IT Standards, Policies, and Procedures
EGIT is implemented through a specific set of standards, policies, and procedures. Let’s understand how each one of these operates.
Policies
A policy is a set of ideas or strategies that are used as a basis for decision-making. They are high-level statements of direction issued by management:
- There can be multiple policies at the corporate level as well as the department level. It should be ensured that department-wise, policies are consistent and aligned with corporate-level policies.
- Policies should be reviewed at periodic intervals to incorporate new processes, technology, and regulatory requirements. An appropriate version history should also be maintained. An IS auditor should check for currency.
- IS auditors should use policies to evaluate and verify compliance.
- An IS auditor should also consider the applicability of policies to third-party vendors and service providers and their adherence to said policies...