Auditing and Evaluating Federal it Systems
Edward F. Kearney, Jeffrey W. Green, Roldan Fernandez, David M. Zavada · 2012
This chapter discusses auditing and evaluation processes of Federal information technology (IT) systems. In the Federal Government, IT auditing is an integral component of the audit process. Cybersecurity is an ongoing focus for Federal agencies as their information systems are frequently under attack by criminals and foreign agents. This chapter provides auditors an overview of the Federal IT audit approach based on guidance published in the Government Accountability Office's (GAO) Federal Information System Controls Audit Manual (FISCAM), dated February 2, 2009. This chapter presents auditors perspective on how changes within the IT industry, such as the evolution of cloud computing, are affecting the role of the IT auditor and the services provided to clients. The information system audit process consists of three phases: the planning phase; the testing phase; and the reporting phase.