SlideShare ist ein Scribd-Unternehmen logo
1 von 16
Downloaden Sie, um offline zu lesen
Mehmet TAŞ
Principal Auditor
IT Audit Group
Turkish Court of Accounts - TCA
mtas@sayistay.gov.tr
 Establishment of Computer-Assisted Audit Group (1997)
 First IT audit (2002)
 IT audit guideline (2007)
 IT audit training activities (2007 - …)
 Expert support in conducting technical tests (2007 - …)
 Establishment of IT Audit Group (2015)
 Audit of e-Government projects (2017)
1
Growing number of e-Government projects
 Transformation of public services to e-Government services by use of ICT
 Modernization and/or integration of e-Government services
2
Low success rate in e-Government projects
 Decision making failures
 Project requirements not described with sufficient clarity
 Poor change management
 Poor risk management
 Information security requirements neglected
 Roles and responsibilities not defined clearly
 Lack of qualified staff
 Communication failures with stakeholders & suppliers …
3
2016-2019 National e-Government Strategy and Action Plan
 Action 1.2.2: Ensuring efficiency of audit for e-government projects in public
sector
Responsible Entity: Turkish Court of Accounts
 A model will be created for the audit of e-Government projects
 A guideline will be prepared for the audit of e-Government projects
 Audit of e-Government projects will be generalized in all public agencies and
institutions
4
 Examination and evaluation of internal controls
 Necessary for successful completion of e-Government projects
 Within efficiency, effectiveness, confidentiality, integrity, availability,
reliability and compliance criteria
5
 Completion
 within defined scope
 within given budget
 at targeted time
 Ensuring
 user-satisfaction with appropriate quality
 information security requirements
 compliance with national policies, entity strategies and relevant legislation
6
 Efficiency
 Effectiveness
 Confidentiality
 Integrity
 Availability
 Reliability
 Compliance
7
 IT Governance/Management
 Project Management
 System Development and Acquisition
 Outsourcing
 Operation & Maintenance
 Business Continuity & Disaster Recovery Planning
 Information Security
 Application Controls
8
 Determine the risks concerning the examined information systems
 Identify the necessary control mechanisms that can minimize these risks
 Check whether these IT controls are established, and if so, whether they are
functioning effectively or not
 Assess the weaknesses in IT controls
 Report the obtained findings according to a certain procedure
9
 Determine the type and the phase of the project
 Identify the audit areas to examine
 Determine risks
 Identify the necessary controls
 Check whether these controls are established, and if so, whether they are
functioning effectively or not
 Detect and assess control weaknesses
 Report material control weaknesses
10
 Preparation/start
 Realization
 Analysis
 Design
 Development
 Testing
 Integration/deployment
 Service delivery/completion
11
12
Preparation/Start Realization Service Delivery/Completion
PROJECT PHASE
AUDIT/CONTROLAREAS
ITGovernance/
Mangement
- Strategic Planning
- Policies and Procedures
- IT Organization, Roles and Responsibilities
- Human Resources & Training
- Requirement Analysis & Management
- Compliance with Legislation
- Risk Management
- Asset Management
- Information Security Management
ProjectManagement
- Integration Management
- Scope Management
- Time Management
- Cost Management
- Quality Management
- Human Resource Management
- Communications Management
- Risk Management
- Procurement Management
- Stakeholder Management
13
Preparation/Start Realization Service Delivery/Completion
Operation&
Maintenance
- Service Level Management
- Configuration Management
- Incident & Problem Management
- Change Management
- Capacity Management
PROJECT PHASE
AUDIT/CONTROLAREAS
System
Development&
Acquisition
- Policies and Procedures
- Analysis
- Requirements Definition
- Design & Code Development
- Acquisition & Configuration
- Test
- Acceptance & Implementation
- Data Transfer
- Monitoring
Outsourcing
- Procurement/Selection of Supplier - Contract - Examination and Acceptance
14
Preparation/Start Realization Service Delivery/Completion
AUDIT/CONTROLAREAS
Information
Security
- Analysis, Design and Realization of System
Security Requirements
- Analysis, Design and Realization of Application
Access Rights and Controls
- Analysis, Design and Realization of Database
Access Rights and Controls
- Physical and Environmental Security
- Network Management and Security
- Operation Systems Management and Security
- Database Management and Security
- Web & Mobile Application Security
Application
Controls
- Input
- Data Transfer
- Process
- Output
PROJECT PHASE
BusinessContinuity&
DisasterRecovery
Planning
- Business Continuity Policy
- Business Continuity Organization
- Risk Assessment
- Business Impact Analysis
- Business Continuity & Disaster Recovery
Planning
- Testing
- Back-up
- Security
- Outsourcing
Thank you for
your attention…
IT Audit Group
Turkish Court of Accounts - TCA

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Agenda, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019
Agenda, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019 Agenda, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019
Agenda, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019
 
United Kingdom - Companies House Response to the Covid-19 Pandemic
United Kingdom - Companies House Response to the Covid-19 PandemicUnited Kingdom - Companies House Response to the Covid-19 Pandemic
United Kingdom - Companies House Response to the Covid-19 Pandemic
 
North Macedonia - Joint Platform for Starting a Business
North Macedonia  -  Joint Platform for Starting a BusinessNorth Macedonia  -  Joint Platform for Starting a Business
North Macedonia - Joint Platform for Starting a Business
 
Azerbaijan - State Tax Service State Registration with Single Procedure
Azerbaijan - State Tax Service State Registration with Single ProcedureAzerbaijan - State Tax Service State Registration with Single Procedure
Azerbaijan - State Tax Service State Registration with Single Procedure
 
Singapore - Seamless Filing Project
Singapore - Seamless Filing ProjectSingapore - Seamless Filing Project
Singapore - Seamless Filing Project
 
List of participants, SIGMA Workshop on Digital Auditing for SAIs, Skopje, No...
List of participants, SIGMA Workshop on Digital Auditing for SAIs, Skopje, No...List of participants, SIGMA Workshop on Digital Auditing for SAIs, Skopje, No...
List of participants, SIGMA Workshop on Digital Auditing for SAIs, Skopje, No...
 
Thailand e-Government Roadmap
Thailand e-Government RoadmapThailand e-Government Roadmap
Thailand e-Government Roadmap
 
Oracle day romania peter erdosi final
Oracle day romania peter erdosi finalOracle day romania peter erdosi final
Oracle day romania peter erdosi final
 
IAESB Standards Development & Initiative: Information and Communication Techn...
IAESB Standards Development & Initiative: Information and Communication Techn...IAESB Standards Development & Initiative: Information and Communication Techn...
IAESB Standards Development & Initiative: Information and Communication Techn...
 
PPT, Moldova, Third ENP East public procurement conference, Tbilisi, 6 Novemb...
PPT, Moldova, Third ENP East public procurement conference, Tbilisi, 6 Novemb...PPT, Moldova, Third ENP East public procurement conference, Tbilisi, 6 Novemb...
PPT, Moldova, Third ENP East public procurement conference, Tbilisi, 6 Novemb...
 
Suggestions for Speedy and Inexpensive Justice
Suggestions for Speedy and Inexpensive JusticeSuggestions for Speedy and Inexpensive Justice
Suggestions for Speedy and Inexpensive Justice
 
PPT, V Nestulia, Third ENP East public procurement conference, Tbilisi, 6 Nov...
PPT, V Nestulia, Third ENP East public procurement conference, Tbilisi, 6 Nov...PPT, V Nestulia, Third ENP East public procurement conference, Tbilisi, 6 Nov...
PPT, V Nestulia, Third ENP East public procurement conference, Tbilisi, 6 Nov...
 
Dividends Divide and Data
Dividends Divide and DataDividends Divide and Data
Dividends Divide and Data
 
E-Governance in Srilanka
E-Governance in SrilankaE-Governance in Srilanka
E-Governance in Srilanka
 
E-Development for a Smart Sri Lanka
E-Development for a Smart Sri LankaE-Development for a Smart Sri Lanka
E-Development for a Smart Sri Lanka
 
Disruptive Trends Affecting Caribbean Accountancy Profession - Staying Ahead ...
Disruptive Trends Affecting Caribbean Accountancy Profession - Staying Ahead ...Disruptive Trends Affecting Caribbean Accountancy Profession - Staying Ahead ...
Disruptive Trends Affecting Caribbean Accountancy Profession - Staying Ahead ...
 
Entrepreneurship at the beginning of change management
Entrepreneurship at the beginning of change managementEntrepreneurship at the beginning of change management
Entrepreneurship at the beginning of change management
 
E sri lanka-- E-Services for Citizens
E sri lanka-- E-Services for CitizensE sri lanka-- E-Services for Citizens
E sri lanka-- E-Services for Citizens
 
Participant Portal - Validation of legal entities and financial capacity chec...
Participant Portal - Validation of legal entities and financial capacity chec...Participant Portal - Validation of legal entities and financial capacity chec...
Participant Portal - Validation of legal entities and financial capacity chec...
 
Nic1
Nic1Nic1
Nic1
 

Ähnlich wie PPT TCA, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019

100531 it management dpa upload
100531 it management dpa upload100531 it management dpa upload
100531 it management dpa upload
plpictimatec
 
Review of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability ModelsReview of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability Models
Alan McSweeney
 
Abdulla Amin AlMudharreb
Abdulla Amin AlMudharrebAbdulla Amin AlMudharreb
Abdulla Amin AlMudharreb
Abdulla Amin
 
OneIS CANHEIT V03 NN
OneIS CANHEIT V03 NNOneIS CANHEIT V03 NN
OneIS CANHEIT V03 NN
Mark Roman
 
Bayo Omisore, IT Auditor-Compliance Analyst
Bayo Omisore, IT Auditor-Compliance AnalystBayo Omisore, IT Auditor-Compliance Analyst
Bayo Omisore, IT Auditor-Compliance Analyst
Bayo Omisore.
 
CV of Mohan M
CV of Mohan MCV of Mohan M
CV of Mohan M
Mohan M
 

Ähnlich wie PPT TCA, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019 (20)

Mirsis Corporate Overview
Mirsis Corporate OverviewMirsis Corporate Overview
Mirsis Corporate Overview
 
dimensions_of_data_quality.pptx
dimensions_of_data_quality.pptxdimensions_of_data_quality.pptx
dimensions_of_data_quality.pptx
 
Get ahead of the cloud or get left behind
Get ahead of the cloud or get left behindGet ahead of the cloud or get left behind
Get ahead of the cloud or get left behind
 
IT Compliance in 2015 - Beyond the “v” model
IT Compliance in 2015 - Beyond the “v” modelIT Compliance in 2015 - Beyond the “v” model
IT Compliance in 2015 - Beyond the “v” model
 
6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness6 Steps to Transition Govt ICT effectiveness
6 Steps to Transition Govt ICT effectiveness
 
1365320.pdf
1365320.pdf1365320.pdf
1365320.pdf
 
100531 it management dpa upload
100531 it management dpa upload100531 it management dpa upload
100531 it management dpa upload
 
Review of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability ModelsReview of Information Technology Function Critical Capability Models
Review of Information Technology Function Critical Capability Models
 
Frameworks For Predictability
Frameworks For PredictabilityFrameworks For Predictability
Frameworks For Predictability
 
Asset Reliability Through Integrated Asset Management
Asset Reliability Through Integrated Asset ManagementAsset Reliability Through Integrated Asset Management
Asset Reliability Through Integrated Asset Management
 
Ch3 cism 2014
Ch3 cism 2014Ch3 cism 2014
Ch3 cism 2014
 
Cisa 2013 ch3
Cisa 2013 ch3Cisa 2013 ch3
Cisa 2013 ch3
 
Introduction to e-Gov Competency Framework (e-GCF) for Digital India Amit S...
Introduction to e-Gov Competency Framework (e-GCF) for Digital India   Amit S...Introduction to e-Gov Competency Framework (e-GCF) for Digital India   Amit S...
Introduction to e-Gov Competency Framework (e-GCF) for Digital India Amit S...
 
senior - projects manager - IT
senior - projects manager - ITsenior - projects manager - IT
senior - projects manager - IT
 
Abdulla Amin AlMudharreb
Abdulla Amin AlMudharrebAbdulla Amin AlMudharreb
Abdulla Amin AlMudharreb
 
Data Governance
Data GovernanceData Governance
Data Governance
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
 
OneIS CANHEIT V03 NN
OneIS CANHEIT V03 NNOneIS CANHEIT V03 NN
OneIS CANHEIT V03 NN
 
Bayo Omisore, IT Auditor-Compliance Analyst
Bayo Omisore, IT Auditor-Compliance AnalystBayo Omisore, IT Auditor-Compliance Analyst
Bayo Omisore, IT Auditor-Compliance Analyst
 
CV of Mohan M
CV of Mohan MCV of Mohan M
CV of Mohan M
 

Mehr von Support for Improvement in Governance and Management SIGMA

Mehr von Support for Improvement in Governance and Management SIGMA (20)

PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Ukraine roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Moldova roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdfPPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -CAF Armenia roadmap.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
PPT - SIGMA-GIZ Academies - Stage 1 - Financial support tu PAR in Montenegro....
 
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdfPPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
 
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdfPhoto gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
Photo gallery - SIGMA-GIZ Academies on QM - Stage 1.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdfPPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - prezentacija gsb podgorica.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF-MONTENEGRO-29-FEB.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF Georgia.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2 and 3.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2  and 3.pdfPPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2  and 3.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - QM Roadmapping Day 2 and 3.pdf
 
Academies-QM_Stage1_Ministry of Higher Education CAF.pdf
Academies-QM_Stage1_Ministry of Higher Education CAF.pdfAcademies-QM_Stage1_Ministry of Higher Education CAF.pdf
Academies-QM_Stage1_Ministry of Higher Education CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - ReSPA and CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Bosnia Herzegovina CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Montenegro CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - North Macedonia CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdfPPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - CAF in Ukraine.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdfPPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
PPT - SIGMA-GIZ Academies - Stage 1 -Serbia CAF.pdf
 
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdfPPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
PPT - SIGMA-GIZ Academies - Stage 1 - SIGMA opening.pdf
 
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
Omnichannel management, by Willem Pieterson - SIGMA Webinars on service desig...
 
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
eZdravlje, by Vladimir Raickovic - SIGMA Webinars on service design and deliv...
 

Kürzlich hochgeladen

Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
gajnagarg
 
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
Cara Menggugurkan Kandungan 087776558899
 
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi EscortsRussian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
Monica Sydney
 
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
gajnagarg
 
Competitive Advantage slide deck___.pptx
Competitive Advantage slide deck___.pptxCompetitive Advantage slide deck___.pptx
Competitive Advantage slide deck___.pptx
ScottMeyers35
 

Kürzlich hochgeladen (20)

Pakistani Call girls in Sharjah 0505086370 Sharjah Call girls
Pakistani Call girls in Sharjah 0505086370 Sharjah Call girlsPakistani Call girls in Sharjah 0505086370 Sharjah Call girls
Pakistani Call girls in Sharjah 0505086370 Sharjah Call girls
 
Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Morena [ 7014168258 ] Call Me For Genuine Models We...
 
Lorain Road Business District Revitalization Plan Final Presentation
Lorain Road Business District Revitalization Plan Final PresentationLorain Road Business District Revitalization Plan Final Presentation
Lorain Road Business District Revitalization Plan Final Presentation
 
2024 UN Civil Society Conference in Support of the Summit of the Future.
2024 UN Civil Society Conference in Support of the Summit of the Future.2024 UN Civil Society Conference in Support of the Summit of the Future.
2024 UN Civil Society Conference in Support of the Summit of the Future.
 
An Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCCAn Atoll Futures Research Institute? Presentation for CANCC
An Atoll Futures Research Institute? Presentation for CANCC
 
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
Cara Gugurkan Pembuahan Secara Alami Dan Cepat ABORSI KANDUNGAN 087776558899
 
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi EscortsRussian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
Russian Escorts in Abu Dhabi 0508644382 Abu Dhabi Escorts
 
Financing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCCFinancing strategies for adaptation. Presentation for CANCC
Financing strategies for adaptation. Presentation for CANCC
 
Cheap Call Girls In Hyderabad Phone No 📞 9352988975 📞 Elite Escort Service Av...
Cheap Call Girls In Hyderabad Phone No 📞 9352988975 📞 Elite Escort Service Av...Cheap Call Girls In Hyderabad Phone No 📞 9352988975 📞 Elite Escort Service Av...
Cheap Call Girls In Hyderabad Phone No 📞 9352988975 📞 Elite Escort Service Av...
 
Peace-Conflict-and-National-Adaptation-Plan-NAP-Processes-.pdf
Peace-Conflict-and-National-Adaptation-Plan-NAP-Processes-.pdfPeace-Conflict-and-National-Adaptation-Plan-NAP-Processes-.pdf
Peace-Conflict-and-National-Adaptation-Plan-NAP-Processes-.pdf
 
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Haldia [ 7014168258 ] Call Me For Genuine Models We...
 
Sustainability by Design: Assessment Tool for Just Energy Transition Plans
Sustainability by Design: Assessment Tool for Just Energy Transition PlansSustainability by Design: Assessment Tool for Just Energy Transition Plans
Sustainability by Design: Assessment Tool for Just Energy Transition Plans
 
Finance strategies for adaptation. Presentation for CANCC
Finance strategies for adaptation. Presentation for CANCCFinance strategies for adaptation. Presentation for CANCC
Finance strategies for adaptation. Presentation for CANCC
 
Call Girl Service in Korba 9332606886 High Profile Call Girls You Can Get ...
Call Girl Service in Korba   9332606886  High Profile Call Girls You Can Get ...Call Girl Service in Korba   9332606886  High Profile Call Girls You Can Get ...
Call Girl Service in Korba 9332606886 High Profile Call Girls You Can Get ...
 
sponsor for poor old age person food.pdf
sponsor for poor old age person food.pdfsponsor for poor old age person food.pdf
sponsor for poor old age person food.pdf
 
Competitive Advantage slide deck___.pptx
Competitive Advantage slide deck___.pptxCompetitive Advantage slide deck___.pptx
Competitive Advantage slide deck___.pptx
 
tOld settlement register shouldnotaffect BTR
tOld settlement register shouldnotaffect BTRtOld settlement register shouldnotaffect BTR
tOld settlement register shouldnotaffect BTR
 
AHMR volume 10 number 1 January-April 2024
AHMR volume 10 number 1 January-April 2024AHMR volume 10 number 1 January-April 2024
AHMR volume 10 number 1 January-April 2024
 
Scaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP processScaling up coastal adaptation in Maldives through the NAP process
Scaling up coastal adaptation in Maldives through the NAP process
 
Just Call VIP Call Girls In Bangalore Kr Puram ☎️ 6378878445 Independent Fem...
Just Call VIP Call Girls In  Bangalore Kr Puram ☎️ 6378878445 Independent Fem...Just Call VIP Call Girls In  Bangalore Kr Puram ☎️ 6378878445 Independent Fem...
Just Call VIP Call Girls In Bangalore Kr Puram ☎️ 6378878445 Independent Fem...
 

PPT TCA, SIGMA Workshop on Digital Auditing for SAIs, Skopje, November 2019

  • 1. Mehmet TAŞ Principal Auditor IT Audit Group Turkish Court of Accounts - TCA mtas@sayistay.gov.tr
  • 2.  Establishment of Computer-Assisted Audit Group (1997)  First IT audit (2002)  IT audit guideline (2007)  IT audit training activities (2007 - …)  Expert support in conducting technical tests (2007 - …)  Establishment of IT Audit Group (2015)  Audit of e-Government projects (2017) 1
  • 3. Growing number of e-Government projects  Transformation of public services to e-Government services by use of ICT  Modernization and/or integration of e-Government services 2
  • 4. Low success rate in e-Government projects  Decision making failures  Project requirements not described with sufficient clarity  Poor change management  Poor risk management  Information security requirements neglected  Roles and responsibilities not defined clearly  Lack of qualified staff  Communication failures with stakeholders & suppliers … 3
  • 5. 2016-2019 National e-Government Strategy and Action Plan  Action 1.2.2: Ensuring efficiency of audit for e-government projects in public sector Responsible Entity: Turkish Court of Accounts  A model will be created for the audit of e-Government projects  A guideline will be prepared for the audit of e-Government projects  Audit of e-Government projects will be generalized in all public agencies and institutions 4
  • 6.  Examination and evaluation of internal controls  Necessary for successful completion of e-Government projects  Within efficiency, effectiveness, confidentiality, integrity, availability, reliability and compliance criteria 5
  • 7.  Completion  within defined scope  within given budget  at targeted time  Ensuring  user-satisfaction with appropriate quality  information security requirements  compliance with national policies, entity strategies and relevant legislation 6
  • 8.  Efficiency  Effectiveness  Confidentiality  Integrity  Availability  Reliability  Compliance 7
  • 9.  IT Governance/Management  Project Management  System Development and Acquisition  Outsourcing  Operation & Maintenance  Business Continuity & Disaster Recovery Planning  Information Security  Application Controls 8
  • 10.  Determine the risks concerning the examined information systems  Identify the necessary control mechanisms that can minimize these risks  Check whether these IT controls are established, and if so, whether they are functioning effectively or not  Assess the weaknesses in IT controls  Report the obtained findings according to a certain procedure 9
  • 11.  Determine the type and the phase of the project  Identify the audit areas to examine  Determine risks  Identify the necessary controls  Check whether these controls are established, and if so, whether they are functioning effectively or not  Detect and assess control weaknesses  Report material control weaknesses 10
  • 12.  Preparation/start  Realization  Analysis  Design  Development  Testing  Integration/deployment  Service delivery/completion 11
  • 13. 12 Preparation/Start Realization Service Delivery/Completion PROJECT PHASE AUDIT/CONTROLAREAS ITGovernance/ Mangement - Strategic Planning - Policies and Procedures - IT Organization, Roles and Responsibilities - Human Resources & Training - Requirement Analysis & Management - Compliance with Legislation - Risk Management - Asset Management - Information Security Management ProjectManagement - Integration Management - Scope Management - Time Management - Cost Management - Quality Management - Human Resource Management - Communications Management - Risk Management - Procurement Management - Stakeholder Management
  • 14. 13 Preparation/Start Realization Service Delivery/Completion Operation& Maintenance - Service Level Management - Configuration Management - Incident & Problem Management - Change Management - Capacity Management PROJECT PHASE AUDIT/CONTROLAREAS System Development& Acquisition - Policies and Procedures - Analysis - Requirements Definition - Design & Code Development - Acquisition & Configuration - Test - Acceptance & Implementation - Data Transfer - Monitoring Outsourcing - Procurement/Selection of Supplier - Contract - Examination and Acceptance
  • 15. 14 Preparation/Start Realization Service Delivery/Completion AUDIT/CONTROLAREAS Information Security - Analysis, Design and Realization of System Security Requirements - Analysis, Design and Realization of Application Access Rights and Controls - Analysis, Design and Realization of Database Access Rights and Controls - Physical and Environmental Security - Network Management and Security - Operation Systems Management and Security - Database Management and Security - Web & Mobile Application Security Application Controls - Input - Data Transfer - Process - Output PROJECT PHASE BusinessContinuity& DisasterRecovery Planning - Business Continuity Policy - Business Continuity Organization - Risk Assessment - Business Impact Analysis - Business Continuity & Disaster Recovery Planning - Testing - Back-up - Security - Outsourcing
  • 16. Thank you for your attention… IT Audit Group Turkish Court of Accounts - TCA