0% found this document useful (0 votes)
9 views6 pages

IT Security Risks and Controls Overview

The document outlines the importance of cybersecurity and IT audit in protecting organizational information assets from unauthorized access. It discusses the roles of management, risk management, and compliance in establishing strong security frameworks, as well as the various sources of cyber threats and the three lines of defense in IT. Additionally, it emphasizes the need for IT auditors to possess technical expertise and the implications for IT governance and risk management.

Uploaded by

ameyu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views6 pages

IT Security Risks and Controls Overview

The document outlines the importance of cybersecurity and IT audit in protecting organizational information assets from unauthorized access. It discusses the roles of management, risk management, and compliance in establishing strong security frameworks, as well as the various sources of cyber threats and the three lines of defense in IT. Additionally, it emphasizes the need for IT auditors to possess technical expertise and the implications for IT governance and risk management.

Uploaded by

ameyu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CYBERSECURITY -3rd line: independent and objective

assurance on governance, risk mgmt., and


-tech, processes, and practices designed to
controls
protect and org’s info assets from
unauthorized access -senior mgmt. and BoD

-controls: IT AUDIT

-strong security frameworks -tech has changed competencies for internal


auditors
-identifying and controlling top risks
-data analytics: how to analyze data and use
-cybersecurity awareness programs
audit software tools
-consideration of internal and
-cybersecurity: key components of info
external threats
security
-strong info security governance
-business continuity and disaster recovery:
-robust response protocol understanding business areas and practices
for recovery
FACTORS AFFECTING IT AUDIT APPROACH
-change mgmt.: knowledge of project mgmt.
1. Proliferation of tech = ^user access
and change processes
2. ^connected devices
-set of controls to mitigate risks
COMMON SOURCES OF CYBER THREATS
during transitions/changes w/in the
1. Nation-states entity
2. Cybercriminals
-newer tech: being tech savvy w/ current
3. Hacktivists
issues one emerging tech and potential
4. Insiders and service providers
impact
5. Developers of substandard services
and products -auditors that work extensively on IT must
have deep IT risk, control and audit expertise
THREE LINES OF DEFENSES FOR IT
-every internal auditor must have a sound
-1st line: mgmt. owns and manages data,
understanding of certain fundamental IT
processes, risks, and controls
concepts
-employees
KEY COMPONENTS OF MODERN UT
-2 line: risk, control, and compliance
nd SYSTEMS
oversight
1. Computer hardware
-by mgmt. -physical components
2. Networks
-ensures that 1st line processes and
-links computers/devices to share
controls are existing and operating
info and workloads
effectively
-client server network: connects 4. Database
client computers with a server -large repository of data contained in
-info processing shared linked files
between client and server -allows data to be easily accessed,
retrieved, and manipulated
-Local area network (LAN): small
-operating database: day-to-day
area (same bldg.)
transaction processing and is
-wide area network (WAN): system continuously updated
of connected LANs -data warehouse: large assemblage
of data stored overtime to support
-intranet: org’s private network
online data analysis and decision
accessible only to org personnel
making
-extranet: accessible to selected 3rd 5. Information
parties (customers/suppliers) -key resource for all enterprises
-information systems: collect, store,
-value-added network (VAN): 3rd
transform data into useful info for
party network that connects org w/
internal and external decision makers
trading partners
6. People
-internet: interconnected networks -chief information officer (CIO):
that is a large and complex system of daily oversight and direction of IT
computer networks -ensures alignment of IT
objectives with overall
3. Computer software
business objectives
-operating system: controls basic
input, processing, and output of the -chief information security officer
computer (CISO): established info security
-manages interconnectivity of polices, procedures, and practices
system hardware devices
-implements monitoring
-utility software: encryption, disk networks and indiv access
space optimization, virus protection control

-database management system -trains indivs on importance of


software: manages data w/in security on corporate access
database, controls access, and and systems
automatically backs-up data
-database administrator: supervises
-application software: used to the design, devt, implementation, and
process transactions maintenance of database, controlling
access, monitoring performance, and
-firewall software: enforces access
upgrade database based on user
controls between networks by
needs
allowing only authorized data
transmissions
-system developers -org cannot effectively and
efficiently implement EDI if
-analysts: survey IT user
trading partners does not have
needs and design new IT
it
systems (what is vs what
should be) -risk: possibility that an event will occur that
will negatively affect the achievement of org
-programmers: construct and
objectives
test software
-power outages,
-information processing personnel:
intercepted/stolen/misused info,
manages centralized IT resources
inaccurate programmed software give
from centralized daily input,
out inaccurate info, infiltrated
processing, and output activities
databases, info risk (invalid info
-end users: managers and employees leading to poor decisions), and
that use the info from the system conceal errors/fraud

IT OPPORTUNITIES AND RISKS IT RISKS

-opportunities: possibility that an event will -not mutually exclusive


occur that will positively affect the
1. Strategic and operational risk
achievement of org objectives
-selection risk: selection of IT
-selling goods online solution is misaligned w/ strategic
objective
-Enterprise Resource Program
-incompatibility of IT solution
(ERP): modular system that integrates
to org system
business processes in one operating
-caused by unqualified
database
decision-makers and
-online real-time processing inadequate info
of transactions, interaction
-development/acquisition and
and sharing of data, improved
deployment risk: problems during
process performance,
devt, acquiring, deploying IT solution
reduction of data redundancy,
timely decision-making -causes delays and cost
overruns
-Electronic Data Interchange (EDI):
computer-to-computer exchange of -caused by insufficient in-
business documents between an org house expertise, inadequate
and trading partners vendor support, untried
software/tech, resistance to
-transaction processing
change
efficiencies and fewer data
processing errors
2. Technical and system risk guest access, lack of strong
-availability risk: unavailability of user access/authentication
system when needed
-fraud and malicious acts risk: theft
-causes delays, business
of IT resources, intentional misuse of
interruptions, lost revenue,
IT resources, intentional distortion of
customer dissatisfaction
info
-caused by hardware/software
malfunctions, unscheduled -caused by disgruntled
maintenance, virus, malicious employees, hackers
acts
IT GOVERNANCE
-hardware/software risk: failure to
-orgs invest in IT since it allows execution of
perform
business strategies
-causes business
-BoD and senior mgmt. owns IT governance
interruptions, temporary or
permanent damage, -governance: IT policies
destruction of data,
-mgmt: standards, organization and mgmt.,
repair/replacement costs
physical and environmental controls
-caused by natural wear and
-technical: system software controls,
tear, natural disasters,
systems devt controls, application-based
viruses, lack of patching
controls
updates, malicious acts
IT RISK MANAGEMENT
-system reliability and information
integrity risk: systematic errors that -identify and mitigate risks
produce irrelevant, inaccurate, and
-identify and exploit opportunities
untimely info
IT CONTROLS
-caused by software
programming errors, weak -general controls: controls on people,
data verification controls, policies, processes, and system components
unauthorized changes
-application controls: controls on
3. Security and compliance risk applications and programs
-access risk: unauthorized
physical/logical access to the system -input controls: correct data is
resulting to theft, misuse, malicious inputted
modifications, or destruction of data -processing controls: data is
-caused by smartphones processed correctly
accessing to company data,
using wireless networks for -output controls: processes release
correct output
IT MANAGEMENT CONTROLS assessment, intrusion testing,
encryption services, change mgmt.
1. IT standards
processes
-support IT policies
-specifically define requirements -system devt and acquisition controls:
-systems devt processes: processes
-documentation of user reqs, process
for designing, developing, testing,
of systems design, structured system
implementing, and maintaining info
devt, testing that ensures operating
systems
effectiveness, and consistent pattern
-systems software configuration:
of control
secure system config
-application controls: all apps that -application-based controls: all input data
support business activities must be is accurate, processed as intended,
controlled completely stored, and accurately outputted
-data structures consistent data
-input controls, processing controls,
definitions ensure that disparate
output controls, integrity controls
systems can access data seamlessly
(monitor data processing and storage
-documentation: specify minimum
for consistent and correct data),
level required
management trail
2. IT organization and mgmt. controls
-provide assurance hat the org is -information security controls: protect an
structured with clearly defined lines info system from unauthorized physical and
of reporting and responsibility w/ logical access
effective control processes
-physical access controls: security
-segregation of duties
over tangible IT resources
-financial controls to ensure
tech yields projected ROI -logical access controls: security
-change mgmt. processes over intangible IT resources (software
3. IT physical and environmental and info)
controls
IMPLICATIONS FOR IT AUDITORS
-protect info system resources
1. IT proficiency and due professional
IT TECHNICAL CONTROLS
care
-form the backbone of mgmt. control -IT auditors must have sufficient
framework knowledge on tech risks and controls
-use tech-based audit techniques
-specific to tech in use
2. Assurance engagement IT
-system software controls: restrict logical responsibilities
access to org systems and apps -assess IT governance supports org
strategies and objectives
-access rights, division of duties,
-evaluate risk exposures
intrusion and vulnerability
3. IT outsourcing
-org still bears the risk and
responsibility for controls
4. Integrated and continuous auditing
-must audit thru the computer (audit
based on outputs and computer
code)
-integrate IT audit into assurance
engagements in increase efficiency
and effectiveness
-continuous auditing
-continuous controls
assessment: focus audit
attention on control
deficiencies
-continuous risk
assessment: highlight
processes/systems with
higher risk lvls

You might also like