View RSS Feed Mailing List Blog Home Page


« The Lord of the Audits Trilogy, Part 1: The Fellowship of the IT Executives | Main | The Lord of the Audits: Part 3 – The Return of ART (Anal Retentive Tony) »

Thursday, November 11, 2010

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a010534aba2f5970c0133f5b72ce4970b

Listed below are links to weblogs that reference The Lord of the Audits, Part 2: The Two Engagements:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

MarkEggleston

Great post. It's always challenging being on the receiving end especially if you don't know "the rules" and what to expect. In ~2004 I earned my Certified Information Systems Auditor (CISA) from ISACA. I didn't especially want to become an auditor but did want to understand how to manage the audit from the receiving end. Your article is a great description of doing all the right things. I love the fact that you interleave communication to your staff with every action step by the auditors. The only things I'd add (any you may have done) are 1) to carefully document any of your interpretations of regulatory guidelines and 2) to always "say what you'll do and do what you said".

Tony Verdone

Thanks for the comments.
As for point 1) yes, we have documented all that can be regarding the process. In fact, we use Sharepoint as the repository for our related SAS70 activities. The auditors love this as they have a single place to go for their test case creation and test process.

As for point 2) agreed. It's a creed we live by. However, in the real world sometimes things don’t always work out as you’re planned. So I may add, when you can't do what you say you will do; be honest and admit it and avoid covering up your failures.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.