A Perspective on the Evolution of Information System Security Audits: Challenges and Implications



Journal of Information System Security
Volume 12, Number 1 (2016)
Pages 4572
ISSN 1551-0123
Sunita Goel — Siena College, USA
Margaret Garnsey — Siena College, USA
Qi Liu — Siena College, USA
Ingrid Fisher — State University of New York at Albany, USA
Information Institute Publishing, Washington DC, USA




Advances in technology have made it possible to capture vast amounts of financial and non-financial information, whilst at the same time shifting more control from the producers and assurers of information to the recipients of information. As a result, threats to Information System (IS) have grown exponentially, which has made IS security audits even more cumbersome. Assessing the effectiveness of internal controls is an important objective of an IS audit, which is distinct from a financial audit that deals with the accuracy of financial statements. Security auditing has been a part of the auditing profession since the late 1970’s, when information technology was first leveraged at a mass scale in organizations for improving efficiency and productivity. Over time, however, as technology has advanced, audits have become increasingly cumbersome. Rapid innovation in technology has forced the auditing profession to lag behind trying desperately to catch up with technology. In this paper, we examine the evolution of IS security auditing and discuss how technology is impacting the audit profession.




Information System Security, Security Audits, Audit Tools, Security Controls, Audit Failures




