What is the scope of IT audit?
The scope of a particular IT audit is normally defined by the scoping document produced near the start of the assignment – typically it relates to certain key risks of concern to management that centre around the computer and/or telecommunications systems. The scope of an audit assignment is normally a balance between breadth (i.e. the range of matters to be reviewed) and depth (i.e. the amount of detail reviewed in each matter). Sensible audit plans allow for a bit of both through mixing broadly-scoped high-level audits (designed to find the most important risk areas) with narrowly-scoped in-depth audits (to give those pesky high risk areas a thorough going-over), and clever audit managers allow staff to blow the budget on certain jobs that just deserve more time. It takes a brave audit manager to accept that an audit finding nothing reportable should be stopped early but it does happen, when the planets align or the moon turns blue. The scope of IT Audit, the function, is hard to def