Anyway, the guest speaker was Mr.Sajid Khan. And he spoke about IT Assurance and Risk Management.
Wouldn't expect there to be much room for creativity there but read on.. =)
IT Risk Management leads to 3 key risks :
- Confidentiality of the Data
- Integrity of the Data; making sure that its reliable
- Availability of the Data
- Earnest and Young
- KPMG
- Price Waterhouse Coopers
- Deloitte
You can assess their services on the following bases :
- IT entry level controls : strategy, policy and procedures, training and development
- IT general level control :
SDLC (System Devp. Life Cycle) and Change Management (Integrity),
Logical Access (Confidentiality),
IT Operations (Availabilty). - IT application controls : with SOX 404 (a requirement to show that internal audits are working) With IT being an integral part of the audit.
No comments:
Post a Comment