< Return to Video

Performing IT Audit Walkthroughs

  • 0:03 - 0:06
    All right. So good morning, guys and thank
  • 0:06 - 0:08
    you for joining me here today. So, today, I
  • 0:08 - 0:10
    just wanted to do a quick training on IT
  • 0:10 - 0:14
    audio walkthroughs, and to be honest, I
  • 0:14 - 0:15
    was planning to record this by myself
  • 0:15 - 0:17
    and then I decided, you know, what, why not
  • 0:17 - 0:19
    just make it a live training and see if
  • 0:19 - 0:22
    others are interested in joining, and you
  • 0:22 - 0:24
    guys are. So, thank you for joining.
  • 0:24 - 0:26
    It's going to be short. This is just
  • 0:26 - 0:29
    going to be 30 minutes, maybe about 15-20
  • 0:29 - 0:31
    minutes of training. And then, I'll see if
  • 0:31 - 0:32
    you guys have any questions.
  • 0:32 - 0:34
    It's intended for YouTube, for
  • 0:34 - 0:36
    transparency sake. So, it will be recorded
  • 0:36 - 0:39
    to YouTube, but the difference is those
  • 0:39 - 0:41
    that are here live with me, you get to
  • 0:41 - 0:43
    ask questions, and those on YouTube can't
  • 0:43 - 0:45
    ask questions right. So, let's go ahead
  • 0:45 - 0:47
    and get started. If you guys are ready to
  • 0:47 - 0:50
    get started, okay. You let me know. Yep, yep,
  • 0:50 - 0:50
    yep.
  • 0:50 - 0:54
    All right. So awesome awesome. So let's go
  • 0:54 - 0:56
    ahead, and get started here. Thank you for
  • 0:56 - 0:59
    joining me here today for a training on
  • 0:59 - 1:02
    IT audit walkthroughs. So in today's
  • 1:02 - 1:05
    training, I just want to give you guys
  • 1:05 - 1:08
    a quick overview or an introduction
  • 1:08 - 1:11
    to what IT audit walkthroughs are. I know
  • 1:11 - 1:13
    many of you might have been searching
  • 1:13 - 1:15
    the internet trying to find additional
  • 1:15 - 1:17
    information on audits, and you may have
  • 1:17 - 1:20
    seen the word walkthrough, right. And you
  • 1:20 - 1:22
    don't understand what that is. So today,
  • 1:22 - 1:23
    I'm just going to give you an
  • 1:23 - 1:25
    introduction to that. And then, we'll see
  • 1:25 - 1:27
    if you guys have any questions related
  • 1:27 - 1:28
    to the topic.
  • 1:28 - 1:31
    Later on, all right. So, I see more of
  • 1:31 - 1:32
    you joining. Thank you for joining, guys.
  • 1:32 - 1:36
    So, before we get started, very brief
  • 1:36 - 1:37
    introduction to myself. I don't want to
  • 1:37 - 1:39
    take too much time here.
  • 1:39 - 1:40
    But for those, that are just meeting
  • 1:40 - 1:43
    me for the first time. My name is Peju Adedeji.
  • 1:43 - 1:46
    I have over 18 years of experience in
  • 1:46 - 1:48
    the I.T space. A lot of that is around IT
  • 1:48 - 1:53
    audit GRC program management. All in the
  • 1:53 - 1:56
    audit and compliance space really. My
  • 1:56 - 1:58
    passion is teaching. That's one of the
  • 1:58 - 2:00
    things that I've always loved to do. So,
  • 2:00 - 2:02
    I'm also a career coach where I help
  • 2:02 - 2:04
    people that are looking to start their
  • 2:04 - 2:07
    careers in I.T cyber security audit, and
  • 2:07 - 2:08
    compliance.
  • 2:08 - 2:12
    Okay, for me, I like practical training
  • 2:12 - 2:14
    recently joined the Forbes coaches
  • 2:14 - 2:16
    council. Again, I really love teaching so
  • 2:16 - 2:19
    I like to be with other coaches trying
  • 2:19 - 2:21
    to develop myself so that I can help my
  • 2:21 - 2:23
    students as well.
  • 2:23 - 2:25
    This year, we've already had multiple
  • 2:25 - 2:26
    six-figure salaries that have come in
  • 2:26 - 2:29
    our program, and so I I'm really excited
  • 2:29 - 2:32
    about what we're doing. So let's go ahead
  • 2:32 - 2:34
    and get started with the training for
  • 2:34 - 2:35
    today.
  • 2:35 - 2:38
    So here are the topics for today.
  • 2:38 - 2:40
    We're going to go over an
  • 2:40 - 2:41
    introduction to IT audit at a higher
  • 2:41 - 2:43
    level. So if you are not familiar with
  • 2:43 - 2:45
    this you can probably check my YouTube
  • 2:45 - 2:47
    channel. And you see the training, I've
  • 2:47 - 2:49
    done it on this in the past.
  • 2:49 - 2:51
    But I'm going to just introduce that
  • 2:51 - 2:53
    because I know some people that are here
  • 2:53 - 2:56
    today may not right have watched any
  • 2:56 - 2:58
    of my videos before or attended any of
  • 2:58 - 3:01
    my training. And then, we'll talk about
  • 3:01 - 3:03
    the IT audit phases because it's during
  • 3:03 - 3:05
    this discussion that we're then going to
  • 3:05 - 3:07
    talk about walkthroughs, because
  • 3:07 - 3:10
    walkthroughs that's one of the phases or
  • 3:10 - 3:12
    part of one of the phases. And there's
  • 3:12 - 3:14
    going to be a bonus review, where I'm
  • 3:14 - 3:15
    going to walk through some actual
  • 3:15 - 3:18
    examples with you. And maybe I'll give
  • 3:18 - 3:20
    you guys a bonus document. But let's see,
  • 3:20 - 3:22
    okay. And at the end I'll give about 10
  • 3:22 - 3:25
    minutes or so for questions.
  • 3:25 - 3:28
    So let's go ahead and start with our
  • 3:28 - 3:30
    introduction to IT audit.
  • 3:30 - 3:32
    I'm not going to go in depth into this
  • 3:32 - 3:34
    like I said, I have a training on my
  • 3:34 - 3:35
    YouTube channel that you guys can watch.
  • 3:35 - 3:38
    But, I do want to introduce this in
  • 3:38 - 3:40
    today's training because I want you to
  • 3:40 - 3:42
    understand what audits are before we
  • 3:42 - 3:45
    talk about walkthroughs, right. So, what's
  • 3:45 - 3:48
    an audit at the end of the day, you know,
  • 3:48 - 3:50
    people have different definitions of
  • 3:50 - 3:52
    what it is, but IT audit at the end of
  • 3:52 - 3:54
    the day, if you want to use simple terms,
  • 3:54 - 3:57
    is an examination of the organization
  • 3:57 - 4:00
    systems to determine if controls are
  • 4:00 - 4:03
    operating effectively. So systems usually
  • 4:03 - 4:05
    have controls in there, and for controls.
  • 4:05 - 4:07
    Again, the prior training I mentioned
  • 4:07 - 4:09
    will have that but think of a control as
  • 4:09 - 4:12
    like a password control, right. When you
  • 4:12 - 4:13
    want to log into your computer, you have
  • 4:13 - 4:15
    to put in a password,
  • 4:15 - 4:16
    or maybe your e-mail you have to put
  • 4:16 - 4:19
    in a password that's a control. So,
  • 4:19 - 4:21
    organization systems have controls, as
  • 4:21 - 4:22
    well,
  • 4:22 - 4:25
    and this controls right.
  • 4:25 - 4:27
    In order, part of an I.T audit is
  • 4:27 - 4:31
    testing and examining those systems to
  • 4:31 - 4:32
    determine if those controls are
  • 4:32 - 4:34
    operating effectively because if they
  • 4:34 - 4:37
    are not operating effectively, then the
  • 4:37 - 4:39
    security of that system right is in
  • 4:39 - 4:42
    question. And you might be wondering, "Well,
  • 4:42 - 4:44
    why should I be concerned about the
  • 4:44 - 4:47
    security or of a system or whether the
  • 4:47 - 4:49
    controls are operating effectively," and
  • 4:49 - 4:51
    the reason is one you want to mitigate
  • 4:51 - 4:54
    risks, right. You don't want people having
  • 4:54 - 4:56
    inappropriate access to your systems, so
  • 4:56 - 4:58
    when I say, "You, I'm in the
  • 4:58 - 5:00
    organization," an organization doesn't
  • 5:00 - 5:03
    want people having inappropriate access
  • 5:03 - 5:06
    to the systems. So, it's important to have
  • 5:06 - 5:09
    controls in place to ensure that that
  • 5:09 - 5:12
    security is there. And as the I.T auditor,
  • 5:12 - 5:14
    right, part of your audit objective or
  • 5:14 - 5:16
    your control objective for your test is
  • 5:16 - 5:18
    determining if security controls are in
  • 5:18 - 5:21
    place. So you are examining those systems
  • 5:21 - 5:23
    to see if those controls are effective
  • 5:23 - 5:25
    in mitigating risks, like I said for
  • 5:25 - 5:28
    example security risks or just even
  • 5:28 - 5:30
    medium compliance and regulatory
  • 5:30 - 5:32
    requirements, right. So in the US, we have
  • 5:32 - 5:34
    servings, okay. Other countries have
  • 5:34 - 5:37
    similar laws and standards as well. We
  • 5:37 - 5:40
    have PCI, SOX, SSA 18, right. So, all those
  • 5:40 - 5:43
    standards depending on what your
  • 5:43 - 5:46
    organization needs to comply with then
  • 5:46 - 5:48
    the audit is going to take place to
  • 5:48 - 5:51
    examine and determine if those controls
  • 5:51 - 5:54
    are meeting those requirements, okay. So
  • 5:54 - 5:58
    that's a summary of what we have of
  • 5:58 - 6:00
    what IT audits are.
  • 6:00 - 6:02
    So,
  • 6:02 - 6:04
    there are three key phases of IT
  • 6:04 - 6:06
    audience, all right. So we have the audio
  • 6:06 - 6:08
    planning phase we have our field
  • 6:08 - 6:10
    workplace, and this is where you have the
  • 6:10 - 6:12
    walkthrough, so that's where the
  • 6:12 - 6:14
    walkthroughs are performed, and you also
  • 6:14 - 6:16
    have the reporting and the follow-up
  • 6:16 - 6:18
    phase. So I'm going to again summarize
  • 6:18 - 6:21
    this. So that I set the stage for what
  • 6:21 - 6:24
    we really want to talk about today, so in
  • 6:24 - 6:25
    your audit planning phase right. This is
  • 6:25 - 6:27
    where you're understanding the
  • 6:27 - 6:30
    organization trying to define the scope,
  • 6:30 - 6:32
    and the objective and also trying to
  • 6:32 - 6:35
    identify what tests you perform so
  • 6:35 - 6:38
    you're essentially just planning for the
  • 6:38 - 6:41
    audit in that phase. Now, the field work
  • 6:41 - 6:42
    phase is, kind of, I'll say, that's where
  • 6:42 - 6:44
    the medium potatoes are right. I guess
  • 6:44 - 6:47
    when you do the real field work for the
  • 6:47 - 6:49
    audit you do your testing and all of
  • 6:49 - 6:51
    that. But, before you actually start
  • 6:51 - 6:53
    testing, you have to perform your
  • 6:53 - 6:55
    walkthroughs, and I'm going to come back
  • 6:55 - 6:57
    to the World Series after I finish the
  • 6:57 - 6:59
    third stage or the third phase.
  • 6:59 - 7:02
    The third phase is where you do the
  • 7:02 - 7:04
    reporting, so you finish planning, you've
  • 7:04 - 7:06
    done the actual testing, and you have
  • 7:06 - 7:09
    results then in the third phase, you're
  • 7:09 - 7:11
    doing your reporting, and your follow-up.
  • 7:11 - 7:13
    So, this is where you type up the report
  • 7:13 - 7:15
    to management on the results. And if
  • 7:15 - 7:18
    there were any issues identified, you can
  • 7:18 - 7:21
    go back, and retest to confirm whether or
  • 7:21 - 7:23
    not, they've been addressed. So those are
  • 7:23 - 7:27
    the three phases of an audit. Now, I want
  • 7:27 - 7:29
    to dial in on that walk through piece
  • 7:29 - 7:30
    because
  • 7:30 - 7:33
    there are many moving parts, right. So as
  • 7:33 - 7:34
    you can imagine an audit is like a
  • 7:34 - 7:36
    pretty big project, right. So, there are
  • 7:36 - 7:39
    many moving pieces and today, I'm now
  • 7:39 - 7:41
    going to focus on the IT audio
  • 7:41 - 7:44
    walkthrough piece right again. The IT or
  • 7:44 - 7:46
    the walkthrough is part of the field
  • 7:46 - 7:48
    work phase.
  • 7:48 - 7:51
    So now, let's talk about what are IT? What
  • 7:51 - 7:54
    other walkthroughs or what, I'm not sure
  • 7:54 - 7:56
    if you know, maybe if you've
  • 7:56 - 7:58
    you rented an apartment, or you bought
  • 7:58 - 8:01
    a house before they give you the keys,
  • 8:01 - 8:03
    right. You, kind of, they will take you to
  • 8:03 - 8:04
    what they call a walkthrough. Typically,
  • 8:04 - 8:07
    right, you just go in kind of just look
  • 8:07 - 8:09
    at how things are before they give you
  • 8:09 - 8:11
    the keys and say, "Okay, we agree that this
  • 8:11 - 8:13
    is the state that you're giving us the
  • 8:13 - 8:16
    house or the apartment in or whatnot." So
  • 8:16 - 8:18
    if you think about that it's not exactly
  • 8:18 - 8:21
    the same, but a walkthrough from the IT audit
  • 8:21 - 8:24
    perspective is you getting a better
  • 8:24 - 8:26
    understanding of the I.T control
  • 8:26 - 8:28
    environment of the company.
  • 8:28 - 8:30
    So what you do at the beginning of the
  • 8:30 - 8:32
    audit, because you're an auditor right,
  • 8:32 - 8:34
    you're not I.T. You're not, if you're an
  • 8:34 - 8:36
    external auditor, you're not working in
  • 8:36 - 8:39
    the company right. So you can't assume
  • 8:39 - 8:41
    that you know everything about that
  • 8:41 - 8:42
    company. You can't assume that you know
  • 8:42 - 8:45
    their control environment. So the reason
  • 8:45 - 8:47
    for that walkthrough is for the auditors
  • 8:47 - 8:51
    to get a better understanding, right, of
  • 8:51 - 8:52
    the control environment that they're
  • 8:52 - 8:55
    going to be auditing. So, it's absolutely
  • 8:55 - 8:58
    critical because if you don't conduct
  • 8:58 - 9:00
    your walkthrough effectively, you might
  • 9:00 - 9:03
    have gaps in your understanding of the
  • 9:03 - 9:05
    control environment, and that's going to
  • 9:05 - 9:08
    ultimately impact right the quality of
  • 9:08 - 9:09
    the control procedures that you choose
  • 9:09 - 9:12
    to perform and your understanding of the
  • 9:12 - 9:15
    impact of the risk. So, walkthroughs are
  • 9:15 - 9:17
    very important because that's where you
  • 9:17 - 9:19
    really get a good understanding of that
  • 9:19 - 9:22
    environment, and a key part of that is
  • 9:22 - 9:26
    that you have to include key players and
  • 9:26 - 9:28
    the control owners from I.T. So, you're
  • 9:28 - 9:30
    not just going to have a random set of
  • 9:30 - 9:31
    people in your work just giving you
  • 9:31 - 9:33
    information about the environment. You
  • 9:33 - 9:35
    have to understand that you have to
  • 9:35 - 9:38
    invite the right players. So if for your
  • 9:38 - 9:40
    IT audit walkthrough, you probably have
  • 9:40 - 9:42
    their management levels there right the
  • 9:42 - 9:44
    people that are responsible for those
  • 9:44 - 9:46
    controls. So the control owners you want
  • 9:46 - 9:48
    to make sure that they are in the room
  • 9:48 - 9:50
    with you or on Zoom if it's virtual,
  • 9:50 - 9:53
    right, explaining their an I.T
  • 9:53 - 9:55
    environment. And even if they're not the
  • 9:55 - 9:57
    key control owner, but they have a part
  • 9:57 - 9:59
    in the process.
  • 9:59 - 10:01
    And, they're a key player or key
  • 10:01 - 10:03
    stakeholder then you want to make sure
  • 10:03 - 10:05
    that they're also in the room with you
  • 10:05 - 10:08
    because if not, then again, you run the
  • 10:08 - 10:12
    risk of not having that information on
  • 10:12 - 10:14
    the control environment. So it's
  • 10:14 - 10:15
    important to have the key players and
  • 10:15 - 10:18
    especially the control owners in the
  • 10:18 - 10:20
    meeting where you're having that walk
  • 10:20 - 10:23
    through and one of the things that
  • 10:23 - 10:25
    you would test there or that you could
  • 10:25 - 10:27
    test, there is a test of design again if
  • 10:27 - 10:29
    you don't know what test of design is,
  • 10:29 - 10:31
    you can watch my prior video, and I'll
  • 10:31 - 10:33
    probably link it when I post this on
  • 10:33 - 10:35
    YouTube, so you can see that video where
  • 10:35 - 10:37
    I talk about test of design in terms of
  • 10:37 - 10:40
    operating effectiveness. So depending on
  • 10:40 - 10:42
    the control that you're testing or the
  • 10:42 - 10:43
    controls that you're reviewing during
  • 10:43 - 10:45
    your walkthroughs, you may be able to
  • 10:45 - 10:48
    perform some tests of design there. Okay.
  • 10:48 - 10:51
    So again, just to summarize this why
  • 10:51 - 10:53
    didn't we conduct I.T audit walkthroughs,
  • 10:53 - 10:56
    it's to understand or better understand
  • 10:56 - 10:58
    the control environment. The I.T control
  • 10:58 - 11:00
    environment that you'll be testing, you
  • 11:00 - 11:02
    should include the key players
  • 11:02 - 11:04
    stakeholders and control owners from it.
  • 11:04 - 11:07
    And during this, you may be able to test
  • 11:07 - 11:11
    the design of controls as, well, okay, one
  • 11:11 - 11:13
    thing I do want to stay here before we
  • 11:13 - 11:16
    move on to the next area is that
  • 11:16 - 11:18
    you'll go through questions should be
  • 11:18 - 11:21
    worded properly, right. So that you can
  • 11:21 - 11:23
    get useful responses from those that
  • 11:23 - 11:25
    you're interviewing. So let me pause here
  • 11:25 - 11:28
    for a second. Have you guys ever asked a
  • 11:28 - 11:30
    question and then you got the wrong
  • 11:30 - 11:32
    answer back? Let me see you guys in the
  • 11:32 - 11:34
    chat just to make sure, you guys are
  • 11:34 - 11:35
    still here with me. Have you ever asked
  • 11:35 - 11:38
    the question and the kind of answers
  • 11:38 - 11:39
    you're getting, you're like, "Okay, maybe I
  • 11:39 - 11:41
    asked the wrong question."
  • 11:41 - 11:43
    Yeah? Okay, so that's the same thing for
  • 11:43 - 11:46
    walkthroughs. So it takes some skill,
  • 11:46 - 11:48
    right? You need to know what questions
  • 11:48 - 11:50
    that you should ask in order to be able
  • 11:50 - 11:52
    to get the right risk. I don't want to
  • 11:52 - 11:54
    use the word, right because it's not
  • 11:54 - 11:56
    really right and wrong, but in order to
  • 11:56 - 11:57
    get
  • 11:57 - 12:00
    good responses, right. Useful responses
  • 12:00 - 12:02
    where you when you're actually testing
  • 12:02 - 12:04
    it makes sense not the kind of response
  • 12:04 - 12:05
    is that when you start testing, it's like
  • 12:05 - 12:07
    okay what they said doesn't make sense
  • 12:07 - 12:09
    based on what I'm looking at right. So,
  • 12:09 - 12:12
    that's a skill you'll need to gain as
  • 12:12 - 12:14
    you go through your walkthroughs because
  • 12:14 - 12:18
    if you don't write, then you run the
  • 12:18 - 12:21
    risk of not getting the responses that
  • 12:21 - 12:24
    will be useful to you in performing your
  • 12:24 - 12:26
    audience. So, here is the bonus part.
  • 12:26 - 12:29
    I'm going to now give you a couple of
  • 12:29 - 12:31
    examples so that, you know. Again, I like
  • 12:31 - 12:33
    practical teaching, so that this can be
  • 12:33 - 12:36
    real to you, okay. So let's look at some
  • 12:36 - 12:38
    sample questions, and there are
  • 12:38 - 12:40
    different parts of IT audits I'm going
  • 12:40 - 12:42
    to look at couple of questions, and
  • 12:42 - 12:44
    logical security.
  • 12:44 - 12:46
    So logical security, this is around
  • 12:46 - 12:49
    access to systems we're not going to go
  • 12:49 - 12:51
    deep into logical security itself, but
  • 12:51 - 12:53
    let's talk about what are some questions
  • 12:53 - 12:56
    right. So, you want you're going to have
  • 12:56 - 12:58
    different levels to your questions. So,
  • 12:58 - 13:01
    for example, you start off with describe
  • 13:01 - 13:03
    the user access provisioning process.
  • 13:03 - 13:05
    This is open-ended. You want to give them
  • 13:05 - 13:07
    the opportunity to describe the whole
  • 13:07 - 13:09
    process for you, and then you can go
  • 13:09 - 13:12
    deeper, right. So who has authority to
  • 13:12 - 13:14
    approve users, and their privileged
  • 13:14 - 13:16
    levels. So you again, you're starting
  • 13:16 - 13:18
    higher getting a broader understanding
  • 13:18 - 13:22
    of the environment, and their process and
  • 13:22 - 13:24
    then you can ask deeper questions based
  • 13:24 - 13:26
    on the controls that you're testing. So,
  • 13:26 - 13:28
    these are just a few examples for you to
  • 13:28 - 13:31
    see what you might ask during a
  • 13:31 - 13:33
    walkthrough, and then
  • 13:33 - 13:34
    again, let me look at change
  • 13:34 - 13:36
    management.
  • 13:36 - 13:38
    So change management again, is another
  • 13:38 - 13:40
    area that we test for in IT. During IT
  • 13:40 - 13:43
    audits, and here you might also start
  • 13:43 - 13:44
    with describe the change management
  • 13:44 - 13:47
    process, right again. Study high level
  • 13:47 - 13:49
    giving them the opportunity to describe
  • 13:49 - 13:51
    the process to you end to end, and then
  • 13:51 - 13:53
    you ask who's required to approve
  • 13:53 - 13:55
    changes. For example, so that's a little
  • 13:55 - 13:59
    bit more, you're diving deeper into
  • 13:59 - 14:01
    maybe one of the controls to get a
  • 14:01 - 14:03
    better understanding of that particular
  • 14:03 - 14:06
    control area, okay. So,
  • 14:06 - 14:08
    hopefully, that was helpful for you
  • 14:08 - 14:09
    guys. Do you guys feel like you have a
  • 14:09 - 14:10
    better understanding of what
  • 14:10 - 14:14
    walkthroughs are now? Yep, okay, good, good,
  • 14:14 - 14:16
    I see. Yes, thank you Diamond, Lake Paul,
  • 14:16 - 14:19
    thank you Ashley. So, that's really what I
  • 14:19 - 14:22
    wanted to cover here today. Again, this is
  • 14:22 - 14:23
    intended to be a short training session,
  • 14:23 - 14:26
    just bite sized. So, that you understand
  • 14:26 - 14:29
    some unique areas in the audit space
  • 14:29 - 14:32
    that would help you, all right. So,
  • 14:32 - 14:34
    rainbow said basically to understand
  • 14:34 - 14:36
    the yeah. So, to understand the IT control
  • 14:36 - 14:39
    environment, and that would help you when
  • 14:39 - 14:41
    you're putting together your
  • 14:41 - 14:44
    procedures of performing your test for
  • 14:44 - 14:48
    your IT audit. All right, so now let's do
  • 14:48 - 14:50
    a summary. I promise you. There'll be some
  • 14:50 - 14:53
    time for Q/A at the end. Let me see if
  • 14:53 - 14:56
    you guys have any questions if you have
  • 14:56 - 14:58
    questions you can put them in the Q/A
  • 14:58 - 15:00
    section, and I'll take a few minutes to
  • 15:00 - 15:02
    answer them here. But let me do a quick
  • 15:02 - 15:04
    summary for you guys because I know some
  • 15:04 - 15:05
    of you
  • 15:05 - 15:08
    joined after we already started.
  • 15:08 - 15:10
    Just to summarize what we talked
  • 15:10 - 15:12
    about here today, we started off by just
  • 15:12 - 15:14
    going through an introduction to IT
  • 15:14 - 15:17
    audits, right. Again, if you want more
  • 15:17 - 15:18
    information there, you can watch that
  • 15:18 - 15:20
    video, I have on the channel, and then we
  • 15:20 - 15:23
    talked about the IT audit faces, right?
  • 15:23 - 15:25
    What are the phases? So, let me pause
  • 15:25 - 15:27
    before I answer the question in the chat.
  • 15:27 - 15:29
    Can you tell me what are the phases that
  • 15:29 - 15:32
    we talked about today?
  • 15:34 - 15:37
    Awesome thanks, Bob.
  • 15:38 - 15:41
    Second phase.
  • 15:43 - 15:48
    Thank you, and then one more
  • 15:49 - 15:52
    reporting, and follow awesome, awesome. On
  • 15:52 - 15:54
    what phase do we have the IT
  • 15:54 - 15:57
    walkthroughs?
  • 16:02 - 16:04
    Walk through his field work, so the field
  • 16:04 - 16:06
    work isn't the ID audio walkthrough
  • 16:06 - 16:09
    happens in the field work stage, and this
  • 16:09 - 16:11
    is where again you're getting a better
  • 16:11 - 16:13
    understanding of the environment? You're
  • 16:13 - 16:15
    talking to the control owners and you're
  • 16:15 - 16:17
    talking to the, all the key
  • 16:17 - 16:20
    stakeholders in the I.T space. And then
  • 16:20 - 16:21
    we just walk through a few examples so
  • 16:21 - 16:23
    that you can see how,
  • 16:23 - 16:26
    how walkthroughs are conducted, okay.
  • 16:26 - 16:29
    So I'm going to pause now, let's see if
  • 16:29 - 16:31
    you guys have any questions. I did tell
  • 16:31 - 16:33
    you, it's going to be about 30 minutes. So
  • 16:33 - 16:35
    I want to make sure that we don't go
  • 16:35 - 16:37
    over time. What questions do you guys
  • 16:37 - 16:39
    have?
  • 16:39 - 16:41
    You guys have any questions, or was this
  • 16:41 - 16:44
    straightforward for you guys.
  • 16:48 - 16:50
    Okay, so great question Nick. And Nick is
  • 16:50 - 16:51
    asking can walkthroughs be done
  • 16:51 - 16:53
    virtually, or does he have to be in
  • 16:53 - 16:54
    person?
  • 16:54 - 16:56
    It can be done virtually, so if you
  • 16:56 - 16:58
    think about the pandemic, right? Where
  • 16:58 - 17:00
    everyone no one went out, right? If we
  • 17:00 - 17:01
    weren't going to the office, we're all
  • 17:01 - 17:03
    working remotely a lot of those
  • 17:03 - 17:05
    walkthroughs were performed remotely
  • 17:05 - 17:08
    because you can have interviews. Now, the
  • 17:08 - 17:10
    difference would be physical security
  • 17:10 - 17:12
    walkthroughs where you have to physically
  • 17:12 - 17:14
    walk through a data center. For example,
  • 17:14 - 17:16
    then you'll have to physically go there
  • 17:16 - 17:17
    but other than that for the most part
  • 17:17 - 17:20
    you can have them virtually. It can be in
  • 17:20 - 17:23
    a meeting on Zoom or whatever meeting
  • 17:23 - 17:27
    software your organization uses.
  • 17:30 - 17:32
    Someone is asking which video should
  • 17:32 - 17:33
    you focus on?
  • 17:33 - 17:35
    Um, I'll say that depends on your
  • 17:35 - 17:37
    interest, right. Because I have a lot of
  • 17:37 - 17:40
    videos on different areas so you can
  • 17:40 - 17:43
    select the one that you want. I'm trying
  • 17:43 - 17:45
    to do a better job posting. I'm pretty
  • 17:45 - 17:47
    busy. I have a full-time job, so training
  • 17:47 - 17:49
    is not the only thing I do.
  • 17:49 - 17:51
    So, I'm trying to do a better job
  • 17:51 - 17:52
    posting, but I'll say watch the video
  • 17:52 - 17:56
    that makes sense to you, all right. So,
  • 17:56 - 17:59
    um oh, what she was asking walkthroughs
  • 17:59 - 18:00
    seem to be like something to be done to
  • 18:00 - 18:03
    enhance your planning. How come it's in
  • 18:03 - 18:04
    the field work phase?
  • 18:04 - 18:07
    It depends on your definition of
  • 18:07 - 18:09
    enhancing your planning right because
  • 18:09 - 18:11
    planning, you're not really doing any
  • 18:11 - 18:13
    work, right? In planning, you actually
  • 18:13 - 18:15
    determine what areas you need to test
  • 18:15 - 18:18
    and that will then determine what areas
  • 18:18 - 18:20
    you need to do your walk through, right.
  • 18:20 - 18:22
    Because you don't necessarily need to
  • 18:22 - 18:25
    test all the areas of I.T. depending on
  • 18:25 - 18:27
    the scope of your audit. So, planning is
  • 18:27 - 18:30
    more scope focused once you identify
  • 18:30 - 18:32
    your scope, and then you know the areas
  • 18:32 - 18:34
    you want to test, then it's reasonable
  • 18:34 - 18:36
    that you would then go do walkthroughs
  • 18:36 - 18:38
    for that area. You don't need to do
  • 18:38 - 18:40
    walkthroughs for everything definitely
  • 18:40 - 18:42
    you don't need to do a walkthrough for
  • 18:42 - 18:45
    an area you don't need to test, okay. So,
  • 18:45 - 18:48
    hopefully that addressed the question
  • 18:48 - 18:52
    the last one. I see here,
  • 18:54 - 18:57
    so Laker is asking what IT audit
  • 18:57 - 18:59
    applications are used as a side ERP
  • 18:59 - 19:01
    systems?
  • 19:01 - 19:02
    I don't know that. That question is
  • 19:02 - 19:04
    really accurate
  • 19:04 - 19:06
    because you're talking about two
  • 19:06 - 19:07
    different things so when you say it
  • 19:07 - 19:10
    audit applications, ERP systems, those are
  • 19:10 - 19:12
    two different things. So maybe you want
  • 19:12 - 19:14
    to reword that question. Let me better
  • 19:14 - 19:15
    understand. If you're talking about
  • 19:15 - 19:18
    applications that the audit team uses
  • 19:18 - 19:20
    for their audit, and GRC you have
  • 19:20 - 19:23
    servicenow, orchard, all of that and then
  • 19:23 - 19:25
    the ERP systems are not audit systems.
  • 19:25 - 19:28
    ERP systems are systems that the
  • 19:28 - 19:30
    organization is using for their
  • 19:30 - 19:33
    operational needs, right. So those are two
  • 19:33 - 19:34
    different things so hopefully that helps,
  • 19:34 - 19:37
    all right.
  • 19:37 - 19:42
    Um, NSHE Iggy is asking, "What's the
  • 19:42 - 19:43
    name of the YouTube channel?" it's your
  • 19:43 - 19:46
    I.T career, maybe I'll find the link. Hold
  • 19:46 - 19:47
    on.
  • 19:47 - 19:49
    I'll put it in the record when I post
  • 19:49 - 19:51
    the recording, I'll send an email out and
  • 19:51 - 19:54
    I'll just, I'll give you guys access
  • 19:54 - 19:56
    to that, because I don't know that I have
  • 19:56 - 19:58
    it handy. Let's see,
  • 19:58 - 19:59
    um.
  • 19:59 - 20:01
    What's the difference between internal
  • 20:01 - 20:03
    and external audit? So sure, I will refer
  • 20:03 - 20:05
    you to my YouTube channel for that just
  • 20:05 - 20:07
    because I have another video that goes
  • 20:07 - 20:09
    into that in depth. So I think that'll
  • 20:09 - 20:14
    probably be more beneficial to you, okay?
  • 20:14 - 20:16
    Sarah is asking, "You missed the
  • 20:16 - 20:17
    training?" Yes, the recording is going to
  • 20:17 - 20:20
    be on YouTube, so I was transparent. I was
  • 20:20 - 20:21
    planning to record this for YouTube
  • 20:21 - 20:24
    anyways, and instead of recording it by
  • 20:24 - 20:25
    myself, I decided to invite you guys to
  • 20:25 - 20:28
    listen to me record it live. So, let's say
  • 20:28 - 20:30
    in the next couple of days, or so you
  • 20:30 - 20:32
    guys should see it on YouTube. The
  • 20:32 - 20:33
    difference is those that are here live
  • 20:33 - 20:37
    get to and ask questions, Okay.
  • 20:37 - 20:41
    All right, so let's now go to, let's see
  • 20:41 - 20:42
    if there any other questions. I will be
  • 20:42 - 20:45
    wrapping up in a few minutes.
  • 20:46 - 20:51
    Lincoln said, "Got it." Okay, good.
  • 20:54 - 20:57
    So she is asking, "Can virtual audit
  • 20:57 - 20:59
    be done for a Physical Operation Center?"
  • 20:59 - 21:00
    Um, it depends on the objective. It
  • 21:00 - 21:02
    depends on what you're testing, but
  • 21:02 - 21:05
    typically if the con, it depends on the
  • 21:05 - 21:07
    controls. So if you don't understand what
  • 21:07 - 21:10
    controls are again. Let me see if I can
  • 21:10 - 21:13
    find that channel for you, but it's
  • 21:13 - 21:15
    the control is what's going to determine
  • 21:15 - 21:17
    how you perform, right. So you can't just
  • 21:17 - 21:19
    take an audit, what, what are you actually
  • 21:19 - 21:21
    testing? Because if the control is a
  • 21:21 - 21:23
    physical control that someone needs to
  • 21:23 - 21:27
    see, write, touch or whatever ,then you
  • 21:27 - 21:29
    will need to do that physically. But, if
  • 21:29 - 21:31
    it doesn't require physical presence
  • 21:31 - 21:33
    then if that control could be tested
  • 21:33 - 21:36
    virtually Okay.
  • 21:36 - 21:39
    All right, let's see if there's any more
  • 21:39 - 21:42
    question. If there are any more questions,
  • 21:42 - 21:45
    hey so, good good good. So thank you guys
  • 21:45 - 21:48
    for joining me here today now. Did you
  • 21:48 - 21:49
    guys let
  • 21:49 - 21:52
    all, some media is asking. Do I have
  • 21:52 - 21:55
    resume workshops on IT audits? Do you
  • 21:55 - 21:57
    mean just training on how to do your
  • 21:57 - 21:59
    your resume is that what you're asking
  • 21:59 - 22:02
    on some media? Okay, so I don't do
  • 22:02 - 22:04
    workshops on resume training. However, I
  • 22:04 - 22:07
    have covered the topic before where I
  • 22:07 - 22:09
    talked about resume mistakes that you
  • 22:09 - 22:11
    might make in IT audit. So if and I think
  • 22:11 - 22:12
    I actually have that on my YouTube
  • 22:12 - 22:15
    channel as well. So, if you go there, I
  • 22:15 - 22:16
    think I have one training where I talk
  • 22:16 - 22:18
    about resume mistakes that you might be
  • 22:18 - 22:19
    making.
  • 22:19 - 22:22
    So I don't do workshops and that now
  • 22:22 - 22:25
    in my full-blown comprehensive training.
  • 22:25 - 22:27
    I do provide resume training for my
  • 22:27 - 22:29
    students. I bring in like a live
  • 22:29 - 22:32
    professional resume writer to come give
  • 22:32 - 22:34
    training to students in one of my
  • 22:34 - 22:36
    courses. So that's something I provide.
  • 22:36 - 22:39
    Because your resume is not just about
  • 22:39 - 22:41
    finding a template online, and putting it
  • 22:41 - 22:43
    together right. Your resume should
  • 22:43 - 22:46
    reflect what, you know, your experience. I
  • 22:46 - 22:48
    think. Okay, I'll answer one more question
  • 22:48 - 22:50
    because we have just one more minute.
  • 22:50 - 22:52
    Did we do control testing in the
  • 22:52 - 22:54
    process of walkthrough only check the
  • 22:54 - 22:55
    design?
  • 22:55 - 22:56
    Typically, during your walkthrough,
  • 22:56 - 22:58
    you're just, that's where you're really
  • 22:58 - 23:00
    doing your design review depending on
  • 23:00 - 23:02
    the control. You may not even be able to
  • 23:02 - 23:03
    really finish that in the walkthrough,
  • 23:03 - 23:06
    but you would look at that there. However,
  • 23:06 - 23:08
    additional testing will be needed to
  • 23:08 - 23:10
    finish your testing procedures. Okay all
  • 23:10 - 23:13
    right. So, I think we're up on time here
  • 23:13 - 23:15
    today. Thank you guys for joining me. If
  • 23:15 - 23:16
    you guys learned something, I promise to
  • 23:16 - 23:18
    you guys you will learn something. All
  • 23:18 - 23:21
    right. Great great great. So before we go
  • 23:21 - 23:23
    let me, just make sure there's a free
  • 23:23 - 23:26
    six figure career guide. So this guide has
  • 23:26 - 23:28
    been downloaded so so many times by so
  • 23:28 - 23:30
    many people. Let me put it in the chat,
  • 23:30 - 23:33
    and it's also going to be available in
  • 23:33 - 23:36
    the YouTube link when I'm done. But if
  • 23:36 - 23:37
    you guys want the guide for those
  • 23:37 - 23:40
    interested in IT audits, go ahead and
  • 23:40 - 23:42
    download this guide.
  • 23:42 - 23:45
    Um and it just walks through some things
  • 23:45 - 23:47
    that you need to know, so make sure you
  • 23:47 - 23:49
    download that guide. it's free. I'm not
  • 23:49 - 23:52
    charging you for that at all. And um, I'm
  • 23:52 - 23:54
    not sure how often I'll do this free
  • 23:54 - 23:56
    training, maybe once a month. I don't know,
  • 23:56 - 23:58
    but if you're on my email list. So if you
  • 23:58 - 24:00
    get that guy, for example, you'll be on my
  • 24:00 - 24:02
    email list. And you'll get invited to
  • 24:02 - 24:04
    this. I don't publicize this small
  • 24:04 - 24:06
    meetings anywhere else. It's just going
  • 24:06 - 24:09
    to be for those on my email list. I think
  • 24:09 - 24:12
    I scroll too fast, okay. There it is. All
  • 24:12 - 24:14
    right, so thank you guys. You guys have a
  • 24:14 - 24:17
    great rest of your day. Bye.
Title:
Performing IT Audit Walkthroughs
Description:

more » « less
Video Language:
English
Duration:
24:21

English subtitles

Revisions Compare revisions