1Audit fundamentals & framework
- 1.1Purpose and framework of systems auditing
Covers how a systems audit evaluates an information system's reliability, safety, efficiency, effectiveness, and compliance from an independent position and makes recommendations for improvement; the difference between an internal audit and an external audit; and the judgment skill of working backward from the audit objective (what one wants to assure) to the audit perspective to apply.
- 1.2System Audit Standards and System Management Standards
Covers the difference in role between the Ministry of Economy, Trade and Industry's System Audit Standards (the auditor's code of conduct: general standards, execution standards, reporting standards) and its System Management Standards (the ideal state of information-system management on the audited side), and how to use each as the auditor's yardstick.
- 1.3Auditor independence, professional ethics, and objectivity
Covers the difference between the independence in mind (an objective, fair, unbiased attitude) and the independence in appearance (being seen as independent by a third party) that a systems auditor must possess; why someone who was personally involved in the audited work lacks independence; and the judgment skill of spotting situations that impair independence while maintaining objectivity, professional ethics, and due professional care.
- 1.4Assurance-type and advisory-type audits
Covers the differences in objective, deliverable, and independence requirements between an assurance-type audit that expresses a degree of assurance, and an advisory-type (consulting) audit whose primary purpose is recommendations for improvement, and the skill of discerning "does the requester want assurance or advice" to judge the audit type and mode of engagement.

