Issues in Banks 174Implementing an Information Systems Audit at a Bank Branch 180Special Considerations in a Core Banking System 185PART TWO: INFORMATION SYSTEMS AUDITING CHECKLISTS 197Chapter 11: ISecGrade Auditing Framework 199Introduction 199Licensing and Limitations 200Methodology 200Domains 200Grading Structure 202Selection of Checklist 203Format of Audit Report 206Using the Audit Report Format 207Chapter 12: ISecGrade Checklists 209Checklist Structure 209Information Systems Audit Checklists 210Chapter 13: Session Quiz 281Chapter 1: Overview of Systems Audit 281Chapter 2: Hardware Security Issues 284Chapter 3: Software Security Issues 286Chapter 4: Information Systems Audit Requirements 288Chapter 5: Conducting an Information Systems Audit 290Chapter 6: Risk-Based Systems Audit 293Chapter 7: Business Continuity and Disaster Recovery Plan 294Chapter 8: Auditing in an E-Commerce Environment 296Chapter 9: Security Testing 297About the Authors 299About the Website 301Index 303