Comparative Analysis of IT Control Frameworks in the Context of SOX By: Malik Datardina, CA, CISA University of Waterloo.

Slides:



Advertisements
Similar presentations
Internal Control–Integrated Framework
Advertisements

Sarbanes-Oxley Act of 2002 UAA – ACCT 316 – Fall 2003 Accounting Information Systems Dr. Fred Barbee.
Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Control and Accounting Information Systems
Control and Accounting Information Systems
Audit Committee in Albania Legal framework Law 9226 /2006 “On banks in Republic of Albania” Law 9901/2008 “On entrepreneurs and commercial companies” Corporate.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
PwC David Devlin 23 April 2002 Auditor Independence in a Global Market Place.
1 Sarbanes-Oxley Section 404 June 29,  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance.
1 Archive Access Audit Keys to Effective Compliance Lifecycle Management.
SOX and IT Audit Programs John R. Robles Thursday, May 31, Tel:
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
1 Pertemuan 6 Internal Control System Matakuliah:A0274/Pengelolaan Fungsi Audit Sistem Informasi Tahun: 2005 Versi: 1/1.
Internal Control Pertemuan 05 s.d 06 Matakuliah: F0712 / Lab Sistem Informasi Akuntansi Tahun: 2007.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
Information Systems Controls for System Reliability -Information Security-
COSO Framework Update IIA Columbus Chapter May 17, 2013
Internal Auditing and Outsourcing
Continual Service Improvement Process
Chapter 9: Introduction to Internal Control Systems
An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.
Chapter 3 Internal Controls.
The Sarbanes-Oxley Act of PricewaterhouseCoopers Introduction of Panel Members The Sarbanes-Oxley Act of 2002 What Companies Should Be Doing Now.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
Karen Evans, national director of the U.S. Cyber Challenge and former Office of Management and Budget administrator Auditor Responsibility?
Vijay V Vijayakumar.  SOX Act  Difference between IT Management and IT Governance  Internal Controls  Frameworks for Implementing SOX  COSO - Committee.
This Lecture Covers Review of Internal Control Definitions.
Anders Malmeby Swedish Working Group on Internal Control Partner and Head of Audit at KPMG Sweden Anders Malmeby Swedish Working Group on Internal Control.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter Three IT Risks and Controls.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
Overview:  Different controls in an organization  Relationship between IT controls & financial controls  The Mega Process Leads  Application of COBIT.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
EEC Internal Control Plan (ICP) FY2013. Direction from Secretary Malone Acting EEC Commissioner Thomas Weber shall initiate a top-to-bottom review of.
Everyone’s Been Hacked Now What?. OakRidge What happened?
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Internal Control in a Financial Statement Audit
1 Chapter Three IT Risks and Controls. 2 The Risk Management Process Identify IT Risks Assess IT Risks Identify IT Controls Document IT Controls Monitor.
Scandals (in the public and private sector)  Enron  Worldcom  Livent  Nortel  HRDC  Sponsorship Scandal.
Presented By Tay Un Soo Senior VP, Bank of Commerce President of ISACA - Malaysia Chapter 1999 National Accountants Conference THRIVING IN THE DIGITAL.
Roadmap to Maturity FISMA and ISO 2700x. Technical Controls Data IntegritySDLC & Change Management Operations Management Authentication, Authorization.
5-1 McGraw-Hill/Irwin ©2007 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk.
Richard F. Chambers, CIA, CGAP Vice President, IIA Learning Center The Institute of Internal Auditors.
Roadmap For An Effective Compliance And Ethics Program The Top Ten Things the Board Must Know [Name of Presenter] [Title] [Date]
Everyone’s Been Hacked Now What?. OakRidge What happened?
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Compliance Audit Subcommittee Reporting Work Plan Copenhagen, Denmark 6th of May 2010.
Chapter 9: Introduction to Internal Control Systems
COBIT®. COBIT® - Control Objectives for Information and related Technology. C OBI T was initially created by the Information Systems Audit & Control Foundation.
ISO Registration Common Areas of Nonconformances.
Internal/External Audit Corporate Governance part 5.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
Service Organization Control Reports What Have We Learned? Chris Bruhn DIRECTOR, IT RISK SERVICES, BKD, LLP SAS 70 ENDS EXIT TO SSAE 16.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Service Organization Control (SOC)
Internal control objectives
COSO Internal Control s Framework
Internal control - the IA perspective
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

Comparative Analysis of IT Control Frameworks in the Context of SOX By: Malik Datardina, CA, CISA University of Waterloo

Introduction SOX avg cost: $5 million/per company Impact on the way of business Increased focus on IT: "The Sarbanes-Oxley legislation has created a greater need for businesses to have IT controls in place” Bill Levant, Partner, Deloitte

Goal Some fundamental questions –How does the SOX legislation result in the implementation of IT Controls? –What IT Controls are expected to be in place?

Agenda Basic issues to be covered: Part I – SOX Basics: What does SOX actually mandate? What does the PCAOB require? What does COSO require? Are there alternatives? Part II: The Frameworks How are COBIT, ITCG, ISO 17799, and SysTrust relevant to SOX and analysis? Part III: Discussion and Suggestions for Further Research

Agenda Public Company SOX Sec 101 – Establishment of the PCAOB Sec 302 – Responsibility for Finan Reporting Sec 404 – Mgmt Assessment of Int Ctrl Sec 409 – Real time issuer disclosures Auditing Standard No. 2: Audit of Internal Control over Financial Reporting Minimum Std  Gen Controls: -Oper Ctrls -SDLC -Access mgmt IT Controls  Application Controls  Info Quality : Timely, Current, Accurate, Accessible, etc. Additional Guidance

What does SOX actually mandate? SOX Sec 101 – Establishment of the PCAOB Sec 302 – Responsibility for Finan Reporting Sec 404 – Mgmt Assessment of Int Ctrl Sec 409 – Real time issuer disclosures Sec 101: Establishes the PCAOB Sec 302: CEO & CFO Responsibility of the FS –Designed effectively –Operating effectively within the last 90 days –Disclosure material weaknesses –Disclosure of frauds; material and otherwise Sec 404 – Mgmt’s Assessment of Controls –Management is responsible –Management assess operating effectiveness –Auditors must also provide an independent assessment of operating effectiveness Sec 409 – Real time disclosure of material changes

What does the PCAOB require? SOX Sec 101 – Establishment of the PCAOB Sec 302 – Responsibility for Finan Reporting Sec 404 – Mgmt Assessment of Int Ctrl Sec 409 – Real time issuer disclosures  Gen Controls: -Oper Ctrls -SDLC -Access mgmt IT Controls  Application Controls Auditing Standard No. 2: Audit of Internal Control over Financial Reporting Minimum Std Guidance Program Development/Program Chgs Computer Operations Access to programs and data Processing Integrity Controls PCAOB

OBJECTIVES: Effectiveness and efficiency of operations Reliability of financial reporting Compliance with the applicable laws and regulations KEY COMPONENTS: Control Environment (e.g. Tone at the Top) Risk Assessment Control activities Information and Communication (e.g. information management). Monitoring

OBJECTIVES: Effectiveness and efficiency of operations Reliability of internal and external financial reporting requirements Compliance with applicable laws, regulations, and internal policies. KEY COMPONENTS: Purpose Commitment Capability Monitoring & Learning

OBJECTIVES: Facilitate its effective and efficient operation Ensure the quality of internal and external reporting ensure compliance with applicable laws, regulations, and internal policies. KEY COMPONENTS: Maintaining a sound system of internal control Reviewing the effectiveness of internal control The board’s statement on internal control Internal audit

Differences “…tighter, easier to grasp model of internal control than the somewhat complex COSO framework.” Robert Moeller on CoCo, former Audit Director of Sears CoCo: 20 Auditable Control Objectives Similarities Similar objectives between all three standards Other Considerations Consider cost-benefit in terms of familiarity with auditors, regulators, etc.

What does the COSO require? SOX Sec 101 – Establishment of the PCAOB Sec 302 – Responsibility for Finan Reporting Sec 404 – Mgmt Assessment of Int Ctrl Sec 409 – Real time issuer disclosures Minimum Std Additional Guidance  Gen Controls: -Oper Ctrls -SDLC -Access mgmt IT Controls  Application Controls  Info Quality : Timely, Current, Accurate, Accessible, etc. Auditing Standard No. 2: Audit of Internal Control over Financial Reporting Data Centr Oper Ctrls System Sftware Ctrls Applictn Systm Dvlpmnt and Maintenance Ctrls Access Security Ctrls COSO

What does the COSO require? CategoryPCAOBCOSO Systems Development Program development  Program changes   System Software Controls  Application System Development and Maintenance Controls OperationsComputer operations  Data Center Operation Controls SecurityAccess to programs and data  Access security controls

What does the COSO require? INFORMATION QUALITY Information is timely, Information is current, Information is accurate, and Information is accessible. OTHER COMPONENTS Control environment (e.g. budget and IT) Risk assessment Monitoring

Public Company SOX Sec 101 – Establishment of the PCAOB Sec 302 – Responsibility for Finan Reporting Sec 404 – Mgmt Assessment of Int Ctrl Sec 409 – Real time issuer disclosures Auditing Standard No. 2: Audit of Internal Control over Financial Reporting Minimum Std  Gen Controls: -Oper Ctrls -SDLC -Access mgmt IT Controls  Application Controls  Info Quality : Timely, Current, Accurate, Accessible, etc. Additional Guidance PART II: The IT Control Framework

COBIT PO2.1 Information Architecture Model CONTROL OBJECTIVE Information should be kept consistent with needs and should be identified, captured and communicated in a form and timeframe that enables people to carry out their responsibilities effectively and on a timely basis. Accordingly, the IT function should create and regularly update an information architecture model, encompassing the corporate data model and the associated information systems. The information architecture model should be kept consistent with the IT long-range plan. PO or “Planning & Organization” represents 1 of the 4 “domains” PO2 represents the High-Level Control “PO2.1 Information Architecture Model” represents the “detailed control objective”. The text that follows explains what is required of this objective. 4domains 34 Hi-Level Objctvs 318 Detailed Objctvs

ISO Security Control Clause (11) Main Security Category (39) Control (135): Each ‘control’ includes the following information: Description of Control Implementation guidance Other information 11 Sec Ctrl Clause 39 Security Categories 135 Controls

ITCG 7 Control Issues 31 Ctrl Objctives 162 Min Ctrl Stds 744 Control Techniques

SysTrust Control LayersSecurityAvailabilityProcessing Integrity On-Line Privacy Confidentiality Policy Communication Procedures Monitoring Totals

Fit with PCAOB/COSO COBITISO 17799ITCGSysTrust General Controls XXXX Application controls XXX Specific category X

Analysis: Suitable Criteria Frameworks  COBITISO 17799ITCGSysTrust Characteristics of Suitable Criteria ↓ RelevanceHighMediumHigh Understan dability MediumHigh Complete ness HighMediumHigh Concisene ss MediumHigh

Discussion and Suggestions for Further Research Ultimate goal: Aid management in stewardship SysTrust: Processing Integrity Principle Overlap between SysTrust, COBIT, ITCG Other frameworks: ITIL, ISO , CMM, etc Outsourcing: SAS70, Sec5970 Other SOX sections: Sec. 409, sec. 802.