حسابرسی سیستم‌ها و فناوری اطلاعات

حسابرسی سیستم‌ها و فناوری اطلاعات

حسابرسی و راهبری فناوری اطلاعات: تحلیل محرک‌های کلیدی و ارزیابی تطبیقی چارچوب‌های COBIT و ITIL

نوع مقاله : ترویجی

نویسندگان
1 کارشناس ارشد، دانشکده مدیریت، گروه حسابداری، دانشگاه تهران، تهران، ایران.
2 دانشجوی دکتری حسابداری، دانشگاه آزار اسلامی تبریز، تبریز، ایران
چکیده
در محیط اقتصادی وابسته به فناوری، درک تکامل حسابرسی فناوری اطلاعات نه تنها برای کارایی عملیاتی، بلکه برای ایمن‌سازی سیستم‌های فناوری اطلاعات و مدیریت مؤثر ریسک‌ها ضروری است. امروزه حسابرسی فناوری اطلاعات نقش محوری در بهبود رویه‌های حسابرسی، تضمین انطباق با قوانین و استانداردها، ارتقای امنیت سایبری، کاهش ریسک‌های کسب‌و‌کار، تسهیل تصمیم‌گیری آگاهانه در فضای تحولات دیجیتال، ایفا می‌کند. در عصر دیجیتال، راهبری و مدیریت ریسک‌های فناوری اطلاعات برای سازمان‌ها، حیاتی است، زیراریسک‌های فناوری اطلاعات به‌طور قابل‌توجهی بر پایداری عملیاتی، امنیت داده‌ها و اعتبار سازمانی تأثیر گذارند. مطالعه حاضر با مروری بر ادبیات، تحلیلی جامع از تکامل حسابرسی فناوری اطلاعات و محرک‌های محوری این تکامل در محیط پویای تحولات دیجیتال ارائه کرده است. همچنین این مطالعه ضمن تبیین تعاریف مختلف راهبری فناوری اطلاعات و ابعاد کلیدی آن، دو چارچوب رایج راهبری سیستم فناوری اطلاعات ، COBIT و ITIL را تبیین، و مزایا و معایب هر یک از چارچوب‌ها را تحلیل کرده است. تحلیل نقاط قوت و ضعف این چارچوب‌ها به سازمان‌ها کمک می‌کند تا رویکردی همسو با اهداف استراتژیک سازمان اتخاذ کنند. با این درک، سازمان‌ها می‌توانند توانایی خود را در مدیریت سیستم‌های فناوری اطلاعات افزایش داده و مزیت رقابتی خود را در بازارهای پویا، تضمین کنند.
کلیدواژه‌ها

موضوعات


Ahmed, S., Singh, M., Doherty, B., Ramlan, E., Harkin, K., Bucholc, M., & Coyle, D. (2023). An empirical analysis of state-of-art classification models in an it incident severity prediction framework. Applied Sciences, 13(6), 3843.https://doi.org/10.3390/app13063843
Alsaleem, E. A., & Husin, N. M. (2023). The impact of information technology governance under COBIT-5 framework on reducing the audit risk in Jordanian companies. International Journal of Professional Business Review: Int. J. Prof. Bus. Rev., 8(2), 4. https://doi.org/10.26668/businessreview/2023.v8i2.1236
Al-Sartawi, A. M. M. (2020). Information technology governance and cybersecurity at the board level. International Journal of Critical Infrastructures, 16(2), 150-161. https://doi.org/10.1504/IJCIS.2020.107265
Al-taee, S. H. H., & Flayyih, H. H. (2022). The impact of the audit committee and audit team characteristics on the audit quality: Mediating impact of effective audit process. International journal of economics and finance studies, 14(03), 249-263. https://sobiad.org/menuscript/index.php/ijefs/article/view/1259
Amorim, A. C., da Silva, M. M., Pereira, R., & Gonçalves, M. (2021). Using agile methodologies for adopting COBIT. Information Systems, 101, 101496. https://doi.org/10.1016/j.is.2020.101496
Andry, J. F., & Setiawan, A. K. (2019). IT governance evaluation using COBIT 5 framework on the national library. Jurnal Sistem Informasi, 15(1). DOI:10.21609/jsi.v15i1.790
Aqel, M. (2013, October 5). Introduction to IT governance using the COBIT framework. Fifth Annual Conference. IT Governance Institute. https://doi.org/10.18844/GJCS.V10I1.4143
Armstrong, P. (1987). The rise of accounting controls in British capitalist enterprises. Accounting, Organizations and Society, 12(5), 415-436. https://doi.org/10.1016/0361-3682(87)90029-8
Asen, A., Bohmayr, W., Deutscher, S., González, M., & Mkrtchian, D. (2019). Are you spending enough on cybersecurity? Boston Consulting Group. https://www.bcg.com/publications/2019/are-you-spending-enough-cybersecurity
Azizi, M., Hakimi, M., Amiri, F., & Shahidzay, A. K. (2024). The Role of IT (Information Technology) Audit in Digital Transformation: Opportunities and Challenges. Open Access Indonesia Journal of Social Sciences, 7(2), 1473-1482. https://doi.org/10.37275/oaijss.v7i2.230
Bayu, I. P. G. A. K., PNa, E. P., Sudanaa, A. K. O., Wirdiania, N. K. A., & Paramarthaa, I. B. A. (2021). Evaluation of IT Governance at Office X using the COBIT 5 Framework. Jurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi), 9(1), 1-12. DOI:10.24843/JIM.2021.v09.i01.p01
Berghout, E., & Fijneman, R. (2023). Auditing complexity. Advanced Digital Auditing, 9. http://thuvienso.ktkt.edu.vn:8080/jspui/bitstream/BETU_TV/3098/1/Advanced%20Digital%20Auditing.pdf.
Betti, N., & Sarens, G. (2021). Understanding the internal audit function in a digitalised business environment. Journal of Accounting & Organizational Change, 17(2), 197-216. https://doi.org/10.1108/JAOC-11-2019-0114
Chaney, C., & Kim, G. (2007) The integrated auditor. The Internal Auditor 64(4), 46–51. https://www.academia.edu/120144136/Integrated_internal_audit_in_management_system
Danutirta, A. S., Hariadhy, R. P., & Lubis, M. (2022). Evaluating IT governance implementation in the plantation company using COBIT 5 framework DSS01 domain. In Proceedings of the 6th International Conference on E-Commerce, E-Business and E-Government (pp. 91-95). DOI:10.1145/3537693.3537752
Flint, D. (1988). Philosophy and principles of auditing: An introduction. Macmillan Education. https://www.abebooks.com/9780333311165/Philosophy-Principles-Auditing-Introduction-David-0333311167/plp
Frogeri, R. F., Pardini, D. J., Cardoso, A. M. P., Prado, L. Á., Piurcosky, F. P., & Portugal Júnior, P. D. S. (2020). IT governance in SMEs: Proposal of a theoretical model through an interdisciplinary perspective. RISTI - Revista Ibérica de Sistemas e Tecnologias de Informação, 2020(E27).
Fu, Q., Abdul Rahman, A. A., Jiang, H., Abbas, J., & Comite, U. (2022). Sustainable supply chain and business performance: The impact of strategy, network design, information systems, and organizational structure. Sustainability, 14(3), 1080. https://doi.org/10.3390/su14031080
Gill, G., & Cosserat, G. (1996). Modern auditing in Australia (4th edition). John Wiley & Sons. https://catalogue.nla.gov.au/catalog/1111763.
Gunawan, N. K., Hadiprakoso, R. B., & Kabetta, H. (2020). Comparative study between the integration of ITIL and ISO/IEC 27001 with the integration of COBIT and ISO/IEC 27001. In IOP Conference Series: Materials Science and Engineering (Vol. 852, No. 1, p. 012128). IOP Publishing. DOI:10.1088/1757-899X/852/1/012128
Haouam, D. (2020). IT governance impact on financial reporting quality using COBIT framework. Global Journal of Computer Sciences: Theory and Research, 10(1), 1-10. DOI:10.18844/gjcs.v10i1.4143
Henriques, D., Pereira, R. F., Almeida, R., & Mira da Silva, M. (2020). IT governance enablers in relation to IoT implementation: A systematic literature review. DOI:10.17323/2500-2597.2020.1.48.59
Information Systems Audit and Control Association. (2018). COBIT® 2019 Framework: Introduction and Methodology. Isaca. https://www.isaca.org/resources/news-and-trends/industry-news/2020/cobit-2019-and-cobit-5-comparison.
Joshi, A., Benitez, J., Huygh, T., Ruiz, L., & De Haes, S. (2022). Impact of IT governance process capability on business performance: Theory and empirical evidence. Decision Support Systems, 153, 113668. DOI:10.1016/j.dss.2021.113668
Kee, R. (1993). Data processing technology and accounting: A historical perspective. Accounting Historians Journal, 20(2), 187-216. https://doi.org/10.2308/0148-4184.20.2.187
Khamees, B. A. (2023). Information technology governance and bank performance: a situational approach. International journal of financial studies, 11(1), 44. https://doi.org/10.3390/ijfs11010044
Leung P, Coram P, Cooper, B. (2007) Modern auditing & assurance services (3rd ed.). John Wiley & Sons, Australia. https://catalogue.nla.gov.au/catalog/3792672
Levstek, A., Pucihar, A., & Hovelja, T. (2022). Towards an adaptive strategic IT governance model for SMEs. Journal of Theoretical and Applied Electronic Commerce Research, 17(1), 230-252. https://doi.org/10.3390/jtaer17010012
Maulana, Y. M. (2024). Information technology governance using control objectives for information and related technology: Review. Jurnal Teknik Informatika dan Sistem Informasi, 9(3). https://doi.org/10.28932/jutisi.v9i3.6494
McAfee, A., & Brynjolfsson, E. (2008). Investing in the IT that makes a competitive difference. Harvard business review, 86(7/8), 98.
Mensah, I. K. (2020). Impact of government capacity and E-government performance on the adoption of E-Government services. International Journal of Public Administration, 43(4). DOI:10.1080/01900692.2019.1628059
Mock, T. J., & Turner, J. L. (1981). Internal accounting control evaluation and auditor judgment: Auditing research monograph, 3. American Institute of Certified Public Accountants (AICPA). https://files01.core.ac.uk/download/pdf/288032236.pdf
Mueller, R., & Yin, R. (2023). Sentry insurance and california consumer privacy act: a business case on IT governance, data security, and compliance. Issues in Information Systems, 24(3). DOI:10.48009/3_iis_2023_115
Nguyen, N. P., Hang, N. T. T., Hiep, N., & Flynn, O. (2023). Does transformational leadership influence organisational culture and organisational performance: Empirical evidence from an emerging country. IIMB Management Review, 35(4), 382-392. DOI:10.1016/j.iimb.2023.10.001
Olagunju, A. O., & Owolabi, S. A. (2021). Historical evolution of audit theory and practice. International Journal of Management Excellence (ISSN: 2292-1648), 16(1), 2252-2259. DOI:10.17722/ijme.v16i1.1197
Ozkan, N., Tarhan, A. K., Gören, B., Filiz, İ., & Özer, E. (2020). Harmonizing IT Frameworks and Agile Methods: Challenges and Solutions for the case of COBIT and Scrum. In 2020 15th Conference on Computer Science and Information Systems (FedCSIS) (pp. 709-719). IEEE. DOI:10.15439/2020F47
Phornlaphatrachakorn, K. (2020). Audit committee effectiveness, internal audit quality, financial reporting quality, and organizational success: An empirical investigation of Thai listed firms. International Journal of Business, 25(4), 343-366. https://ijb.cyut.edu.tw/var/file/10/1010/img/866/V25N4-2.pdf
Pratama, R. Y., & Umaroh, S. (2024). An IT Asset Governance model design using COBIT 2019 and ITIL V4 framework at BKU Itenas. In E3S Web of Conferences (Vol. 484, p. 02006). EDP Sciences. DOI:10.1051/e3sconf/202448402006
Queenan, J. W. (1946). The public accountant of today and tomorrow. The Accounting Review, 21(3), 254-260. https://www.jstor.org/stable/240476
Ramamoorti, S., & Weidenmier, M. L. (2004). The pervasive impact of information technology on internal auditing. In C. Dorothy (Ed.), Research opportunities in internal auditing (pp. 223–268). Institute of Internal Auditors Research Foundation.
Roustom, Z. M., Hamwi, K., Armoush, A., & Abubakr, A. A. M. (2025). IT Governance Frameworks and their Impact on the Efficiency of External Audits: Evidence from Companies When Audit Client Adoption. Qubahan Academic Journal, 5(1), 640-661. https://journal.qubahan.com/index.php/qaj/article/view/1517
Saeed, A. H. G., Hussein, L. D. M. D., & Saudi, A. O. A. (2022). The impacts of information technology governance on internal auditing: A literature review. Journal of Administration and Economics, 47(133), 341-347. DOI:10.31272/jae.i133.949
Salehi, M. (2007). An empirical study of corporate audit expectation gap in Iran. Unpublished Doctoral dissertation, University of Mysore, India.
Shariffuddin, N., & Mohamed, A. (2020). IT security and IT governance alignment: a review. In Proceedings of the 3rd International Conference on Networking, Information Systems & Security (pp. 1-8). DOI:10.1145/3386723.3387843
Sholeh, M. B., & Pramudya, N. D. (2025). Comparative Study of Information System Governance Frameworks: Foundations for IT Risk Management Using COBIT 2019 and ITIL. Jurnal Transformatika, 22(2), 73-80. https://doi.org/10.26623/fh0vee39
Tantiono, A., & Legowo, D. (2020). Information system governance in higher education foundation using COBIT 5 framework. International Journal of Recent Technology and Engineering (IJRTE), 8, 2798-2811. DOI:10.35940/ijrte.F8192.038620
Telino, V., Massa, R., Mota, I., Gomes, A., & Moreira, F. (2020). A methodology for creating a macro action plan to improve IT use and its governance in organizations. Information, 11(9), 427. DOI:10.3390/info11090427
Toms, S. (2019). Financial scandals: a historical overview. Accounting and Business Research, 49(5), 477-499. https://doi.org/10.1080/00014788.2019.1610591
Turley, S., & Cooper, M. (2005). Auditing in the United Kingdom: A study of developments in the audit methodologies of large accounting firms. Prentice-Hall International / ICAEW.
Tuttle, B. & Vandervelde, S. D. (2007). An empirical examination of CobiT as an internal control framework for information technology. International Journal of Accounting Information Systems, 8(4), 240–263. https://doi.org/10.1016/j.accinf.2007.09.001
Umam, C., Mahmud, W., Hidajat, M. S., & Setiarso, I. (2023). Information technology management governance analysis using cobit 5 (Case study at Universitas Dian Nuswantoro-PSDKU Kediri). TEKNOSAINS: Jurnal Sains, Teknologi dan Informatika, 10(2), 193-202. DOI:10.37373/tekno.v10i2.469
van den Heuvel, E. (2025). Evolution of IT auditing in a nutshell–journey towards a dynamic landscape. Maandblad voor Accountancy en Bedrijfseconomie, 99(2), 73-83. DOI:10.5117/mab.99.140994
Vasarhelyi, M. A., & Halper, F. B. (2018). The continuous audit of online systems. In M. A. Vasarhelyi & A. Kogan (Eds.), Continuous auditing (pp. 87–104). Emerald Publishing Limited.
Weber, R. A. (2021). Information systems control and audit (10th ed.). Pearson Education. https://www.amazon.com/Information-Systems-Control-Audit-Weber/dp/0139478701

  • تاریخ دریافت 18 آذر 1404
  • تاریخ بازنگری 06 بهمن 1404
  • تاریخ پذیرش 06 اسفند 1404
  • تاریخ انتشار 01 مهر 1404