FISCAM presents a methodology for performing info. system (IS) control audits of governmental entities in accordance with professional standards. FISCAM is designed to be used on financial and performance audits and attestation engagements. The methodology in the FISCAM incorp. the following: (1) A top-down, risk-based approach that considers materiality and significance in determining audit procedures; (2) Evaluation of entitywide controls and their effect on audit risk; (3) Evaluation of general controls and their pervasive impact on bus. process controls; (4) Evaluation of security mgmt. at all levels; (5) Control hierarchy to evaluate IS control weaknesses; (6) Groupings of control categories consistent with the nature of the risk. Illus.U.S. Department of Commerce, National Institute of Standards and Technology, Information Technology Security Training Requirements: A Role-Performance- Based Model, Special Publication 800-16, (Washington, D.C.: April 1998).
|Title||:||Federal Information System Controls Audit Manual (FISCAM)|
|Author||:||Robert F. Dacey|
|Publisher||:||DIANE Publishing - 2010-11|