0% found this document useful (0 votes)
59 views40 pages

IT Governance and Audit Controls Guide

Hot sites are fully equipped backup facilities maintained under contract to allow a company to resume critical operations immediately following a disaster.

Uploaded by

MaeNeth Gullan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
59 views40 pages

IT Governance and Audit Controls Guide

Hot sites are fully equipped backup facilities maintained under contract to allow a company to resume critical operations immediately following a disaster.

Uploaded by

MaeNeth Gullan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Chapter 2

Auditing IT
Governance
Control
2

Learning 1. Understand the risks of 3. Understand the key elements


Objectives incompatible functions and
how to structure the IT
of a disaster recovery plan.

function.
2. Be familiar with the controls
and precautions required to 4. Be familiar with the benefits,
ensure the security of an risks, and audit issues related
organization’s computer to IT outsourcing.
facilities.

Chapter Outline
3

 Information Technology Governance


 Structure of the Information Technology
Function
 The Computer Center
 Disaster Recovery Planning
 Outsourcing of the IT Function
Information
Technology
Governance
5

Information
Technology Key Objective:
Governance  Reduce risk
 Ensure that investsment in IT resources add
value to the organization.
6

IT Governance Three IT governance issues addressed by SOX


Controls and the COSO internal control framework:
 Organizational structure of the IT function.
 Computer center operations.
 Disaster recovery planning.
Structure of
the Corporate
IT Function
8

Two Organizational 1. Centralized Data Processing System


Model
2. Distributed Data Processing System
9
10
Primary Service Areas: 11
Database Administration
• responsible for the security and integrity of the database.
Data Processing
• manages the computer resources used to perform the day – to day
processing of transactions.
Data Conversion
• Transcribes transaction data from hard-copy source documents into
computer input.
Computer Operations
• Manages the conversion of electronic files produced in data
conversion.
Data Library
• A room adjacent to computer operations that provides safe storage
for the off-line data files.
System Development and Maintenance
• System Development – responsible for analyzing user needs and
designing new systems to satisfy those needs. Key participants are
system professionals, end users and stakeholders.
• System Maintenance - assumes responsibility for keeping the
system current with user needs.
12

1. Separating Systems Development from


Segregation of Computer Operations
Incompatible IT 2. Separating Database Administration
Functions from Other Functions
3. Separating New Systems Development
from Maintenance
13
14

Alternative 1. Inadequate documentation a chronic


Organization of problem.
Systems
Development
Problems 2. When system programmer has
maintenance responsibilities, potential
for fraud is increased
15

The Distributed
Model
16
17

Risks 1. Inefficient use of resources


Associated with 2. Destruction of audit trails.
DDP
3. Inadequate segregation of
duties.
4. Hiring qualified professionals
5. Lack of standards.
18

Advantages of
DDP ○ Cost Reductions
○ Improved Cost Control Responsibility
○ Improve User Satisfaction
○ Backup Flexibility
19

Controlling the Implement a corporate IT function:


DDP  Central testing of commercial software and
Environment hardware.
 User services to provide technical help.
 Standard-setting body.
 Personnel review.
20

Audit procedures in a centralized IT


organization:
Audit
Objective ○ Review relevant documentation to determine
if individuals or groups are performing
incompatible functions.
○ Review systems documentation and
maintenance records to verify maintenance
programmers are not designers.
○ Observe to determine if segregation policy is
being followed.
21
Audit procedures in a distributed IT organization:
 Review relevant documentation to determine if
individuals or groups are performing
Audit incompatible duties.
Objective  Verify corporate policies and standards are
published and provided to distributed IT units.
 Verify compensating controls are in place when
needed.
 Review system documentation to verify
applications, procedures and databases are in
accordance with standards.
The Computer
Center
23

Physical location:
The Computer  Directly affects risk of destruction
Center from a disaster.
 Away from hazards and traffic.
Construction:
 Ideally: single-story, solidly constructed
with underground utilities.
 Windows should not open and an air
filtration system should be in place.
24

Access:
 Should be limited with locked doors,
The Computer cameras, key card entrance and sign-in
Center logs.
Air conditioning
 should provide appropriate temperature
and humidity for computers.
Fire suppression:
 Alarms, fire extinguishing system,
appropriate construction, fire exits.
25

Fault tolerance is the ability of the system


to continue operation when part of the
The Computer system fails.
Center  Total failure can occur only if multiple
components fail.
 Redundant arrays of independent disks
(RAID) involves using parallel disks with
redundant data and applications so if one
disk fails, lost data can be
reconstructed.
 Uninterruptible power supplies.
26

 Auditor must verify that physical


controls and insurance coverage are
Audit Procedures: adequate.
The Computer
 Procedures include:
Center
Tests of physical construction.
Tests of the fire detection system.
Tests of access control.
Tests of RAID.
Tests of the uninterruptible power supply.
Tests of insurance coverage.
Disaster Recovery
Planning
28
29

1. Identify critical applications


Disaster 2. Create a disaster recovery team:
Recovery
Planning 3. Provide second-site backup
4. Specify back-up and off-site storage
procedures
Identify critical applications:
Short-term survival requires restoration of cash flow generating
functions.
Applications supporting those functions should be identified and
prioritized in the restoration plan.
Task of identifying critical items and prioritizing applications requires
active participation of user departments, accountants and auditors.

30
31

Create a disaster recovery team:


Team members should be experts in their areas and have assigned
tasks.

Provide second-site backup:


Necessary ingredient in a DRP is that it provides for duplicate data
processing facilities following a disaster.

Specify back-up and off-site storage procedures


All data files, applications, documentation and supplies needed to
perform critical functions should be automatically backed up and stored
at a secure off-site location.
32

Mutual aid pact is an agreement between


organizations to aid each other with data
Second-Site
processing in a disaster.
Backups

Empty shell or cold site plan involves


obtaining a building to serve as a data
center in a disaster.
 Recovery depends on timely
availability of hardware.
33

Recovery operations center or hot site


plan is a fully equipped site that many
Second-Site
companies share.
Backups

Internally provided backup may be


preferred by organizations with many
data processing centers.
34

○ Operating Systems Backup


Back Up and Off ○ Application Backup
Site Storage
○ Backup Documentation
Procedures
○ Backup Data Files
○ Backup Supplies and Source Documents
○ Testing the DRP
35

To verify DRP is a realistic solution, the following tests may be


DRP Audit performed:
Procedures  Evaluate adequacy of backup site arrangements.
 Review list of critical applications for completeness.
 Verify copies of critical applications and operating systems are
stored off-site.
 Verify critical data files are backed up in accordance with the
DRP.
 Verify that types and quantities of items specified in the DRP
exist in a secure location.
 Verify disaster recovery team members are current employees
and aware of their assigned responsibilities.
Outsourcing
the IT
Function
37

Benefits of IT outsourcing include:


Outsourcing the IT  Improved core business processes.
Function  Improved IT performance.
 Reduced IT costs.
38

Commodity IT assets which are not


unique to an organization and easily
Outsourcing the IT
acquired in the marketplace.
Function

Specific IT assets which are unique and


support an organization’s strategic
objectives.
39

○ Failure to perform.
Risks Inherent ○ Vendor exploitation.
to IT
○ Outsourcing costs exceed benefits.
Outsourcing
○ Reduced security.
○ Loss of strategic advantage.
40
 Use of a service organization does not reduce
management’s responsibilities under SOX for
Audit ensuring adequate IT internal controls.
Implications of  SSAE 16 replaced SAS 70 and is the
IT Outsourcing definitive standard by which auditors
can gain knowledge that processes and
controls at third-party vendors are
adequate to prevent or detect
material errors.
 Report provides a description of service provider’s
description using either the carve-out or the
inclusive method

You might also like