A Framework for Auditing Web-Based Information Systems
DOI:
https://doi.org/10.5281/zenodo.6998530Keywords:
Web-Based Information Systems, Evaluation of Information Systems Information, Hierarchical Analytical ProcessAbstract
The last decade has seen growth at an unprecedented rate in the development of Web-based information systems (Web Based Information Systems or WBIS). Large investments are currently being made in WBIS systems. There is a real concern about whether we have already realized the true capacity and scope within WBIS organizations. As a consequence, it is paying increasing attention to evaluating the inherent contribution of WBIS. In this work, an audit methodology for WBIS is proposed. This methodology has two main characteristics: 1) it structures the process of audit as a hierarchical tree of evaluation, using a process model hierarchical analytical, 2) which allows the evaluation of a WBIS according to a set specific criteria based on the quality, security and readability of your requirements. Unlike other approaches, this methodology allows auditors independents, companies and users can reduce the time and effort required to evaluate a WBIS.
Metrics
References
Akoka J., Comyn-Wattiau I. (2000) Auditing Computer and Management Information Systems –Concepts, Methodologies and Applications, en Encyclopedia of Library and Information Science, Kent A. (Editor), Marcel Dekker, Inc. New York.
Atzeni P., Merialdo P., Sindoni G. (2002) Web Site Evaluation : Methodology and Case Study, DASWIS 2001, , Notas de lectura en Computer Science, N° 2465, Springer-Verlag, 2002.
Brown, W., Nasuti, F. (2005). What ERP Systems can Tell us about Sarbanes- Oxley. Information Management and Computer Security, 13(4), 311-327.
Cadbury Report (1994) “Internal Control and Financial Reporting.
Champlain J.J (1998) Auditing Information Systems – A Comprehensive Reference Guide, John Wiley & Sons, Inc., New York.
Chang, J. C.-J., & King, W. R. (2005). Measuring the Performance of Information Systems: A Functional Scorecard. Journal of Management Information Systems, 22(1), 85-115.
Collier P., Dixon R., (1995) “The Evaluation and Audit of Management Information Systems”, Managerial Auditing Journal, Vol. 10.
Danna E., Laroche A., (2000) “Auditing Web Sites Using Their Access Patterns”, http://www9.org/final-posters/poster25.html, 9th WWW Conference, Amsterdam.
Deshpande Y., Chandrarathna A., Ginige A. (2002) “Web Site Auditing – First Step Towards Reengineering”, Proceedings of SEKE’02.
Dewan R., Jing B., Seidmann A. (2000) “Adoption of Internet Based Product Customization and Pricing Strategies, Journal of Management Information Systems, Fall 2000, Vol. 17, N°2.
Grembergen, W. V., Haes, S. D., & Moons, J. (2005). Linking Business Goals to IT Goals and COBIT Processes. Information Systems Control Journal, 4, 18-22.
Hermanson, D. R. (2006). Internal Auditing: Getting Beyond The Selection 404 Implementation Crisis. Internal Auditing, 21(3), pp. 39-41.
InDIMENSIONS Consulting Group, Web Site Audit, http://www.indimensions.com.
Lewin J., “Web Site Audit and Evaluation”, http://www.lewingroup.com.
Nicho M. (2008) “Information Technology Audit: Systems Alignment and Effectiveness Measures”, Ph.D Dissertation, AUT University.
Simonsson, M., Johnson, P., & Wijkstrom, H. (2007). Model Based IT Governance Maturity Assessments With COBIT. Paper presentado en la 15a Conferencia Europea de Sistemas de Información, Suiza.
Singleton, T. W. (2006). COBIT- A Key to Success as an IT Auditor. Information Systems Control Journal, 1.
Wang S. (2001). “Toward a General Model for Web-Based Information Systems”, International Journal on Information Management, Vol. 21.
Published
How to Cite
Issue
Section
License
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This journal adheres to the Creative Commons license in the definition of its policy of open access and reuse of published material, in the following terms:
- Accessibility to articles and other publications in whole or in part under the concept of copying, distribution, public communication , interactive access (through the Internet or other means), explicitly maintaining the recognition of the author or authors and the journal itself (authorship acknowledgment).
- Warning that if the articles are remixed, modified or fragments used in other creations, the modified material cannot be distributed, nor is it allowed to reconstruct versions from the original published articles (derived works).
- The use of the contents of the published articles, in whole or in part, for profit (non-commercial recognition) is prohibited.
The author retains copyright, transfers or grants exclusive commercial rights to the publisher, and a non-commercial license is used.