Reader small image

You're reading from  CISA – Certified Information Systems Auditor Study Guide - Second Edition

Product typeBook
Published inJun 2023
PublisherPackt
ISBN-139781803248158
Edition2nd Edition
Right arrow
Author (1)
Hemang Doshi
Hemang Doshi
author image
Hemang Doshi

Hemang Doshi has more than 15 years of experience in the field of system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management. He has authored several books for certification such as CISA, CRISC, CISM, DISA, and enterprise risk management.
Read more about Hemang Doshi

Right arrow

Information Systems Implementation

It is very important for an information systems auditor to understand the implementation process of information systems. They need to determine, evaluate, and address various risks associated with the implementation process. Information systems implementation is the process of ensuring that a system is operational. It involves either the creation of a new system from scratch or the migration of an old system to a new one.

The following topics will be covered in this chapter:

  • Testing methodology
  • System migration
  • Post-implementation review

By the end of the chapter, you, as an IS auditor, will have a firm understanding of the core concepts of information systems implementation.

Testing Methodology

Testing is one of the critical elements of the System Development Life Cycle (SDLC). The objective of testing is to ensure that the system is capable of fulfilling its intended objective. For the CISA exam, you need to understand the following testing methodologies:

  • Unit testing
  • Integration testing
  • System testing:
    • Functionality tests
    • Recoverability tests
    • Security tests
    • Load tests
    • Volume tests
    • Stress tests
  • Performance testing
  • Final acceptance testing:
    • Quality Assurance Test (QAT)
    • User Acceptance Test (UAT)
  • Regression testing
  • Sociability testing
  • Pilot testing
  • Parallel testing
  • White box testing
  • Black box testing
  • Alpha testing
  • Beta testing

Unit Testing

The following are some of the important aspects of unit tests:

  • Unit tests include tests of each separate program or module.
  • Testing is generally conducted by the developers themselves. It is conducted as and when a program or module is ready, and it...

System Migration

System migration is the process of transferring IT resources (mostly data) to a new hardware or software platform with the purpose of gaining better business value.

IS auditors should ensure the following for efficient, effective, and accurate system and data migration:

  • Processes should be in place to preserve the format, coding, structure, and integrity of the data to be migrated.
  • Processes should be in place to test the migrated data for its integrity and completeness.
  • Data conversion processes must have audit trails and logs to verify the accuracy and completeness of the converted data.

The migration process should ensure the following:

  • There is no disruption of routine operations.
  • There is appropriate security control over data, ensuring confidentiality, integrity, and availability.

The migration process should also ensure the availability of fall-back arrangements. That is, tools and applications should be available...

Post-Implementation Review

The post-implementation review is the process of determining and evaluating the performance of the system against the requirements and objectives defined in the business case. The post-implementation review is conducted once the project is implemented and completed. These are the objectives of conducting a post-implementation review:

  • To determine the extent to which a project met its objectives and addressed the originally defined requirements
  • To determine the cost-benefit analysis and return on investment
  • To determine the lessons learned from the project to improve future projects

The project development team and business users should jointly conduct a post-implementation review. From the IS audit perspective, the post-implementation review is conducted to determine the adequacy and effectiveness of the system. The IS auditor’s prime focus should be to determine the controls built into the new system.

Key Aspects from the...

Summary

In this chapter, you understood various testing methodologies, different approaches to system migration and cutover techniques, and the objectives of post-implementation reviews. You also learned how to conduct post-implementation reviews of systems to determine whether project deliverables, controls, and requirements have been met.

The following are some important topics covered in this chapter:

  • Unit tests include tests of each separate program or module. Testing is generally conducted by the developers themselves. They are conducted as and when a program or module is ready, and it is not necessary to wait until the entire system is completed. Unit testing is done through a white box approach wherein the internal program logic is tested.
  • System migration is the process of transferring IT resources (mostly data) to a new hardware or software platform with the objective of gaining better business value.
  • Changeover is the process of shifting to a new system...

Chapter Review Questions

Before you proceed to Chapter 7, Information Systems Operations, it is recommended that you solve the practice questions from this chapter first. These chapter review questions have been carefully crafted to reinforce the knowledge you have gained throughout this chapter. By engaging with these questions, you will solidify your understanding of key topics, identify areas that require further study, and build your confidence before moving on to new concepts in the next chapter.

Note

A few of the questions may not be directly related to the topics in the chapter. They aim to test your general understanding of information systems concepts instead.

The following image shows an example of the practice questions interface.

Figure 6.4: CISA practice questions interface

Figure 6.4: CISA practice questions interface

To access the end-of-chapter questions from this chapter, follow these steps:

  1. Open your web browser and go to https://packt.link/3zWZj. You will see the...
lock icon
The rest of the chapter is locked
You have been reading a chapter from
CISA – Certified Information Systems Auditor Study Guide - Second Edition
Published in: Jun 2023Publisher: PacktISBN-13: 9781803248158
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Author (1)

author image
Hemang Doshi

Hemang Doshi has more than 15 years of experience in the field of system audit, IT risk and compliance, internal audit, risk management, information security audit, third-party risk management, and operational risk management. He has authored several books for certification such as CISA, CRISC, CISM, DISA, and enterprise risk management.
Read more about Hemang Doshi