SlideShare a Scribd company logo
SCOPE OF WORK
1 IT DUE DILIGENCE
A) Overall Assessment of the IT Environment
1. High level review of the IS/IT environment, the internal procedures and internal
infrastructure;
2. Inquiries with responsible IT personnel and the company’s management;
3. High level review of internal guidelines, policies and procedures;
4. Observation of the Company’s premises and data center; and
5. Identification of the IT issues and classification of their potential financial impact.
B) Strategy support
6. High level review of:
o IS/IT strategy;
o IT budgets and their plausibility (OPEX, CAPEX);
o Planned and recently completed changes/upgrades; and
o IS/IT contracts.
7. Assessment of the IT services – internal and external.
C) IT operations
8. Understanding of the business operations support by the IT function;
9. Evaluation of the scope and adequacy of the IT support;
10. Understanding of the IT systems;
11. System management and control;
12. Internal and external SLAs; and
13. Development, testing and release management.
D) IT assets
14. High level review of:
o Hardware sufficiency (capability to support business)and monitoring;
o Hardware cost and aging;
o Software licenses and related costs; and
o Network infrastructure – network diagrams.
E) System and data security
15. High level review of:
o Internal policies, procedures and standards in the systemand data security area;
o Security administration and monitoring;
o System security (application, database,operating systemand network level);
o Data protection standards; and
o User management standards.
16. Identification of the key IT security issues and classification of their potential impact.
F) Business continuity
17. High level review of:
o Business Continuity Plans;
o Disaster Recovery Plans;
o Backup management
o Data centersecurity; and
o Data centercapabilities.
18. Evaluation of the Disaster recovery capabilities.
G) IT HR issues
19. Evaluation of the Company’s IT organization chart;
20. Review of the job descriptions and employment contracts of the IT staff; and
21. Analysis of IT personnel expenses and training costs.
H) IT audits
22. Review of the IS/IT audit reports (internal and external);
23. Review of the reports from security assessments;and
24. Identification of the key IT issues and classification of their potential impact.

More Related Content

PDF
IT General Controls Presentation at IIA Vadodara Audit Club
PPT
IT System & Security Audit
PPT
Security audit
PPTX
ITGC audit of ERPs
PPTX
Information System Architecture and Audit Control Lecture 1
PPT
The Importance of Security within the Computer Environment
PPTX
Auditing SOX ITGC Compliance
IT General Controls Presentation at IIA Vadodara Audit Club
IT System & Security Audit
Security audit
ITGC audit of ERPs
Information System Architecture and Audit Control Lecture 1
The Importance of Security within the Computer Environment
Auditing SOX ITGC Compliance

What's hot (20)

PPT
Introduction to it auditing
PPTX
PPTX
It audit methodologies
PPT
Rothke Patchlink
PPTX
IT General Controls
PDF
It Security Audit Process
PPT
5.4 it security audit (mauritius)
PPT
3c 2 Information Systems Audit
PPT
Information System Architecture and Audit Control Lecture 2
PPTX
03.1 general control
PPT
IT Audit methodologies
PPT
Security Audit Best-Practices
PDF
AReNA - Debate Is Machine Learning Mature Enough
PDF
Steps in it audit
PPTX
CIE AS Level Applied ICT Unit 4 - Systems Life Cycle
PPTX
Full Cybersecurity Regulations Overview for DoD Prime and Subcontractors
PPTX
Security
PPTX
Security Audit Information – Physical
PPTX
Auditing information System
Introduction to it auditing
It audit methodologies
Rothke Patchlink
IT General Controls
It Security Audit Process
5.4 it security audit (mauritius)
3c 2 Information Systems Audit
Information System Architecture and Audit Control Lecture 2
03.1 general control
IT Audit methodologies
Security Audit Best-Practices
AReNA - Debate Is Machine Learning Mature Enough
Steps in it audit
CIE AS Level Applied ICT Unit 4 - Systems Life Cycle
Full Cybersecurity Regulations Overview for DoD Prime and Subcontractors
Security
Security Audit Information – Physical
Auditing information System
Ad

Viewers also liked (11)

PDF
SCOPE OF WORK
PDF
Feasibility Study on the Use of Mobile Positioning Data in Tourism Statistics...
PDF
Tourism business planning
PPT
Scope of work
PPTX
Eco tourism project paper
PDF
Feasibility study for Tourist Destination and Attraction
PPTX
Car care project feasibility study
PPTX
A Project Feasibility Study for the Establishment of E&J Farms
DOCX
Feasibility Study (Water Refilling Station)
PPTX
Tourism Planning
PPTX
Feasibility report -basic concepts with example
SCOPE OF WORK
Feasibility Study on the Use of Mobile Positioning Data in Tourism Statistics...
Tourism business planning
Scope of work
Eco tourism project paper
Feasibility study for Tourist Destination and Attraction
Car care project feasibility study
A Project Feasibility Study for the Establishment of E&J Farms
Feasibility Study (Water Refilling Station)
Tourism Planning
Feasibility report -basic concepts with example
Ad

Similar to Scope of work IT DD (20)

PDF
Patina Technology Assessment
PDF
Patina Technology Assessment
PPTX
What is technology due diligence and why is it important © dr pete technology...
PPTX
Utf8''it organizational planning report
PDF
Cobit as IT Management Best Practice Framework
PPTX
04-Business-Vision-Executive-Communication-Template.pptx
PPTX
IT Governance for Board Members
PPT
Formal Information Technology in a Small, Growing Company
PDF
IT & the Auditor
DOCX
WLS Services Brochure March 2013
PDF
20CS024 Ethics in Information Technology
PPTX
Frameworks For Predictability
PPTX
IT Capabilty Assessment 150713
PPTX
CISA Training - Chapter 2 - 2016
PPT
Data Protection Governance IT
PPTX
Overview-of-an-IT-Audit-Lesson-1.pptx
PDF
Auditing Systems Development
DOCX
C09 07222011 101525 Page 88IT leader who had just been.docx
PDF
Understanding co bit 4.1
DOCX
Running head AUDITING INFORMATION SYSTEMS PROCESS .docx
Patina Technology Assessment
Patina Technology Assessment
What is technology due diligence and why is it important © dr pete technology...
Utf8''it organizational planning report
Cobit as IT Management Best Practice Framework
04-Business-Vision-Executive-Communication-Template.pptx
IT Governance for Board Members
Formal Information Technology in a Small, Growing Company
IT & the Auditor
WLS Services Brochure March 2013
20CS024 Ethics in Information Technology
Frameworks For Predictability
IT Capabilty Assessment 150713
CISA Training - Chapter 2 - 2016
Data Protection Governance IT
Overview-of-an-IT-Audit-Lesson-1.pptx
Auditing Systems Development
C09 07222011 101525 Page 88IT leader who had just been.docx
Understanding co bit 4.1
Running head AUDITING INFORMATION SYSTEMS PROCESS .docx

More from Ivan Piskunov (10)

PDF
Электронная подпись и счет-фактуры в бухгалтерском учете
PDF
Особенности проведения аудита безопасности корпоративной IT-инфраструктуры_PH...
PDF
Человеческий фактор [без]опасного интернета
PPTX
Как сэкономить, вложив в информационную безопасность?
PDF
Аудит ИБ как инструмент повышения эффективности вашего бизнеса
PPTX
Анти-фрод системы: правовые и технические аспекты, перспективы применения и ...
PPTX
Современные технологии и инструменты анализа вредоносного ПО_PHDays_2017_Pisk...
DOCX
Вопросы для интервью ISO 27001
PDF
ISO 27001 (v2013) Checklist
DOCX
Scope of work IT DD
Электронная подпись и счет-фактуры в бухгалтерском учете
Особенности проведения аудита безопасности корпоративной IT-инфраструктуры_PH...
Человеческий фактор [без]опасного интернета
Как сэкономить, вложив в информационную безопасность?
Аудит ИБ как инструмент повышения эффективности вашего бизнеса
Анти-фрод системы: правовые и технические аспекты, перспективы применения и ...
Современные технологии и инструменты анализа вредоносного ПО_PHDays_2017_Pisk...
Вопросы для интервью ISO 27001
ISO 27001 (v2013) Checklist
Scope of work IT DD

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Spectroscopy.pptx food analysis technology
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Encapsulation theory and applications.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Electronic commerce courselecture one. Pdf
PDF
cuic standard and advanced reporting.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Spectroscopy.pptx food analysis technology
Dropbox Q2 2025 Financial Results & Investor Presentation
Encapsulation theory and applications.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Review of recent advances in non-invasive hemoglobin estimation
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Electronic commerce courselecture one. Pdf
cuic standard and advanced reporting.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
MYSQL Presentation for SQL database connectivity
Network Security Unit 5.pdf for BCA BBA.
Encapsulation_ Review paper, used for researhc scholars
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Per capita expenditure prediction using model stacking based on satellite ima...

Scope of work IT DD

  • 1. SCOPE OF WORK 1 IT DUE DILIGENCE A) Overall Assessment of the IT Environment 1. High level review of the IS/IT environment, the internal procedures and internal infrastructure; 2. Inquiries with responsible IT personnel and the company’s management; 3. High level review of internal guidelines, policies and procedures; 4. Observation of the Company’s premises and data center; and 5. Identification of the IT issues and classification of their potential financial impact. B) Strategy support 6. High level review of: o IS/IT strategy; o IT budgets and their plausibility (OPEX, CAPEX); o Planned and recently completed changes/upgrades; and o IS/IT contracts. 7. Assessment of the IT services – internal and external. C) IT operations 8. Understanding of the business operations support by the IT function; 9. Evaluation of the scope and adequacy of the IT support; 10. Understanding of the IT systems; 11. System management and control; 12. Internal and external SLAs; and 13. Development, testing and release management. D) IT assets 14. High level review of: o Hardware sufficiency (capability to support business)and monitoring; o Hardware cost and aging; o Software licenses and related costs; and o Network infrastructure – network diagrams. E) System and data security 15. High level review of: o Internal policies, procedures and standards in the systemand data security area; o Security administration and monitoring; o System security (application, database,operating systemand network level); o Data protection standards; and o User management standards. 16. Identification of the key IT security issues and classification of their potential impact. F) Business continuity 17. High level review of: o Business Continuity Plans; o Disaster Recovery Plans; o Backup management o Data centersecurity; and o Data centercapabilities.
  • 2. 18. Evaluation of the Disaster recovery capabilities. G) IT HR issues 19. Evaluation of the Company’s IT organization chart; 20. Review of the job descriptions and employment contracts of the IT staff; and 21. Analysis of IT personnel expenses and training costs. H) IT audits 22. Review of the IS/IT audit reports (internal and external); 23. Review of the reports from security assessments;and 24. Identification of the key IT issues and classification of their potential impact.