What's changed: Initial version
1.2System Audit Standards and System Management Standards
Covers the difference in role between the Ministry of Economy, Trade and Industry's System Audit Standards (the auditor's code of conduct: general standards, execution standards, reporting standards) and its System Management Standards (the ideal state of information-system management on the audited side), and how to use each as the auditor's yardstick.
For a systems auditor to point out "what is lacking compared with the ideal state," a basis (yardstick) for comparison is needed. The Ministry of Economy, Trade and Industry publishes two standards: the System Audit Standards are the auditor's own code of conduct for "how the auditor should conduct the audit," and the System Management Standards are the ideal state of management (the source of evaluation items during the audit) for "how the audited organization should manage its information systems." This section builds an understanding that the two are standards with different roles—"the norm for the auditing side" versus "the ideal state for the audited side"—and develops the ability to judge which to reference as the criterion in practice.
1.2.1The three categories of the System Audit Standards
- The general standards define the requirements the auditor themselves must possess—the auditor's qualification, independence, professional ethics, and audit capability. The auditor's independence (in mind and in appearance), objectivity, and maintenance of professional competence are positioned here.
- The execution standards are standards concerning the process of conducting the audit—formulating the audit plan, carrying out the audit, obtaining and evaluating audit evidence, and preparing audit working papers. The risk-based approach and the appropriate selection and execution of audit procedures are included here.
- The reporting standards concern reporting audit results, defining the matters to be stated in the audit report (the audit scope, procedures performed, findings discovered, recommendations for improvement, opinions, etc.) and the timeliness and objectivity of reporting. The concept of follow-up (confirming the state of improvement) also relates here.
1.2.2The role of the System Management Standards
- The System Management Standards systematize the ideal state of management (a guide to controls) that an organization should have at each phase of planning, developing, operating, and maintaining information systems. Control items are presented by category—IT governance, planning, development, operation, maintenance, common tasks, etc.—and are used as the evaluation items and comparison basis when the auditor assesses "whether the audited organization's management is adequate."
- In a word, the relationship between the two standards is: the System Audit Standards are the auditor's "code of conduct," and the System Management Standards are the audited organization's "ideal state." The auditor conducts their own audit procedures appropriately against the audit standards, and evaluates the audited organization's actual state against the management standards (or specific rules and laws). It is important not to confuse which is the norm for the auditor and which is the yardstick for evaluation.
Most-tested: the System Audit Standards are the auditor's code of conduct (three categories: general/execution/reporting); the System Management Standards are the ideal state of the audited organization's information-system management (the source of evaluation items); and independence and professional ethics belong to the general standards. The key to judgment is not confusing the "direction" of the two standards (the auditing side vs. the audited side).
Suppose you are a systems auditor, proceeding with an audit of an organization's information-system operations management. A staff member of the audited organization asks, "Against which standard do you evaluate whether our system operations are appropriate?" Answering only "we evaluate against the System Audit Standards" confuses the direction of the standards—the System Audit Standards are the norm for me, the auditor, to maintain independence and conduct the audit with appropriate procedures, whereas the basis for the evaluation items measuring whether the audited organization's operations management is adequate is primarily the System Management Standards (together with that organization's internal rules, relevant laws, and contracts). Correctly, then, it is appropriate to explain: "I evaluate whether operational controls—change management, access management, backup, incident response—are established and operating by reconciling them against the ideal state of management shown in the System Management Standards and your operational rules, and I point out and recommend on the gaps. Separately, whether I am conducting this audit objectively from an independent position is something I discipline myself against the System Audit Standards (general and execution standards)." In the field, consciously distinguishing "the standard that disciplines the auditor's own conduct (audit standards)" from "the yardstick that evaluates the audited organization's management (management standards)" clarifies the basis for findings and underpins the persuasiveness of the audit.
| Standard | Direction (subject) | Main content |
|---|---|---|
| System Audit Standards (general) | The auditing side (the auditor) | Qualification, independence, professional ethics, audit capability |
| System Audit Standards (execution) | The auditing side (the auditor) | Procedures for planning, execution, evidence gathering, working papers |
| System Audit Standards (reporting) | The auditing side (the auditor) | Report contents, timeliness/objectivity of reporting |
| System Management Standards | The audited side (the audited organization) | Ideal state of planning/development/operation/maintenance management (evaluation items) |
Trap: "Whether the audited organization's information-system management is adequate is evaluated by reconciling against the management items shown in the System Audit Standards" is wrong—the ideal state for the audited organization (the source of evaluation items) is primarily the System Management Standards, while the System Audit Standards are the auditor's own code of conduct. Also wrong: "the general standards define the audit's execution procedures"—execution procedures are the execution standards; the general standards are the category defining the auditor's independence, professional ethics, and qualification.
1.2.3Section summary
- The System Audit Standards are the auditor's code of conduct, comprising three categories: general (qualification, independence, ethics), execution (procedures), and reporting
- The System Management Standards are the ideal state of the audited organization's information-system management and serve as the source of evaluation items and comparison basis during the audit
- The two standards differ in direction—"the norm for the auditing side" versus "the ideal state for the audited side"—and it is important not to confuse them as criteria
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. A staff member of the audited organization asks, "Which standard is used as the basis for evaluating whether our system operations management is appropriate?" Which explanation by the systems auditor is most appropriate?
Q2. Which statement about the categories of general, execution, and reporting standards in the System Audit Standards is most appropriate?
Q3. Which best explains the relationship between the System Audit Standards and the System Management Standards?

