This chapter describes concepts, methodologies and tools used for auditing computer and management information systems. It encompasses both technological and managerial aspects. It details the main concepts (audit process, audit domains, audit criteria). It concentrates on two main methodologies for information systems auditing: COBIT proposed by the Information Systems Audit and Control Foundation (ISACF) and INFAUDITOR developed by the authors. A few examples of audit results are presented.
