IT Audit and Risk Consulting

Minimize

The IT Audit and Consulting practice of Stantons International offers a full range of specialist IT assurance and risk related services at extremely competitive rates. We specialise in the delivery of IT security, assurance and risk consulting services and have delivered services to Commonwealth, State and Territory Governments for more than 30 years. Due to our specialist nature we offer an independent consulting and assurance service in relation to IT related functions, this can cover both technical and/or strategic areas of an organisation.

Our methodologies are scalable and flexible to meet a broad range of client needs and to align with statutory requirements and the risk profile of the organisation. For delivery of our engagements we can bring our complete suite of methods and supporting tools or alternatively, work within your established frameworks and supplement this with our own tools, methods and practices as appropriate. Our typical baselines in relation to our engagements are:

  • AS/NZS 27001 / 27002 “Information Technology — Security Techniques - Code of practice for Information Security Management”
  • AS2834 Computer Accommodation
  • IT Infrastructure Library (ITIL)
  • COBIT 4.1 (Control objectives for Business and Information Related Technology)
  • Relevant internal policy / legislative environment.

We pride ourselves in being able to perform technically complex reviews and we expect all our IT audit staff to possess qualifications in IT as well as accounting or related field.

Our services cover governance, control and risk. The following are examples of areas we actively provide assurance over:

  • IT General Control Environment
  • Application Control Environment including implementation reviews
  • IT Corporate Governance, Operations and Service Management
  • IT Configuration and Implementation
  • IT Security / Vulnerability Assessment (Internal and External environments including wireless)
  • IT Probity Advisory
  • Risk Management
  • Software Management
  • Business Process Mapping / Gap Analysis
  • Business Continuity Management / Disaster Recovery Planning
  • Incident Management
  • Software Application Controls
  • Server Management
  • Computer Accommodation
  • Green IT
  • IT Audit Training
  • Regulatory Body Compliance Audits.

Our strong understanding of current industry standards and ability to adapt organisational specific processes, risks and priorities allows us to undertake unique engagements that provide independent assurance, strategies, designs etc to applicable stakeholders within the organisation.


James Cottrill