August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Karl Heins -- Director of IT Audit Services Office of the University.

Slides:



Advertisements
Similar presentations
Internal Control Integrated Framework
Advertisements

Internal Control–Integrated Framework
Federal Audit Executive Council (FAEC) June 2012 Bi-Monthly Meeting Heather I. Keister Doris G. Yanger June 14, 2012 Green Book Update.
Chapter 10 Accounting Information Systems and Internal Controls
Control and Accounting Information Systems
Control and Accounting Information Systems
Prepared by Wa'el Bibi,CPA,CIA,CISA1 Internal Control Integrated Framework An Overview.. Bibi Consulting COSO’s Source: COSO’s Internal Control Integrated.
Internal Control.
Audit Committee in Albania Legal framework Law 9226 /2006 “On banks in Republic of Albania” Law 9901/2008 “On entrepreneurs and commercial companies” Corporate.
Managing Fraud Risk in Government 2015 IIA District Conference March 10, 2015 David A. King, CPA, CFE – Director, Special Investigations North Carolina.
Security Controls – What Works
Under the Microscope Business Officers Meeting March 7, 2006 Presented by Randy Van Dyke Internal Control.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
August 9, 2005 UCCSC IT Security at the University of California A New Initiative Jacqueline Craig. Director of Policy Information Resources and.
© 2002 Association of Certified Fraud Examiners. All rights reserved. The Certified Fraud Examiners’ Fraud Prevention Checkup - An Introduction Toby J.F.
INTERNAL CONTROL. INTERNAL CONTROL DEFINED  INTERNAL CONTROL IS A PROCESS - EFFECTED BY AN ENTITY'S BOARD OF DIRECTORS, MANAGEMENT, AND OTHER PERSONNEL.
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Operational Auditing--Fall Accounting Business Skills “The What”  Business perspective  Organizational focus  Bias for action  Communication.
Operational Auditing---Spring 2000 (2/3) 1 Accounting Business Skills “The What” 4 Business perspective 4 Organizational focus 4 Bias for action 4 Communication.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Managing Fraud Risk in Higher Education 2014 UNC Fall Controller's Workshop November 10, 2014 David A. King, CPA, CFE – Director, Special Investigations.
The University of California Strengthening Business Practices: The Language of Our Control Environment Dan Sampson Assistant Vice President Financial Services.
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Chapter 11.  The board is ultimately responsible for risk management  Oversee strategic risks, operational risks, and financial risks  Many federal.
National Association of College and University Attorneys 1 November 11, 2009 NACUA Fall 2009 Workshop November 2009.
 Corporate governance is based on three interrelated components: corporate governance principles, functions and mechanisms.
Internal Auditing and Outsourcing
Why Information Governance….instead of Records & Information Management? Angela Fares, RHIA, CRM, CISA, CGEIT, CRISC, CISM or
Central Piedmont Community College Internal Audit.
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Chapter 9: Introduction to Internal Control Systems
An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.
Chapter 3 Internal Controls.
UNM and Health System Internal Audit Departments Internal Audit Department Orientation Manu Patel, Internal Audit Director Purvi Mody, Executive Director,
Establishing A Compliance Program: It Makes Sense
INTERNAL CONTROL OVER FINANCIAL REPORTING
Chapter Three IT Risks and Controls.
Chapter 5 Internal Control over Financial Reporting
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Compliance Management Platform ™. Compliance Management Platform Compliance is the New Marketing – Position yourself to thrive in the new regulatory and.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
Richard F. Chambers, CIA, CGAP Vice President, IIA Learning Center The Institute of Internal Auditors.
The Connection between Risk Management and Internal Control in Organizations Mag. Norbert Wagner Budapest,
13.6 Legal Aspects Corporate IT Security Policy. Objectives Understand the need for a corporate information technology security policy and its role within.
IT Controls Global Technology Auditing Guide 1.
Chapter 9: Introduction to Internal Control Systems
Internal Control Systems
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
Control and Security Frameworks Chapter Three Prepared by: Raval, Fichadia Raval Fichadia John Wiley & Sons, Inc
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
COMPLIANCE MANAGEMENT – VARIOUS PROVISIONS OF LABOUR LAW and STATUTORY REGULATIONS BY OPTIMUM COMPLIANCE CONSULTANTS PVT LTD.
Internal Controls For Municipalities Vermont State Auditor’s Office – August 2008.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
Board Structure & Responsibilities Governing Board Online Training Module.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
SUNY Maritime Internal Control Program. New York State Internal Control Act of 1987 Establish and maintain guidelines for a system of internal controls.
CPA Gilberto Rivera, VP Compliance and Operational Risk
Chapter 9 Control, security and audit
PEM PAL IA COP Internal Control Working Group COSO Principles
Internal control objectives
Internal Control Integrated Framework
Building the Foundation of Compliance
Building the Foundation of Compliance
Internal control - the IA perspective
Unit 11 October 22, 2017.
Internal Audit’s Role in Preventing Fraud and Corruption
Costanza Schivi - 9 April 2019
Presentation transcript:

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Karl Heins -- Director of IT Audit Services Office of the University Auditor UC Office of the President

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Why Security Programs Are Important New Legal Requirements –CA Privacy Law -- SB1386 –HIPAA –SOX Increasing Threats Trends –Automation; speed of attack tools –Increasing sophistication of attack tools –Faster discovery of vulnerabilities –Increasing permeability of firewalls –Increasing asymmetric threat –Increasing threat from infrastructure attacks Increasing Use of Technology

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs COSO Components for Governance Control Environment –Board, Management and Employee commitment to internal controls Risk Assessment –Identification and analysis of risk exposures Control Activities –Detective Controls –Preventive Controls Information and Communication –Information is captured and reported timely Monitoring –Oversight and evaluation of control effectiveness –Reporting and acting on deficiencies

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Audit’s Role -- Security’s Role Auditors – Evaluating the effectiveness of control systems, and contribute to ongoing effectiveness. Often a significant monitoring role. Chartered by Board Management, including Security Professionals are responsible for the system of internal controls. As delegated by Board

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Work of Auditors Focus on Controls –Financial Controls –Compliance with Laws, Regulations and Policy –Efficiency and Effectiveness Types of Work –Audits –Investigations –Advice and Consultation

August 9, 2005UCCSC Converting Policy to Reality Building Campus Security Programs Where you do not have Authority, tips to Influence Standing Logic Outside Expert Passion