科技报告详细信息
Using Assurance Models in IT Audit Engagements
Baldwin, Adrian ; Beres, Yolanta ; Shiu, Simon
HP Development Company
关键词: audit;    assurance;    compliance;    Sarbanes-Oxley;    SOX;    risk;    security;   
RP-ID  :  HPL-2006-148R1
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

The document describes an innovative way to assess the effectiveness of internal IT controls where the control framework is first captured in the models and then the models are used to analyse the evidence gathered from the IT environment. The aim is to lift the risk and control management lifecycle from a series of people based processes to one where model based technology enhances, connects and where appropriate automates the process. Modelling in such an approach means capturing the relationship between controls and the way the controls should be analyzed for effectiveness and compliance to regulations and internal policies. This document presents how the model based assurance approach has been applied to automate the analysis of critical IT internal controls during several IT application audits in HP, and the value and benefits we have seen in using models to drive real-time analysis and measurements of the operating environment.

【 预 览 】
附件列表
Files Size Format View
RO201804100000015LZ 845KB PDF download
  文献评价指标  
  下载次数:34次 浏览次数:24次