Affiliation:
1. Kuban State Agrarian University named after I.T. Trubilin (Kuban SAU)
Abstract
Subject. This article focuses on the issues related to the audit of information systems and cybersecurity.
Objectives. The article aims to determine the key areas of legal regulation of information security audit, taking into account the requirements of the time, technical capabilities and digital transformations taking place in society and the global space.
Methods. For the study, we used a case study method, analysis, computational and graphical method, data systematization, and the ecosystem approach.
Results. The article identifies gaps in the methodological framework and statutory regulation of the audit of information systems, substantiates the need for systematization and further development of the legislative framework for the audit of information security, and identifies the objects of information technologies that require special attention. It proposes to make certain changes to the Federal Law On Auditing regarding the introduction of information security checks of business entities into the list of other services, as well as develop standards for government auditing, which will unify this type of activity.
Conclusions and Relevance. The number of cybercrimes is steadily growing, and this is due to both the widespread digitalization of ecosystems and the high level of technical and intellectual training of persons committing fraudulent actions. Ensuring the information security of economic entities and government agencies is impossible without conducting an audit that reduces the risk of cyber threats. The results of the study can be used to develop the regulatory framework for the audit of information systems, as well as for further scientific research and practical application.
Publisher
Publishing House Finance and Credit
Reference19 articles.
1. Selezneva I.P., Sitnov A.A. [Audit in the context of digitalization of the Russian economy: risks, opportunities, and limitations]. Problemy ekonomiki i yuridicheskoi praktiki = Economic Problems and Legal Practice, 2020, vol. 16, no. 4, pp. 98–103. URL: Link (In Russ.)
2. Makarenko S.I. [Audit of information security – the main stages, conceptual framework, classification of types]. Sistemy upravleniya, svyazi i bezopasnosti, 2018, no. 1, pp. 1–29. (In Russ.) URL: Link
3. Kashirskaya L.V., Zurnadzh'yants Yu.A. [Objects of information security audit and directions of their verification]. Auditor, 2022, vol. 8, no. 1, pp. 21–31. URL: Link (In Russ.)
4. Bulyga R.P., Safonova I.V. [Transformation of audit methodology with the use of Blockchain and DLT technologies]. Uchet. Analiz. Audit = Accounting. Analysis. Auditing, 2021, vol. 8, no. 5, pp. 6–13. (In Russ.) URL: Link
5. Safonova M.F., Kisilevich T.I. [Transformation of information and analytical audit support during the digitalization of economic and accounting systems]. Mezhdunarodnyi bukhgalterskii uchet = International Accounting, 2022, vol. 25, iss. 7, pp. 780–805. (In Russ.) URL: Link