RELATIONSHIP OF TASK TO KNOWLEDGE STATEMENT Pert-2 The TASK Statement are what the CISA candidate is expected to know how to do. The KNOWLEDGE Statement.

Slides:



Advertisements
Similar presentations
IT Governance & Quality Management
Advertisements

Enterprise Grants Management The Time is Right. Transformation From To.
Chapter 10 Accounting Information Systems and Internal Controls
ACG 6415 SPRING 2012 KRISTIN DONOVAN & BETH WILDMAN IT Security Frameworks.
Agenda COBIT 5 Product Family Information Security COBIT 5 content
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
Auditor General’s Office One key audit focus area – Compliance with Laws and Regulations.
TI BISNIS ITG using COBIT &
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
Security Controls – What Works
By Collin Smith COBIT Introduction By Collin Smith
Internal Control Concepts Knowledge. Best Practices for IT Governance IT Governance Structure of Relationship Audit Role in IT Governance.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
ISO 17799: Standard for Security Ellie Myler & George Broadbent, The Information Management Journal, Nov/Dec ‘06 Presented by Bhavana Reshaboina.
Information Security Governance and Risk Chapter 2 Part 1 Pages 21 to 69.
First Practice - Information Security Management System Implementation and ISO Certification.
The Information Systems Audit Process
Plug and Socket Preparing IT Management for Governance Rob England v6v6.
Internal Auditing and Outsourcing
The Role of the Actuary in a General Insurance Company Yangon, Myanmar 14 July 2014 Scott Yen.
Governance of the IT Function
IAEA International Atomic Energy Agency How do you know how far you have got? How much you still have to do? Are we nearly there yet? What – Who – When.
Evolving IT Framework Standards (Compliance and IT)
Continual Service Improvement Process
INFORMATION ASSURANCE USING C OBI T MEYCOR C OBI T CSA & MEYCOR C OBI T AG TOOLS.
Chapter Three IT Risks and Controls.
Overview:  Different controls in an organization  Relationship between IT controls & financial controls  The Mega Process Leads  Application of COBIT.
Challenges in Infosecurity Practices at IT Organizations
Presented by: Meg Boyd The Blue Mountains Drinking Water System: DWQMS Overview.
Roadmap to Maturity FISMA and ISO 2700x. Technical Controls Data IntegritySDLC & Change Management Operations Management Authentication, Authorization.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Committee of Sponsoring Organizations of The Treadway Commission Formed in 1985 to sponsor the National Commission on Fraudulent Financial Reporting “Internal.
Building Capability.  In order to successfully operate an architecture function within an enterprise, it is necessary to put in place appropriate organization.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
TI Tata Kelola Sistem dan Teknologi Informasi BISNIS &
ITIL Framework. What is ITIL ? ITIL stands for the Information Technology Infrastructure Library. ITIL is the international de facto management framework.
Security Standards and Threat Evaluation. Main Topic of Discussion  Methodologies  Standards  Frameworks  Measuring threats –Threat evaluation –Certification.
Advanced Accounting Information Systems Day 20 Control and Security Frameworks October 9, 2009.
IT Governance: COBIT, ISO17799 & ITIL. Introduction COBIT ITIL ISO17799Others.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
IT GOVERNANCE  Objective : The objective of this area is to ensure that the Certified Information Systems Auditor ( CISA ) candidate understands and can.
Samantha Schreiner University of Illinois at Urbana- Champaign BA 559 – Professor Michael Shaw December 15 th, 2008 A Survey of IT Governance Through COBIT,
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
TMS - Cooperation partner of TÜV SÜD EFFECTIVE SERVICE MANAGEMENT based on ISO/IEC & ISO/IEC
The Second Annual Medical Device Regulatory, Reimbursement and Compliance Congress Presented by J. Glenn George Thursday, March 29, 2007 Day II – Track.
12-CRS-0106 REVISED 8 FEB 2013 BAI (Build, Acquire, and Implement) CDG4I3 / Audit Sistem Informasi Angelina Prima K | Gede Ary W. KK SIDE
2/20/2016 Leveraging IT Governance and COBIT Chip Council, PhD, CGEIT, CISM, CISA Matt Schmidt, MS, CISSP, CISA Adjunct Professors, University of Minnesota.
Control and Security Frameworks Chapter Three Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Getting to Grips with CobiT – Enterprise Architecture, a conseptual approach to IT Covernance or how to understand the difference between IT Governance.
Alex Ezrakhovich Process Approach for an Integrated Management System Change driven.
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
Belgian Technical Cooperation Internal audit presentation.
IT Auditor’s Role in IT Governance Fred C. Roth, CISA MIS Training Institute Session 425.
ForrTel: IT Governance Frameworks
Presented by. Information! Information is a key resource for all enterprises. Information is created, used, retained, disclosed and destroyed. Technology.
COBIT 5 Executive Summary © 2012 ISACA. All rights reserved.1.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
#327 – Legal and Regulatory Risk: Silent and Possibly Deadly Deborah Frazer, CPA CISA CISSP Senior Director, Internal Audit PalmSource, Inc.
12-CRS-0106 REVISED 8 FEB 2013 EDM (Evaluate, Direct, and Monitor) CDG4I3 / Audit Sistem Informasi Angelina Prima K | Gede Ary W. KK SIDE
Donald JG Chiarella, PhD, CISM, CDMP, PEM, CHS-CIA, MBA.
Michael J. Novak ASQ Section 0511 Meeting, February 8, 2017
EITS Planning & Decision Support
Introduction What is IS Audit
CIGFARO ANNUAL CONFERENCE – 11 OCTOBER 2017
همسویی چارچوب‏هاو به‏روشهای حاکمیت و مدیریت فناوری اطلاعات
Governance, audit and digital preservation
Change Management and COBIT®. ISACA London Chapter Presentation
Data Governance & Management Skills and Experience
VOTE 26: AGRICULTURE ESTIMATE OF NATIONAL EXPENDITURE 2003/04
Presentation transcript:

RELATIONSHIP OF TASK TO KNOWLEDGE STATEMENT Pert-2 The TASK Statement are what the CISA candidate is expected to know how to do. The KNOWLEDGE Statement delineate what CISA candidate is expected to know in order to perform the TASK The TASK and KNOWLEDGE Statements are approximately mapped in table 1. insofar as it is possible to do so. Note that although there is often overlap, each TASK Statement will generally map to several KNOWLEDGE Statement. 2-1

Table 1., TASK and KNOWLEDGE Statement Mapping TASK Statement KNOWLEDGE Statement T1. Evaluate the effectiveness of IT, KS.1 Knowledge of the purpose of IT strate governance structure to ensure tegies, policesn, standards and the adequate board control over the procedures for an organization and decision, directions and performan- the essential element of each KS.1a Knowledge of IT governance framework KS.1b Knowledge of tne use of control frame- works (cth. CoBiT, COSO, ISO ) KS.1c Knowledge of practices for monitoring and reporting of IT performence (cth. Balanced Scorecards, key performan- ce indikator=KPI ) KS.1d Knowledge of IT resource investment and allocation practices (cth. Portfolio management ROI ) 2-2

T,2 Evaluate IT organizational structure KS.2a Knowledge of the purpose of IT strategies, and human resources (personnel) polices, standards and procedures for an or- management to ensure that they ganization and the essential elements of support the organization’s strategies each and objectives KS.2b Knowledge of organizational structure roles and responsibilities related to the use and management of IT KS.2c Knowledge of IT human resources (personnel) management. T.3 Evaluate the IT Strategy and process KS.3a Knowledge of the purpose of IT strategies, for their development, approval, im- policies, standards and procedures for an plementation and maintenance to organization and the essential elements of ensure that they support the organi- each. zation’s strategies and objectives KS.3b Knowledge of the processes for the deve- of IT strategirs, policies, standards and pro- cedures ( cth.protection of information as- sets, business continuity and disaster reco - very, systems and infrastructure life cycle. KS.3c Knowledge of quality management strategies and policies. 2-3

TASK and Knowledge Statement Mapping ( Continued T.4 Evaluate the organizational’sKS.4a Knowledge of the processes for the de- IT policies, standards, proce velopment,implementation and mainte dures and processes for their nance of IT strategies, policies, stan – development, approval, imple dards and procedures (cth. Protection mentation and maintenance to of information assets, business conti ensure that they support the IT nuity and disaster recovery, systems strategy and comply with regu- and infrastructure life cycle manage – latory and legal requirements. Ment and IT service delivery and sup- port. KS.4b Knowledge of generally accepted inter national IT standards and guidlines. KS4.c Knowledge of relevant legislative and regulatory issues (cth. Privacy, Intellec tual Property, Corporate governance requirements) 2-4

TASK and KNOWLEDGE Statement Mapping ( Continued ) T.5 Evaluate management practices KS.5a Knowledge of the processes for the de to ensure compliance with the velopment, implementation and mainte the organization’s IT strategy, nance of IT strategies, policies, stand policies, standards and produres ard and procedures (cth. Protection of information assets, business continui ty and disaster recovery, systems and infrastrutures life cycle management and IT service delivery and support. KS.5b Knowledge of quality management strategies and policies. KS.5c Knowledge of generally accepted inter national IT standards and guidlines. KS.5d Knowledge of enterprise IT architectu re and its implications for setting long-term strategies directions. KS.5e Knowledge of the use of control frame works (cth. CoBit, COSO, ISO ) KS.5f Knowledge of the use of maturity and process and improvement models ( Cth. CMM, CoBit ). KS.5g Knowledge of contrating strategies, processes and contract management practices. 2-5

TASK and KNOWLEDGE Statement Mapping ( continued 0 KS.5h Knowledge of IT human resource (personnel ) management. KS.5i Knowledge of IT resource investment and allocation practices (cth. Portfolio management ROI ) T.6 Evaluate IT resource invest KS.6a Knowledge of IT human resource ( ment,use and allocation prac personnel ) management. tices to ensure aligment with the organization’s strategies and objectives. T.7 Evaluate IT contracting stra- KS.7a Knowledge of contracting startegies, pro tegies and policies and con- cesses and contract management prac- to ensure tahat they support tices. the organization’s strategies and objectives. 2-6

TASK and KNOWLEDGE Statement Mapping ( Continued ) T.8 Evaluate risk management KS.8a Knowledge of the processes for the deve- practices to ensure that the lopment implementation and maintenance organization’s IT-related risk of IT strategies, policies, standards and are property managed. Procedures (cth. Protection of information assets, business continuity and disaster recovery, systems and infrastructure life cycle management and IT service delivery and support. KS.8b Knowledge of risk management ad toond methodology and tools. T.9 Evaluate monitoring and as- KS.9a Knowledge of quality management strate surance practices to ensure gies and policies. that the board and execu- KS.9b. Knowledge of practices for monitoring tive management receives andreporting of IT performance (cth.BSC, sufficient and timely informa KPI ). tion about IT performance ========= thank for your attention ========= 2-7