auditing your (big) data strategy

12
Auditing your (Big) Data Strategy Presented by: Stewart Mantell General Manager, Internal Audit TAL

Upload: others

Post on 14-May-2022

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Auditing your (Big) Data Strategy

Auditing your (Big) Data StrategyPresented by:

Stewart Mantell

General Manager, Internal Audit

TAL

Page 2: Auditing your (Big) Data Strategy

Intro

• Why is data important

• The new oil?

• Value of Data

• Data risk

Source: APRA

Page 3: Auditing your (Big) Data Strategy

Understanding your data (strategy)

• Does your organisation understand its data• “knowing is half the battle”

• Data classification

• Context is key• What, why, where, how

Page 4: Auditing your (Big) Data Strategy

Knowing where your data is

• Data sources and uses proliferate

• Is data held internally, or with providers

• Think laterally

• Shadow IT and growth of cloud services

Source: IIA

Page 5: Auditing your (Big) Data Strategy

Data Classification – a foundation

• Data classification• Criticality and sensitivity

• Content, Context, User

• A number of general definitions• Generally available / public / unclassified

• Internal Use only

• Confidential /restricted

• Commercial in Confidence / highly restricted

• Tools can be used to gather information, but…Source: AWS

Page 6: Auditing your (Big) Data Strategy

Auditing Considerations

• Regulatory Considerations• Consideration of approach / design in line with regulatory

guidance e.g. CPS 231,232, 234

• Vendor / legal risks• Privacy regime / jurisdiction

• Customer Consent

• Organisational Risk Appetite

• Termination of services and repatriation of data

Page 7: Auditing your (Big) Data Strategy

Auditing Considerations (contd)

• Technology Considerations – what are the threats• Based on architecture, on prem vs cloud

• Look at layers – infrastructure and app

• Threat analysis: Data Breach, Malicious Encryption, Fraud, DoS, APT

• Operational Considerations – how is data being used• predictive vs reactive, system of record vs system of insight /

enquiry

• Governance, Monitoring, Testing

Page 8: Auditing your (Big) Data Strategy

Cloud

• Increasing use of cloud as part of Big Data strategies

• Shared service model for controls

• Audit assurance over cloud providers

Source: AWSSource: APRA

Page 9: Auditing your (Big) Data Strategy

CPS 234 – Information Security• Resilience against

information security incidents (including cyberattacks)

• Maintain an information security capability that is commensurate with information security vulnerabilities and threats.

Governance & Policy Framework

Information Security Capability

Defined Information Assets

Documented Controls

Systematic Testing Program

Internal Audit Review

Notification Process

Page 10: Auditing your (Big) Data Strategy

Leveraging the use of Big Data

• Use Big Data for Internal Audit Analytics

• Rise in the use of Data and Big Data and harnessing that for Internal Audit

• Make the most of scarce audit resources

Page 11: Auditing your (Big) Data Strategy

Guidance on managing and auditing (big) data risk

• IIA – GTAG Understanding and Auditing Big Data

• CPG 235

• CPS 234

• APRA Cloud guidance

• ISACA

Page 12: Auditing your (Big) Data Strategy

Summary

• Context is key to understanding big data risk

• Data classification is a foundation

• There are specific considerations when using cloud

• CPS 234 is driving focus on security, but don’t forget about quality

• Harness data and big data for audit work

• Leverage industry thinking IIA, APRA, ISACA