The first thing I try to explain to new auditors (or clients going through an audit for the first time) is what techniques IT auditors use to audit. Most people unfamiliar with auditing have no idea what's about to happen. Are the auditors going to run a magic tool? Are the auditors going to comb through every piece of paperwork in the office? Both? The truth is all of auditing is pretty much broken down into four audit techniques: Inquiry (talking to people), Observation (observing processes), Inspection (looking over paperwork or system configurations), and Reperformance (reperforming a process).
IT Audit Techniques: Inquiry, Observation, Inspection, Re-performance
Inquiry
Inquiry is the process of gathering information directly from an individual who is familiar with the subject matter or control being tested. Inquiry may be written (i.e. email) or oral (i.e. interview).
When to use Inquiry: It is best to use inquiry to gain a basic understanding of complex processes and is always used in combination with observations and inspections.
Strengthen Inquiry with: Corroboration- inquire with multiple people when possible or use it to supplement another form of testing or evidence. Avoid relying on inquiry alone when possible.
Common Pitfalls to Avoid: Verify the person you are inquiring with has appropriate expertise, job title and authority to speak on the record concerning the control/process being verified. Always note the time of inquire and job title of the people inquired with and obtain written inquiries when possible
Observation
Observation is the process or procedure of observing processes take place or witnessing physical items in place and operating as described. These might also be considered walkthroughs.
When to use Observation: It is best to use observations for controls related to physical security, logical security automated controls, data center hardware and for many process controls (this may overlap with re-performance). Examples may include:
- Verifying that various data center safe guards such as fire suppression systems, UPS devices and HVAC systems are in place.
- Verifying that keycard and biometric access systems, security cameras and locked server cages are in place and operating effectively.
- Verifying that certain processes and automated controls in software exist and operate as described (this may overlap with re-performance).
Inspection
Inspection is the examination of documentation that serves of evidence that a control is in place. Inspection often times involves gathering populations and creating samples for testing, but can also overlap with observations (e.g. inspecting fire suppression inspection records while observing that the fire suppression system is in place)
When to use Inspection: Inspection is appropriate when having to verify controls that pertain to entire populations are in place, such as those related to logical access and change management systems. Inspection is also applicable to reviewing company policies and verifying that proper segregation of duties is in place. Examples may include:
- Verify that users with access to corporate IT systems are all current employees and that access is appropriate based on job title and responsibilities by assessing/testing a sample of users from a system-generating population.
- Verifying samples of change management tickets and testing for appropriate segregation of duties, management approvals, rollback procedures, etc.
- Reviewing Master Service Agreements, organization policies, and organization charts for various attributes.
Re-Performance
Re-performance is independently recreating a process to verify that it is operating effectively. Re-performance may also include recreating a process in tandem with an observation to observe an otherwise automated process. Re-performance offers the highest level of assurance that a process is in place and operating effectively.
When to use Re-performance: Re-performance is best used to verify automated IS processes are in place and operating effectively.
Strengthen Re-performance with: Complete documentation of the Re-performance process from start to finish, to help the reviewer gain assurance that the process was accurately re-performed. Include sample input values, query parameters or files used during the process and their output, in the documentation.
Common Pitfalls to Avoid: According to ISACA, a re-performance of a control is technically supposed to be independently performed by the auditor. Be aware of how client interactions might interfere or impact the re-performance process. For example, in cases where you must rely on the client to re-perform a control or process, abstain from leading the client or dictating the control to them. Focus on re-creating the process as it operates in day-to-day operations, then verify that it conforms to the official process and control description.
We welcome all critiques, improvements, and comments! Thank you for taking the time to read more about inquiry observation inspection performance. Please share below in the comments.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)