EY helps clients create long-term value for all stakeholders. Enabled by data and technology, our services and solutions provide trust through assurance and help clients transform, grow and operate.
At EY, our purpose is building a better working world. The insights and services we provide help to create long-term value for clients, people and society, and to build trust in the capital markets.
Comment Letter - GAO's proposal to update the methodology for assessing design, implementation and operating effectiveness of information system controls
In our comment letter, we support the efforts of the Government Accountability Office (GAO) to update the Federal Information System Controls Audit Manual (FISCAM) to reflect changes in relevant auditing standards, guidance, control criteria and technology since the last revision in 2009. We suggest certain clarifications to enhance the proposed guidance and reduce potential diversity in implementation. FISCAM provides the methodology to assess the design, implementation and operating effectiveness of controls over information systems in audits of federal and governmental entities.