Verified Document

Business Continuity Plan Audits Research Paper

Change Management Audit While technology and information systems are there in order to make management much more efficient, these systems may also expose an organizations to various risks which might often be serious in nature. These risks increase when changes are brought about in an existing system. In order to minimize such risks it is important that organizations have a change management plan, which is duly audited and tested for compliance before change is implemented.

With the advent and progress in the field of Information Technology, the corporate sector across the globe has increased the incorporation of technology in business practices greatly over the years. Besides assisting in communication and production related tasks, Management Information Systems and knowledge managements are important and integral part of organizational management that play a vital role in ensuring efficiency and quality management. That said, the rapid progressions in technology mean that the preceding technologies become obsolete over a period of time and therefore organizations should be ready to adapt to change. However, there is a room for possible risk factors associated with implementation for such changes and therefore it is important that organizations have a change management plan and change management auditing system in place.

In simple terms, a change management auditing is concerned with minimizing or preventing risks associated with bringing about changes in...

The auditing revolves around assessing risks such as security violation and leakage of information to unauthorized parties, presence of errors or malware in the system, efficiency of information management, designation of duties and authorities and protection of system against third party penetration.
Scope of Audit

The scope of change management audits cover analysis, monitoring and reviewing of procedures within an organization pertaining to change management. It reviews the policies and mechanisms that an organization has in place for testing, monitoring, authorizing, initiation and modification of application and information and recovery and backups of information. Moreover, it also reviews the security systems that an organization has in place for the protection of the information system (Kanter & Pitman, 1995). Audit timelines are important to make sure that the deliverables and set objectives are met as per requirement and in time, and all security procedures and change management plans pass the required standard. Failure to do so might increase the risks such as production of low quality service, third party access to sensitive data or malware or harmful codes being distributed to unauthorized parties.

Risks and Risk Management Strategies

As stated earlier, incorporation of change increases exposure to various risks which can often be sensitive in nature. It could often…

Sources used in this document:
References

Beasley, M.S., Branson, B.C., & Hancock, B.V. (2008). Rising Expectations: Audit Committee Oversight of Enterprise Risk Management. Journal of Accountancy, 205(4), 44+.

Kanter, H., & Pitman, M.K. (1995). A New Approach to Audit Risk Assessment. The Government Accountants Journal, 44(2), 49+.
Cite this Document:
Copy Bibliography Citation

Related Documents

Business Continuity Plan Testing and Auditing
Words: 707 Length: 2 Document Type: Research Paper

Business Auditing and Testing Business Auditing Testing and auditing is an essential of a business plan. Business plan is a blueprint followed in the successful launch or re launch an operation. It conveys the business prospects, growth and describes the product market. Business and auditing plan helps in preparedness of emergencies as a safety precaution for the continuity of a business. This planning ensures that services of a business continue when there

Business Workplace Continuity and Contingency
Words: 3113 Length: 10 Document Type: Thesis

Threats due to weather include floods, earthquakes, hurricanes, tornadoes and blizzards. Planning for weather events should be very realistic in nature. Major weather events usually occur in 25, 50 and 100-year cycles. Disease outbreaks are also a big threat. A potential flu pandemic could be detrimental to many businesses. For example, the bird flu pandemic scenarios that are floating around are being modeled on the Spanish flu pandemic of

It Infrastructure to the Day-To-Day
Words: 4621 Length: 16 Document Type: A-Level Coursework

Table 1 Since the manufacturing activities at JMC should be brought back online in a period of 12 hours, it is evident from the above table that the classification of the disaster recovery plan is mission critical.The whole focus of Disaster recovery Plan is to try and restore the operation of various system components that are termed as mission critical. The process of restoring the system does not have to be

Disaster Recovery Refers to the IT Components
Words: 1705 Length: 6 Document Type: Essay

Disaster recovery refers to the IT components of the business that, in times of a disaster, need to be safeguarded so that business can be continued. Disaster recovery is more a preventive plan set in motion prior to the organization and implementation of the business than a series of actions that are followed once the disaster hits the company. Given that most companies are, to a large extent and in

Auditing the Role of Databases
Words: 5292 Length: 16 Document Type: Essay

In other words, if the financial difficulties they encounter are the fault of the auditing firm, they will have protection from any legal ramifications they may have encountered from faulty accounting or auditing measures. Preventive measures are also part of the internal controls of the auditing firm itself, so that each person who works with that firm knows the measures that are to be taken to make sure auditing

Disaster Recovery Economic Impact of
Words: 4492 Length: 15 Document Type: Thesis

There is a modern emphasis, which has resulted from the experience of the economic impact of disaster, on a more extensive and 'distributed' mode of thinking about disaster recovery. This is an important factor that should be stressed as it has direct implications in terms of the economic aspects of disaster recovery planning in an increasingly networked and technologized contemporary working environment. This aspect is cogently expressed in a

Sign Up for Unlimited Study Help

Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.

Get Started Now