Control Objectives: Audits and risk management
No control objectives match the current filters.
Analyze and quantify the risks to in scope systems and information.
SNow
Classification: PreventiveState: Published
Analyze and quantify the risks to in scope systems and information.
Approve risk assessment methodologies at the executive management level within the organization.
SNow
Classification: PreventiveState: Published
Approve risk assessment methodologies at the executive management level within the organization.
Approve the results of the risk assessment as documented in the risk assessment report.
SNow
Classification: PreventiveState: Published
Approve the results of the risk assessment as documented in the risk assessment report.
Assess the potential level of business impact risk associated with control weaknesses.
SNow
Classification: DetectiveState: Published
Assess the potential level of business impact risk associated with control weaknesses.
Assess the quality of the audit program in regards to the staff and their qualifications.
SNow
Classification: DetectiveState: Published
Assess the quality of the audit program in regards to the staff and their qualifications.
Assign a probability of occurrence to all types of threats in the threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Assign a probability of occurrence to all types of threats in the threat and risk classification scheme.
Assign the audit to impartial auditors.
SNow
Classification: PreventiveState: Published
Assign the audit to impartial auditors.
Assign the internal Information Technology audit staff to be independent from the Information Technology group reporting to the Board of Directors.
SNow
Classification: PreventiveState: Published
Assign the internal Information Technology audit staff to be independent from the Information Technology group reporting to the Board of Directors.
Assign the roles and responsibilities for the Board of Directors and senior management in the Audit function.
SNow
Classification: PreventiveState: Published
Assign the roles and responsibilities for the Board of Directors and senior management in the Audit function.
Audit in scope audit items and compliance documents as defined in the audit scope.
SNow
Classification: PreventiveState: Published
Audit in scope audit items and compliance documents as defined in the audit scope.
Children (6)
- Audit the in scope system according to the test plan using r...
- Determine if the audit assertion's in scope controls are rea...
- Determine if the audit assertion's in scope procedures are a...
- Determine the accurateness of the audit assertion's in scope...
- Include the causes of identified in scope control deficienci...
- Investigate the nature and causes of identified in scope con...
Audit the in scope system according to the test plan using relevant evidence.
SNow
Classification: PreventiveState: Published
Audit the in scope system according to the test plan using relevant evidence.
Audits and risk management
SNow
Classification: IT Impact ZoneState: Published
Audits and risk management
Categorize the systems, information, and data by risk profile in the threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Categorize the systems, information, and data by risk profile in the threat and risk classification scheme.
Collect all work papers for the audit and audit report into an engagement file.
SNow
Classification: PreventiveState: Published
Collect all work papers for the audit and audit report into an engagement file.
Communicate information about risks to all interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Communicate information about risks to all interested personnel and affected parties.
Communicate with the organization about any missing audit documentation.
SNow
Classification: PreventiveState: Published
Communicate with the organization about any missing audit documentation.
Conduct a Business Impact Analysis based on the risk assessment findings in the risk assessment report.
SNow
Classification: DetectiveState: Published
Conduct a Business Impact Analysis based on the risk assessment findings in the risk assessment report.
Conduct a performance review of the external auditor's performance during the audit process.
SNow
Classification: PreventiveState: Published
Conduct a performance review of the external auditor's performance during the audit process.
Correlate the business impact of identified risks in the risk assessment report.
SNow
Classification: PreventiveState: Published
Correlate the business impact of identified risks in the risk assessment report.
Define and assign the external auditor's roles and responsibilities.
SNow
Classification: PreventiveState: Published
Define and assign the external auditor's roles and responsibilities.
Define the roles and responsibilities for personnel assigned to tasks in the Audit function.
SNow
Classification: PreventiveState: Published
Define the roles and responsibilities for personnel assigned to tasks in the Audit function.
Determine any errors or material omissions in the audit assertion that affect in scope control implementations.
SNow
Classification: DetectiveState: Published
Determine any errors or material omissions in the audit assertion that affect in scope control implementations.
Determine if the audit assertion's in scope controls are reasonable.
SNow
Classification: DetectiveState: Published
Determine if the audit assertion's in scope controls are reasonable.
Determine if the audit assertion's in scope procedures are accurately documented.
SNow
Classification: PreventiveState: Published
Determine if the audit assertion's in scope procedures are accurately documented.
Determine if the in scope system has been implemented as described in the audit assertion.
SNow
Classification: DetectiveState: Published
Determine if the in scope system has been implemented as described in the audit assertion.
Determine the accurateness of the audit assertion's in scope system description.
SNow
Classification: DetectiveState: Published
Determine the accurateness of the audit assertion's in scope system description.
Determine the effectiveness of in scope controls.
SNow
Classification: DetectiveState: Published
Determine the effectiveness of in scope controls.
Determine the implementation status of the audit assertion's in scope controls.
SNow
Classification: DetectiveState: Published
Determine the implementation status of the audit assertion's in scope controls.
Disclose any audit irregularities in the audit report.
SNow
Classification: PreventiveState: Published
Disclose any audit irregularities in the audit report.
Distribute a written audit assertion of the audit scope and audit terms to interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Distribute a written audit assertion of the audit scope and audit terms to interested personnel and affected parties.
Children (9)
- Include any in scope uncorrected errors or non-compliance is...
- Include how in scope material events are monitored and logge...
- Include how the audit scope matches in scope controls in the...
- Include how the in scope system is designed and implemented ...
- Include in scope change controls in the audit assertion.
- Include the end users and affected parties of the in scope s...
- Include the in scope controls and compliance documents in th...
- Include the in scope risk assessment processes in the audit ...
- Include the in scope services offered or in scope transactio...
Distribute the approved risk assessment report to interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Distribute the approved risk assessment report to interested personnel and affected parties.
Document and communicate a corrective action plan based on the risk assessment findings.
SNow
Classification: CorrectiveState: Published
Document and communicate a corrective action plan based on the risk assessment findings.
Document test plans for auditing in scope controls.
SNow
Classification: DetectiveState: Published
Document test plans for auditing in scope controls.
Edit the audit assertion for accuracy.
SNow
Classification: PreventiveState: Published
Edit the audit assertion for accuracy.
Employ risk assessment methodologies that take into account prior risk assessment findings of the same scope.
SNow
Classification: PreventiveState: Published
Employ risk assessment methodologies that take into account prior risk assessment findings of the same scope.
Establish a risk acceptance level that is appropriate to the organization's risk appetite.
SNow
Classification: PreventiveState: Published
Establish a risk acceptance level that is appropriate to the organization's risk appetite.
Establish and maintain a Risk Scoping and Measurement Definitions Document.
SNow
Classification: PreventiveState: Published
Establish and maintain a Risk Scoping and Measurement Definitions Document.
Establish and maintain a risk assessment program to manage internal threats and external threats.
SNow
Classification: PreventiveState: Published
Establish and maintain a risk assessment program to manage internal threats and external threats.
Establish and maintain a threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Establish and maintain a threat and risk classification scheme.
Establish and maintain an audit program.
SNow
Classification: PreventiveState: Published
Establish and maintain an audit program.
Children (10)
- Assess the quality of the audit program in regards to the st...
- Assign the audit to impartial auditors.
- Audit in scope audit items and compliance documents as defin...
- Establish and maintain organizational audit reports.
- Implement a corrective action plan in response to the audit ...
- Include agreement to the audit scope and audit terms in the ...
- Include materiality levels in the audit terms.
- Include the scope and work performed in the audit report.
- Provide auditors access to all in scope records, in scope as...
- Require the audit report to be complete.
Establish and maintain organizational audit reports.
SNow
Classification: PreventiveState: Published
Establish and maintain organizational audit reports.
Children (14)
- Collect all work papers for the audit and audit report into ...
- Include a statement that access to the report is restricted ...
- Include any of the organization's use of compensating contro...
- Include information about the organization being audited and...
- Include items that pertain to third parties in the audit rep...
- Include items that were excluded from the audit report in th...
- Include that the audit findings are not a predictive analysi...
- Include that this is the audit opinion in the audit report.
- Include the date of the audit in the audit report.
- Include the organization's audit assertion of the in scope s...
- Include the organization's description of the in scope syste...
- Include the organization's privacy practices in the audit re...
- Include the pass or fail test status of all in scope control...
- Include the word independent in the title of audit reports.
Establish and maintain risk assessment procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain risk assessment procedures.
Establish and maintain risk profiling procedures for internal risk assessments.
SNow
Classification: PreventiveState: Published
Establish and maintain risk profiling procedures for internal risk assessments.
Establish and maintain the risk assessment framework.
SNow
Classification: PreventiveState: Published
Establish and maintain the risk assessment framework.
Children (5)
- Correlate the business impact of identified risks in the ris...
- Document and communicate a corrective action plan based on t...
- Establish and maintain a risk assessment program to manage i...
- Integrate the corrective action plan based on the risk asses...
- Perform a gap analysis to review in scope controls for ident...
Evaluate any refusal by the organization to provide missing audit documentation.
SNow
Classification: PreventiveState: Published
Evaluate any refusal by the organization to provide missing audit documentation.
IT General Controls
SNow
Classification: DetectState: Published
Implement a corrective action plan in response to the audit report.
SNow
Classification: CorrectiveState: Published
Implement a corrective action plan in response to the audit report.
Include a statement that access to the report is restricted based on least privilege in the audit report.
SNow
Classification: PreventiveState: Published
Include a statement that access to the report is restricted based on least privilege in the audit report.
Include access to work papers in external auditor outsourcing contracts.
SNow
Classification: PreventiveState: Published
Include access to work papers in external auditor outsourcing contracts.
Include agreement to the audit scope and audit terms in the audit program.
SNow
Classification: PreventiveState: Published
Include agreement to the audit scope and audit terms in the audit program.
Include any in scope material events that might affect the assertion in the audit assertion.
SNow
Classification: PreventiveState: Published
Include any in scope material events that might affect the assertion in the audit assertion.
Include any in scope uncorrected errors or non-compliance issues in the audit assertion.
SNow
Classification: PreventiveState: Published
Include any in scope uncorrected errors or non-compliance issues in the audit assertion.
Include any of the organization's use of compensating controls that were not audited in the audit report.
SNow
Classification: PreventiveState: Published
Include any of the organization's use of compensating controls that were not audited in the audit report.
Include any out of scope components of in scope systems in the audit report.
SNow
Classification: PreventiveState: Published
Include any out of scope components of in scope systems in the audit report.
Include audit subject matter in the audit program.
SNow
Classification: PreventiveState: Published
Include audit subject matter in the audit program.
Include how access to in scope systems, personnel and in scope records are provided to the auditor in the audit terms.
SNow
Classification: PreventiveState: Published
Include how access to in scope systems, personnel and in scope records are provided to the auditor in the audit terms.
Include how in scope material events are monitored and logged in the audit assertion.
SNow
Classification: PreventiveState: Published
Include how in scope material events are monitored and logged in the audit assertion.
Include how the audit scope matches in scope controls in the audit assertion.
SNow
Classification: PreventiveState: Published
Include how the audit scope matches in scope controls in the audit assertion.
Include how the in scope system is designed and implemented in the audit assertion.
SNow
Classification: PreventiveState: Published
Include how the in scope system is designed and implemented in the audit assertion.
Include if in scope control deviations allow in scope controls to be performed acceptably in the work papers.
SNow
Classification: DetectiveState: Published
Include if in scope control deviations allow in scope controls to be performed acceptably in the work papers.
Include in scope change controls in the audit assertion.
SNow
Classification: PreventiveState: Published
Include in scope change controls in the audit assertion.
Include information about the organization being audited and the auditor performing the audit in the audit report.
SNow
Classification: PreventiveState: Published
Include information about the organization being audited and the auditor performing the audit in the audit report.
Include items that pertain to third parties in the audit report.
SNow
Classification: PreventiveState: Published
Include items that pertain to third parties in the audit report.
Include items that were excluded from the audit report in the audit report.
SNow
Classification: PreventiveState: Published
Include items that were excluded from the audit report in the audit report.
Include material changes in information processes, Information Systems, and assets that could affect audits in the audit terms.
SNow
Classification: PreventiveState: Published
Include material changes in information processes, Information Systems, and assets that could affect audits in the audit terms.
Include materiality levels in the audit terms.
SNow
Classification: PreventiveState: Published
Include materiality levels in the audit terms.
Include security threats and hazards to the system in the threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Include security threats and hazards to the system in the threat and risk classification scheme.
Include security vulnerabilities based upon threats to the system in the threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Include security vulnerabilities based upon threats to the system in the threat and risk classification scheme.
Include that the audit findings are not a predictive analysis of future compliance in the audit report.
SNow
Classification: PreventiveState: Published
Include that the audit findings are not a predictive analysis of future compliance in the audit report.
Include that the organization is the responsible party for designing and implementing the in scope controls it identified in the audit scope in the audit report.
SNow
Classification: PreventiveState: Published
Include that the organization is the responsible party for designing and implementing the in scope controls it identified in the audit scope in the audit report.
Include that the organization is the responsible party for specifying in scope controls not defined by law or contractual obligation in the audit report.
SNow
Classification: PreventiveState: Published
Include that the organization is the responsible party for specifying in scope controls not defined by law or contractual obligation in the audit report.
Include that the organization is the responsible party for the content of its audit assertion and in scope system description in the audit report.
SNow
Classification: PreventiveState: Published
Include that the organization is the responsible party for the content of its audit assertion and in scope system description in the audit report.
Include that this is the audit opinion in the audit report.
SNow
Classification: PreventiveState: Published
Include that this is the audit opinion in the audit report.
Include the attestation standards the auditor follows in the audit report.
SNow
Classification: PreventiveState: Published
Include the attestation standards the auditor follows in the audit report.
Include the audit opinion regarding the accurateness of the in scope system description in the audit report.
SNow
Classification: PreventiveState: Published
Include the audit opinion regarding the accurateness of the in scope system description in the audit report.
Include the causes of identified in scope control deficiencies in the work papers.
SNow
Classification: PreventiveState: Published
Include the causes of identified in scope control deficiencies in the work papers.
Include the date of the audit in the audit report.
SNow
Classification: PreventiveState: Published
Include the date of the audit in the audit report.
Include the end users and affected parties of the in scope system in the audit assertion.
SNow
Classification: PreventiveState: Published
Include the end users and affected parties of the in scope system in the audit assertion.
Include the in scope controls and compliance documents in the audit assertion.
SNow
Classification: PreventiveState: Published
Include the in scope controls and compliance documents in the audit assertion.
Include the in scope risk assessment processes in the audit assertion.
SNow
Classification: PreventiveState: Published
Include the in scope risk assessment processes in the audit assertion.
Include the in scope services offered or in scope transactions processed in the audit assertion.
SNow
Classification: PreventiveState: Published
Include the in scope services offered or in scope transactions processed in the audit assertion.
Include the nature and causes of identified in scope control deviations in the audit report.
SNow
Classification: PreventiveState: Published
Include the nature and causes of identified in scope control deviations in the audit report.
Include the organization's audit assertion of the in scope system in the audit report.
SNow
Classification: PreventiveState: Published
Include the organization's audit assertion of the in scope system in the audit report.
Include the organization's description of the in scope system in the audit report.
SNow
Classification: PreventiveState: Published
Include the organization's description of the in scope system in the audit report.
Include the organization's privacy practices in the audit report.
SNow
Classification: PreventiveState: Published
Include the organization's privacy practices in the audit report.
Include the pass or fail test status of all in scope controls in the audit report.
SNow
Classification: PreventiveState: Published
Include the pass or fail test status of all in scope controls in the audit report.
Include the process of using evidential matter to test in scope controls in the audit report.
SNow
Classification: PreventiveState: Published
Include the process of using evidential matter to test in scope controls in the audit report.
Include the process of using evidential matter to test in scope controls in the test plan.
SNow
Classification: PreventiveState: Published
Include the process of using evidential matter to test in scope controls in the test plan.
Include the results of the risk assessment in the risk assessment report.
SNow
Classification: PreventiveState: Published
Include the results of the risk assessment in the risk assessment report.
Include the risks to the organization's key personnel and assets in the threat and risk classification scheme.
SNow
Classification: PreventiveState: Published
Include the risks to the organization's key personnel and assets in the threat and risk classification scheme.
Include the roles and responsibilities involved in risk assessments in the risk assessment program.
SNow
Classification: PreventiveState: Published
Include the roles and responsibilities involved in risk assessments in the risk assessment program.
Include the scope and work performed in the audit report.
SNow
Classification: PreventiveState: Published
Include the scope and work performed in the audit report.
Include the scope and work to be performed in external auditor outsourcing contracts.
SNow
Classification: PreventiveState: Published
Include the scope and work to be performed in external auditor outsourcing contracts.
Children (5)
Include the word independent in the title of audit reports.
SNow
Classification: PreventiveState: Published
Include the word independent in the title of audit reports.
Include whether the use of compensating controls are necessary in the audit report.
SNow
Classification: PreventiveState: Published
Include whether the use of compensating controls are necessary in the audit report.
Include why specific criteria are ignored by in scope controls in the audit assertion.
SNow
Classification: PreventiveState: Published
Include why specific criteria are ignored by in scope controls in the audit assertion.
Integrate the corrective action plan based on the risk assessment findings with other risk management activities.
SNow
Classification: PreventiveState: Published
Integrate the corrective action plan based on the risk assessment findings with other risk management activities.
Investigate the nature and causes of identified in scope control deviations.
SNow
Classification: DetectiveState: Published
Investigate the nature and causes of identified in scope control deviations.
Manage third party audits.
SNow
Classification: PreventiveState: Published
Manage third party audits.
Perform a gap analysis to review in scope controls for identified risks and implement new controls, as necessary.
SNow
Classification: DetectiveState: Published
Perform a gap analysis to review in scope controls for identified risks and implement new controls, as necessary.
Perform risk assessments for all target environments, as necessary.
SNow
Classification: PreventiveState: Published
Perform risk assessments for all target environments, as necessary.
Children (5)
- Approve the results of the risk assessment as documented in ...
- Distribute the approved risk assessment report to interested...
- Include the results of the risk assessment in the risk asses...
- Update the risk assessment upon changes to the risk profile.
- Update the risk assessment upon discovery of a new threat.
Prioritize and select controls based on the risk assessment findings.
SNow
Classification: PreventiveState: Published
Prioritize and select controls based on the risk assessment findings.
Provide auditors access to all in scope records, in scope assets, personnel and in scope procedures.
SNow
Classification: PreventiveState: Published
Provide auditors access to all in scope records, in scope assets, personnel and in scope procedures.
Require the audit report to be complete.
SNow
Classification: DetectiveState: Published
Require the audit report to be complete.
Retain copies of external auditor outsourcing contracts and engagement letters.
SNow
Classification: PreventiveState: Published
Retain copies of external auditor outsourcing contracts and engagement letters.
Review and agree with the risk assessment findings.
SNow
Classification: PreventiveState: Published
Review and agree with the risk assessment findings.
Review external auditor outsourcing contracts and engagement letters.
SNow
Classification: PreventiveState: Published
Review external auditor outsourcing contracts and engagement letters.
Review management's response to issues raised in past audit reports.
SNow
Classification: DetectiveState: Published
Review management's response to issues raised in past audit reports.
Review past audit reports for specific process steps and calculations that were stated to support the audit report's conclusions.
SNow
Classification: DetectiveState: Published
Review past audit reports for specific process steps and calculations that were stated to support the audit report's conclusions.
Review past audit reports.
SNow
Classification: DetectiveState: Published
Review past audit reports.
Review the adequacy of the external auditor's work papers and audit reports.
SNow
Classification: PreventiveState: Published
Review the adequacy of the external auditor's work papers and audit reports.
Review the adequacy of the internal auditor's audit reports.
SNow
Classification: DetectiveState: Published
Review the adequacy of the internal auditor's audit reports.
Review the adequacy of the internal auditor's work papers.
SNow
Classification: DetectiveState: Published
Review the adequacy of the internal auditor's work papers.
Review the audit assertion furnished by the organization for accuracy.
SNow
Classification: DetectiveState: Published
Review the audit assertion furnished by the organization for accuracy.
Review the audit program scope as it relates to the organization's profile.
SNow
Classification: DetectiveState: Published
Review the audit program scope as it relates to the organization's profile.
Review the audit scope when the Risk Profile is updated.
SNow
Classification: PreventiveState: Published
Review the audit scope when the Risk Profile is updated.
Review the conclusions of the external auditor's work papers and audit reports.
SNow
Classification: PreventiveState: Published
Review the conclusions of the external auditor's work papers and audit reports.
Review the external auditor's qualifications.
SNow
Classification: PreventiveState: Published
Review the external auditor's qualifications.
Review the external auditors involvement in assessing Information Technology controls.
SNow
Classification: PreventiveState: Published
Review the external auditors involvement in assessing Information Technology controls.
Review the issues of non-compliance from past audit reports.
SNow
Classification: DetectiveState: Published
Review the issues of non-compliance from past audit reports.
Review the risk assessment procedures, as necessary.
SNow
Classification: PreventiveState: Published
Review the risk assessment procedures, as necessary.
Take appropriate action if missing audit documentation compromises the audit.
SNow
Classification: PreventiveState: Published
Take appropriate action if missing audit documentation compromises the audit.
Take appropriate action to correct deficiencies identified in the audit report.
SNow
Classification: DetectiveState: Published
Take appropriate action to correct deficiencies identified in the audit report.
Update the risk assessment upon changes to the risk profile.
SNow
Classification: DetectiveState: Published
Update the risk assessment upon changes to the risk profile.
Update the risk assessment upon discovery of a new threat.
SNow
Classification: DetectiveState: Published
Update the risk assessment upon discovery of a new threat.