Let's have a look at quality assurance and quality management processes in IT in detail. According to CISA Review Manual (CRM), the IS auditor must understand the concepts, processes, roles, and responsibilities of quality assurance and quality management within the company.
Quality assurance
Quality assurance (QA) is a process that aims to provide adequate confidence that an item or product conforms to the requirements developed. QA staff verify that changes to the system are approved, checked, and implemented in a controlled manner. Quality control (QC) is a method for performing tests or reviews to verify that the product is free of defects and meets the user's requirements.
Generally, QA personnel perform two distinct tasks:
- QA: Provides assurance that an object or product meets the requirements as lain down
- QC: Observation strategies or exercises to ensure that quality-related criteria are fulfilled
The following table differentiates...