Databases, comprised of data and database management systems, store data so that they can be used by different programs without concern for the data structure or organization. The ability of databases to accommodate large volumes of data, has led databases to be widely adopted. Despite this widespread adoption, however, databases continue to be a prime target for malicious actors due to the intrinsic value of the business and personal data stored, processed and transmitted on them.
To assist auditors in providing assurance over the deployment of databases, ISACA offers a Database Audit Program. This audit program provides control objectives, controls and testing for audit components. Included in the audit program is general testing for databases such as secure default database configurations, database logging, database backups/recovery, user access management, change management, and database encryption. Testing considerations specific to commonly used database platforms (MySQL 8.0.27, MS SQL Server 2019, and Oracle 19.3 Enterprise) also include:
• MySQL 8.0.27 — Authorizing database access and prepared statements
• MS SQL Server 2019 — Using parameterized dynamic SQL statements
• Oracle 19.3 Enterprise — Assessing external procedure security
This audit program acknowledges the privacy and confidentiality concerns arising from the use of databases and provides auditors with a tool to evaluate databases to determine if the control environment is operating as designed.
After completing check-out, your download will be available under MyISACA > Resources.