Updating ISSAI Project Proposal SAI India Comptroller and Auditor General of India1
Background ISSAI Information Systems Security Audit – only ISSAI in 5300 series of ISSAIs on IT Audit Adopted in October 1995; due for review in 2013 Comptroller and Auditor General of India2
Findings of Preliminary Review Generational changes in the field of Information Technology – Technological e.g. Internet, computing capabilities, user interfaces, frameworks (ISO 27000, etc.) – Maturity of users and also auditors! – Spread (large no of interconnected databases linked through networks; users) – Service Potential (large no. of Information Systems providing services to citizens) Existing ISSAI focuses more on management aspects of security of Information Systems Above add to the vulnerabilities of Information Systems, particularly in the public sector Comptroller and Auditor General of India3
Proposal Updating ISSAI 5310 on priority basis Focus Areas – Desirable to have clear and distinct audit orientation to audit of Information Systems’ Security bringing out compliance and substantive audit issues – Focus on audit methodology with references to CoBIT, etc. for standardisation – Provision for development of next level of ISSAIs dealing with specific issues concerning Information Systems’ Security Audit – Updating list of threats and countermeasures in light of new developments in the field – Outlining the audit process Comptroller and Auditor General of India4
Proposal Steps suggested – Identify Review Team – Identify modifications to be carried out SAI India has prepared a Draft ISSAI which can be considered by the Review Team for the purpose – Update ISSAI 5310 as per the Due Process Comptroller and Auditor General of India5
Timelines Stage-1: The Project Proposal – The project proposal is proposed to be approved by the KSC Steering Committee by 10th May Stage-2: The Exposure Draft – The project group would prepare the exposure draft of the ISSAI-5310 by 30th June 2013 and thereafter, the exposure draft would be open for comments for 90 days i.e. up to 30th September Stage-3: The endorsement version – The draft ISSAI would be approved in the 64th Governing Board meeting to be held on 21st October 2013 for endorsement to XXI INCOSAI. Stage-4: Final ISSAI – The ISSAI would be approved by XXI INCOSAI to be held from October 2013 and available for the entire INTOSAI community. Comptroller and Auditor General of India6
THANKS Comptroller and Auditor General of India7