1 Executive Briefing October 16, 2001 2  Deputy State Auditor, MIS & IT Audit, Commonwealth of Massachusetts  Adjunct faculty at Bentley College 

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

. . . a step-by-step guide to world-class internal auditing
Internal Control–Integrated Framework
PRESENTATION ON MONDAY 7 TH AUGUST, 2006 BY SUDHIR VARMA FCA; CIA(USA) FOR THE INSTITUTE OF INTERNAL AUDITORS – INDIA, DELHI CHAPTER.
IMFO Audit & Risk Indaba June 2012
Chapter 10 Accounting Information Systems and Internal Controls
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley The CPA Profession Chapter 2.
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
TI BISNIS ITG using COBIT &
COBIT - II.
1 IT Directors Briefing October 16,  Deputy State Auditor, MIS & IT Audit, Commonwealth of Massachusetts  Adjunct faculty at Bentley College.
IS Audit Function Knowledge
Quality evaluation and improvement for Internal Audit
The Information Systems Audit Process
COBIT Framework Introduction. Problems with IT? – Increasing pressure to leverage technology in business strategies – Growing complexity of IT environments.
The CPA Profession Chapter 2.
SAFA- IFAC Regional SMP Forum
Purpose of the Standards
Trinidad & Tobago Corporate Governance Code 2013
Board responsibility for internal control and risk management by Kiattisak Jelatianranat Chairman, The Institute of Internal Auditors of Thailand Director,
1 Business Continuity and Compliance Working Together Kristy Justice, AVP WaMu Card Services 08/19/2008.
How can projects be controlled?
Guiding principles for the Federal acquisition system
Opportunities & Implications for Turkish Organisations & Projects
Charting a course PROCESS.
Conducting the IT Audit
Control environment and control activities. Day II Session III and IV.
Internal Auditing and Outsourcing
Information Security Governance 25 th June 2007 Gordon Micallef Vice President – ISACA MALTA CHAPTER.
Management Guidelines IT Governance Institute
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Continual Service Improvement Process
The CPA Profession Chapter 2 By Arens et. al. Learning Objective 1 Describe the nature of CPA firms, what they do, and their structure.
Planning an Audit The Audit Process consists of the following phases:
INFORMATION ASSURANCE USING C OBI T MEYCOR C OBI T CSA & MEYCOR C OBI T AG TOOLS.
Chapter Three IT Risks and Controls.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Certificate IV in Project Management Introduction to Project Management Course Number Qualification Code BSB41507.
Agency Risk Management & Internal Control Standards (ARMICS)
Presented By Tay Un Soo Senior VP, Bank of Commerce President of ISACA - Malaysia Chapter 1999 National Accountants Conference THRIVING IN THE DIGITAL.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
Institute of Internal Auditors COBIT Presentation October 9, 2001.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Kathy Corbiere Service Delivery and Performance Commission
0 ©2015 U.S. Education Delivery Institute While there is no prescribed format for a good delivery plan, it should answer 10 questions What a good delivery.
Or How to Gain and Sustain a Competitive Advantage for Your Sales Team Key’s to Consistently High Performing Sales Organizations © by David R. Barnes Jr.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
PIC EU-28 Conference Paris, 26 – 27 November 2015 PIC An EU Approach Assurance Maps An Introductory workshop Nathan Paget United Kingdom.
#325 - CobiT and Service Delivery Debra Mallette, CISA, CSSBB Kaiser Permanente IT.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
IT Auditor’s Role in IT Governance Fred C. Roth, CISA MIS Training Institute Session 425.
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
Company LOGO Chapter4 Internal control systems. Internal control  It is any action taken by management to enhance the likelihood that established objectives.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
1 Using CobiT to Enhance IT Security Governance LHS © John Mitchell John Mitchell PhD, MBA, CEng, CITP, FBCS, MBCS, FIIA, CIA, CISA, QiCA, CFE LHS Business.
ISACA Willamette Valley Chapter Luncheon Thursday, March 20, 2008 Practical Auditors Guide for CobiT Steve Balough, CISA.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
BIL 424 NETWORK ARCHITECTURE AND SERVICE PROVIDING.
Contents IT BALANCED SCORECARD AND BUSINESS BALANCED SCORECARD
Alignment of COBIT to Botswana IT Audit Methodology
Taking the STANDARDS Seriously
COBIT 5 and GRC Date.
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

1 Executive Briefing October 16, 2001

2  Deputy State Auditor, MIS & IT Audit, Commonwealth of Massachusetts  Adjunct faculty at Bentley College  Member of CobiT Steering Committee  Served as member of Y2K Coordinating Council, Commonwealth of Massachusetts  International President of ISACA/F  Served as member of Governor’s Commission on Computer Crime, Governor’s Commission on Computer Technology and Law, and Governor’s Task Force on E- Commerce 

3  How does responsible managment keep the ship on course?  How do we achieve satisfactory results for our clients and stake-holders?  How do we adapt in a timely manner to “best practices” for our organization’s environment?

4 When we spend a lot of money and what we have built doesn’t work, or is difficult to maintain, or is not accepted, or appears vulnerable, People have a lot to say

5 Stakeholders apply pressure Shareholders and Executive Lower cost, higher profitability and increased market share Customers and Staff More functionality at lower cost and greater ease of use Society Greater accountability for executives in private and public sector

6 E-business Factors u Guarantee of delivery u Customer service u Ease of use u Increased dependence u Security What are the customers saying ?

7 u Focus on Operational Risk within which security and IT are very significant u All major risk issues have been caused by breakdowns in 3 Internal control 3 Oversight 3 Information Technology What signals are regulators giving? Federal Reserve

8 Most Pressing Concerns about Information Technology  Security  Availability  Integrity and Effectiveness  Cost

9 September 11 th has Impacted us all in a Whole Lot of Ways  Personal  Economic  Security  Risk

10 Measures?Scales? Indicators?

11 The Answer Lies In:  Having clear understandings of the strategic value of technology  Bringing that strategic value to reality  Having appropriate frameworks of control  Employing the fundamentals of IT goverance  Building mechanisms to provide adequate assurance that IT governance objectives are addressed

12 CobiT CobiT’s Control Objectives and Management Guidelines are valuable IT governance tools that help in the understanding and management of risks and benefits associated with information integrity, security and availability and the management of related IT.

13 lAuthoritative, up-to-date set of generally accepted IT control objectives and control practices for day-to-day use by business managers and auditors. lStructured and organized to provide a powerful control model

14  Executive Summary -- Senior Executives (CEO, COO, CFO, CIO)  Framework -- Senior Operational Management (Directors of IS and Audit / Controls)  Control Objectives -- Middle Management (Mid-Level IS and IS Audit/ Controls Managers)  Audit Guidelines -- The Line Manager and Controls Practitioner (Applications or Operations Manager and Auditor)  Implementation Tool Set -- Any of the above  Management Guidelines -- Management and Audit

15  Management Guidelines Includes: – Critical Success Factors – Key Performance Indicators – Key Goal Indicators – Maturity models C OBI T

16  Right information, to only the right party, at the right time.  Information that is relevant, reliable and secure.  Information provided by systems that have integrity by a well-managed and properly controlled IT environment.

17 IT Governance Objectives  IT is aligned with the business enabling the entity to maximize benefit  IT resources are safeguarded and used in a responsible and ethical manner  IT-related risks are addressed through appropriate controls and managed to minimize risk and exposure

18  Need for better operational control  While technology makes new business processes possible, it may come with reduced control  Demand for increased effectiveness, efficiency and security  Strategic importance of technology  The need to hold officers and senior management accountable and strengthen governance

19  Addresses key attributes of information produced by IT.  Provides a working control model for IT- related control objectives  Links recommended control practices for IT to business and control objectives.  Assists in evaluating appropriateness of controls

20 CobiT is an Authoritative Source  Built on a sound framework of control and IT-related control practices.  Aligned with de jure and de facto standards and regulations.  Has undergone expert review and exposure process, now in its 3 rd edition

21 CobiT Sources Professional standards for internal control and auditing (COSO, IFAC, AICPA, IIA, etc) Technical standards (ISO, EDIFACT, etc.) Codes of Conduct Qualification criteria for IT systems and processes (ISO9000, ITSEC, TCSEC, etc.) Industry practices and requirements from industry forums (ESF, I4) Emerging industry-specific requirements from banking, e-com, IT manufacturing.

22 Based on a Strong Foundation and Sound Principles of Internal Control

23 What is Internal Control? How it is defined impacts its design, exercise, and evaluation.

24 Control (as defined by C OBI T ) The policies, procedures, practices and organizational structures designed to provide reasonable assurance that business objectives will be achieved and that undesired events will be prevented or detected and corrected.  Source: C OBI T Control Objectives, p. 12.

25 IT Control Objective A statement of desired result or purpose to be achieved by implementing control procedures in a particular IT activity

26 Internal Control Controls are framed by what is to be attained (control objectives) and the means to attain those goals (the controls).

27 CobiT Incorporates Key Internal Control Requirements ð Systemization ð Documentation ð Standards, defined expectations ð Measurement ð Appropriate risk assessment

28 CobiT Incorporates Key Internal Control Requirements ð Well-defined operational and control objectives ð Appropriate controls ð Competent and trustworthy people ð Monitoring & evaluation

29 CobiT Framework  Built on an understanding of the:  relationship of controls to control objectives,  importance of focusing on the relationship of control objectives to business objectives and business processes,  value of managed processes and resources tied to strategic initiatives.

30 BUSINESS PROCESSES BUSINESS PROCESSES INFORMATION IT RESOURCES data application systems technology facilities people data application systems technology facilities people effectiveness efficiency confidentiality integrity Availability Compliance reliability effectiveness efficiency confidentiality integrity Availability Compliance reliability Information Criteria ? Do they match? Framework What you need What you get

31 Framework’s Three Components  “Business Requirements” for Information  IT Resources  IT Processes

32 Information Criteria -- The 1st Component  Effectiveness  Efficiency  Confidentiality  Integrity  Availability  Compliance  Reliability of Information

33 IT Resources -- The 2nd Component  Data  Application Systems  Technology  Facilities  People

34 Domains Processes Tasks & Activities Natural grouping of processes, often matching an organizational domain of responsibility A series of joined tasks & Activities with natural (control) breaks. Actions needed to achieve a measurable result. Activities have a life-cycle whereas tasks are discrete (4) (34) (318) Information Processes ( 3rd component )

35 Planning/ Organization Acquisition / Implementation Delivery / Support Monitoring COBIT Domains: Information Processes (3rd Component)

36 How do they relate ? IT Processes IT Resources IT Resources Business Requirements  Data  Information Systems  Technology  Facilities  Human Resources  Planning and organisation  Aquisition and implementation  Delivery and Support  Monitoring  Effectiveness  Efficiency  Confidenciality  Integrity  Availability  Compliance  Information Reliability

37 IT Resource Management CobiT underscores and demonstrates that IT resources need to be managed by naturally grouped processes to provide organizations with type and quality, and security of information required to achieve organizational objectives.

The WATERFALL Navigation Aid -- High Level Control Objectives for Each Process The control of which satisfy is enabled by considering IT Processes Business Requirements Control Statements Control Practices See Framework, p

39 CobiT’s Control Objectives  Contains management control practices by high-level control objective within four categories, or domains, of the control objectives.  Contains statements of the desired results or purposes to be achieved by implementing specific control procedures within an IT activity.  Assists in establishing clear policy and good practices for IT control

40 Planning and Organization  Strategy and tactical plans for IT  Identify ways that IT can best contribute to the achievement of business objectives  Plan, communicate, and manage the realization of the strategic vision  Establish the IT organization, and  Set the stage for managing information and the technology infrastructure

41 Acquisition and Implementation Domain  IT solutions – Identified – Developed or acquired – Implemented – Integrated into the business processes  Change and maintain existing systems

42 Delivery and Support Domain  Deliver required services  Ensure security and continuity of services  Set up support processes, including training  Process data (including “application” controls)

43 Monitoring Domain  Regularly assess IT processes for – Quality – Appropriateness of controls – Compliance with control requirements  Addresses management oversight of organization’s control provisions  Provide for an audit function

44 Relation to Other Control Models CobiT is in alignment with other control models: – COSO – COCO – Cadbury – King

45 Reinforces Control Responsibilities  Management -- has primary responsibility for ensuring that controls are in place and in effect to provide reasonable assurance that operational and control objectives will be met.  Users -- exercise and monitor controls.  Audit -- evaluates, advises and provides statements of assurance regarding the adequacy of controls.

47 As a control model, CobiT should be As a control model, CobiT should be tailored to agency, IT platform, and system standards and system standards Use CobiT as the Structure to which you link agency-specific operational and control requirements, policies, and standards

48 Using CobiT  Organizational tool  Management tool  Good practices standard  Strengthen third-party contracts  Criteria for Evaluation  Strengthen risk management  Basis for improved management

49 Using CobiT in Evaluating IT Controls ð Selecting areas or control objectives for evaluation ð Determining type of evaluation ð Engagement/assessment planning ð Framing scope and evaluation objectives to CobiT ð Development of control assessment approach

50 Use of CobiT to Plan Control Evaluations  Assessing the control environment and identifying high risk processes  Conducting a high-level and detailed policy and procedures review  Performing a control review  Using CobiT-related matrices

51 Using CobiT Matrices to Focus on:  IT Functions – Their importance? – Level of performance? – Control documentation?  Responsible Parties of IT – Performed by? – Contracted services? – Primary responsible party?  Risk Assessment – Importance, level of risk, control documentation

52 CobiT Helps Identify Key Risks to the Organization è Unaware of the risks è Poor understanding of CSFs è Absence of KPIs è No “scorecard” or basis of measurement è Absence of monitoring and evaluation è Weak IT control environment

53 CobiT helps senior management, business process owners, and IT gain increased benefit from independent examiners

54 Audit Insight: Overview of Audit Planning  Auditee selection (may be CobiT driven)  Entrance Conference and on-site preaudit information gathering (CobiT)  Develop proposed scope and audit objectives (CobiT-framed)  Finalize audit work program (CobiT- framed)  Engagement conference (reference CobiT as criteria) and audit (CobiT as review criteria)

55 Audit Planning:  Who are they? ( type of agency, enabling legislation )  What do they do? ( mission, business objectives )  How do they plan to do it? ( strategy/plan )  How do they do it? ( functions, processes )  With what resources? ( IT, operational resources, management & staff, raw materials, etc.)  By what rules? ( policies, standards, legal and regulatory requirements )  Under what risks? ( risk analysis )

56 Audit Planning:  Who does it? ( internal & external players, their roles and responsibilities )  Who knows what is done? ( reporting lines, designated points of accountability )  How do they known it is done right? ( measurement registers, assurance mechanisms, evaluations, score cards, etc. )  Where are they? ( centralized or distributed )

57 Audit Guidelines  They are evaluation guidelines.  Generic guideline identifies various tasks to be performed in assessing ANY control objective within a process. This generic guideline extracted all repetitive tasks into one -- to be performed for all control objectives.  34 others are specific process-oriented task suggestions to provide management assurance that a control objective is being addressed.

58 Obtaining an understanding of business requirements, related risks, and relevant control measures Evaluating the appropriateness of stated controls Assessing compliance by testing whether the stated controls are working as prescribed, consistently and continuously. Substantiating the risk of the control objective not being met by using analytical techniques and/or consulting alternative sources. The IT process is therefore audited by:

59 Organization & Management Review è Clarity and appropriateness of responsibility definitions è assignment of responsibilities è points of accountability è reporting mechanisms for actions taken and activities performed è Efforts to monitor and evaluate adequacy of exercise of responsibilities

60 Using Cobit to Address Third-Party Providers of IT-Related Services è Are desired processes are in place? è Have we established accountability è Do we agree on the levels of control? è Do the service contracts adequately identify deliverables and responsibilities? è Is there ongoing monitoring and evaluation of providers and partners?

61 Using the Management Guidelines

62  Are they doing the right things?  Are they doing it the right way?  Are they being done well?  Are we getting benefits? What IT Problem? IT governance is the responsibility of the board of directors and consists of the leadership, organizational structures and processes that ensure that the organization’s IT sustains and extends the organization’s strategies and objectives. What does the agency do?  Cascading strategy and goals  Organizational alignment  A control framework  Balanced Business Scorecard How does management react?

63 u Starts from the premise that IT needs to deliver the information that the enterprise needs to achieve its objectives. u Promotes process focus and process ownership u Divides IT into 34 processes belonging to four domains u Looks at fiduciary, quality and security needs of enterprises and provides for seven information criteria that can be used to generically define what the business requires from IT u Effectiveness u Efficiency u Availability, u Integrity u Confidentiality u Reliability u Compliance. u Planning u Acquiring & Implementing u Delivery & Support u Monitoring CobiT : An IT control framework

64 l “Due diligence” l IT is strategic to the business l IT is critical to the business l Expectations and reality don’t match l IT involves huge investments and large risks Why governance?

65 If so, wouldn’t you want to know whether your information technology organization is:  Likely to achieve its objectives?  Resilient enough to learn and adapt?  Judiciously managing the risks it faces?  Appropriately recognizing opportunities and acting upon them? IT is strategic to most businesses

66  Generic and action oriented  For the purpose of IT Control profiling - what’s important? Awareness - where’s the risk? Benchmarking - what do others do?  Supporting decision making and follow up Key performance indicators of IT processes Critical success factors of controls Control implementation choices Management Guidelines

67 Management Guidelines Critical Success Factors l the most important things to do to increase the probability of success of the process l observable - usually measurable - characteristics of the organisation and process l are either strategic, technological, organizational or procedural in nature l focus on obtaining, maintaining and leveraging capability and skills l expressed in terms of the IT process, not necessarily the business

68 Management Guidelines Key Goal Indicators l describe the outcome of the process and are therefore a ‘lag’ indicator, i.e., measurable after the fact l Are an indicator of the success of the process but may also be expressed in terms of the business contribution if that contribution is specific to the IT process l represent the process goal, i.e., a measure of “what”, a target to achieve l may also describe a measure of the impact of not reaching the process goal l KGIs are IT oriented but are also business driven l Are expressed in precise measurable terms wherever possible

69 Management Guidelines Key Performance Indicators l are a measure of “how well” the process is performing l predict the probability of success or failure in the future, i.e. KPIs are ‘LEAD’ indicators l are process oriented but IT driven l focus on the process and learning dimensions of the balanced scorecard l are expressed in precise measurable terms l should help in improving the IT process

70 Maturity Models Refer to business requirements and control capabilities at different levels Are scales that lend themselves to pragmatic comparison Are scales where the difference can be made measurable in an easy manner Are recognizable as a “profile” of the enterprise in relation to IT governance and control Assist in determining As-Is and To-Be positions relative to IT governance and control maturity Lend themselves to support gap analysis to determine what needs to be done to achieve a chosen level

Non- Existent InitialRepeatableDefinedManagedOptimised Enterprise current status International standard guidelines Industry best practice Enterprise strategy Legend for symbols usedLegend for rankings used 0 - Management processes are not applied at all 1 - Processes are ad hoc and disorganised 2 - Processes follow a regular pattern 3 - Processes are documented and communicated 4 - Processes are monitored and measured 5 - Best practices are followed and automated Start from a Maturity Model

72 What Management should do  Align IT strategy with business goals  Cascade strategy and goals down into the agency  Set up organizational structures that facilitate strategy implementation  Adopt a control and governance framework  Provide IT infrastructures that facilitate creation and sharing of business information  Embed responsibilities for risk management in the organization  Focus on important IT processes and core IT competencies  Measure performance (Balanced Business Scorecard)

73 CobiT Recognizes  IT is an integral part of the organization  IT governance is an integral part of corporate governance  Focus on control objectives can strengthen appropriateness and use of internal controls  Measurement is crucial to internal control  Monitoring and evaluation are integral to a system of internal control

74 Benefits of CobiT  Supports IT governance objectives.  Helps ensure that IT processes are defined and assigned.  Helps to focus on control objectives.  Leads to more cost-effective IT services.  Helps management to better utilize internal and external auditors  Provides benchmarks for best practices for IT management and IT control

75 Benefits of CobiT  Helps ensure the organization complies with applicable rules, regulations and contractual obligations.  Opportunity for complementary adoption of COSO and CobiT (or other control models).  Authoritative nature of Cobit encompassing adoption of well-recognized and established standards for IT control.

76 Benefits of CobiT  Strengthens assessment, understanding and exercise of appropriate internal controls.  Provides a good framework for risk assessment and risk management.  Improves communication among management, business process owners, users and auditors regarding IT governance, and between internal and external audit.  Helps auditors and control professionals to be proactive business advisors.

77 Benefits of CobiT  Provides a framework for ensuring that outsourced IT functions are addressed in third- party contracts.  Helps to strengthen the relationship between IT Services and the user community through improved SLAs.  Supports management’s efforts to demonstrate due diligence with respect to IT-based operations.

78 Benefits of CobiT Helps to provide reasonable assurance that: – IT process objectives are understood – IT risks have been identified – Appropriate controls have been implemented – Appropriate monitoring and evaluation processes in effect – IT process objectives and can be achieved.

79 CobiT  Strengthens the understanding, design, implementation, exercise, and evaluation of internal control through improved focus on information criteria and IT-related control objectives  Strengthens management’s efforts to “ensure” and Audit’s efforts to provide “assurance”

80 A Tip regarding CobiT  CobiT is generic - adapt it to your organization in cooperation with the business-process owners! – Determine focus (quality, security, fiduciary) – Harmonize existing policies and procedures with CobiT – Determine control responsibilities – Identify key performance indicators and critical success factors

81 Another Tip or Two  Study it carefully -- it takes some time to understand - keep in mind that you are dealing with a control framework  Start with CobiT’s Control Objectives Framework and progress to the Management Guidelines.  Build the mechanisms to provide assurance that control objectives are being addressed and that controls are working as intended

82 CobiT For additional information: or or give me a call at (617) ext 135

Go Forth and C OBI T ize Thank You 83