Auditing methodology on legal compliance of enterprise information systems

被引:2
作者
Kim, Sangkyun [1 ]
机构
[1] Kangwon Natl Univ, Dept Ind Engn, Chuncheonsi, Gangwondo, South Korea
关键词
audit; methodology; compliance; enterprise information system; TECHNOLOGY; SECURITY; INTERNET; MANAGEMENT;
D O I
10.1504/IJTM.2011.039315
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In spite of the scepticism, that information technology (IT) compliance is useless enforcement, which does not contribute to an economic balance of the organisations, IT compliance is a mandatory responsibility of the organisations for their survival enforced by legalised rules. To review and update enterprise information systems to be in compliance with various laws is not an easy work because previous studies on information engineering or security engineering do not provide a specialised methodology for IT compliance. The most critical problem that the organisations are facing is that it is very difficult to identify what they should do for IT compliance. An auditing methodology, which identifies the problems of and provides guides on IT compliance would be the solution for the problems that organisations are facing. This paper provides an auditing methodology, which consists of an auditing target, checklist, process model, evaluation indices and reference model. The methodology proposed in this paper helps IT staffs, managements and auditors to improve the level of IT compliance and manage an auditing project effectively.
引用
收藏
页码:270 / 287
页数:18
相关论文
共 34 条
[1]  
Alpar P., 1990, Journal of Management Information Systems, V7, P55, DOI 10.1080/07399019008968344
[2]  
[Anonymous], 270012005 ISOIEC
[3]   THE USE OF DECISION CRITERIA IN SELECTING INFORMATION-SYSTEMS TECHNOLOGY INVESTMENTS [J].
BACON, CJ .
MIS QUARTERLY, 1992, 16 (03) :335-353
[4]   Ideological reactions to Sarbanes-Oxley [J].
Baker, C. Richard .
ACCOUNTING FORUM, 2008, 32 (02) :114-124
[5]   The information audit: An integrated strategic approach [J].
Buchanan, S ;
Gibb, F .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 1998, 18 (01) :29-47
[6]   The information audit: Theory versus practice [J].
Buchanan, Steven ;
Gibb, Forbes .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2008, 28 (03) :150-160
[7]   The use of the World Wide Web for commercial purposes [J].
Cheung, WM .
INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 1998, 98 (3-4) :172-+
[8]  
Choi W., 2000, METHODOLOGY AUDITING
[9]  
DiCenzo C., 2005, USER SURVEY E MAIL A
[10]  
Gordon L.A., 2006, J ACCOUNT PUBLIC POL, V25, P503, DOI DOI 10.1016/J.JACCPUBPOL.2006.07.005