IT Audit Risk Assessment

Posted By: auditor42

IT Audit Risk Assessment - 02/11/19 06:27 PM

Does everyone have a separate IT Audit Risk Assessment for determining the audit schedule from the Enterprise Wide RA? I am needing to separate the two so I can have a more detailed IT Audit RA. Does anyone have one they would be willing to share?
Posted By: osucpa

Re: IT Audit Risk Assessment - 02/12/19 03:58 PM

These are always hard questions to answer and each institution is different. Does your IT Department have a Risk Assessment of their processes?
Posted By: auditor42

Re: IT Audit Risk Assessment - 02/12/19 04:04 PM

They have a GLBA Risk Assessment that is done by a third party. The third party also does an ebanking and cybersecurity RA for us. But no their is really not one done by the IT Department on their processes.
Posted By: osucpa

Re: IT Audit Risk Assessment - 02/12/19 04:48 PM

I would start there and recommend they create a risk assessment of their processes. Have them start with their critical items. What I have found over the years IT Departments believe everything they do is critical.
Posted By: auditor42

Re: IT Audit Risk Assessment - 02/12/19 07:22 PM

Okay, thank you for your help!