1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, 12-13 October 2009 Introduction to IT audits PART II IT.

Slides:



Advertisements
Similar presentations
. . . a step-by-step guide to world-class internal auditing
Advertisements

New IA IA Clinic March 30, Definition of Internal Auditing Internal auditing is an independent, objective assurance and consulting activity designed.
PRESENTATION ON MONDAY 7 TH AUGUST, 2006 BY SUDHIR VARMA FCA; CIA(USA) FOR THE INSTITUTE OF INTERNAL AUDITORS – INDIA, DELHI CHAPTER.
Auditing, Assurance and Governance in Local Government
STRATEGIC PLANNING FOR Post-Clearance Audit (PCA)
ITAuditing Using GAS & CAATs
S16: Auditing Standards.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Draft information note on the Annual.
Developing Global Professional Standards Shanker Gopalkrishnan, CMC, FIMC Chair, Global Professional Standards Committee, ICMCI IMCI National Convention,
Assurance, Attestation, and Internal Auditing Services
By Collin Smith COBIT Introduction By Collin Smith
IS Audit Function Knowledge
1 Pertemuan 3 Auditing Standards and Responsibilities Matakuliah:A0274/Pengelolaan Fungsi Audit Sistem Informasi Tahun: 2005 Versi: 1/1.
The Internal Audit Function in the Public Sector
Quality evaluation and improvement for Internal Audit
Office of Inspector General (OIG) Internal Audit
External Quality Assessments
Purpose of the Standards
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Conducting the IT Audit
REVIEW AND QUALITY CONTROL
Internal Auditing and Outsourcing
© 2007 ISACA ® All Rights Reserved DAMA-NCR Chapter Meeting March 11, 2008.
C. P. Mansoor S. Ahmed M. Com, PGDBA.  Not confined to Independent Audit  Systematic Examination of  Records  Procedures  Systems  Operations.
The Institute of Internal Auditors
Session 3 & 4. Institute of Internal Auditors Inc (IIA) was created for internal auditors in 1941 Generally accepted criteria of a profession are: –Adopting.
Essential Enterprise IT Governance with COBIT®5 Date: 7 th and 8 th October 2015 Time: 9 am to 5.30 pm Venue: Iverson Associates, Center Point Bandar Utama,
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 System evaluation and sampling – first.
Chapter Three IT Risks and Controls.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Implementation of Article 73 Ljubljana,
OVERVIEW OF INFORMATION SYSTEM (IS) AUDITING NORHAFIZAH BINTI ABDUL MUDALIP YAP YONG TECK TAN YUAN JUE TAY QIU JIE GROUP MEMBER:
Appendix E – Checklist for Review of Performance Audits Presented by: Ashton Coleman Department of Defense Office of the Inspector General August 16, 2012.
IIA_Tampa_ Beth Breier, City of Tallahassee1 IT Auditing in the Small Audit Shop Beth Breier, CPA, CISA City of Tallahassee
Presented By Tay Un Soo Senior VP, Bank of Commerce President of ISACA - Malaysia Chapter 1999 National Accountants Conference THRIVING IN THE DIGITAL.
Standards and Guidelines for IS Auditing (ISACA).
Taking the STANDARDS Seriously... what they are and why they are so critically important to internal audit professionalism.
The Institute and the Profession: 1 Personalize your title and presenter here. The Institute and the Profession The Institute and the Profession: 1.
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Internal Quality Assessment Process Internal.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
ISSAI 400 Compliance Auditing
 Definition of a quality Audit  Types of audit  Qualifications of quality auditors  The audit process.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Coordination between the Commission and.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
RTI, MUMBAI / CH 91 QUALITY ASSURANCE IN PERFORMANCE AUDIT QUALITY ASSURANCE IN PERFORMANCE AUDIT DAY 9 SESSION NO.1 (THEORY) BASED ON CHAPTER 9 PERFORMANCE.
Chapter 02 Professional Standards McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union IT audits Workshop 2 – Report Ljubljana, October 2009 Mr. Gilles.
IT Assurance using CobiT Round Table Saturday, March 19th 2008 Philip DE PICKER president of Isaca.be Monique GARSOUX vice-president IT Assurance of Isaca.be.
1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Report from Workshop No. 1 Systems evaluations.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Internal Audit Agency Integrity + Professionalism INTERNAL AUDIT AGENCY ISACA Presentation 15 July, 2013 Alisa Hotel, ACCRA.
Internal Audit Quality Assessment Guide
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
MS in IT Auditing, Cyber Security, and Risk Assessment
Hans Nieuwlands CIA CGAP CCSA CEO IIA Netherlands
IS4680 Security Auditing for Compliance
Dr. Ir. Yeffry Handoko Putra
Audit of predetermined objectives
MODULE 8: GOVERNANCE AUDIT EVIDENCE AND REVIEW
How to Survive an External Quality Assessment
Assurance, Related Services and Internal Auditing
MODULE 2 INTRODUCTION TO GOVERNANCE AUDIT
IPOS’ Quality Management System under ISO 9001 Standard
A Framework for Control
Governance, audit and digital preservation
Independent Internal Audit Quality Reviews
Taking the STANDARDS Seriously
Presentation transcript:

1 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Introduction to IT audits PART II IT Audit International Standards, Practices & Guidance Ljubljana, October 2009 Monique Garsoux ISACA Chapter Vice-President Monique Garsoux ISACA Chapter Vice-President

2 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Introduction The MIS has to be : –Reliable –Continuous –Secure –Efficient/effective –Compliant All authorities need an independent IT audit because –It is their responsibility –They should have reports on the IT risks evaluation based on objective assessment criteria –Their IT system should be effective

3 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 The association of IT auditors : ISACA The IT audit is an internationnally regulated profession. Founded in 1969, as the EDP Auditors Association (EDPAA) More than 86,000 members in 160 countries Members include internal & external auditors, Chief Information Officers, Information security and control professionals and IT consultants More than 175 chapters worldwide 33 Chapters in Europe

4 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 The IT Auditors team The IT auditor has to respect professional standards, certification, skills and expertise. The IT auditor should be qualified for the work. The IT auditor has frameworks and best practices as the support for his work.

5 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 IT auditor has to be competent Hold certifications –Certified Information Systems Auditor™ (CISA ® ) –Certified Information Security Manager ® ( CISM ® ) –Certified in the Governance of Enterprise IT ® (CGEIT ® ) Apply Standards and Frameworks –IS auditing standards, guidelines, procedures, IS control standards –Frameworks to be used :CobiT & IT Assurance Guide and more… Keep informed and trained : –Conferences and education –Information :K-NET ® –Publications

6 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 What the IT auditor does … A formal, independent and systematic assessment of the IT system that must meet specific criteria (effectiveness, integrity, confidentiality, completeness, availability, compliance, reliability). He produces a written report on risks, weaknesses, findings and recommendations. He follows the action plans from the auditees. Code of Professional Ethics : guides the professional and personal conduct of IT Auditors (Independence and Objectivity, Reasonable Expectation, Management’s Acknowledgement, Training and Proficiency, Knowledge of the Subject Matter; Due Professional Care). 6 |

7 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 The steps of the work of the IT auditor presentation7 |

8 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 The IT auditor uses the Cobit Framework (Control Objectives for Information Technology)

9 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Contents of IT audits Contents of IT audits 1.IT General Controls The IT environment audit Audited General Controls –Logical access controls over infrastructure, applications, and data. –System development (Analysis and programming). –Program change controls. –Data centre physical security controls. –System and data backup and recovery controls. –Computer operation controls 9 | MIS Accounting Document ITGCs

10 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 IT application Audits. In the IT systems controls are automated and designed to ensure the complete and accurate processing of data, from input through output. They ensure that only complete, accurate, authorized and valid data is entered, calculated, updated and produced in a computer system. This is verified by the IT Auditor 10 | InputProcessOutput Interfaces Contents of IT audits

11 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Example of the IT audit Framework AC1 Source document preparation & authorisation Example of tests from Cobit to be realized by the IT auditor

12 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 –Reports consist of a written text accompanied with detailed information. –It is organised in such a manner as to permit the reader to understand, in greater depth, the areas included in the scope of the report; the work performed; the findings obtained (audit opinion); and the issues, concerns, risks, etc., identified. –The report is based on the findings and the recommendations themselves substantiated by the tests and investigations performed 12 | Reporting done by the IT Auditor

13 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 References for Cobit and the Assurance Guide and IT assurance framework -> free downloadableWWW.ISACA.ORG For information on IT audit &Training

14 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Conclusion IT audit is a mature and regulated profession with available tools and techniques from ISACA.

15 Homologues Group Meeting Slovenia, October 2009 Republika SlovenijaEuropean Union Ljubljana, October 2009 Thank you for your attention! Tel: Tel: