Automated machine compliance auditor (AMCA)

Added Title

AMCA

Date of Publication

12-10-2018

Document Type

Master's Thesis

Degree Name

Master of Science in Information Technology

Subject Categories

Computer Sciences

College

College of Computer Studies

Department/Unit

Information Technology

Thesis Adviser

Danny Cheng

Abstract/Summary

The process of examination and evaluation of an organization’s information technology infrastructure, operations, controls and policies is called an IT Audit. This process allows an organization to evaluate their current standing in terms of protection and integrity, availability and confidentiality maintenance of an IT asset. On the other hand, a subtype of IT Audit is called a compliance audit. Compliance audit is the term used by security professionals and auditors as the process of evaluating if a given instance correctly follows the points specified in a certain compliance document. Majority of the compliance audit processes today are performed manually. These manual processes involve the manual mapping of an audit scan result to a compliance requirement or the manual identification of all IT asset and their current controls. As the number of IT assets to be audited increases, the more challenging it becomes in terms of compliance monitoring. To solve this problem, the study was able to develop compliance audit tool that enabled auditors of an organization to automatically link an audit scan result of an IT asset to a specific requirement of a compliance document for continuous compliance monitoring. The series of tests indicated on this study proved that the tool is capable of linking an audit scan result to a compliance requirement, creation of customized scans, automated configuration scanning of remote IT assets and has been validated by industry experts who participated on the study.

Abstract Format

html

Language

English

Format

Electronic

Accession Number

CDTG007189

Physical Description

1 computer optical disc, 4 3/4 in.

Keywords

Information technology—Auditing; Compliance auditing

Embargo Period

5-30-2024

This document is currently not available here.

Share

COinS