Information technology is a highly dynamic, rapidly changing environment. IT auditors are expected to stay current with the latest tools, technologies, and trends, and may need to do additional research to prepare for specific audits. This book is designed to help aspiring and active internal auditors take a step back and understand the general process and activities involved in conducting an audit around technology. A New Auditor s Guide to Planning, Performing, and Presenting IT Audits is primarily based on:
The IIA s International Professional Practices Framework (IPPF)
The IIA s Global Technology Audit Guides (GTAGs)
ISACA s IS Guidelines, Standards, and Procedures
Guidance issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO)
Other relevant recognized industry standards and organizations
This book uses a simplified four-layer technology model of networks, operating systems, databases, and applications. It provides easily understandable concepts of the technology environment that can be applied in most organizations with little modification.
Nelson Gibbs, CIA, CISA, CISSP, CISM, CGEIT, is a senior manager in the Internal Audit Transformation group of Deloitte & Touche, where he specializes in technology and works extensively in the financial services industry. He has deep knowledge of information security, IT controls and infrastructure, and business process application risk management. He has more than 16 years experience in information systems operations and auditing.
Gibbs received an MBA from the University of California at Irvine with an emphasis in information technology. He frequently lectures on business and technology security issues, both in the United States and internationally. He was a member of The Institute of Internal Auditors (IIA s) Global Advanced Technology Committee for three years and currently sits on The IIA s Professional Conferences Committee.