0% found this document useful (0 votes)
17 views41 pages

IT Risk Management Audit Guide

The document outlines the processes of IT risk management and business continuity procedures, emphasizing the importance of identifying, analyzing, and treating IT risks to protect organizational information systems. It details the steps involved in risk management, including risk identification, analysis, treatment strategies, and the development of disaster recovery and business continuity plans. The document also highlights the need for continuous improvement and training to ensure effective implementation of these strategies.

Uploaded by

Eah Mayy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views41 pages

IT Risk Management Audit Guide

The document outlines the processes of IT risk management and business continuity procedures, emphasizing the importance of identifying, analyzing, and treating IT risks to protect organizational information systems. It details the steps involved in risk management, including risk identification, analysis, treatment strategies, and the development of disaster recovery and business continuity plans. The document also highlights the need for continuous improvement and training to ensure effective implementation of these strategies.

Uploaded by

Eah Mayy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

AUDITING IT RISK MANAGEMENT

AND BUSINESS CONTINUITY


PROCEDURES
AUDITING IN A CIS ENVIRONMENT
IT RISK MANAGEMENT
IT RISK MANAGEMENT

• IT risk management is the process of identifying risk to an organization’s


information systems and taking steps to reduce the risk to an acceptable level.
• Risk management involve three major activities:
Risk identification - knowing the applicable IT risk to the information system
Risk analysis - determining the extent of exposure to IT risks
Risk response/treatment - implementation of strategies to address significant risks
RISK APPETITE AND RESIDUAL RISK

• Risk management does not entail total elimination of IT risks due to:
• Inherent limitation of internal control procedures
• Cost involved in implementing strategies to address risks against perceived benefits
• Risk appetite refers to the quantity and nature risks that organizations are willing to accept based on the
assessed trade-off between cost and benefit.
• Conservative organizations will have low tolerance to IT risks and will implement very stringent strategies to protect its
IT systems.
• Aggressive organizations will have high tolerance to IT risks and would have less stringent controls.
• Residual risks pertains to the IT risks that the organization will accept and will be not be addressed.
• Risks that will significantly impact the organization must be address and prevented/mitigated.
• Risks deemed insignificant will be accepted by the organization.
IT RISK IDENTIFICATION
IT RISK IDENTIFICATION

• IT Risk identification requires the organization to identify, classify and prioritize:


• The IT resources that must be protected by the organization, and

• The threats that poses danger on identified IT resources.


Classifying and prioritizing Identifying and prioritizing
Identifying IT resources
IT resources threats to IT resources
• IT resources assets refer to the • IT resources must be classified • Threats will be identified based on
components of the information based on its criticality or the existing IT resources of the
system used by the organization. importance to the organization. organizations.

• Potential threats on identified IT • IT resources deemed critical to the • Significant threats that is deemed
resources must be determined and organization will be prioritized in to adversely affect the
assessed. the risk management process. organization will be prioritized in
the risk management process.
INFORMATION TECHNOLOGY RESOURCES

Component Description
Hardware Physical infrastructures used in the information system.
Software Programs installed on the hardware that execute user commands.
People Employees and trusted outside service providers involved in the IT system.
Data Information processed, transmitted and stored in the information system.
Network Connectivity of the information system, either within or outside the organization.
Procedures Instructions on the internal logic and user tasks in the information system.
DETERMINING VALUE TO IT RESOURCES

Factor Description
Criticality IT resource is valuable if it is crucial in the organization’s operation and
success.
Financial impact IT resource has value it if helps in generating revenues and profits
Replacement cost IT resource is valuable if it is expensive to recover when lost or
destroyed.
Protection cost IT resource is valuable if it requires a high cost to protect against
threats.
Reputation cost IT resource is valuable if public knowledge would cause damage to reputation
and potential liability.
THREATS TO IT RESOURCES

Environmental threats Technological threats Human threats

Threats caused by environmental Threats caused by failures in the Threats involving human agents, which
factors not involving human agents and components in an information system. may be accidental (non-malicious) or
is beyond the organization’s control. intentional (malicious).
Typically includes:
Typically includes: • Hardware failure Typically includes:
• Natural disasters • Software failure • Trespassing/Unauthorized access
• Service interruptions • Technological obsolescence • Sabotage
• Extortion
• Malware
• Human error
• Theft
IT RISK ANALYSIS
IT RISK ANALYSIS

• IT Risk analysis requires the organization to:


• Identify vulnerabilities in its information system

• Assess the probability and potential impact of treats to the information system
Vulnerability identification Probability analysis Impact analysis

• Vulnerability pertains to a • For any given threat and IT • A threat, when realized, will have
weakness in the IT system that resource, the probability that the some effect on the organization.
makes the probability of one or threat will be realized needs to be • Impact analysis is the study of
more threats more likely. estimated. estimating the impact of specific
• Vulnerability analysis is the review • Management will need to perform threats on specific IT resources.
of the IT system to discover some research and develop a best
weaknesses that could lead to a estimate, based on available data.
risk of occurrence of a threat.
QUALITATIVE RISK ANALYSIS

• A qualitative risk analysis is an in-depth examination of in-scope assets with a


detailed study of threats (and their probability of occurrence), vulnerabilities (and
their severity), and statements of impact.
• The threats, vulnerabilities, and impact are all expressed in qualitative terms such as
High-Medium-Low or in quasi-numeric terms such as a 1–5 numeric scale.
• The purpose of qualitative risk analysis is to identify the most critical risks in the
organization, based on these rankings.
• The value in a qualitative risk analysis is the ability to quickly identify the most
critical risks without the additional burden of identifying precise financial impacts.
QUANTITATIVE RISK ANALYSIS

• Quantitative risk analysis is a risk analysis approach that uses numeric methods to measure risk.

• The advantage of quantitative risk analysis is the statements of risk in terms that can be easily
compared with other IT resources and risks.

Annualized rate of occurrence (ARO)


Asset value (AV)
Estimated number of times a threat will occur
in a year (e.g., if threat occurs twice a year, Annualized loss expectancy (ALE)
Value assigned to an IT resource, which is
ARO is 2.0; if every two year, ARO is 0.5) [ARO x SLE]
equivalent to potential financial loss,
replacement cost and reputation cost.
This is the expected annualized loss on
Single loss expectancy (SLE) IT resource value due to threat realization.
[AV x EF]

Exposure factor (EF) The amount of expected financial loss on IT


resources when the threat occurred once.
Percentage of the IT resource’s total value
that will be lost when a threat occurs.
SAMPLE QUANTITATIVE RISK ANALYSIS

Management is currently assessing the potential exposure of the organization if its server gets destroyed by natural
causes. It currently has a value of P500 thousand, but will require P1 million to replace. The organization do not expect
to recovery anything when its server gets destroyed. D ata shows servers breaks down once every five years.

Annualized rate of occurrence (ARO)


=0.20
Asset value (AV) = P1.5 million Annualized loss expectancy (ALE)
Threat is estimated to occur once every five P1.5 million x 0.20 = P300 thousand
Financial loss = P500 thousand years or 1/5.
Replacement cost = P1.5 million This figure will be compared to other risk
Single loss expectancy (SLE) analyzed to determine which will have the
P1.5 million x 100% = P1.5 million highest level of exposure.

Exposure factor (EF) – 100% The organization will incur a single loss of
P1.5 million if the server gets destroyed once
The full value of the asset will be lost if the
asset is destroyed
IT RISK TREATMENT
IT RISK TREATMENT

IT risk treatment pertains to the development of strategies that will address identified threats to
IT resources and vulnerabilities on the IT system.
Implementation and
Strategy selection Justify strategy
monitoring
• There are various strategies that • The cost of implementing a • Selected strategy must be
an organization can implement to strategy must be justified based on implemented throughout the
address identified IT risks. its perceived benefits. organization.
• Require performance of feasibility
• Determination of appropriate studies and cost-benefit analyses. • Strategies are monitored to
strategy depends on various determine whether the control is
factors, such as risk appetite, working effectively in addressing
threat level and asset value. identified risk.
RISK TREATMENT STRATEGIES

Component Description

Risk mitigation • Implementation of solutions, policies and procedures that will reduce an identified risk.
• Examples of risk mitigation strategy includes installing anti-virus software to prevent malware
attack and password controls to prevent unauthorized access to system and program files.
Risk transfer • Some or all the risk is being transferred to some external entity, such as an insurance company or
business partner.
• Examples of risk transfer strategy include purchasing an insurance policy to shield the
organization from potential asset damage or loss and outsourcing certain business processes.
Risk avoidance • The organization abandons the activity altogether, effectively taking IT resource out of
service so that the threat is no longer a threat.
• Examples of risk avoidance strategy includes closure of a business site that is prone to
natural disaster or terminating an entire database to prevent leakage of personal information.
Risk acceptance • The choice to do nothing on potential exploitation of vulnerabilities.
• Can only be done on treats identified are assessed to be within the organization’s risk appetite.
• Not applicable on risk that can cause serious damage to the organization.
STRATEGY SELECTION

Feasibility study

• Alternative strategies are assessed against major constraints (restrictions/ limitations) so that
management can determine the organization’s ability to implement those strategies.

• Factors considered in the strategy feasibility study includes:


Technical Economic Legal Operational Schedule
feasibility feasibility feasibility feasibility feasibility
Availability of technology Availability of funds to Identification of conflicts Degree of compatibility Ability of the
necessary to develop and implement a strategy between the strategy and between the existing organization to
implement a strategy the organization’s legal procedures and implement strategy within
responsibilities. personnel skills of the an acceptable timeline.
organization and the
strategy.
STRATEGY SELECTION

Cost-benefit analysis
Cost-benefits analysis enables the management to determine whether the benefits of
implementing a strategy outweighs the related costs.

Benefit of implementing controls Cost of implementing controls


• Acquisition and development
• Protection of IT resources
• Implementation costs
• Address vulnerabilities
• Training costs
• Loss prevention
• Vendor-support costs
• Maintenance costs
DISASTER RECOVERY AND BUSINESS CONTINUITY
PURPOSE OF RECOVERY AND CONTINUITY PLANS

• Disaster recovery and business continuity planning are activities undertaken


to reduce risks related to the onset of disasters and other disruptive events.

• The primary objective of recovery and continuity plans is to improve the


chances that the organization will survive a disaster without incurring costly or
even fatal damage to its most critical activities.
IMPACT OF DISASTERS TO ORGANIZATIONS

Component Description

Direct damage Corporate assets may be directly damaged or destroyed by natural disasters.

Utility outage Disasters may affect utilities such as power or water, which can incapacitate business operations.

Transportation Disasters may damage or render transportation systems unusable for a period.

Supplier shortage Disasters may affect suppliers which can lead to shortage of needed supplies and services.

Staff availability A communitywide or regional disaster that affects businesses is likely to also affect homes and families.

Customer availability Disasters may force or dissuade customers from traveling to business locations to conduct business.
THE BUSINESS CONTINUITY PLANNING PROCESS

• Organizations must be fully prepared in the event of a disaster

• Disaster preparedness required identifying the kinds of disasters that are


likely to happen and their possible effects on the organization.

• The business continuity process is a life-cycle process, meaning, it is not a one-


time event or activity but a continuous set of activities that result in the
ongoing preparedness for disaster that continually adapts to changing
business conditions and that continually improves.
THE BCP PROCESS
STEP 1: DEVELOP A BCP POLICY

• A formal BCP effort must flow from the existence of a formal policy and be included in the
overall governance model.
• BCP should be an integral part of the IT control framework, not lie outside of it.
• The BCP policy should include or cite:
• Specific controls that ensure that key activities in the BCP life cycle are performed appropriately
• Specific business processes (or departments or divisions within an organization) that are included in the BCP
and DRP effort
STEP 2: CONDUCT BUSINESS IMPACT ANALYSIS

• The objective of the business impact analysis (BIA) is to identify the impact that
different scenarios will have on ongoing business operations.

• The BIA involve the following activities:


• Collection of key business processes and IT systems - The BCP teams needs to establish a
detailed list of all identifiable processes and systems that will be analyzed for potential impact of a
disaster.

• Formulation of statement of impact - A statement of impact is a qualitative or quantitative


description of the impact if the process or system were incapacitated for a time (e.g., customer
record cannot be accessed if the ERP system gets corrupted).
STEP 3: PERFORM CRITICALITY ANALYSIS

• Criticality analysis is a study of every system and process on the following aspects:
• Impact on the organization if it is incapacitated

• Likelihood of incapacitation, and

• Estimated cost of mitigating the risk or impact of incapacitation

• Criticality analysis is closely related to the over-all risk management activity of the
organization.
STEP 4: ESTABLISH RECOVERY TARGETS

• The organization sets its recovery time objective and recovery point objective.
• The recovery time objective (RTO) period from the onset of an outage until the
resumption of service, usually measured in hours or days. Critical business operation
will require shorter recovery time, meaning, it needs to resumes as soon as possible
to prevent the paralysis of operations.
• A recovery point objective (RPO) is the period for which recent data will be
irretrievably lost in a disaster, which is usually dependent on the frequency of back-
up or replication interval. Data and activities done after the recover point will be
permanently lost when a disaster affected the organization.
STEP 5: DEVELOP RECOVERY AND CONTINUITY
STRATEGIES AND PLANS
• After specific recovery target have been established, the BCP project team can start devising
ways to meet these targets.

• Recovery and continuity strategies should include the following:


• Site recovery options

• Recovery and resilience technologies

• Backup and restoration


STEP 6: TEST RECOVERY AND CONTINUITY PLANS

• The value of a recovery and continuity plan is established once it is proven to work effective after testing.

• Types of tests that can be performed on recovery and continuity plans include:

Document review Walkthroughs Simulation Parallel and cutover tests

A document review test is a review A walkthrough involves the review A simulation is a test of disaster A parallel test is an actual test of
of documentations on recovery and of recovery and continuity recovery and business continuity recovery and business continuity
continuity plans and procedures. document performed by an entire procedures where the participants response plans. It is performed by
Typically done by individuals on group of individuals in a live take part in a “mock disaster” to running the live system and the
their own at their own pace, but discussion. add some realism to the process of back-up system and establish the
within a specified time constraints thinking their way through parallelism between the two.
or emergency response documents.
deadlines that may have been A cutover test is like a parallel test,
established. but only the back-up system is
running to determine the its ability
to manage real workload in a
disaster.
STEP 7: TRAIN PERSONNEL

• The value and usefulness of a high-quality set of disaster response and continuity plans and procedures
will be greatly diminished if those responsible for carrying out the procedures are unfamiliar with them.
• Forms of personnel training includes:
• Review of recovery and continuity documentations
• Participation in walkthroughs
• Participation in simulations
• Participation in parallel and cutover tests
STEP 8: PERIOD REVIEW AND UPDATE OF
RECOVERY AND CONTINUITY PLANS
• Changes in business processes and technology can render establish recovery and continuity
plans to be obsolete.
• Organization needs to establish a schedule where the recovery and continuity plans will be
reviewed, depending on the assessed rate of change in the organization.
• Every change in business processes and information systems should include a step to review
and update relevant recovery and business continuity documents.
• Periodic testing of recovery and continuity documents and plan should be performed to
validate its accuracy and relevance and identify any issues or exceptions requiring corrective
actions.
FEATURES OF A BUSINESS CONTINUITY PLAN
IDENTIFICATION OF CRITICAL APPLICATIONS

• Recovery efforts must concentrate on restoring firm applications and


associated files that are critical to the short-term survival of the organization.

• Short-term survival requires the restoration of those functions that generate


cash flows sufficient to pay-off maturing obligations and sustain daily
operations (example, customer balance and sales).

• Application priorities may change over time. Consequently, the BCP must be
updated to reflect new developments and identify critical applications.
CREATION OF A DISASTER RECOVERY TEAM

• Recovering from a disaster depends on timely corrective action.

• To avoid serious omissions or duplication of effort during implementation of


the contingency plan, task responsibility must be clearly defined and
communicated to the personnel involved.
SITE RECOVERY OPTIONS

There should be a planned site where information systems reside in case the currently place of business is partially or fully
destroyed.
Option Description

Hot sites • An alternate processing center where backup systems are already running and can assume production
workload.
• Best choice for systems where recovery target are short.
• Provides the least back-up recovery site risk but entails a high cost.
Warm sites • An alternate processing center where recovery systems are present, but at a lower state of readiness than a hot site.

Cold sites • An alternate processing center where the degree of readiness for recovery systems is low.
• Normally no more than an empty building space, or just allocated space on a computer room floor.
Mobile sites • A portable recovery center that can be delivered to almost any location in the world.
• A mobile site can be transported by truck, and have its own generator, communications, and cooling capabilities.
Reciprocal • A data center that is operated by another company.
sites • Two or more organizations with similar processing needs will draw up a legal contract that obligates one or more of
the organizations to temporarily house another party’s systems in the event of a disaster.
• Reciprocal agreement pledges not only floor space but also the use of the reciprocal partner’s computer system.
• Provides the least back-up recovery site cost but entails a high risk.
RECOVERY AND RESILIENCE TECHNOLOGY

The organization needs to survey and select technologies that is critical to achieve recovery
time and recovery point objectives.
Technology Description

Redundant array of • Creates virtual disk volumes over an array of disk storage devices and can be configured so that
Independent Disks the failure of any individual disk drive in the array will not affect the availability of data on the disk
(RAID) array.
• Usually implemented on a hardware device called a disk array, which is a chassis in which
several hard disks can be installed and connected to a server
Replication • An activity where data on a storage system is also copied over a network to another storage system.
• Result in up-to-date data that exists on two or more storage systems.
Server cluster • A cluster is a characteristic of two or more servers to appear as a single server resource.
• When an application is implemented on a cluster and one of the servers in the cluster fails, the
other server (or servers) in the cluster will continue to run the application.
Network • An application that requires high availability and resilience may require redundant network connections
connectivity and and redundant network services.
services
BACK-UP AND RESTORATION

• It is essential for organizations to have fresh copies of its information that exist elsewhere that
is stored in a form that enables IT personnel to easily download into alternative systems.
• The organization should review its back-up capability in terms of:
• Degree of ease of back-up management
• Back-up time
• System flexibility
• Need for newer technology
• Confidence in back-up technology

• Backup media must be stored off-site in a secure location.


AUDIT PROCEDURES ON THE BUSINESS
CONTINUITY PLAN
AUDIT OBJECTIVE

To assess the adequacy and feasibility of the Business Continuity Plan in


dealing with a catastrophe that could deprive the organization of its IT
resources.
AUDIT PROCEDURES

• Review completeness of the list of critical applications.

• Verify the existence of the disaster recovery team.

• Evaluate adequacy of the backup site arrangement.

• Verify off-site storage and back-up of critical IT resources.

• Examine insurance policies related to loss of property and assets and assess
if the insurance coverage is sufficient to cover the cost of recovery.

You might also like