Continental Audit Services :: Database Audits, Mainframe Audits, Z/0s audit, Unix Audit, Windows Audit, Db2 Audit, Oracle Audit, As/400 Audit, system I Audit, IT Audit
Proud Members
The Institute of Internal Auditors
Information Systems Audit and Control Association
International Information Systems Security Certification Consortium
Certified Auditors Dedicated
to Secure Technology

// Risk and Control
// Best practices
// Core systems

IT Risk Assessment

IT Risk Assessment consists of an analysis of the probability and impact from different negative scenarios that may affect an organization’s IT environment. Risks are reduced through controls that make the occurrence of a negative event less likely.

A risk assessment is especially valuable to develop intelligent audit plans, detailed schedules and work programs. Also important is the value added through an efficient allocation of IT resources.

Continental’s risk approach is based on industry best practices from the US National Institute of Standards and Technology (NIST) and the Institute of Internal Auditors (IIA). We also use Federal Financial Institutions Examination Council (FFIEC) guidelines.

Continental auditors start with a survey of the technology that exists in an organization (systems, applications, networks, databases, facilities, key personnel) and identify specific threats and vulnerabilities. We use classic risk calculations to measure inherent and residual risks taking into account existing security controls. Where gaps in controls are identified, remedial action is recommended to the appropriate management.

Some of the areas that we cover in our IT risk assessments are displayed to the right. Please contact Continental Audit Services to request a proposal tailored to meet your specific requirements.
Contact
  • IT system identification and inventory
  • Business and IT process analysis
  • Threat identification (security, availability, performance, compliance)
  • Vulnerability assessment
  • Criticality assessment
  • Control design analysis
  • Control effectiveness analysis
  • Likelihood / probability estimation
  • Impact analysis
  • Risk matrix calculations
  • COBiT Maturity Model Assessment
  • Inherent risk
  • Residual risk
  • Control gap analysis
  • Risk mitigation
  • Results documentation
 
Continental Audit Blog
Recent Articles Published