# Information Systems Auditor

*/JobTypes/Information_Systems_Auditor*

## Neighborhood

### Related (signature role)

- [IT Audit and Assurance Firm](/CompanyTypes/IT_Audit_and_Assurance_Firm) — signature role · CompanyTypes

### Related (delivered by)

- [Evaluate data processing applications for institutions under examination to develop recommendations ...](/Tasks/Evaluate_data_processing_applications_for_institutions_under_examination_to_develop_recommendations_...) — delivered by · Tasks
- [Audit information system](/Processes/Audit_information_system) — delivered by · Processes

### Perform

- [Recommend control enhancements](/Tasks/Recommend_control_enhancements) — perform · Tasks
- [Document Audit Findings](/Tasks/Document_Audit_Findings) — perform · Tasks
- [Assess system data integrity](/Tasks/Assess_system_data_integrity) — perform · Tasks
- [Test IT general controls](/Tasks/Test_IT_general_controls) — perform · Tasks
- [Validate Remediation Evidence](/Tasks/Validate_Remediation_Evidence) — perform · Tasks
- [Review existing standards, controls, or equipment used, recommending changes or upgrades as needed.](/Tasks/Review_existing_standards,_controls,_or_equipment_used,_recommending_changes_or_upgrades_as_needed.) — perform · Tasks
- [Plan IT Audit Scope](/Tasks/Plan_IT_Audit_Scope) — perform · Tasks
- [Document Compliance Gaps and Findings](/Tasks/Document_Compliance_Gaps_and_Findings) — perform · Tasks
- [Assess Compliance Against Regulatory Frameworks](/Tasks/Assess_Compliance_Against_Regulatory_Frameworks) — perform · Tasks
- [Evaluate IT risk and control design](/Tasks/Evaluate_IT_risk_and_control_design) — perform · Tasks
- [Examine access, change, and operations controls](/Tasks/Examine_access,_change,_and_operations_controls) — perform · Tasks
- [Present audit results to management and committees](/Tasks/Present_audit_results_to_management_and_committees) — perform · Tasks
- [Recommend remediation and verify closure](/Tasks/Recommend_remediation_and_verify_closure) — perform · Tasks
- [Document audit findings and risks](/Tasks/Document_audit_findings_and_risks) — perform · Tasks
- [Plan information systems audits](/Tasks/Plan_information_systems_audits) — perform · Tasks
- [Evaluate access and change management controls](/Tasks/Evaluate_access_and_change_management_controls) — perform · Tasks
- [Assess system security configurations](/Tasks/Assess_system_security_configurations) — perform · Tasks
- [Test IT general and application controls](/Tasks/Test_IT_general_and_application_controls) — perform · Tasks

### Required knowledge

- [Regulatory and Compliance Requirements](/Knowledge/Regulatory_and_Compliance_Requirements) — requires knowledge · Knowledge
- [Regulatory Compliance](/Knowledge/Regulatory_Compliance) — requires knowledge · Knowledge
- [IT Audit Frameworks](/Knowledge/IT_Audit_Frameworks) — requires knowledge · Knowledge
- [Audit Methodologies](/Knowledge/Audit_Methodologies) — requires knowledge · Knowledge
- [Audit Procedures and Standards](/Knowledge/Audit_Procedures_and_Standards) — requires knowledge · Knowledge
- [IT Audit Standards](/Knowledge/IT_Audit_Standards) — requires knowledge · Knowledge
- [IT General Controls](/Knowledge/IT_General_Controls) — requires knowledge · Knowledge
- [General and application controls](/Knowledge/General_and_application_controls) — requires knowledge · Knowledge
- [IT risk and governance concepts](/Knowledge/IT_risk_and_governance_concepts) — requires knowledge · Knowledge
- [IT Control Frameworks](/Knowledge/IT_Control_Frameworks) — requires knowledge · Knowledge
- [IT Risk Concepts](/Knowledge/IT_Risk_Concepts) — requires knowledge · Knowledge

### Requires ability

- [Written Expression](/Ability/Written_Expression) — requires ability · Ability
- [Attention to detail](/Ability/Attention_to_detail) — requires ability · Ability
- [Deductive reasoning](/Ability/Deductive_reasoning) — requires ability · Ability
- [Problem sensitivity](/Ability/Problem_sensitivity) — requires ability · Ability
- [Selective Attention](/Ability/Selective_Attention) — requires ability · Ability
- [Inductive Reasoning](/Ability/Inductive_Reasoning) — requires ability · Ability

### Required skills

- [Critical Thinking](/Skills/Critical_Thinking) — requires skill · Skills
- [Audit Sampling](/Skills/Audit_Sampling) — requires skill · Skills
- [Evidence Evaluation](/Skills/Evidence_Evaluation) — requires skill · Skills
- [Audit planning and scoping](/Skills/Audit_planning_and_scoping) — requires skill · Skills
- [Evidence documentation](/Skills/Evidence_documentation) — requires skill · Skills
- [Findings communication](/Skills/Findings_communication) — requires skill · Skills
- [IT control testing](/Skills/IT_control_testing) — requires skill · Skills
- [Risk and control evaluation](/Skills/Risk_and_control_evaluation) — requires skill · Skills
- [Audit Documentation](/Skills/Audit_Documentation) — requires skill · Skills
- [Control Testing](/Skills/Control_Testing) — requires skill · Skills
- [Risk Evaluation](/Skills/Risk_Evaluation) — requires skill · Skills

### Type of

- [Information Security Analyst](/Occupations/Information_Security_Analyst) — type of · Occupations
- [Auditors](/Occupations/Auditors) — type of · Occupations
- [Accountants and Auditors](/Occupations/Accountants_and_Auditors) — type of · Occupations

### Uses software

- [Data Analysis Software](/Software/Data_Analysis_Software) — uses software · Software
- [Governance Risk and Compliance Platform](/Software/Governance_Risk_and_Compliance_Platform) — uses software · Software
- [TeamMate](/Software/TeamMate) — uses software · Software
- [ACL Analytics](/Software/ACL_Analytics) — uses software · Software
- [SQL clients](/Software/SQL_clients) — uses software · Software
- [ServiceNow GRC](/Software/ServiceNow_GRC) — uses software · Software
- [Audit Management Software](/Software/Audit_Management_Software) — uses software · Software
- [Data Analytics Software](/Software/Data_Analytics_Software) — uses software · Software
- [Microsoft Excel](/Software/Microsoft_Excel) — uses software · Software

### Engage in

- [Test IT general controls](/Activities/Test_IT_general_controls) — engage in · Activities
- [Evaluate access and change controls](/Activities/Evaluate_access_and_change_controls) — engage in · Activities
- [Document Audit Findings and Exceptions](/Activities/Document_Audit_Findings_and_Exceptions) — engage in · Activities
- [Plan and scope information systems audits](/Activities/Plan_and_scope_information_systems_audits) — engage in · Activities
- [Evaluate access and change management controls](/Activities/Evaluate_access_and_change_management_controls) — engage in · Activities
- [Test IT general and application controls](/Activities/Test_IT_general_and_application_controls) — engage in · Activities

### Problems this exposes

- [segregation-of-duties conflicts span systems with no unified entitlement view](/Problems/segregation-of-duties_conflicts_span_systems_with_no_unified_entitlement_view) — exposes problem · Problems
- [control-testing samples are small and point-in-time, missing drift between audits](/Problems/control-testing_samples_are_small_and_point-in-time,_missing_drift_between_audits) — exposes problem · Problems
- [IT general controls map inconsistently to multiple overlapping frameworks (NIST, ISO, PCI)](/Problems/IT_general_controls_map_inconsistently_to_multiple_overlapping_frameworks_(NIST,_ISO,_PCI)) — exposes problem · Problems
- [remediation tracking of prior-year findings lives in spreadsheets disconnected from the GRC tool](/Problems/remediation_tracking_of_prior-year_findings_lives_in_spreadsheets_disconnected_from_the_GRC_tool) — exposes problem · Problems
- [evidence collection (access lists, change tickets, configs) for SOX/SOC2 is a manual screenshot grind](/Problems/evidence_collection_(access_lists,_change_tickets,_configs)_for_SOX%2FSOC2_is_a_manual_screenshot_grind) — exposes problem · Problems
