Auditing methodology on legal compliance of enterprise information systems

被引:2
|
作者
Kim, Sangkyun [1 ]
机构
[1] Kangwon Natl Univ, Dept Ind Engn, Chuncheonsi, Gangwondo, South Korea
关键词
audit; methodology; compliance; enterprise information system; TECHNOLOGY; SECURITY; INTERNET; MANAGEMENT;
D O I
10.1504/IJTM.2011.039315
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In spite of the scepticism, that information technology (IT) compliance is useless enforcement, which does not contribute to an economic balance of the organisations, IT compliance is a mandatory responsibility of the organisations for their survival enforced by legalised rules. To review and update enterprise information systems to be in compliance with various laws is not an easy work because previous studies on information engineering or security engineering do not provide a specialised methodology for IT compliance. The most critical problem that the organisations are facing is that it is very difficult to identify what they should do for IT compliance. An auditing methodology, which identifies the problems of and provides guides on IT compliance would be the solution for the problems that organisations are facing. This paper provides an auditing methodology, which consists of an auditing target, checklist, process model, evaluation indices and reference model. The methodology proposed in this paper helps IT staffs, managements and auditors to improve the level of IT compliance and manage an auditing project effectively.
引用
收藏
页码:270 / 287
页数:18
相关论文
共 50 条
  • [1] Legal Aspects of Statistical Sampling in Tax Compliance Auditing
    van Brederode, Robert F.
    INTERTAX, 2014, 42 (01): : 18 - 27
  • [2] Compliance auditing of Pressure Relief Systems
    Drennen, Todd W.
    Dancey, Jeffrey
    Chemical Engineering Progress, 2023, (April) : 32 - 39
  • [3] Compliance Auditing of Pressure Relief Systems
    Drennen, Todd W.
    Dancey, Jeffrey
    CHEMICAL ENGINEERING PROGRESS, 2023, 119 (04) : 32 - 39
  • [4] A Meta-model for Legal Compliance and Trustworthiness of Information Systems
    Zarrabi, Fatemeh
    Pavlidis, Michalis
    Mouratidis, Haralambos
    Islam, Shareeful
    Preston, David
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2012, 2012, 112 : 46 - 60
  • [5] Feasibility of automated information security compliance auditing
    Longley, D.
    Branagan, M.
    Caelli, W. J.
    Kwok, L. F.
    PROCEEDINGS OF THE IFIP TC 11/ 23RD INTERNATIONAL INFORMATION SECURITY CONFERENCE, 2008, : 493 - +
  • [6] Introduction to an integrated methodology for development and implementation of enterprise information systems
    Leem, CS
    Kim, SK
    JOURNAL OF SYSTEMS AND SOFTWARE, 2002, 60 (03) : 249 - 261
  • [7] INFORMATION-SYSTEMS AUDITING
    不详
    INFORMATION & MANAGEMENT, 1984, 7 (01) : 39 - 43
  • [8] AUDITING MANAGEMENT INFORMATION SYSTEMS
    LINDGREN, LH
    JOURNAL OF SYSTEMS MANAGEMENT, 1969, 20 (06): : 22 - 27
  • [9] AUDITING INTO COMPLIANCE
    KASPRISIN, CA
    TRANSFUSION, 1994, 34 (01) : 5 - 6
  • [10] INTEGRATED AUDITING OF ENTERPRISE MANAGEMENT SYSTEMS IN A GLOBALIZED ENVIRONMENT
    Majernik, Milan
    Daneshjo, Naqib
    Stofkova, Katarina Repkova
    Sanciova, Gabriela
    GLOBALIZATION AND ITS SOCIO-ECONOMIC CONSEQUENCES, 16TH INTERNATIONAL SCIENTIFIC CONFERENCE PROCEEDINGS, PTS I-V, 2016, : 1261 - 1269