预览加载中,请您耐心等待几秒...
1/2
2/2

在线预览结束,喜欢就下载吧,查找使用更方便

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

COBIT在信息系统审计中的研究与应用 Abstract COBIT(ControlObjectivesforInformationandRelatedTechnology)isaframeworkforthegovernanceandmanagementofenterpriseIT.ItisdesignedtohelporganizationsimprovetheirITgovernanceandmanagement,andtoensurethatITsupportsthebusinessneedsandobjectives.ThispaperwillexploretheuseofCOBITininformationsystemauditing,includingitsroleinassessingITrisks,evaluatingITcontrols,andprovidingassuranceonITgovernance. Introduction TheimportanceofIThasbecomeincreasinglyrecognizedinthecurrentbusinessenvironment.AsIThasbecomemoreintegratedintobusinessprocesses,therisksassociatedwithIThaveincreasedaswell.Therefore,ITgovernanceandmanagement,especiallyinthecontextoftheauditprocess,isbecomingmorecriticalthanever.COBIT,developedbytheInformationSystemsAuditandControlAssociation(ISACA),isaframeworkthatprovidesguidanceonITgovernance,management,andcontrol.ItiswidelyusedbyorganizationsworldwidetoaligntheirITactivitieswithbusinessobjectivesandmanageITrisks. UseofCOBITinInformationSystemAuditing AssessingITRisks ThefirststepinanyauditistoassesstherisksassociatedwithIT.COBITprovidesguidanceonidentifyingandassessingITrisks,includingtheITriskmanagementprocess.ITrisksareclassifiedintoseveralcategories,includingstrategic,operational,financial,andcompliancerisks.COBIThelpsinidentifyingtherisksassociatedwiththesecategoriesandprovidesguidanceonhowtoassessthem. EvaluatingITControls ThenextstepistoevaluatetheeffectivenessofITcontrols.COBITprovidesguidanceondevelopingandimplementingITcontrolsthatarealignedwithbusinessobjectives.ITcontrolsincludegeneralcontrolsandapplicationcontrols.GeneralcontrolsarerelatedtotheoverallITenvironmentwhileapplicationcontrolsarespecifictoindividualITapplications.COBITprovidesdetailedguidanceonhowtoevaluatethecontrolseffectively. ProvidingAssuranceonITGovernance Finally,COBITprovidesguidanceonprovidingassuranceonITgovernance.AssuranceisprovidedthroughITaudits,whichassesstheeffectivenessofITcontrolsandthealignmentofITwithbusinessobjectives.COBITprovidesguidanceonho