Download presentation
Presentation is loading. Please wait.
1
Governance, audit and digital preservation
April 14, 2004 Governance, audit and digital preservation Boudien J. Glashouwer RE RI CISA April 14, 2004
2
Governance, audit and digital preservation
April 14, 2004 Table of contents Governance Quality and Maturity Information Security Audit Digital preservation April 14, 2004 Erpanet - Antwerp
3
Strategic business goals
Governance, audit and digital preservation April 14, 2004 Strategic business goals Profit or Non-profit Core business is digital preservation or Digital preservation is secondary April 14, 2004 Erpanet - Antwerp
4
Governance, audit and digital preservation
April 14, 2004 Legislation Democracy Buying and selling agreements Computer crime Transparency Privacy Finance Specific laws Records management April 14, 2004 Erpanet - Antwerp
5
Governance, audit and digital preservation
April 14, 2004 Hot issues Sarbanes Oxley Act, 2002, USA Financial reporting, auditing, internal control, standard setting, corporate governance Basel II, New Basel Capital Accord, 2003, Europe Limitation of credit risks and operational risks in banking April 14, 2004 Erpanet - Antwerp
6
Governance, audit and digital preservation
April 14, 2004 Governance How to keep the ship on course? How to achieve objectives? How to timely adapt? Governance manage, control, account for and supervise April 14, 2004 Erpanet - Antwerp
7
Governance, audit and digital preservation
April 14, 2004 Goals, strategy and policy Laws and regulations Standards and control models Commitment on top level Plan Do Needs Responsibilities Projects Communication Meetings Organisation Quality Security Management cycle Correct/ Adapt Check Monitor, evaluate, learn New standards? Adapt policy Measure Alignment Compliance Assessment Audit/assurance April 14, 2004 Erpanet - Antwerp
8
Plan
9
Governance & control models
Governance, audit and digital preservation April 14, 2004 Governance & control models COSO USA, Internal Control Integrated Framework, 1992 business ethics, effective internal control, corporate governance COBIT Governance, control and audit for IT and related technology, 1996 IT-controls support the COSO-framework April 14, 2004 Erpanet - Antwerp
10
Governance, audit and digital preservation
April 14, 2004 COSO Committee of Sponsoring Organisations of the Treadway Commission (fraudulent financial reporting) Internal Control Integrated Framework 1. Control environment (company level) 2. Risk assessment (achieve objectives) 3. Control activities (policies, procedures, practices, general & application controls) 4. Information and communication (at all levels) 5. Monitoring of the internal control (oversight) April 14, 2004 Erpanet - Antwerp
11
Governance, audit and digital preservation
April 14, 2004 CobiT Planning and Organisation strategy, quality, human resources Acquisition and Implementation systems development and installing Delivery and Support service levels, operations, security Monitoring internal control, assurance, audit April 14, 2004 Erpanet - Antwerp
12
Do
13
Governance, audit and digital preservation
April 14, 2004 Business Performance Manage business Take action Produce Can be a bakery or digital preservation... April 14, 2004 Erpanet - Antwerp
14
Quality and maturity of business processes
Governance, audit and digital preservation April 14, 2004 Quality and maturity of business processes ISO 9000 general quality ISO records management ITIL IT Infrastructure Library EFQM, total quality management April 14, 2004 Erpanet - Antwerp
15
Information Security Risk analysis business processes Awareness
Standard ISO 17799 Baseline security levels Manager, security-officer, security manager, auditor Service Level Agreement (SLA and SLM) Certification April 14, 2004 Erpanet - Antwerp
16
Check
17
Monintoring & Measuring
Critical Success Factors Key Goal Indicators Key Performance Indicators Dashboards Scorecards Benchmarking April 14, 2004 Erpanet - Antwerp
18
Auditing Internal audit External audit Self assessment
Internal Audit Service External audit Financial auditing Operational auditing IT/EDP-auditing April 14, 2004 Erpanet - Antwerp
19
Resources Business processes People Application systems Technology
input, througput, output, outcome People Application systems Technology Facilities Data April 14, 2004 Erpanet - Antwerp
20
Criteria Effectiveness Efficiency Confidentiality Integrity
Availability Compliance Reliability April 14, 2004 Erpanet - Antwerp
21
Audit approach Legislation, standards Management norms Audit plan
Audit tools Report Communication Certification? April 14, 2004 Erpanet - Antwerp
22
Correct/Adapt
23
Improvement Define maturity level Learn Take small steps
Grow and improve quality of business processes! April 14, 2004 Erpanet - Antwerp
24
Digital preservation No information, no control...
Without digital preservation governance, control and audit not possible! Can the audit of business processes be enough or… Do we need a special preservation audit or certificate? April 14, 2004 Erpanet - Antwerp
25
Take the challenge Enjoy this conference in Antwerp! April 14, 2004
Erpanet - Antwerp
26
Websites www.coso.org www.isaca.org www.erpanet.org April 14, 2004
Erpanet - Antwerp
27
Contact Het Expertise Centrum, The Hague www.hec.nl
April 14, 2004 Erpanet - Antwerp
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.