Auditing methodology on legal compliance of enterprise information systems

被引:2
|
作者
Kim, Sangkyun [1 ]
机构
[1] Kangwon Natl Univ, Dept Ind Engn, Chuncheonsi, Gangwondo, South Korea
关键词
audit; methodology; compliance; enterprise information system; TECHNOLOGY; SECURITY; INTERNET; MANAGEMENT;
D O I
10.1504/IJTM.2011.039315
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In spite of the scepticism, that information technology (IT) compliance is useless enforcement, which does not contribute to an economic balance of the organisations, IT compliance is a mandatory responsibility of the organisations for their survival enforced by legalised rules. To review and update enterprise information systems to be in compliance with various laws is not an easy work because previous studies on information engineering or security engineering do not provide a specialised methodology for IT compliance. The most critical problem that the organisations are facing is that it is very difficult to identify what they should do for IT compliance. An auditing methodology, which identifies the problems of and provides guides on IT compliance would be the solution for the problems that organisations are facing. This paper provides an auditing methodology, which consists of an auditing target, checklist, process model, evaluation indices and reference model. The methodology proposed in this paper helps IT staffs, managements and auditors to improve the level of IT compliance and manage an auditing project effectively.
引用
收藏
页码:270 / 287
页数:18
相关论文
共 50 条
  • [21] An Architecture to Facilitate Security Assurance and Legal Compliance for Call Auditing in the Wholesale Electricity Market
    Tesfamicael, Aklilu Daniel
    Liu, Vicky
    Mckague, Matthew
    Caelli, William
    IEEE ACCESS, 2021, 9 : 146437 - 146453
  • [22] INTERNAL AUDITING OF MODERN INFORMATION-SYSTEMS
    WILL, HJ
    MANAGERIAL FINANCE, 1979, 5 (02) : 171 - 187
  • [23] Assessing the Economic Benefits of Information Systems Auditing
    Westland, J. Christopher
    INFORMATION SYSTEMS RESEARCH, 1990, 1 (03) : 309 - 324
  • [24] Auditor's Guide to Information Systems Auditing
    Cannon, David
    Godwin, Joseph H.
    Goldberg, Stephen R.
    JOURNAL OF CORPORATE ACCOUNTING AND FINANCE, 2007, 18 (06): : 85 - 87
  • [25] The Future of Enterprise Information Systems
    Sunyaev, Ali
    Dehling, Tobias
    Strahringer, Susanne
    Da Xu, Li
    Heinig, Martin
    Perscheid, Michael
    Alt, Rainer
    Rossi, Matti
    BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2023, 65 (06) : 731 - 751
  • [26] Intelligent information systems in enterprise
    Nikravesh, M
    Proceedings of the 8th Joint Conference on Information Sciences, Vols 1-3, 2005, : 66 - 73
  • [27] On localization of enterprise information systems
    Saha, Goutarn Kumar
    RESEARCH AND PRACTICAL ISSUES OF ENTERPRISE INFORMATION SYSTEMS II, VOL 1, 2008, 254 : 545 - 551
  • [28] Information Systems for Enterprise Architecture
    Moscoso Zea, Oswaldo
    ENFOQUE UTE, 2014, 5 (01): : 16 - 29
  • [29] The Future of Enterprise Information Systems
    Ali Sunyaev
    Tobias Dehling
    Susanne Strahringer
    Li Da Xu
    Martin Heinig
    Michael Perscheid
    Rainer Alt
    Matti Rossi
    Business & Information Systems Engineering, 2023, 65 : 731 - 751
  • [30] Advances in enterprise information systems
    Ling Li
    Ricardo Valerdi
    John N. Warfield
    Information Systems Frontiers, 2008, 10 : 499 - 501