NaviSite named SVC 2014 Cloud Company of the Yea... » NaviSite takes home the top prize for its work with PMGC Technology Group Ltd. to deliver enterprise... Zylpha adopts Adobe EchoSign as E-Signature Soluti... » Zylpha has adopted Adobe EchoSign, an e-signature solution, that will allow Zylpha customers to incr... €1bn CONTRACT TO DEVELOP CUTTING EDGE RADAR FOR ... » A €1bn (approximately £800m) contract for the development of a new electronic radar system for the E... Game-changing threat intelligence service combin... » London: Complete cybersecurity service provider, SecureData has today launched SecureData GI (Greate... New cellular certification adds to Opengear’s out-... » Sandy, UT: Opengear has announced the addition of the ACM5504-5-GS-I and the ACM5508-2-GS-I remote m... Zertificon's decade of success » Berlin: On its 10th anniversary, IT-Security specialist Zertificon looks back on a successful decade... KREA enhances network capabilities with Claviste... » KREA, Turkey’s largest e-mail marketing company, has enhanced its network capabilities following a d... Patch Tuesday: Adobe update » Yesterday Adobe published the second update (APSB14-26) of Adobe Flash this month, an out of band re... Templar Executives awarded CESG certification fo... » Cyber security specialist Templar Executives has become one of the first organisations to gain accre... NBCS supports calls for collaboration in fight aga... » “We couldn’t agree more with the recent comments made by Georgina Barnard, TP Crime Reduction & Part...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

Rolling Meadows, IL, USA: As enterprises increasingly face vast amounts of digital information and the consumerization of IT (BYOD), the role of information systems auditors has become more critical—and complex—than ever. To help audit and assurance professionals meet their increasing demands and responsibilities, ISACA, a nonprofit association serving 100,000 IT professionals in 180 countries, has developed more than 40 customizable IT audit/assurance programs, including two new releases:

 

 

Identity Management Audit/Assurance Program, which helps auditors provide management with an independent assessment of the effectiveness of identity management and its policies, procedures and governance activities. The review focuses on identity management standards, guidelines and procedures, as well as implementation and governance of these activities.

Software Assurance Audit/Assurance Program, which helps auditors provide management with an assessment of the maturity and effectiveness of the enterprise’s policies and procedures relating to the development, acquisition and deployment of software; identify deficiencies in internal controls; and identify control weaknesses in the processes to develop, acquire and deploy software that can affect the reliability, accuracy, stability and security of the enterprise’s information.

Other ISACA audit programs topics include bring your own device (BYOD), cybercrime, social media, crisis management, change management and cloud computing.

“ISACA’s audit programs can be used by auditors worldwide as a road map for specific assurance processes,” said Greg Grocholski, CISA, international president of ISACA and global business finance director for the Ventures and Business Development unit within The Dow Chemical Company. “They can be customized by IT auditors in any type of environment to help them conduct effective reviews that will help ensure trust and value from the enterprise’s information systems.”

The audit/assurance programs are based on the standards and guidance in ISACA’s IT Assurance Framework (ITAF) and align with the globally recognized COBIT 5 business framework for governance and management of IT. They have been developed by experienced assurance professionals and are peer reviewed. The programs are downloadable in a Word document and can be easily customized to fit specific operating environments. They also can be used by security and business professionals, who will benefit from applying the control objectives and audit steps to make the respective scope areas more robust.