Processes related to information technology and systems are fundamental to generating reliable information for companies. As such, they can be verified and improved through an IT audit process, covering the following aspects:

  • Testing whether the IT environment — including physical and logical infrastructure, corporate network, and control and management systems — is operating effectively;
  • Obtaining evidence on the sufficiency, accuracy and validity of data produced in the IT environment, for the processing, recording, control, security and communication of activities, products and services provided;
  • Applying compliance questionnaires (COBIT, COSO, ITIL);
  • Examining internal policies and standards and comparing them against responses to prior inquiries; and
  • Monitoring the physical infrastructure together with the IT department.

Our IT audit covers, among other aspects, the following:

  • Access Control Policy;
  • Information Technology Security Policy;
  • Business Continuity Plan;
  • Network topology;
  • IT organizational chart;
  • Review of access and activity logs;
  • Compliance controls;
  • Access security policies;
  • Verification of backup data integrity;
  • Periodic testing of security and operational continuity of information systems, particularly controls maintained in electronic form.