cisa review courses - slides part2

28
LOGO CISA Review Course Iyad Mourtada, CIA, CMA, CFE, CPLP Introduction to IT Governance

Upload: iyad-mourtada

Post on 12-May-2015

1.655 views

Category:

Business


0 download

TRANSCRIPT

Page 1: CISA Review Courses - Slides Part2

LOGO

CISA Review Course

Iyad Mourtada, CIA, CMA, CFE, CPLP

Introduction to IT Governance

Page 2: CISA Review Courses - Slides Part2

wps.cn/moban

Company Logo

IT Value Delivery

Stakeholders Value Drivers

Performance Measurement

Risk Management

Strategic Alignment

IT GOVERNANCE

Page 3: CISA Review Courses - Slides Part2

CORPORATE GOVERNANCE

Company Logo

Audit Role in IT Governance:

- Improve the quality and effectiveness of the IT governance Implementation. - Ensure compliance with IT governance initiatives implemented

Page 4: CISA Review Courses - Slides Part2

CORPORATE GOVERNANCE

Company Logo

Information Security Governance

•IS Governance should be integrated with IT Governance •The focus should be on

• Integrity of information• Continuity of services • Information assets protection

Page 5: CISA Review Courses - Slides Part2

CORPORATE GOVERNANCE Enterprise Architecture

Organizations should in structured way document its IT assets in to facilitate understanding, management and planning for IT investments

• Performance• Business• Service component• Technical • Data

Company Logo

Page 6: CISA Review Courses - Slides Part2

CORPORATE GOVERNANCE IS Roles & Responsibilities

•Systems analysis •Security Architect•Application programming•Systems programming•Network management

Company Logo

Page 7: CISA Review Courses - Slides Part2

Segregation of Duties Within IS- Security administration and change management- Computer operations and system development- System development and System design- System development and systems maintenance

- Segregated - Segregated - Segregated

Page 8: CISA Review Courses - Slides Part2

wps.cn/moban

Risk Management

Page 9: CISA Review Courses - Slides Part2
Page 10: CISA Review Courses - Slides Part2
Page 11: CISA Review Courses - Slides Part2
Page 12: CISA Review Courses - Slides Part2

Risk Definitions

“Risk is the possibility that an event will occur and adversely affect the achievement of objectives.”

COSO ERM – Integrated Framework (Jersey City, NJ: AICPAs, 2004), P5

“Risk [is] the possibility of an event occurring that will have an impact on the achievement of objectives. Risk is measured in terms of impact and likelihood”

IPPF (Altamonte Springs, FL: IIA, 2011), p.43

Page 13: CISA Review Courses - Slides Part2

Business Objectives

Strategic Objectives Operations Objectives Reporting Objectives Compliance Objectives COSO ERM – Integrated Framework (Jersey City, NJ: AICPAs, 2004), P5

Page 14: CISA Review Courses - Slides Part2

Risks

Company Logo

- Personnel Risk- Information Security Risk - Outsourcing Risk - Operational Risk - Financial Risk - Compliance Risk - Business Process Risk

Page 15: CISA Review Courses - Slides Part2

Fraud

Lawsuits

Penalties and fines

Increased market share

New product development

Increased revenue

Creating shareholder

value

+

VALUE

Preserving shareholder

value

Valu

e a

nd

Ris

k

Enterprise Risk Management (ERM) as an essential tool for good corporate governance, Rahaju Pal, Deloitte - Enterprise Risk Services ,September 2010

Page 16: CISA Review Courses - Slides Part2

Estimating Annual Losses

Company Logo

Single Loss Expectancy = Asset Value $ X Exposure factor %

Annual Loss Expectancy = Single Loss Expectancy X Annual rate of Occurrence

Page 17: CISA Review Courses - Slides Part2

Impact and Probability

Page 18: CISA Review Courses - Slides Part2

Managing Risk

Control

Share/Transfer Mitigate & Control

Accept (Mointor)

High Risk

Medium Risk

Medium Risk

Low Risk

Low

High

High

IMPACT

PROBABILITY

Page 19: CISA Review Courses - Slides Part2

Business Process Reengineering

Company Logo

- Business Efficiency

- Improved Techniques

- New Requirements

BPR project is strategic in nature

Page 20: CISA Review Courses - Slides Part2

Principles for BPR

Company Logo

- Think Big

- Incremental

- Hybrid Approach

Page 21: CISA Review Courses - Slides Part2

BPR Implementation Steps

Company Logo

- Envision

- Initiate

- Diagnose

- Redesign

- Reconstruct

- Evaluate

Page 22: CISA Review Courses - Slides Part2

Role of IS in BPR

Company Logo

- Enable the new process though automation- Provide IT Project Management Tools- Provide IT Support - Help in integrating business processes with the IT systems.

Page 23: CISA Review Courses - Slides Part2

Business Process Documentation

Company Logo

- Process Maps

- Risk Assessment

- Benchmarking

- Roles and Responsibilities

- Tasks and Activities

- Process Controls and Data Process Restrictions

Page 24: CISA Review Courses - Slides Part2

Business Process Documentation

Company Logo

- Process Maps

- Risk Assessment

- Benchmarking

- Roles and Responsibilities

- Tasks and Activities

- Process Controls and Data Process Restrictions

Page 25: CISA Review Courses - Slides Part2

Question1:

Company Logo

What is the main purpose of the IT Steering Committee?

A.Implement the New IT System

B.Review vender contracts

C.Identify business issues and objectives

D.Develop the IT Plan and Strategy

Page 26: CISA Review Courses - Slides Part2

Question2:

Company Logo

Which of the following strategies is used in business process reengineering with the big thinking approach?

A.Bottom-up

B.Business Impact Analysis

C.Outsourcing

D.Top-Down

Page 27: CISA Review Courses - Slides Part2

Question3:

Company Logo

An organization implements IT governance to ensure that it aligns its IT strategy with:

A.IT Objectives

B.Enterprise Objectives.

C.Audit Objectives.

D.Control Objectives.

Page 28: CISA Review Courses - Slides Part2

Question4:

Company Logo

Security Administrator performs a very important role in:

A. Creating the security policy

B.Testing Security System

C. Maintaining access rules

D. Ensuring data integrity