SlideShare a Scribd company logo
1 of 19
Download to read offline
Prepare to be Audited
 (The auditor is coming!
 The auditor is coming!)


    IT Best Practices

                        Bob Sturm
                        Director, IT Validation
Life Cycle of an Audit
What                      Responsibility

Request for information   IT Quality

Introductory meeting      IT Quality & Mngrs.
Information gathering &   IT Quality and
analysis                  Auditee(s)
Audit Close-out           IT Quality & Mngrs.

Reporting & follow-up     IT Quality
Prepare for the Audit

• HOW?
 – Attend this training.
 – Read and understand the sample
   questions in the handout.


• WHY?
 – You may be asked these questions.
Three Basic Concepts


• Follow the IT Policy Manual

• Adhering to our ITMS principles means we
  are Audit Ready!

• Understand the scope and objectives of
  the audit as explained by IT Quality
Preparing – IT Quality’s
          Responsibilities


• Email people an auditor(s) is coming
• Appoint an escort to be the host for the
  auditor(s)
• Ensure work space & appropriate
  badge access
• Arrange for a conference room where
  auditor(s) can meet
Preparing – IT Quality’s
      Responsibilities (More)

• Ensure a guest wireless network is
  available. Contact IT security if more
  bandwidth is needed.
• Confirm that management is available for
  the opening and closing meeting
• Confirm that personnel who have key roles
  in areas under review are available
Assign Tasks for Audit

• IT Quality and Managers meet to assign
  tasks needed for the audit
What’s Expected of You

• KEY - Know our ITMS practices inside and
  out!
• Know what is expected per your job
  description
• Understand applicable SOPs, WIs and
  other procedures for your job
• If unsure about anything, ask your
  manager or IT Quality
Conduct and Etiquette
NO                                 YES 

• Be professional, respectful and truthful with
  the auditor
• Have a positive attitude
• If you anticipate a finding, contact IT Quality
• Don’t take anything the auditor says
  personally
• Defend our systems and processes but don’t
  be overly defensive or argue with the auditor
Conduct and Etiquette - More


• Keep the atmosphere and the
  conversation friendly but professional
• Do not try to influence an auditor’s
  judgment
• Recognize when you are right and when
  you are wrong
• Do not become emotionally involved in
  the review
Conduct and Etiquette – Even More

• Be wary of an auditor who veers off topic
  and requests information not associated
  with the scope and objectives of audit
  – Defer these requests to IT Quality or your
    manager
• If the auditor requests information deemed
  proprietary, sensitive or highly confidential,
  refer the auditor to IT Quality or your
  manager
Responding to Questions

• IMPORTANT! – Answer only the questions
  posed by the auditor. Do NOT volunteer
  extra information or expand unnecessarily
  on any answer.
• Answer all questions truthfully. Do NOT
  stretch the truth or be misleading.
• Provide adequate and accurate answers.
  – Just the facts, not opinions!
Responding to Questions
      - More
• Before answering a question, be sure to
  understand the question.
• If unsure about the question, ask for
  clarification or paraphrase the question.
• Do NOT guess at the question!
• If unsure of an answer, inform the auditor you
  are not sure. Let auditor know you will get an
  answer or bring in a person who knows the
  answer.
• Follow up and set a date!
Sample Questions

• Is there a documented and approved disaster
  recovery plan on file? Has it been tested to
  ensure reliability?
• How are assets, including data safeguarded?
• Has the computer system been developed in
  a manner consistent with applicable
  regulatory guidances and industry standards?
• Do personnel have requisite training,
  education and experience to perform their job
  function and is the training documented?
Sample Questions - More

• What methods are established for traceability
  of documentation, including changes?
• What procedures exist to assure that
  standards are followed?
• Is approval authority for deliverable
  documentation clearly established?
• What procedures exist to assure the prompt
  detection and correction of deficiencies?
• Are acceptance tests monitored by QA?
Requests for Documents
• All document requests are handled by IT
  Quality or Managers
• Route all documents through IT Quality or
  Managers
• Put documents onto a SharePoint site set
  up for the audit by IT Quality
Audit Closeout – IT Quality and
         Managers
• Purpose is for the auditor to summarize
  events of the audit and present preliminary
  observations of non-conformance.
• Auditors present the facts of their findings.
• Our company ensures the root cause of the
  issue is determined
• Our company discusses the level of risk
  associated with the finding
Audit Closeout – IT Quality and
      Managers (More)
• Discuss potential solutions to the findings
• Our company ensures the auditor is not
  overly prescriptive in their
  recommendations.
• Provides an opportunity to discuss any
  misunderstandings that may have arisen
• IT Quality will ask about expected delivery
  of the formal report
Reference Material to READ

• Preparation for the Audit – IT Best
  practices, www.pharmait.co.uk,
  – Read pp 31-35.

• Software Quality Assurance Audits
  Guidebook, NASA, November 1990
  – Read Appendix B pp 17-21 (Sample Questions).

More Related Content

What's hot

Use Of Techniques And Technology In Internal Audit
Use Of Techniques And Technology In Internal AuditUse Of Techniques And Technology In Internal Audit
Use Of Techniques And Technology In Internal AuditManoj Agarwal
 
Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010Donald E. Hester
 
Good documentation practices
Good documentation practicesGood documentation practices
Good documentation practicesBangaluru
 
Cisa exam mock test questions-1
Cisa exam mock test questions-1Cisa exam mock test questions-1
Cisa exam mock test questions-1Hemang Doshi
 
Generalized audit-software
Generalized audit-softwareGeneralized audit-software
Generalized audit-softwarekzoe1996
 
CSV Audit Presentation
CSV Audit PresentationCSV Audit Presentation
CSV Audit PresentationRobert Ruemer
 
Computer-Assisted Audit Tools and Techniques
Computer-Assisted Audit Tools and TechniquesComputer-Assisted Audit Tools and Techniques
Computer-Assisted Audit Tools and Techniques_supriadi
 
PECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliancePECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliancePECB
 
Computer Audit an Introductory
Computer Audit an IntroductoryComputer Audit an Introductory
Computer Audit an IntroductoryMNorazizi HM
 
Computer system validation
Computer system validation Computer system validation
Computer system validation ShameerAbid
 
05.2 auditing procedure application controls
05.2 auditing procedure   application controls05.2 auditing procedure   application controls
05.2 auditing procedure application controlsMulyadi Yusuf
 
03.2 application control
03.2 application control03.2 application control
03.2 application controlMulyadi Yusuf
 
The Business Case for Integrated Design Controls
The Business Case for Integrated Design ControlsThe Business Case for Integrated Design Controls
The Business Case for Integrated Design ControlsGreenlight Guru
 
The Coming Age of Continuous Auditing
The Coming Age of Continuous AuditingThe Coming Age of Continuous Auditing
The Coming Age of Continuous Auditingcarlabrut
 
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...Shay Ginsbourg
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Ydemikaelyde
 
Test Data Approach
Test Data ApproachTest Data Approach
Test Data Approachkzoe1996
 

What's hot (20)

Cv 1
Cv 1Cv 1
Cv 1
 
Use Of Techniques And Technology In Internal Audit
Use Of Techniques And Technology In Internal AuditUse Of Techniques And Technology In Internal Audit
Use Of Techniques And Technology In Internal Audit
 
Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010Information Systems Audit & CISA Prep 2010
Information Systems Audit & CISA Prep 2010
 
Good documentation practices
Good documentation practicesGood documentation practices
Good documentation practices
 
Cisa exam mock test questions-1
Cisa exam mock test questions-1Cisa exam mock test questions-1
Cisa exam mock test questions-1
 
Generalized audit-software
Generalized audit-softwareGeneralized audit-software
Generalized audit-software
 
CSV Audit Presentation
CSV Audit PresentationCSV Audit Presentation
CSV Audit Presentation
 
Ch2 2009 cisa
Ch2 2009 cisaCh2 2009 cisa
Ch2 2009 cisa
 
Computer-Assisted Audit Tools and Techniques
Computer-Assisted Audit Tools and TechniquesComputer-Assisted Audit Tools and Techniques
Computer-Assisted Audit Tools and Techniques
 
PECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliancePECB Webinar: ISO Internal Audits - A signpost to ISO compliance
PECB Webinar: ISO Internal Audits - A signpost to ISO compliance
 
Computer Audit an Introductory
Computer Audit an IntroductoryComputer Audit an Introductory
Computer Audit an Introductory
 
Computer system validation
Computer system validation Computer system validation
Computer system validation
 
05.2 auditing procedure application controls
05.2 auditing procedure   application controls05.2 auditing procedure   application controls
05.2 auditing procedure application controls
 
03.2 application control
03.2 application control03.2 application control
03.2 application control
 
Software Quality
Software Quality Software Quality
Software Quality
 
The Business Case for Integrated Design Controls
The Business Case for Integrated Design ControlsThe Business Case for Integrated Design Controls
The Business Case for Integrated Design Controls
 
The Coming Age of Continuous Auditing
The Coming Age of Continuous AuditingThe Coming Age of Continuous Auditing
The Coming Age of Continuous Auditing
 
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...
Ginsbourg.com - Presentation of a Plan for Medical Device Software Validation...
 
2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde2016-06-08 FDA Inspection Readiness - Mikael Yde
2016-06-08 FDA Inspection Readiness - Mikael Yde
 
Test Data Approach
Test Data ApproachTest Data Approach
Test Data Approach
 

Similar to Prepare for an I.T. Audit

How to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsHow to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsMontrium
 
Proactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxProactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxSafetyChain Software
 
Proactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxProactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxSafetyChain Software
 
Preparing for your Food Safety Audit
Preparing for your Food Safety AuditPreparing for your Food Safety Audit
Preparing for your Food Safety AuditPECB
 
20-MOD 8 Self and Work Management-20-07-2023.ppt
20-MOD 8 Self and Work Management-20-07-2023.ppt20-MOD 8 Self and Work Management-20-07-2023.ppt
20-MOD 8 Self and Work Management-20-07-2023.pptabhichowdary16
 
The FDA just called, Now What?
The FDA just called, Now What?The FDA just called, Now What?
The FDA just called, Now What?MasterControl
 
Your project selected_for_audit_sip18_project_auditors
Your project selected_for_audit_sip18_project_auditorsYour project selected_for_audit_sip18_project_auditors
Your project selected_for_audit_sip18_project_auditorsJoy Gumz
 
Internal Audits and Other Tactics to Improve Your EHS Program
Internal Audits and Other Tactics to Improve Your EHS ProgramInternal Audits and Other Tactics to Improve Your EHS Program
Internal Audits and Other Tactics to Improve Your EHS ProgramTriumvirate Environmental
 
Are you in control of Testing, or does Testing control you?
Are you in control of Testing, or does Testing control you? Are you in control of Testing, or does Testing control you?
Are you in control of Testing, or does Testing control you? SQALab
 
Root Cause Analysis: Think Again! - by Kevin Stewart
Root Cause Analysis: Think Again! - by Kevin StewartRoot Cause Analysis: Think Again! - by Kevin Stewart
Root Cause Analysis: Think Again! - by Kevin StewartASQ Reliability Division
 
software testing metrics do's - don'ts-XBOSoft-QAI Webinar
software testing metrics do's - don'ts-XBOSoft-QAI Webinarsoftware testing metrics do's - don'ts-XBOSoft-QAI Webinar
software testing metrics do's - don'ts-XBOSoft-QAI WebinarXBOSoft
 
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI Webinar
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI WebinarSoftware Quality Metrics Do's and Don'ts - XBOSoft-QAI Webinar
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI WebinarXBOSoft
 
Successful EHS Auditing Insights from a Client's Perspective
Successful EHS Auditing Insights from a Client's PerspectiveSuccessful EHS Auditing Insights from a Client's Perspective
Successful EHS Auditing Insights from a Client's PerspectiveAntea Group
 
Next generation pentest your company cannot buy
Next generation pentest your company cannot buyNext generation pentest your company cannot buy
Next generation pentest your company cannot buyVlad Styran
 
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...Владимир Стыран - Пентест следующего поколения, который ваша компания не може...
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...UISGCON
 
"Defining your Quality Strategy" by John Belbute
"Defining your Quality Strategy" by John Belbute"Defining your Quality Strategy" by John Belbute
"Defining your Quality Strategy" by John BelbuteAgile Connect®
 
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptxkashifmajeedjanjua
 
TechClimb_Webinar_PPT_working_1014
TechClimb_Webinar_PPT_working_1014TechClimb_Webinar_PPT_working_1014
TechClimb_Webinar_PPT_working_1014Laura J. Wilcox
 

Similar to Prepare for an I.T. Audit (20)

How to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qmsHow to prepare for an audit and maintain oversight within your e qms
How to prepare for an audit and maintain oversight within your e qms
 
Proactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxProactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptx
 
Proactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptxProactive Internal Auditing (QMMI) - April 2023.pptx
Proactive Internal Auditing (QMMI) - April 2023.pptx
 
Preparing for your Food Safety Audit
Preparing for your Food Safety AuditPreparing for your Food Safety Audit
Preparing for your Food Safety Audit
 
20-MOD 8 Self and Work Management-20-07-2023.ppt
20-MOD 8 Self and Work Management-20-07-2023.ppt20-MOD 8 Self and Work Management-20-07-2023.ppt
20-MOD 8 Self and Work Management-20-07-2023.ppt
 
The FDA just called, Now What?
The FDA just called, Now What?The FDA just called, Now What?
The FDA just called, Now What?
 
Your project selected_for_audit_sip18_project_auditors
Your project selected_for_audit_sip18_project_auditorsYour project selected_for_audit_sip18_project_auditors
Your project selected_for_audit_sip18_project_auditors
 
Internal Audits and Other Tactics to Improve Your EHS Program
Internal Audits and Other Tactics to Improve Your EHS ProgramInternal Audits and Other Tactics to Improve Your EHS Program
Internal Audits and Other Tactics to Improve Your EHS Program
 
Are you in control of Testing, or does Testing control you?
Are you in control of Testing, or does Testing control you? Are you in control of Testing, or does Testing control you?
Are you in control of Testing, or does Testing control you?
 
Root Cause Analysis: Think Again! - by Kevin Stewart
Root Cause Analysis: Think Again! - by Kevin StewartRoot Cause Analysis: Think Again! - by Kevin Stewart
Root Cause Analysis: Think Again! - by Kevin Stewart
 
Beginning auditor (1)
Beginning auditor (1)Beginning auditor (1)
Beginning auditor (1)
 
software testing metrics do's - don'ts-XBOSoft-QAI Webinar
software testing metrics do's - don'ts-XBOSoft-QAI Webinarsoftware testing metrics do's - don'ts-XBOSoft-QAI Webinar
software testing metrics do's - don'ts-XBOSoft-QAI Webinar
 
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI Webinar
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI WebinarSoftware Quality Metrics Do's and Don'ts - XBOSoft-QAI Webinar
Software Quality Metrics Do's and Don'ts - XBOSoft-QAI Webinar
 
Successful EHS Auditing Insights from a Client's Perspective
Successful EHS Auditing Insights from a Client's PerspectiveSuccessful EHS Auditing Insights from a Client's Perspective
Successful EHS Auditing Insights from a Client's Perspective
 
Next generation pentest your company cannot buy
Next generation pentest your company cannot buyNext generation pentest your company cannot buy
Next generation pentest your company cannot buy
 
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...Владимир Стыран - Пентест следующего поколения, который ваша компания не може...
Владимир Стыран - Пентест следующего поколения, который ваша компания не може...
 
Chapter03
Chapter03Chapter03
Chapter03
 
"Defining your Quality Strategy" by John Belbute
"Defining your Quality Strategy" by John Belbute"Defining your Quality Strategy" by John Belbute
"Defining your Quality Strategy" by John Belbute
 
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx
512915984-CISAsadsadasdasdasdasdasdas-Domain-1-Slides.pptx
 
TechClimb_Webinar_PPT_working_1014
TechClimb_Webinar_PPT_working_1014TechClimb_Webinar_PPT_working_1014
TechClimb_Webinar_PPT_working_1014
 

Recently uploaded

Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 

Prepare for an I.T. Audit

  • 1. Prepare to be Audited (The auditor is coming! The auditor is coming!) IT Best Practices Bob Sturm Director, IT Validation
  • 2. Life Cycle of an Audit What Responsibility Request for information IT Quality Introductory meeting IT Quality & Mngrs. Information gathering & IT Quality and analysis Auditee(s) Audit Close-out IT Quality & Mngrs. Reporting & follow-up IT Quality
  • 3. Prepare for the Audit • HOW? – Attend this training. – Read and understand the sample questions in the handout. • WHY? – You may be asked these questions.
  • 4. Three Basic Concepts • Follow the IT Policy Manual • Adhering to our ITMS principles means we are Audit Ready! • Understand the scope and objectives of the audit as explained by IT Quality
  • 5. Preparing – IT Quality’s Responsibilities • Email people an auditor(s) is coming • Appoint an escort to be the host for the auditor(s) • Ensure work space & appropriate badge access • Arrange for a conference room where auditor(s) can meet
  • 6. Preparing – IT Quality’s Responsibilities (More) • Ensure a guest wireless network is available. Contact IT security if more bandwidth is needed. • Confirm that management is available for the opening and closing meeting • Confirm that personnel who have key roles in areas under review are available
  • 7. Assign Tasks for Audit • IT Quality and Managers meet to assign tasks needed for the audit
  • 8. What’s Expected of You • KEY - Know our ITMS practices inside and out! • Know what is expected per your job description • Understand applicable SOPs, WIs and other procedures for your job • If unsure about anything, ask your manager or IT Quality
  • 9. Conduct and Etiquette NO  YES  • Be professional, respectful and truthful with the auditor • Have a positive attitude • If you anticipate a finding, contact IT Quality • Don’t take anything the auditor says personally • Defend our systems and processes but don’t be overly defensive or argue with the auditor
  • 10. Conduct and Etiquette - More • Keep the atmosphere and the conversation friendly but professional • Do not try to influence an auditor’s judgment • Recognize when you are right and when you are wrong • Do not become emotionally involved in the review
  • 11. Conduct and Etiquette – Even More • Be wary of an auditor who veers off topic and requests information not associated with the scope and objectives of audit – Defer these requests to IT Quality or your manager • If the auditor requests information deemed proprietary, sensitive or highly confidential, refer the auditor to IT Quality or your manager
  • 12. Responding to Questions • IMPORTANT! – Answer only the questions posed by the auditor. Do NOT volunteer extra information or expand unnecessarily on any answer. • Answer all questions truthfully. Do NOT stretch the truth or be misleading. • Provide adequate and accurate answers. – Just the facts, not opinions!
  • 13. Responding to Questions - More • Before answering a question, be sure to understand the question. • If unsure about the question, ask for clarification or paraphrase the question. • Do NOT guess at the question! • If unsure of an answer, inform the auditor you are not sure. Let auditor know you will get an answer or bring in a person who knows the answer. • Follow up and set a date!
  • 14. Sample Questions • Is there a documented and approved disaster recovery plan on file? Has it been tested to ensure reliability? • How are assets, including data safeguarded? • Has the computer system been developed in a manner consistent with applicable regulatory guidances and industry standards? • Do personnel have requisite training, education and experience to perform their job function and is the training documented?
  • 15. Sample Questions - More • What methods are established for traceability of documentation, including changes? • What procedures exist to assure that standards are followed? • Is approval authority for deliverable documentation clearly established? • What procedures exist to assure the prompt detection and correction of deficiencies? • Are acceptance tests monitored by QA?
  • 16. Requests for Documents • All document requests are handled by IT Quality or Managers • Route all documents through IT Quality or Managers • Put documents onto a SharePoint site set up for the audit by IT Quality
  • 17. Audit Closeout – IT Quality and Managers • Purpose is for the auditor to summarize events of the audit and present preliminary observations of non-conformance. • Auditors present the facts of their findings. • Our company ensures the root cause of the issue is determined • Our company discusses the level of risk associated with the finding
  • 18. Audit Closeout – IT Quality and Managers (More) • Discuss potential solutions to the findings • Our company ensures the auditor is not overly prescriptive in their recommendations. • Provides an opportunity to discuss any misunderstandings that may have arisen • IT Quality will ask about expected delivery of the formal report
  • 19. Reference Material to READ • Preparation for the Audit – IT Best practices, www.pharmait.co.uk, – Read pp 31-35. • Software Quality Assurance Audits Guidebook, NASA, November 1990 – Read Appendix B pp 17-21 (Sample Questions).