From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Evaluation of controls

Evaluation of controls

- [Narrator] Okay, so let's talk a little bit about the evaluation of IT controls because of course, as auditors, a huge part of what we do is evaluating these controls. So let's start off by just talking about the different types of controls. So first of all, we can talk about controls at the business level or at the IT level. So when we talk about business process level controls, these are those controls that are specific to business process. We're focusing in on the business, whereas at the IT level, the IT controls that are tied to the business, here's where you're going to see general IT controls like change management, then authentication, and some of those controls that are relevant anywhere in any environment. Now, what's important with our controls is that we have a balanced layered defense. And our controls should come across three categories. Administrative controls like policies, procedures, standards, guidelines, technical controls that we tend to think of like encryption…

Contents