The goal of this document is to illustrate the importance of the IS audit in the security process and to explain in detail the tasks associated with the IS audit. On the one hand, the guide illustrates how an organisation can establish the IS audit in the organisation and which activities need to be carried out by the organisation in conjunction with the IS audit, for example evaluations of IS audit reports or the planning and co-ordination of the IS audits. On the other hand, the IS auditors are provided with a practical guideline containing concrete specifications and information on.