lembar kerja pemeriksaan - gunadarma...

16
Lembar Kerja Pemeriksaan Bahan Bacaan: 1. Lance M. Turcato (2006). Integrating COBIT® into the IT Audit Process (Planning, Scope Development, Practices). ISACA. 2. Federal Financial Institutions Examination Council (2003). IT EXAMINATION HANDBOOK: AUDIT. 3. Federal Financial Institutions Examination Council (2006). IT EXAMINATION HANDBOOK: INFORMATION SECURITY 4. Federal Financial Institutions Examination Council (1996). IT EXAMINATION HANDBOOK: INFORMATION SYSTEM, VOLUME 1. 5. FEDERAL INFORMATION SYSTEM CONTROLS AUDIT MANUAL (FISCAM). United States Government Accountability Office., 2009.

Upload: vuongdan

Post on 18-Aug-2018

288 views

Category:

Documents


16 download

TRANSCRIPT

Page 1: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Lembar Kerja Pemeriksaan Bahan Bacaan: 1. Lance M. Turcato (2006). Integrating COBIT® into the IT Audit

Process (Planning, Scope Development, Practices). ISACA. 2. Federal Financial Institutions Examination Council (2003). IT

EXAMINATION HANDBOOK: AUDIT. 3. Federal Financial Institutions Examination Council (2006). IT

EXAMINATION HANDBOOK: INFORMATION SECURITY 4. Federal Financial Institutions Examination Council (1996). IT

EXAMINATION HANDBOOK: INFORMATION SYSTEM, VOLUME 1. 5. FEDERAL INFORMATION SYSTEM CONTROLS AUDIT MANUAL

(FISCAM). United States Government Accountability Office., 2009.

Page 2: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Drilling Down to the Technology Infrastructure

MYOB, Value Plus, Zahir, Excell, dll

PC Stand Alone (Windows/Open Sources)

Page 3: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Understanding the Technology Infrastructure

Semakin kompleks infrastruktur IT maka semakin kompleks pemeriksaannya

(ruang lingkup, lembar kerja, laporan, dll)

Page 4: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

IT Audit Universe

Page 5: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Security Audit Universe

Page 6: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Map Audit Universe To COBIT®

Page 7: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe
Page 8: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

ACCESS RIGHTS ADMINISTRATION

Financial institutions should have an effective process to administer access rights. The process should include:

• Assigning users and devices only the access required to perform their required functions,

• Updating access rights based on personnel or system changes,

• Reviewing periodically users’ access rights at an appropriate frequency based on the risk to the application or system, and

• Designing appropriate acceptable-use policies and require users to agree to them in writing.

Examples (FFIEC, 2006)

Page 9: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Policies, Standards, Guidelines & Procedures

Page 10: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe
Page 11: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe
Page 12: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

COBIT® Control Assessment Questionnaire

Page 13: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Examples (FFIEC)

Work Program

Page 14: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Work Program (FISCAM) Information System Controls Audit Planning Checklist

Organization and Key Systems/Applications

Kodifikasi/ Kearsipan

Page 15: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Work Program (FISCAM) Application Level General Controls (AS) - AS-2: Implement effective application access controls

Page 16: Lembar Kerja Pemeriksaan - Gunadarma Universitybhermana.staff.gunadarma.ac.id/Downloads/files/39328/LHP.pdf · Lembar Kerja Pemeriksaan ... lembar kerja, laporan, dll) IT Audit Universe

Work Program (FISCAM)

Rating/

Scoring

Rating/

Scoring