Basics to Performing Value-added IT Audits

Published  . 0 views
↓ Download
Basics to Performing Value-added IT Audits
1 / 1
Basics to Performing Value-added IT Audits - slide 1 of 39 Basics to Performing Value-added IT Audits - slide 2 of 39 Basics to Performing Value-added IT Audits - slide 3 of 39 Basics to Performing Value-added IT Audits - slide 4 of 39 Basics to Performing Value-added IT Audits - slide 5 of 39 Basics to Performing Value-added IT Audits - slide 6 of 39 Basics to Performing Value-added IT Audits - slide 7 of 39 Basics to Performing Value-added IT Audits - slide 8 of 39 Basics to Performing Value-added IT Audits - slide 9 of 39 Basics to Performing Value-added IT Audits - slide 10 of 39 Basics to Performing Value-added IT Audits - slide 11 of 39 Basics to Performing Value-added IT Audits - slide 12 of 39 Basics to Performing Value-added IT Audits - slide 13 of 39 Basics to Performing Value-added IT Audits - slide 14 of 39 Basics to Performing Value-added IT Audits - slide 15 of 39 Basics to Performing Value-added IT Audits - slide 16 of 39 Basics to Performing Value-added IT Audits - slide 17 of 39 Basics to Performing Value-added IT Audits - slide 18 of 39 Basics to Performing Value-added IT Audits - slide 19 of 39 Basics to Performing Value-added IT Audits - slide 20 of 39 Basics to Performing Value-added IT Audits - slide 21 of 39 Basics to Performing Value-added IT Audits - slide 22 of 39 Basics to Performing Value-added IT Audits - slide 23 of 39 Basics to Performing Value-added IT Audits - slide 24 of 39 Basics to Performing Value-added IT Audits - slide 25 of 39 Basics to Performing Value-added IT Audits - slide 26 of 39 Basics to Performing Value-added IT Audits - slide 27 of 39 Basics to Performing Value-added IT Audits - slide 28 of 39 Basics to Performing Value-added IT Audits - slide 29 of 39 Basics to Performing Value-added IT Audits - slide 30 of 39 Basics to Performing Value-added IT Audits - slide 31 of 39 Basics to Performing Value-added IT Audits - slide 32 of 39 Basics to Performing Value-added IT Audits - slide 33 of 39 Basics to Performing Value-added IT Audits - slide 34 of 39 Basics to Performing Value-added IT Audits - slide 35 of 39 Basics to Performing Value-added IT Audits - slide 36 of 39 Basics to Performing Value-added IT Audits - slide 37 of 39 Basics to Performing Value-added IT Audits - slide 38 of 39 Basics to Performing Value-added IT Audits - slide 39 of 39
Description: Basics to Performing Value-added IT Audits Presented by: Edwin Caron, CISM, CRISC, CIA, CISA, CBE Background Edwin Caron, CIA, CISM, CRISC, CISA, CBE - A Management Consultant with Guidehouse LLC (formerly, PwCs National Security

Related Topics

Download Presentation

"Basics to Performing Value-added IT Audits" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Basics to Performing Value-added IT Audits Presented by:
Edwin Caron, CISM, CRISC, CIA, CISA, CBE<br>
slide2. Background Edwin Caron, CIA, CISM, CRISC, CISA, CBE - A Management Consultant with Guidehouse LLC (formerly, PwC’s National Security Practice), Mr. Caron began his career at The Navy Exchange Service Command (NEXCOM) as an internal auditor. He has almost 20 years of experience in IT Risk Management and Audit, and Audit Readiness consulting.
Edwin grew up in Norfolk, Virginia, and graduated from Old Dominion University with a BS/BA in Finance.
He lives in Springfield VA with his wife (Erica), son (Sixto) and pup (Isabella Stinker).<br>
slide3. Agenda Defining a “value-added” IT Audit
Defining IT Audit Universe
Examples of “Low-hanging Fruit”
Summary Session
Q&A<br>
slide4. Quiz<br>
slide5. Quiz Question #1: How would you define Value-added audit?<br>
slide6. Defining “Value-added”<br>
slide7. Defining “Value-added” “Value” means different things to different people, depending on their perspective<br>
slide8. Quiz<br>
slide9. Quiz Question #2: What is the value of IT Auditors?<br>
slide10. Defining “Value-added” Provide independent and/or objective operational analysis following a systematic and disciplined approach to examine business functions and control activities and provide recommendations which improve control and governance processes thereby helping the organization achieve its strategies and objectives.<br>
slide11. Defining “Value-added” Implement risk-based IT audit procedures based on a formal risk assessment methodology<br>
slide12. What are we auditing The “IT audit universe”<br>
slide13. What are we auditing Common Controls<br>
slide14. What are we auditing Technical Controls<br>
slide15. What are we auditing Other Reviews<br>
slide16. In Other Words The “IT audit universe”
An inventory of audit areas that is compiled and maintained to identify areas for audit during the audit planning process.<br>
slide17. Common Control Areas Governance - IS/IT strategy, policies, remediation of findings, performance monitoring and continuous audits;<br>
slide18. Common Control Areas Governance - IS/IT strategy, policies, remediation of findings, performance monitoring and continuous audits;
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity;<br>
slide19. Common Control Areas Governance - IS/IT strategy, policies, remediation of findings, performance monitoring and continuous audits;
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity;
External service providers—Telecommunications, outsourcers, cloud service providers, maintenance companies, consultants, auditors, contract and relationship management, performance monitoring, and management (both at headquarters and delegated to remote offices)<br>
slide20. Technical Areas Business applications—Software (both packaged and custom), mobile apps, end-user computing (particularly spreadsheets and personal databases), license management, updates, patches and fixes, change management, accreditation, etc.<br>
slide21. Technical Areas Business applications—Software (both packaged and custom), mobile apps, end-user computing (particularly spreadsheets and personal databases), license management, updates, patches and fixes, change management, accreditation, etc.
Mobile—Bring your own device (BYOD), lost and compromised devices, access to sensitive corporate data, participation in social networks, disclosures of sensitive information, etc.<br>
slide22. Technical Areas Business applications—Software (both packaged and custom), mobile apps, end-user computing (particularly spreadsheets and personal databases), license management, updates, patches and fixes, change management, accreditation, etc.
Mobile—Bring your own device (BYOD), lost and compromised devices, access to sensitive corporate data, participation in social networks, disclosures of sensitive information, etc.
Emerging Technologies – Artificial Intelligence, RPA and Distributed Ledger Technology<br>
slide23. Other Reviews and Assessment Areas Security—Frameworks (e.g., ISO 27001 or NIST SP800-xx), awareness, certifications, breaches, etc.
Risk management—Frameworks (e.g., COBIT 5 for Risk), risk assessments, mitigation measures, reviews, etc.
Data—Quality, classification, data models, database administration, etc., and guidelines used
IS/IT projects—Departures from plan (time/budget), change management, project management, changing risk areas, etc.<br>
slide24. How we audit Defining audit objectives for each audit area<br>
slide25. Audit Objectives Audit Area
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity.

Audit Objectives could include:<br>
slide26. Audit Objectives Audit Area
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity.

Audit Objectives could include:
Operating systems “are securely configured and protected from unauthorized modification”.<br>
slide27. Audit Objectives Audit Area
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity.

Audit Objectives could include:
Review of controls over physical and logical access to data center and hosted applications”.<br>
slide28. Audit Objectives Audit Area
Operations - Data centers, secure configuration of local and wide area networks, physical and logical security, disaster recovery and business continuity.

Audit Objectives could include:
Assessment of disaster recovery and business continuity plans and test methodologies.<br>
slide29. How we audit Defining audit objectives for each area<br>
slide30. How we audit Defining audit objectives for each area
Understanding Risk Tolerance<br>
slide31. How we audit Defining audit objectives for each area
Understanding Risk Tolerance
Perform an assessment of the risks of adverse events<br>
slide32. How we audit Defining audit objectives for each area
Understanding Risk Tolerance
Perform an assessment of the risks of adverse events (What if?)<br>
slide33. What if? 2+2 = 5<br>
slide34. What if? If 2+2 = 5, then there must be
misconfiguration of a business logic/rules resulting in systemic errors impacting every business transaction<br>
slide35. What if? The use of unlicensed software exposes organizations to possible litigation<br>
slide36. What if? Major changes to existing applications and/or the introduction of new systems or data requirements increase the risks of data corruption<br>
slide37. Summary Establishing a “risk-based” IT Audit plan determines the priorities of the internal audit activity by linking critical risks to specific objectives and business processes to organize the audit universe and prioritize the risks<br>
slide38. Summary The inclusion of IT audit coverage is essential to a value-added audit function;
Provides an early warning system;
Identifies issues and creates the opportunity for resolution before the issue becomes a “surprise.”
Integration with emerging technologies, provides a risk-agile and resilient internal audit program<br>
slide39. Questions ?<br>