SlideShare ist ein Scribd-Unternehmen logo
1 von 15
W E D N E S D A Y , N O V E M B E R 2 0 , 2 0 1 3
Access Rights Review
5/19/2016
Governance Model
1
Purpose
The Need
Shared Ownership
Key Elements
Audit Team
Department Reviews
New Access Management Policy
Access Rights Review Process
Schedule (up to Pilot, after Pilot)
Schedule A – Periodic Reviews
11/20/2013
Create a reliable and
consistent corporate model
to identify and evaluate user
access rights that is….
Purpose
11/20/2013
In compliance with the security and risk
management process.
2
The Need
11/20/2013
1
• Response to internal and external Audits
2
• Culture of compliance – “it’s the right thing to do”
3
• Enforce the Principle of “least privilege”
4
• Identify access and permissions to MeM systems
5
• Detect inappropriate access to MeM systems
6
• Correct inaccuracy access thus reducing risk for the
organization
3
Shared Ownership
11/20/2013
Re s p o n s i b i l i t yOwn ers h ipAu th ority
EXECUTIVE
TEAM
INITIATIVE FINANCE
PROCESS IS OPERATIONS
DATA BUSINESS UNITS
4
Key Elements
11/20/2013
Coordinate/
Conduct
Process
Review &
Approve
Schedule
Approve
Reports
Approve
Process
Coordinate
Kickoff
Review
Findings
Integrate
Corporate
Policies (3)
Schedule
Identify
Systems to
Review
Determine
Periodic
Reviews
Determine
Start/End
Dates
Determine
Data Owner
Get
Schedule
Approval
Reports
Identify
Reports
Determine
Report
Data
Determine
Report
Format
Determine
Delivery
Method
Get
Report
Approval
Pilot
Determine
Process
Select
System to
Pilot
Perform
Process
Review/
Fine-Tune
Process
Get
Process
Approval
5
Audit Team
11/20/2013
Audit
Team
Finance
(Controller or
External Auditor)
Compliance
(Compliance
Manager)
6
Audit Team
Data Owners
IT
11/20/2013
Department Reviews
7
11/20/2013
New Access Management Policy
8
11/20/2013
9
7.1 Department Reviews Process
11/20/2013
10
7.2 Audits Process
11/20/2013
11
Schedule (Up to Pilot)
11/20/2013
12
Schedule (after Pilot)
11/20/2013
13
Periodic Reviews
11/20/2013
14
Questions
Q & A

Weitere ähnliche Inhalte

Ähnlich wie Governance Model - Slide Show

Tugas control & audit sistem informasi
Tugas control & audit sistem informasiTugas control & audit sistem informasi
Tugas control & audit sistem informasiNur Fatrianti
 
Control and Audit Information System
Control and Audit Information SystemControl and Audit Information System
Control and Audit Information Systemarif prasetyo
 
Kontrol & Audit Sistem Informasi
Kontrol & Audit Sistem InformasiKontrol & Audit Sistem Informasi
Kontrol & Audit Sistem Informasidwiki apsyarin
 
NACD Directorship_Sept-Oct 2016_Director Advisory_Eisner
NACD Directorship_Sept-Oct 2016_Director Advisory_EisnerNACD Directorship_Sept-Oct 2016_Director Advisory_Eisner
NACD Directorship_Sept-Oct 2016_Director Advisory_EisnerLena Licata
 
Data Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and MonitoringData Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and MonitoringJim Kaplan CIA CFE
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrainInfosecTrain
 
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMS
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMSCISA Domain 1 The Process On AUDITING INFORMATION SYSTEMS
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMSShivamSharma909
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)Muhammad Azmy
 
Lecture 17 sas framework internal control - james a. hall book chapter 3
Lecture 17  sas framework internal control - james a. hall book chapter 3Lecture 17  sas framework internal control - james a. hall book chapter 3
Lecture 17 sas framework internal control - james a. hall book chapter 3Habib Ullah Qamar
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management FrameworkTreasury Consulting LLP
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated frameworkIrfan Ahmed - ACA, CICA
 
Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk ConsultingPrashant Jain
 
2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot SpotsRon Steinkamp
 
Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
COSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfCOSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfAliehaDhea
 

Ähnlich wie Governance Model - Slide Show (20)

Tugas control & audit sistem informasi
Tugas control & audit sistem informasiTugas control & audit sistem informasi
Tugas control & audit sistem informasi
 
Control and Audit Information System
Control and Audit Information SystemControl and Audit Information System
Control and Audit Information System
 
Kontrol & Audit Sistem Informasi
Kontrol & Audit Sistem InformasiKontrol & Audit Sistem Informasi
Kontrol & Audit Sistem Informasi
 
NACD Directorship_Sept-Oct 2016_Director Advisory_Eisner
NACD Directorship_Sept-Oct 2016_Director Advisory_EisnerNACD Directorship_Sept-Oct 2016_Director Advisory_Eisner
NACD Directorship_Sept-Oct 2016_Director Advisory_Eisner
 
Sppt chap003
Sppt chap003Sppt chap003
Sppt chap003
 
Data Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and MonitoringData Analytics for Auditors Analysis and Monitoring
Data Analytics for Auditors Analysis and Monitoring
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrain
 
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMS
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMSCISA Domain 1 The Process On AUDITING INFORMATION SYSTEMS
CISA Domain 1 The Process On AUDITING INFORMATION SYSTEMS
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
 
Coso Monitoring - Templates
Coso Monitoring - TemplatesCoso Monitoring - Templates
Coso Monitoring - Templates
 
Lecture 17 sas framework internal control - james a. hall book chapter 3
Lecture 17  sas framework internal control - james a. hall book chapter 3Lecture 17  sas framework internal control - james a. hall book chapter 3
Lecture 17 sas framework internal control - james a. hall book chapter 3
 
Itrisksisaudit1
Itrisksisaudit1Itrisksisaudit1
Itrisksisaudit1
 
Internal Control & Risk Management Framework
Internal Control & Risk Management FrameworkInternal Control & Risk Management Framework
Internal Control & Risk Management Framework
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated framework
 
Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk Consulting
 
2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Internal control system
Internal control systemInternal control system
Internal control system
 
COSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdfCOSO_2013_Framework_on_Internal_Control.pdf
COSO_2013_Framework_on_Internal_Control.pdf
 
COSO 2013 and The Auditor
COSO 2013 and The AuditorCOSO 2013 and The Auditor
COSO 2013 and The Auditor
 

Mehr von Deborah Obasogie

Java Technical Design Document
Java Technical Design DocumentJava Technical Design Document
Java Technical Design DocumentDeborah Obasogie
 
Technical Specification - Database
Technical Specification - DatabaseTechnical Specification - Database
Technical Specification - DatabaseDeborah Obasogie
 
requirements_traceability_matrix_sample
requirements_traceability_matrix_samplerequirements_traceability_matrix_sample
requirements_traceability_matrix_sampleDeborah Obasogie
 
Tivoli Support Documentation
Tivoli Support DocumentationTivoli Support Documentation
Tivoli Support DocumentationDeborah Obasogie
 
SoftwareRequirementSpecification.docx
SoftwareRequirementSpecification.docxSoftwareRequirementSpecification.docx
SoftwareRequirementSpecification.docxDeborah Obasogie
 
Core Skills Assessment Requirements Module 4.0
Core Skills Assessment Requirements Module 4.0Core Skills Assessment Requirements Module 4.0
Core Skills Assessment Requirements Module 4.0Deborah Obasogie
 
Project Overview Statement (POS)
Project Overview Statement (POS)Project Overview Statement (POS)
Project Overview Statement (POS)Deborah Obasogie
 
Guidewire billing center system
Guidewire   billing center systemGuidewire   billing center system
Guidewire billing center systemDeborah Obasogie
 
Guidewire - BillingCenter System
Guidewire - BillingCenter SystemGuidewire - BillingCenter System
Guidewire - BillingCenter SystemDeborah Obasogie
 
Airlines Financial Analysis
Airlines Financial AnalysisAirlines Financial Analysis
Airlines Financial AnalysisDeborah Obasogie
 
Web Portal reporting Strategy and Recommendation
Web Portal reporting Strategy and RecommendationWeb Portal reporting Strategy and Recommendation
Web Portal reporting Strategy and RecommendationDeborah Obasogie
 
Performance Analaysis - Earned Value Analysis
Performance Analaysis - Earned Value AnalysisPerformance Analaysis - Earned Value Analysis
Performance Analaysis - Earned Value AnalysisDeborah Obasogie
 

Mehr von Deborah Obasogie (20)

Scrum30Secpptx
Scrum30SecpptxScrum30Secpptx
Scrum30Secpptx
 
Java Technical Design Document
Java Technical Design DocumentJava Technical Design Document
Java Technical Design Document
 
Technical Specification - Database
Technical Specification - DatabaseTechnical Specification - Database
Technical Specification - Database
 
requirements_traceability_matrix_sample
requirements_traceability_matrix_samplerequirements_traceability_matrix_sample
requirements_traceability_matrix_sample
 
Tivoli Support Documentation
Tivoli Support DocumentationTivoli Support Documentation
Tivoli Support Documentation
 
SoftwareRequirementSpecification.docx
SoftwareRequirementSpecification.docxSoftwareRequirementSpecification.docx
SoftwareRequirementSpecification.docx
 
Core Skills Assessment Requirements Module 4.0
Core Skills Assessment Requirements Module 4.0Core Skills Assessment Requirements Module 4.0
Core Skills Assessment Requirements Module 4.0
 
SubversionGuide.docx
SubversionGuide.docxSubversionGuide.docx
SubversionGuide.docx
 
Project Overview Statement (POS)
Project Overview Statement (POS)Project Overview Statement (POS)
Project Overview Statement (POS)
 
Guidewire billing center system
Guidewire   billing center systemGuidewire   billing center system
Guidewire billing center system
 
Guidewire - BillingCenter System
Guidewire - BillingCenter SystemGuidewire - BillingCenter System
Guidewire - BillingCenter System
 
Airlines Financial Analysis
Airlines Financial AnalysisAirlines Financial Analysis
Airlines Financial Analysis
 
Jira Issue Types
Jira Issue TypesJira Issue Types
Jira Issue Types
 
Web Portal reporting Strategy and Recommendation
Web Portal reporting Strategy and RecommendationWeb Portal reporting Strategy and Recommendation
Web Portal reporting Strategy and Recommendation
 
Performance Analaysis - Earned Value Analysis
Performance Analaysis - Earned Value AnalysisPerformance Analaysis - Earned Value Analysis
Performance Analaysis - Earned Value Analysis
 
Story & Estimate
Story & EstimateStory & Estimate
Story & Estimate
 
Word 2013
Word 2013Word 2013
Word 2013
 
Excel 2013
Excel 2013Excel 2013
Excel 2013
 
User Guide
User GuideUser Guide
User Guide
 
DeptReview
DeptReviewDeptReview
DeptReview
 

Governance Model - Slide Show