Information System (IS) Audit assesses the effectiveness, reliability and security of the information technology systems that support business and banking operations. It examines general IT controls, application controls, data integrity and compliance with relevant security and regulatory standards.
Scope of IS Audit
The review covers:
IT general controls including access management and change management
Application controls over critical systems
Data integrity, backup and recovery procedures
Cybersecurity and network security measures
Compliance with RBI IT and cybersecurity guidelines where applicable
Methodology
A risk-based approach is followed:
Understanding of the IT environment and architecture
Identification of key risks and control objectives
Testing of controls and system configurations
Review of policies, procedures and incident logs
Outcomes
The audit provides an assessment of the control environment around information systems and highlights areas requiring strengthening of IT governance and security.