Information Technology Reference
In-Depth Information
testing the system. In most cases, it would be ideal for the users to perform walk-throughs
such as data capture, printing invoices, processing transactions, and backing up data. Such
walk-throughs would enable the users to appropriately comment on the functionalities in
the system.
The IS auditor has an important task of testing the system to ensure that the controls are
working as designed and are effective. The IS auditor apart from using testing tools might
also be required to carry out walk-throughs, such as testing that access controls are working
and the audit trail is capturing activities on the system as designed.
It would be important for the IS auditor, just as for the testing team, to develop testing
procedures which would be used during testing. Procedures help to ensure consistency in
testing the application system. Testing procedures should have been developed right at the
beginning of the project or were already in the auditor's toolkit.
During testing, one important tool the IS auditor should insist on is ensuring the testing
process is managed effectively through the use of change management controls. This tool
enables the development team to manage all changes being made on the system. Once a
test is conducted and an issue is raised, the test team will investigate further and conduct
appropriate tests before making recommendations to the project manager. If the testing is
accepted and approved, the change is implemented. Changes should not be implemented
without the approval of senior management or the project manager. This ensures that there
is consistency in the testing process.
Depending on what is being tested, the IS auditor will be required to have appropriate skills
for the task. Lack of the right competencies might impact on the achievement of the testing
objectives.
It has always been a challenge to find IS auditors with the right skills combination. It is
often recommended to use other experts to complement the skills of the IS auditor. Using
an IS audit team would be desirable as it would include auditors with various skills and
also other experts with development skills in the platform being used by the software deve-
lopers. Often it is not easy to find experts with the correct skills because software is some-
times developed for a particular enterprise only.
At the end of the testing process, a number of changes would have been identified and re-
commended. It would be up to the development team to assess how these changes fit into
the new system and whether the project objectives are being met. It is possible that new
changes might create new problems for the development team.
User and System Administration Training
Once the system has been developed and is ready for deployment, the project team might
consider embarking on training users and IT administrators who will use and support the
Search WWH ::




Custom Search