Technology Audit Plan ----BCSY University

Slides:



Advertisements
Similar presentations
MSCG Training for Project Officers and Consultants: Project Officer and Consultant Roles in Supporting Successful Onsite Technical Assistance Visits.
Advertisements

Internal Audit Who? What? When? How? Why? In brief...
1 LBNL Enterprise Computing (EC) January 2003 LBNL Enterprise Computing.
Pertemuan Matakuliah: A0214/Audit Sistem Informasi Tahun: 2007.
Office of Inspector General (OIG) Internal Audit
Measuring the effectiveness of government IT systems Current ANAO initiatives to enhance IT Audit integration and support in delivering Audit outcomes.
Buffalo State College Internal Control Program Presented to: Buffalo State College Line Staff Delivered by: BSC IC Program & Department Managers.
Created May 2, Division of Public Health Managing Records What is a Record? What is a Records Retention & Disposition Schedule? Why is this Important?
Chicagoland IASA Spring Conference
Roles and Responsibilities
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Agency Risk Management & Internal Control Standards (ARMICS)
Advanced Program in Auditing and Accounting Regulation Module 12 Enhancing Statutory Audit Quality from a Financial Regulator’s Perspective Presenter:
Project Kick-off Meeting Presented By: > > > > Office of the Chief Information Officer.
College Reviews An Overview Presented by Howard Lutwak, CIA Director of Internal Audit January 2004.
Enterprise Cybersecurity Strategy
WESTERN PA CHAPTER OF THE AMERICAN PAYROLL ASSOCIATION – NOVEMBER 4, 2015 Risk Management for Payroll.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Primary Steps for Achieving ISO Certification.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
Audit Committee 1 June 2005 Overview of the Audit Function in the Council and Role of Audit Committee.
Management Innovation – Finance
Auditing Concepts.
Internal and external control in an automated environment
CPA Gilberto Rivera, VP Compliance and Operational Risk
Finance Committee Update
IS4550 Security Policies and Implementation
Compliance with Framework of Quality Control - General & Specific Controls CA Vimal Chopra, Ex Chairman of CIRC of ICAI.
Career and Financial Management
Data Architecture World Class Operations - Impact Workshop.
Software Configuration Management
February 24, 2017 Alain Gonthier, P.Eng.
Pressure Cooker: Access Controls in New and Existing ERP Systems
Service Owner: Andrea Beesing 9 February 2016
Implementation Strategy July 2002
ServiceNow Implementation Knowledge Management
Responsibilities & Tasks Week 2
Chapter 9 Control, security and audit
Project Roles and Responsibilities
TRINITY UNIVERSITY HOSPITAL INTERNAL EXIT MEETING
Technology Audit Plan ----BCSY University
AAHRPP Accreditation Welcome to the University of Georgia’s presentation for accreditation of the human research protection program (HRPP). This presentation.
Office 365 Security Assessment Workshop
Audit Planning Presentation - Disaster Recovery Plan
SQL Database Audit Planning
Active Directory Audit
CHANGE MANAGEMENT FOR WINDOWS OS
Scope management Chapter 5 Copyright ©2016 Pearson Education, Inc.
Guidance notes for Project Manager
UNLV Data Governance Executive Sponsors Meeting
[INSERT APPLICABLE REGIONAL ENTITY NAME/LOGO]
Alignment of COBIT to Botswana IT Audit Methodology
Cybersecurity Special Public Meeting/Commission Workshop for Natural Gas Utilities September 27, 2018.
IS4550 Security Policies and Implementation
Sam Houston State University
IS4680 Security Auditing for Compliance
Project Management Process Groups
WHAT TO EXPECT: A CROWN CORPORATION’S GUIDE TO A SPECIAL EXAMINATION
IS4680 Security Auditing for Compliance
Employee engagement Delivery guide
Sam Houston State University
TRINITY UNIVERSITY HOSPITAL
TECHNOLOGY ASSESSMENT
Internal Audit Who? What? When? How? Why? In brief . . .
Security Policies and Implementation Issues
An overview of Internal Controls Structure & Mechanism
Process and Procedure Documentation
Presentation transcript:

Technology Audit Plan ----BCSY University Class: MIS-5201 Team Member: Marsha Billups Qiyu Chen Ping Sun Qianru Yang

Agenda Technology background overview Scope of your audit Risk assessment IT Audit team members’ roles and responsibilities in this audit Key dates and deliverable Breakdown of audit hours for planning, testing, reporting phases

Background BCSY University is a private university located in Downtown Boston. There is a Intensive English Language Program (IELP) department in BCSY university attracts students from all over the world to the historic city of Boston, a cultural, artistic and culinary center. IELP department’s enterprise application has vulnerability on change management, and data protection which may impact user authentication, confidentiality, integrity, availability.

Audit Scope IT Asset Management Data Protection Problem Management

Risk Assessment - Major changes Risks: USB devices risk Dependent financial office risk Dumpster diving risk Changes: Using uniform USB drives that were given by department Building independent financial office Using paper shredders for all hard copy documents

Risk Assessment - Main Risks Operation Risk: Weak account and password access control Cross Training Risk: Weak separate duties control High Authority Risk: Weak authority division Significant Project Risk: System using in uncontrolled place and environment Paper Documents Holding Risk: Weak physical control for hard copy documents.

Risk Assessment - Impact/Likelihood Risk Category Impact Likelihood Overall Operation Risk High Cross Training Risk Moderate Low High Authority Risk Significant Project Risk Paper Documents Holding Risk

Audit Team Members The Boss, Audit Manager Marsha Billups.IT Audit Lead Qiyu Chen, Sr. IT Auditor Ping Sung, IT Auditor Qianru Yang - IT Auditor

IT Audit Manager Roles & Responsibilities Accountable for Audit Onsite for Kick-Off Meeting, Key Walk-Throughs & Audit close-out Ensures Audit process standardization across platforms Identifies & resolves Audit issues Communicates with Sr. Leadership Reviews all Audit documents Authors Executive Audit Summary and Audit Report

IT Lead Auditor Roles & Responsibilities Plans Audit & Authors Scope letter with Management review Helps ensure Audit process standardization across platforms Leads all aspects of the audit, risk assessment, controls analysis & review process including planning, control analysis, testing, reporting, and making/writing recommendations Manages Audit teams day-to-day activities Communicates with Leadership Prepares, reviews & compiles all Audit work papers Drafts/Compiles comprehensive Audit Report for Manager

Sr. IT Auditor Roles & Responsibilities Owns, designs, plans & executes Audit plan for assigned Audit area(s) Communicates with assigned Audit Area owner(s) Performs review of IT policies, standards & procedures Recommends corrective actions to improve controls, enhance operations & increase efficiency Performs independent testing and prepares/consolidated workpapers Identifies, develops, documents & helps resolve audit issues Assists in the preparation of the draft Audit Report Reviews work of supporting IT Auditor

IT Auditor Roles & Responsibilities Supports Sr. It Auditor in planning & execution of Audit of assigned area Works with the Audit Area to secure requested data in an easily accessible, organized manner Performs independent testing & prepares associated work papers Reviews IT policies, standards & procedures Recommends corrective actions to improve controls, enhance operations & increase efficiency Identifies, develops, documents & helps resolve audit issues Assists in the preparation of the draft Audit Report

Breakdown of audit hours for planning, testing, reporting phases

Key Dates & Deliverables

Questions? Thank you!!!