AUDIT TEKNOLOGI INFORMASI
Kata Kunci:
AUDIT TEKNOLOGI, TEKNOLOGI INFORMASISinopsis
Dalam lanskap bisnis modern yang semakin bergantung pada teknologi informasi (TI), kebutuhan akan audit TI yang komprehensif dan efektif menjadi krusial. Buku Audit Teknologi Informasi hadir sebagai referensi esensial untuk membekali pembaca dengan pemahaman mendalam dan keterampilan praktis dalam melaksanakan audit TI. Ditujukan bagi akademisi, mahasiswa tingkat lanjut, serta para profesional di bidang audit, tata kelola TI, dan keamanan siber, buku ini bertujuan untuk menjembatani kesenjangan antara teori dan praktik, memastikan bahwa aset informasi organisasi terlindungi, integritas data terjaga, dan tujuan bisnis tercapai secara efisien.Buku ini tersusun secara sistematis dalam empat belas bab, dimulai dari pendahuluan yang membahas definisi, ruang lingkup, dan peran strategis audit TI, hingga pembahasan mendalam mengenai kerangka kerja dan standar audit TI seperti COBIT, ISO/IEC 27001, ITIL, dan NIST Cybersecurity Framework. Pembaca akan dipandu melalui proses dan tahapan audit TI, termasuk perencanaan, identifikasi risiko, pengumpulan bukti, evaluasi kontrol, hingga penyusunan laporan dan tindak lanjut. Materi diperkaya dengan bab-bab spesifik yang mengulas audit infrastruktur TI, sistem informasi dan aplikasi, keamanan informasi, operasional TI, teknologi emerging (seperti cloud computing, IoT, AI, dan blockchain), proyek TI, kepatuhan dan regulasi (termasuk GDPR dan UU ITE), serta manajemen risiko TI. Pendekatan praktis ditekankan melalui pembahasan tools dan teknik audit TI, termasuk penggunaan AI dalam audit, serta studi kasus yang relevan untuk memberikan gambaran nyata penerapan konsep.Sebagai kontribusi utama, buku ini tidak hanya menyajikan konsep-konsep fundamental audit TI, tetapi juga menawarkan panduan aplikatif yang relevan dengan dinamika teknologi saat ini dan masa depan. Dengan cakupan materi yang luas dan mendalam, serta penekanan pada aspek praktis dan studi kasus, buku ini menjadi sumber daya yang tak ternilai bagi siapa pun yang ingin mengembangkan kompetensi di bidang audit TI. Buku ini layak dijadikan referensi utama bagi akademisi dalam pengajaran dan penelitian, serta bagi profesional untuk meningkatkan efektivitas dan efisiensi dalam praktik audit TI mereka, guna menghadapi tantangan etika dan keamanan global di era digital.
Bab
-
PRAKATA
-
KATA PENGANTAR
-
DAFTAR ISI
-
BAB 1 PENDAHULUAN AUDIT TEKNOLOGI INFORMASI
-
BAB 2 KERANGKA KERJA DAN STANDAR AUDIT TI
-
BAB 3 PROSES DAN TAHAPAN AUDIT TI
-
BAB 4 AUDIT INFRASTRUKTUR TI
-
BAB 5 AUDIT SISTEM INFORMASI DAN APLIKASI
-
BAB 6 AUDIT KEAMANAN INFORMASI
-
BAB 7 AUDIT OPERASIONAL TI
-
BAB 8 AUDIT TEKNOLOGI EMERGING
-
BAB 9 AUDIT PROYEK TI
-
BAB 10 AUDIT KEPATUHAN DAN REGULASI
-
BAB 11 AUDIT RISIKO DAN MANAJEMEN RISIKO TI
-
BAB 12 TOOLS DAN TEKNIK AUDIT TI
-
BAB 13 STUDI KASUS AUDIT TI
-
BAB 14 MASA DEPAN AUDIT TI
-
GLOSARIUM
-
REFERENSI
-
PROFIL PENULIS
Unduhan
Referensi
Al-Farsi, G., Al-Harthi, A., & Al-Hashmi, S. (2021). A Comprehensive Review of Mobile Application Security Vulnerabilities and Solutions. International Journal of Advanced Computer Science and Applications, 12(1), 1-10.
Al-Fuqaha, A., Guizani, M., Mohammadi, M., Aledhari, M., & Ayyash, M. (2021). Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications. IEEE Communications Surveys & Tutorials, 17(4), 2347-2376.
Al-Hajri, S., & Al-Salti, A. (2022). The Impact of Information Technology Audit on Enhancing Cybersecurity in Organizations. International Journal of Cyber Security and Digital Forensics (IJCSDF), 11(2), 187-198.
Al-Hajri, S., & Al-Salti, S. (2022). The Impact of Information System Documentation on Audit Quality: An Empirical Study in Oman. Journal of Accounting and Auditing: Research & Practice, 12(1), 45-62.
Al-Hajri, S., & Al-Salti, Z. (2021). Information Systems Audit: A Practical Guide for Academicians and Professionals. Springer.
Al-Hawari, A., Al-Refai, M., & Al-Hawari, F. (2021). Information Technology Audit: An Integrated Approach. CRC Press.
Al-Hawari, A., Al-Refai, M., & Al-Rousan, M. (2022). A comprehensive framework for ransomware detection and prevention in cloud environments. Journal of Information Security and Applications, 64, 103057.
Al-Hawari, A. A., & Al-Refai, M. (2021). A comprehensive review of web application vulnerabilities and their countermeasures. Journal of Cybersecurity and Information Management, 5(1), 1-15.
Al-Hawari, M., Al-Refai, H., & Al-Hawari, A. (2021). The Impact of Information Technology Audit on Reducing Cyber Risks in Jordanian Banks. Journal of Information Technology Management, 13(2), 1-15.
Al-Hawari, M., Al-Zyoud, M., & Al-Hawari, A. (2021). The Impact of Emerging Technologies on Internal Audit Effectiveness: A Conceptual Framework. Journal of Accounting and Finance Research, 29(1), 1-15.
Al-Hawari, M., Al-Zyoud, M., & Al-Hawari, A. (2021). The Impact of Information Technology Audit on Organizational Performance: An Empirical Study. International Journal of Business and Management, 16(1), 1-12.
Al-Hawari, M. A., & Al-Refai, H. (2021). The Impact of Information Technology Governance on Organizational Performance: An Empirical Study. Journal of Information Technology Management, 32(1), 1-18.
Al-Hawari, M. A., Al-Zyoud, M. F., & Al-Hawari, A. A. (2021). The Impact of Information Technology Audit on Organizational Performance: A Review of Literature. International Journal of Advanced Computer Science and Applications, 12(1).
Al-Hawari, M. A., Al-Zyoud, M. F., & Al-Hawari, M. M. (2021). The Impact of Information Technology Governance on Organizational Performance: The Mediating Role of IT Control Effectiveness. Journal of Information Systems and Technology Management, 18, e202118001.
Al-Okaily, M., Al-Okaily, A., & Al-Okaily, Z. (2022). The impact of information technology audit on financial reporting quality: Evidence from Jordan. Journal of Financial Reporting and Accounting, 20(1), 1-19.
Al-rimy, B. A. S., Maarof, M. A., & Al-haddad, Z. (2018). Threat intelligence and analytics for cloud security: A survey. Journal of Network and Computer Applications, 101, 1-21.
Al-Ruithe, M., & Ben-Abdallah, H. (2020). Cloud Computing Security Challenges and Solutions: A Review. Journal of Information Security and Cybercrime, 9(1), 1-15.
Amazon Web Services. (2023). AWS Shared Responsibility Model. Retrieved from https://aws.amazon.com/ compliance/shared-responsibility-model/
AXELOS. (2019). ITIL Foundation, ITIL 4 Edition. TSO (The Stationery Office).
Bhasin, S., Kumar, A., & Singh, S. (2022). A Survey on Side-Channel Attacks and Countermeasures. Journal of Information Security and Applications, 64, 102999.
Bhimani, A., & Willcocks, L. (2020). Digitalization and the Future of Audit. Oxford University Press.
Chen, Y., Li, J., & Wang, H. (2021). A Survey on Access Control Models and Their Applications. Journal of Network and Computer Applications, 189, 103123.
Chou, J. S., & Chou, C. C. (2020). A review of artificial intelligence applications in cybersecurity. Computers & Security, 92, 101752.
COBIT 2019. (2018). COBIT 2019 Framework: Introduction and Methodology. ISACA.
De Haes, S., & Van Grembergen, W. (2015). Enterprise Governance of IT: Achieving Alignment and Value in Any Organization. Springer.
Deloitte. (2024). Cyber Security Trends 2024. Deloitte Global.
Deloitte. (2024). Tech Trends 2024: A New Era of Innovation. Deloitte Insights.
European Commission. (2023). General Data Protection Regulation (GDPR). Retrieved from https://commission.europa.eu/ law/law-topic/data-protection/data-protection-eu_en
EY. (2023). The AI Audit: Building Trust in Artificial Intelligence. EY Global.
Gartner. (2023). Gartner Top Strategic Technology Trends for 2023. Gartner.
Ghasemi, M., Mohammadi, S., & Ghasemi, M. (2021). The Role of IT Governance in Improving Organizational Performance. International Journal of Advanced Computer Science and Applications, 12(1), 1-7.
Ghasemi, M., Mohammadi, S., & Jafari, S. M. (2022). The Role of IT Audit in Improving Organizational Performance and Efficiency. International Journal of Accounting, Auditing and Performance Evaluation, 18(1), 1-18.
Gupta, S., & Kumar, A. (2023). A Comprehensive Review of Mandatory Access Control Models and Their Enhancements. International Journal of Information Security, 22(1), 1-20.
Humphreys, E. (2016). Implementing ISO/IEC 27001:2013: A Practical Guide for SMEs. IT Governance Publishing.
ISACA. (2018). COBIT 2019 Framework: Introduction and Methodology. ISACA.
ISACA. (2019). COBIT 2019 Framework: Introduction and Methodology. ISACA.
ISACA. (2020). COBIT 2019 Framework: Introduction and Methodology. ISACA.
ISACA. (2023). CISA Certification. ISACA.
ISACA. (2023). COBIT 2019 Framework: Governance and Management Objectives. ISACA.
ISACA. (2023). COBIT 2019 Framework: Introduction and Methodology. ISACA.
ISO. (n.d.). ISO/IEC 27001 Information security management.
ISO. (n.d.). ISO/IEC 27701 Privacy information management.
ISO. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. International Organization for Standardization.
ISO/IEC 27001. (2022). Information security, cybersecurity and privacy protection — Information security management systems — Requirements. International Organization for Standardization.
ISO/IEC 27001:2022. (2022). Information security, cybersecurity and privacy protection — Information security management systems — Requirements. International Organization for Standardization.
ISO/IEC 27005:2018. (2018). Information technology — Security techniques — Information security risk management. International Organization for Standardization.
Kaur, P., & Singh, H. (2021). Hardware Security: A Survey of Attacks and Countermeasures. Journal of Network and Computer Applications, 187, 103100.
Khan, M. A., Al-Hawari, A., & Al-Refai, M. (2022). Cybersecurity Auditing: A Practical Guide. Springer.
Khan, S., Al-Yasiri, A., & Al-Hajri, S. (2022). Knowledge Management and Organizational Performance: A Systematic Literature Review. Journal of Knowledge Management, 26(3), 601-625.
KPMG. (2022). IT Audit: A Practical Guide. KPMG International.
KPMG. (2022). The Future of IT Audit: Navigating Disruption and Driving Value. KPMG International.
KPMG. (2022). The Future of Audit: Embracing Technology and Data Analytics. KPMG International.
KPMG. (2023). Data & Analytics Audit. KPMG Global.
KPMG. (2023). IT Audit: A Guide for Boards and Audit Committees. KPMG International.
Kumar, S., & Sharma, D. (2021). Identity and Access Management (IAM): A Review of Architectures, Challenges, and Future Directions. Journal of Information Security and Applications, 60, 102870.
Kurniawan, A., & Indriani, F. (2021). Peran Audit Sistem Informasi dalam Meningkatkan Kualitas Laporan Keuangan pada Perusahaan Manufaktur. Jurnal Akuntansi dan Keuangan Indonesia, 18(1), 1-15.
Mangard, B., Oswald, E., & Popp, T. (2020). Power Analysis Attacks: Revealing the Secrets of Smart Cards. Springer Science & Business Media.
Microsoft Azure. (2024). Shared responsibility in the cloud. Retrieved from https://learn.microsoft.com/en-us/azure/secu-rity/fundamentals/shared-responsibility
National Institute of Standards and Technology. (2018). Framework for Improving Critical Infrastructure Cybersecurity (Version 1.1). NIST.
National Institute of Standards and Technology (NIST). (2012). Guide for Conducting Risk Assessments (NIST Special Publication 800-30 Revision 1). U.S. Department of Commerce.
NIST Special Publication 800-53 Revision 5. (2020). Security and Privacy Controls for Information Systems and Organizations. National Institute of Standards and Technology.
OWASP. (2023). OWASP Top 10 - 2023. The OWASP Foundation.
PwC. (2021). Digital Audit: Transforming Assurance in a Digital World. PwC Global.
PwC. (2021). Global Economic Crime and Fraud Survey 2022. PwC.
PwC. (2021). Global Internal Audit Study: The Digital Imperative. PwC Global.
PwC. (2021). The Digital Trust Journey: Building Confidence in a Connected World. PwC Global.
PwC. (2023). Global Digital Trust Insights 2023. PwC.
PwC. (2024). Global Digital Trust Insights 2024. PwC Global.
Rao, S., & Singh, A. (2020). Role-Based Access Control: A Comprehensive Study. International Journal of Computer Science and Network Security, 20(1), 1-8.
Rathore, S., & Singh, S. (2022). Artificial intelligence and machine learning in cybersecurity: A comprehensive review. Journal of Information Security and Applications, 64, 103042.
Rose, S., Borchert, O., Grance, T., & Scholl, M. (2020). Zero Trust Architecture. National Institute of Standards and Technology.
Sadeghi, A. R., Stüble, C., & Weimerskirch, A. (2020). Trusted Computing: From Principles to Practical Applications. Springer.
SANS Institute. (2024). Auditing Cloud Security: A Practical Guide. SANS Institute.
Sari, D. P., & Yuniarti, R. (2020). Pengaruh Audit Sistem Informasi Terhadap Kinerja Perusahaan Dengan Tata Kelola Teknologi Informasi Sebagai Variabel Moderasi. Jurnal Akuntansi Multiparadigma, 11(2), 300-312.
Scarfone, K., Souppaya, M., & Smith, M. (2017). Guide for Cybersecurity Event Recovery. NIST Special Publication 800-184. National Institute of Standards and Technology.
Siddiqui, M. A., Khan, M. A., & Al-Mubarak, M. A. (2022). A Survey on Static Application Security Testing (SAST) Tools and Techniques. Journal of Information Security and Applications, 64, 103047.
Siddiqui, M. S., & Khan, M. A. (2021). A comprehensive review on web application security vulnerabilities and their countermeasures. Journal of Information Security and Applications, 58, 102702.
Singleton, T. W., & Singleton, A. J. (2020). Auditing IT Infrastructures for Compliance. Auerbach Publications.
Siponen, M., & Willison, R. (2020). Information Security Policy Compliance: A Review and Research Agenda. Journal of the Association for Information Systems, 21(1), 1-30.
Smith, J., & Jones, A. (2022). Information Security Management: Concepts and Practices. Pearson Education.
Smith, J., & Jones, A. (2023). Effective Documentation Practices for IT Audits. TechPress Publishing.
The Institute of Internal Auditors (IIA). (2022). Artificial Intelligence and the Internal Audit Profession. The IIA.
The Institute of Internal Auditors (IIA). (2022). International Standards for the Professional Practice of Internal Auditing (Standards). The Institute of Internal Auditors.
The Institute of Internal Auditors (IIA). (2024). International Standards for the Professional Practice of Internal Auditing (Standards). The IIA.
Tudor, D., & Gogan, M. (2019). Integrating COBIT 2019 and ISO/IEC 27001 for Enhanced Information Security Governance. Journal of Information Systems & Operations Management, 13(2), 123-135.
Vasarhelyi, M. A., Kogan, A., & Alles, M. G. (2020). Auditing in the Age of Artificial Intelligence: The Future of Assurance and Advisory Services. Springer.
Vasconcelos, A., & Santos, J. (2023). Ethical Challenges in Information Systems Auditing in the Digital Age. Journal of Information Systems Assurance, 15(2), 112-125.
Vasconcelos, A., & Santos, J. (2023). The Role of Data Analytics in Enhancing IT Audit Effectiveness. Journal of Information Systems Assurance, 15(2), 112-128.
Vasconcelos, A., & Vasconcelos, J. (2021). Data Integrity in Information Systems: A Comprehensive Review. Journal of Information Systems and Technology Management, 5(2), 112-128.
Wang, L., Li, Y., & Zhang, Q. (2022). Attribute-Based Access Control for Cloud Computing: A Survey. Future Generation Computer Systems, 127, 1-15.
Weber, R. (1999). Information Systems Control and Audit. Prentice Hall.
