SlideShare ist ein Scribd-Unternehmen logo
1 von 16
IT KNOWLEDGE
CA Professional Stage - Knowledge Level, ICAB
Tutor: Mohammad Abdul Matin
Chapter 5
Internal Control in Computer
Based Business System
Chapter Outline
 Control, IT Internal Control, IT Internal Audit
 Responsibility of Control
 Control Objectives and Techniques
 Control over Acquisition, Implementation and Changes
 Risk Assessment
 Business Continuity Plan
 Overview of ERP
Control Objectives for IT (COBIT)
 Developed in 1996 as generally accepted information
technology control objectives for day-to-day use.
 COBIT 4.1 has around 34 high level processes and
covers 201 control objectives in four domains:
– Planning & Organization
– Acquisition & Implementation
– Delivery & Support
– Monitoring & Evaluation
Control Objectives for IT (COBIT)
 A complete COBIT package contains:
Executive Summary: Summary, principles, concepts, synopsis of
the framework, etc.
Framework: Defines the different (34) high level and other IT
processes in four domains. Also defines the Information criteria.
Control Objectives: Defines the (210) control objectives in the
form of statements throughout the high level processes.
Management & Implementation Guidelines: Composed of
Maturity Models to help defining and comparing expectations,
CSFs, KPIs, Key Goals Indicators, industry norms, etc.
Control Objectives for IT (COBIT)
IT Assurance Guide: Tools to assess if the IT controls linked to the
respective control objectives are achieving results. Compatible
with ISACA’s (Information System Audit and Control Association)
and ITAF’s (Information Technology Assurance Framework)
standards.
Audit Trails
Logs that are designed to record activity at the system
application and user levels to provide detective control
related to security, issue finding, etc.
 Audit Trail Objectives:
– Detecting unauthorized access
– Facilitating reconstruction of failure events or problems
– Establishing personal accountability
Controls – IS Selection, Acquisition
 Strategic Master Plan
A strategic master plan to ensure appropriateness and priority
 Project Control
Project Management, resource and time planning with responsibilities
 Data Processing Schedule
Backend tasks to be distributed and scheduled to maximize resource
usage
 System Performance Measurement
Throughput and time based utilization measurements
 Post-Implementation Review
Compare the cost and benefit between plan and implementation
Post Implementation Review (PIR)
 Post Implementation Review (PIR) of an initiative is
performed to mainly assess if the following were met as per
expectation / plan:
– Business Objectives (budget, deadline, benefits, etc.)
– User Expectations (friendliness, workload, reliability, etc.)
– Technical Requirements (expandability, ease of operation,
interconnectivity with external systems, etc.)
 PIR is typically performed after any project is completed, has
become stable and not being significantly changed/modified
as a result of errors or realizations.
 PIR should be performed by independent IS
consultant/team who had not been involved in the original
initiative/project/development.
Business Continuity Planning (BCP)
Key Objectives of a BCP
– Safety of people at the time of a disaster
– Continue critical business operations
– Minimize the duration of disruption of regular operations
– Minimize immediate damage or losses (data and equipment)
– Establishing management succession and emergency powers
– Facilitate effective coordination of recovery tasks
– Reduce the complexity in recovery
– Identify critical lines of business and supporting functions
Business Continuity Planning (BCP)
Eight Phases of Developing a BCP
i. Pre-planning activities
ii. Vulnerability assessment
iii. Business impact analysis
iv. Definitions of requirements
v. Plan development
vi. Testing program
vii. Maintenance program
viii. Plan testing and implementation
Enterprise Resource Planning (ERP)
 ERP system is a fully integrated business management
system covering different functional areas of an
enterprise.
 ERP systems can be general or industry specific.
Components integrated within a ERP system can vary
depending on the organizational needs and priority.
 Examples of ERP systems: SAP, Oracle EBS, Dynamics AX,
IFS, Glovia, Infor, Sage, etc.
Enterprise Resource Planning (ERP)
 Benefits of a ERP System
– Integrated Financial Systems
– Standardized Processes
– Shared, Real-time Information
 Implementation of ERP Systems
– Corporate culture
– Process change
– Management support
– Project Manager competence
– The ERP Team
– Project Methodology
– Training
– Commit to the change
ERP Example: SAP
 World’s most used tier one ERP system developed by
SAP AG, a German company.
 SAR R/3 System Architecture:
– Presentation layer
– Application layer
– Database layer
 Can run on many different O/S and Database platforms
 Can be distributed into multiple systems for load
management and other objectives.
Common SAP R/3 Functional Modules
Exam Questions
 What is control? What are the purposes of internal
control? Explain the five key components required for
effective internal control.
 What is Audit Trail? Explain its objectives.
 Describe Post Implementation Review (PIR).
 Why is information system security important?
 Explain “vulnerability management” and “threat
management” in management of IT security
 What is disaster recovery plan? Describe major areas of
a disaster recovery planning document.
 What is ERP? Explain SAP as a ERP system.
Thank You

Weitere ähnliche Inhalte

Was ist angesagt?

ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsMohammad Abdul Matin Emon
 
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyMohammad Abdul Matin Emon
 
ICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITMohammad Abdul Matin Emon
 
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureMohammad Abdul Matin Emon
 
Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Yasir Khan
 
Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Yasir Khan
 
DEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISDEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISHiren Selani
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubKaushal Trivedi
 
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...Arnab Roy Chowdhury
 
Erp case study
Erp case studyErp case study
Erp case studyUMaine
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)Muhammad Azmy
 
Bua 235 bpm-chap 7
Bua 235 bpm-chap 7Bua 235 bpm-chap 7
Bua 235 bpm-chap 7UMaine
 
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshMohammad Abdul Matin Emon
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Hendri Eka Saputra
 
The IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessThe IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessArnab Roy Chowdhury
 

Was ist angesagt? (20)

ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
 
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
 
ICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of IT
 
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
 
ERP for IT
ERP for ITERP for IT
ERP for IT
 
Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1
 
Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2
 
System planning
System planningSystem planning
System planning
 
3c 2 Information Systems Audit
3c   2   Information Systems Audit3c   2   Information Systems Audit
3c 2 Information Systems Audit
 
DEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISDEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MIS
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
 
The organization structure, managers and activities
The organization structure, managers and activities The organization structure, managers and activities
The organization structure, managers and activities
 
Unit Iii
Unit IiiUnit Iii
Unit Iii
 
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
 
Erp case study
Erp case studyErp case study
Erp case study
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
 
Bua 235 bpm-chap 7
Bua 235 bpm-chap 7Bua 235 bpm-chap 7
Bua 235 bpm-chap 7
 
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)
 
The IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessThe IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of Business
 

Andere mochten auch

ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIMohammad Abdul Matin Emon
 
Chinese AAT Project progress updated
Chinese AAT Project progress updatedChinese AAT Project progress updated
Chinese AAT Project progress updatedAAT Taiwan
 
Chic Paintings, by Janet Hill
Chic Paintings, by Janet HillChic Paintings, by Janet Hill
Chic Paintings, by Janet Hillmaditabalnco
 
Zimele presentation IT strategy
Zimele presentation  IT strategyZimele presentation  IT strategy
Zimele presentation IT strategySam Mandebvu
 
Decision making
Decision makingDecision making
Decision makingOnline
 
Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)William Jordan
 
Ethics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sEthics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sBabasab Patil
 
Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
Financial Management Lesson Notes
Financial Management Lesson NotesFinancial Management Lesson Notes
Financial Management Lesson NotesEkrem Tufan
 
Financial statement analysis
Financial statement analysisFinancial statement analysis
Financial statement analysisAnuj Bhatia
 
The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016Peak Sales Recruiting
 

Andere mochten auch (14)

ICAB - ITA Chapter 1 class 3 - IT Strategy
ICAB - ITA Chapter 1 class 3 - IT StrategyICAB - ITA Chapter 1 class 3 - IT Strategy
ICAB - ITA Chapter 1 class 3 - IT Strategy
 
ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
 
Chinese AAT Project progress updated
Chinese AAT Project progress updatedChinese AAT Project progress updated
Chinese AAT Project progress updated
 
Aat in german
Aat in germanAat in german
Aat in german
 
Chic Paintings, by Janet Hill
Chic Paintings, by Janet HillChic Paintings, by Janet Hill
Chic Paintings, by Janet Hill
 
Zimele presentation IT strategy
Zimele presentation  IT strategyZimele presentation  IT strategy
Zimele presentation IT strategy
 
Decision making
Decision makingDecision making
Decision making
 
Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)
 
Ethics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sEthics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom s
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Financial Management Lesson Notes
Financial Management Lesson NotesFinancial Management Lesson Notes
Financial Management Lesson Notes
 
Financial statement analysis
Financial statement analysisFinancial statement analysis
Financial statement analysis
 
The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016
 
Financial management
Financial managementFinancial management
Financial management
 

Ähnlich wie ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems

CONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceCONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceYalcin Gerek
 
Conig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceConig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceYalcin Gerek
 
Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Tej Kiran
 
Inroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxInroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxnagarajan740445
 
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxRamanaBulusu1
 
Information technology for managers
Information technology for managersInformation technology for managers
Information technology for managersDebashish Sahu
 
Aim PPT For Oracle HRMS
Aim PPT For Oracle HRMSAim PPT For Oracle HRMS
Aim PPT For Oracle HRMSRajiv reddy
 
Elico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions Singapore
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
Oracle AIM Methodology
Oracle AIM MethodologyOracle AIM Methodology
Oracle AIM MethodologyFeras Ahmad
 
Use COBIT for IT SAVINGS
Use COBIT for IT SAVINGSUse COBIT for IT SAVINGS
Use COBIT for IT SAVINGSSanjiv Arora
 

Ähnlich wie ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems (20)

Aim crisp handout
Aim crisp handoutAim crisp handout
Aim crisp handout
 
CONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceCONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information Governance
 
Conig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceConig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information Governance
 
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
 
Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)
 
Inroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxInroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptx
 
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
 
Information technology for managers
Information technology for managersInformation technology for managers
Information technology for managers
 
ERP 04
ERP 04ERP 04
ERP 04
 
Aim PPT For Oracle HRMS
Aim PPT For Oracle HRMSAim PPT For Oracle HRMS
Aim PPT For Oracle HRMS
 
Oracle Aim Methodology
Oracle Aim MethodologyOracle Aim Methodology
Oracle Aim Methodology
 
Elico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation Approach
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
Erp 2
Erp 2Erp 2
Erp 2
 
Chapter 1 erp
Chapter 1 erpChapter 1 erp
Chapter 1 erp
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
Mba ii ewis u iv erp
Mba ii ewis u iv erpMba ii ewis u iv erp
Mba ii ewis u iv erp
 
Rabelani dagada wbs erp
Rabelani dagada wbs erpRabelani dagada wbs erp
Rabelani dagada wbs erp
 
Oracle AIM Methodology
Oracle AIM MethodologyOracle AIM Methodology
Oracle AIM Methodology
 
Use COBIT for IT SAVINGS
Use COBIT for IT SAVINGSUse COBIT for IT SAVINGS
Use COBIT for IT SAVINGS
 

Kürzlich hochgeladen

Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3JemimahLaneBuaron
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptxVS Mahajan Coaching Centre
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxpboyjonauth
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdfssuser54595a
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docxPoojaSen20
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformChameera Dedduwage
 
Student login on Anyboli platform.helpin
Student login on Anyboli platform.helpinStudent login on Anyboli platform.helpin
Student login on Anyboli platform.helpinRaunakKeshri1
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdfQucHHunhnh
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Sapana Sha
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 

Kürzlich hochgeladen (20)

Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3Q4-W6-Restating Informational Text Grade 3
Q4-W6-Restating Informational Text Grade 3
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions  for the students and aspirants of Chemistry12th.pptxOrganic Name Reactions  for the students and aspirants of Chemistry12th.pptx
Organic Name Reactions for the students and aspirants of Chemistry12th.pptx
 
Introduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptxIntroduction to AI in Higher Education_draft.pptx
Introduction to AI in Higher Education_draft.pptx
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
18-04-UA_REPORT_MEDIALITERAСY_INDEX-DM_23-1-final-eng.pdf
 
mini mental status format.docx
mini    mental       status     format.docxmini    mental       status     format.docx
mini mental status format.docx
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy Reform
 
Student login on Anyboli platform.helpin
Student login on Anyboli platform.helpinStudent login on Anyboli platform.helpin
Student login on Anyboli platform.helpin
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111Call Girls in Dwarka Mor Delhi Contact Us 9654467111
Call Girls in Dwarka Mor Delhi Contact Us 9654467111
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 

ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems

  • 1. IT KNOWLEDGE CA Professional Stage - Knowledge Level, ICAB Tutor: Mohammad Abdul Matin Chapter 5 Internal Control in Computer Based Business System
  • 2. Chapter Outline  Control, IT Internal Control, IT Internal Audit  Responsibility of Control  Control Objectives and Techniques  Control over Acquisition, Implementation and Changes  Risk Assessment  Business Continuity Plan  Overview of ERP
  • 3. Control Objectives for IT (COBIT)  Developed in 1996 as generally accepted information technology control objectives for day-to-day use.  COBIT 4.1 has around 34 high level processes and covers 201 control objectives in four domains: – Planning & Organization – Acquisition & Implementation – Delivery & Support – Monitoring & Evaluation
  • 4. Control Objectives for IT (COBIT)  A complete COBIT package contains: Executive Summary: Summary, principles, concepts, synopsis of the framework, etc. Framework: Defines the different (34) high level and other IT processes in four domains. Also defines the Information criteria. Control Objectives: Defines the (210) control objectives in the form of statements throughout the high level processes. Management & Implementation Guidelines: Composed of Maturity Models to help defining and comparing expectations, CSFs, KPIs, Key Goals Indicators, industry norms, etc.
  • 5. Control Objectives for IT (COBIT) IT Assurance Guide: Tools to assess if the IT controls linked to the respective control objectives are achieving results. Compatible with ISACA’s (Information System Audit and Control Association) and ITAF’s (Information Technology Assurance Framework) standards.
  • 6. Audit Trails Logs that are designed to record activity at the system application and user levels to provide detective control related to security, issue finding, etc.  Audit Trail Objectives: – Detecting unauthorized access – Facilitating reconstruction of failure events or problems – Establishing personal accountability
  • 7. Controls – IS Selection, Acquisition  Strategic Master Plan A strategic master plan to ensure appropriateness and priority  Project Control Project Management, resource and time planning with responsibilities  Data Processing Schedule Backend tasks to be distributed and scheduled to maximize resource usage  System Performance Measurement Throughput and time based utilization measurements  Post-Implementation Review Compare the cost and benefit between plan and implementation
  • 8. Post Implementation Review (PIR)  Post Implementation Review (PIR) of an initiative is performed to mainly assess if the following were met as per expectation / plan: – Business Objectives (budget, deadline, benefits, etc.) – User Expectations (friendliness, workload, reliability, etc.) – Technical Requirements (expandability, ease of operation, interconnectivity with external systems, etc.)  PIR is typically performed after any project is completed, has become stable and not being significantly changed/modified as a result of errors or realizations.  PIR should be performed by independent IS consultant/team who had not been involved in the original initiative/project/development.
  • 9. Business Continuity Planning (BCP) Key Objectives of a BCP – Safety of people at the time of a disaster – Continue critical business operations – Minimize the duration of disruption of regular operations – Minimize immediate damage or losses (data and equipment) – Establishing management succession and emergency powers – Facilitate effective coordination of recovery tasks – Reduce the complexity in recovery – Identify critical lines of business and supporting functions
  • 10. Business Continuity Planning (BCP) Eight Phases of Developing a BCP i. Pre-planning activities ii. Vulnerability assessment iii. Business impact analysis iv. Definitions of requirements v. Plan development vi. Testing program vii. Maintenance program viii. Plan testing and implementation
  • 11. Enterprise Resource Planning (ERP)  ERP system is a fully integrated business management system covering different functional areas of an enterprise.  ERP systems can be general or industry specific. Components integrated within a ERP system can vary depending on the organizational needs and priority.  Examples of ERP systems: SAP, Oracle EBS, Dynamics AX, IFS, Glovia, Infor, Sage, etc.
  • 12. Enterprise Resource Planning (ERP)  Benefits of a ERP System – Integrated Financial Systems – Standardized Processes – Shared, Real-time Information  Implementation of ERP Systems – Corporate culture – Process change – Management support – Project Manager competence – The ERP Team – Project Methodology – Training – Commit to the change
  • 13. ERP Example: SAP  World’s most used tier one ERP system developed by SAP AG, a German company.  SAR R/3 System Architecture: – Presentation layer – Application layer – Database layer  Can run on many different O/S and Database platforms  Can be distributed into multiple systems for load management and other objectives.
  • 14. Common SAP R/3 Functional Modules
  • 15. Exam Questions  What is control? What are the purposes of internal control? Explain the five key components required for effective internal control.  What is Audit Trail? Explain its objectives.  Describe Post Implementation Review (PIR).  Why is information system security important?  Explain “vulnerability management” and “threat management” in management of IT security  What is disaster recovery plan? Describe major areas of a disaster recovery planning document.  What is ERP? Explain SAP as a ERP system.