Benefits You Will Gain through This workshop:
- Aligning IT with your business goals, maximizing the benefit of IT to your
business functions, and minimizing the associated risks that come with IT
- Discovering strategies in fraud prevention and detection
- Recognizing the contracts and vendors for outsourced services
- Ensuring vendors are protecting the confidentiality, reliability, and the
availability of the services and data your organization depends upon to continue
to survive and profit
- Mastering how staff need to be especially trained to audit your outsourced
services in order to keep your own organization safe
- Determining organization performed an IT audit specifically aimed at documenting
compliance with the new financial legislation enacted around the world since
the Enron and Worldcom fiascos
- Evaluating new IT controls reports ready to accompany your financials
- Identifying the knowledge, skills, and task lists they need to immediately
improve data controls according to business and regulatory compliance needs.
Who should register for this course?
- Chief Executive Officers
- Chief Operating Officers
- Chief Financial Officers
- Chief Information Officers
- Chief Technology Officers
- Chief Information Security Officers
- Operation managers
- IT managers
- Contract managers
- Security managers
- Audit managers
- Audit Committee Members
- Accountant
- Financial Auditor
- System Auditor
- IS Auditing Specialist
DOMAIN 1:
COURSE ORIENTATION AND IT AUDIT OVERVIEW
- Introduction
- The Impact of IT on Organizations
- IT Governance
- IT and Transaction Processing
- The Work of an IT Auditor
- The Relationship between Financial and IT Audits
- IT Audit Skills
- Technical Skills
- General Personal and Business Skills
- Professional IT Auditor Organizations and Certifications
- The Information Systems Audit and Control
Association (ISACA)
- The Institute of Internal Auditors (IIA)
- The Association of Certified Fraud Examiners (ACFE)
- The American Institute of Certified Public
Accountants (AICPA)
- Security Management Credentials
a) CISA / CISM
b) CISSP
- Structuring IT Audits
- AICPA Audit Standards and Guidelines
- International Federation of Accountants (IFAC)
Guidelines
- ISACA Standards, Guidelines, and Procedures
DOMAIN 2:
LEGAL AND ETHICAL ISSUES FOR IT AUDITORS
- Introduction
- Code of Ethics
- Irregular and Illegal Acts
- Professional Guidance
- Regulatory and Legal Issues
- Legal Contracts
- Sarbanes-Oxley Overview and Action Items
- E. Computer Crime and Intellectual Property
- Computer Crime
- Intellectual Property
- Efforts to Thwart Cybercrime
- Cyber Information Crimes
- Cybercrime and IT Auditors
- Privacy Issues
DOMAIN 3:
INFORMATION TECHNOLOGY RISKS AND CONTROLS
- Introduction
- Identifying Information Technology Risks
- Business Risk
- Audit Risk
- Security Risk
- Continuity Risk
- Assessing Information Technology Risks
- Threats and Vulnerabilities
- Risk Indicators and Risk Measurement
- Identifying Information Technology Controls
- COSO and Other Control Models
- Statements on Auditing Standards
- SAS 94
(1) Understanding and Implementing SAS 94
(a) Which IT Risks need to be considered?
(2) What Are The Relevant Planning Issues?
(3) Implementation Strategies
- COBIT
- Executive Overview
- Background
- The COBIT Framework - Setting the Scene for
Implementation
- Systems Reliability Assurance
- Documenting Information Technology Controls
- Internal Control Narratives
- Flowcharts
- Internal Control Questionnaires
- Monitoring Information Technology Risks and Controls
DOMAIN 4:
IT DEPLOYMENT RISKS
- Introduction
- Developing Strategic Plans
1. Professional Guidance
2. IT Function Scorecard
- Managing Development Projects
- Acquiring Software Applications
- Developing Software Applications
1. Conducting a Feasibility Study
2. Considering Additional Systems Development Issues
F. Changing Software Applications
- Implementing Software Applications
1. Implementation Strategies
2. Implementation Planning
3. Other Implementation Issues
DOMAIN 5:
IT NETWORKS AND TELECOMMUNICATIONS RISKS
- Introduction
- Network and Telecommunications Technologie
- Network Components
- Types of Networks
- Protocols and Software
- Risks to IT Network and Telecommunications Systems
- Social Engineering
- Physical Infrastructure Threats Programmed Threats
- Denial of Service Attacks
- Software Vulnerabilities
- Auditing IT Network and Telecommunications Security
- Network Security Administration
- Authentication
a) Identification and Authentication
b) Authorization and Accountability
- Firewalls
- Intrusion Detection Systems
- Penetration Testing
- Auditing Network Security
DOMAIN 6:
USING COMPUTER ASSISTED AUDIT TOOLS AND TECHNIQUES (CAATS)
- Introduction to CAATTS
1. Definition of CAATTS
2. Types of CAATTS
a) Intacct Audit
b) CCH Inc.
c) PWC TeamMate
- Audit Productivity Software
1. Electronic Working Papers
2. Groupware
3. Time and Billing Software
4. Reference Libraries
5. Document Management
- Generalized Audit Software Tools
1. Data Extraction and Analysis
a) ACL
b) CA-Easytrieve
2. Statistical Analysis
3. Audit Expert Systems
- Computer Assisted IT Audit Techniques
1. Professional Standards and Guidelines
2. Ten Steps to Using CAATs
3. CAATs to Validate Application Integrity
4. CAATs to Verify Data Integrity
5. CAATs to Detect Fraud
- Class Lab: Working with ACL
- Continuous Auditing Techniques
DOMAIN 7:
CONDUCTING THE IT AUDIT
- Introduction
- Audit Standards
- The IT Audit Life Cycle
- Planning
- Risk Assessment, or “What Can Go Wrong?”
a) Implementing the Risk-Based Audit Approach
- Gathering Evidence for IS Audit
a) Types of Evidence
b) Reliability of Evidence
c) Evidence Gathering Techniques
d) Audit Sampling
- Forming Conclusions
- The Audit Opinion
- Following Up
- Four Main Types of IT Audits
- Attestation
- Findings and Recommendations
- SAS 70 Audit
- Auditing “Service Organizations”
- Service Auditor Reports
- Case Study 5.2: Significant Risk with Service
Organization Application
- Case Study 5.5: Service Organization without a
SAS 70
- Examining Vendor Contracts
- SAS 94 Audit
- Using CobiT to Perform an Audit
DOMAIN 8:
FRAUD AND FORENSIC AUDITING
- Understanding Fraud
- Why Fraud Occurs
- Major Fraud Studies
- IT Fraud
a) Case Study 9.6:
Fraud Resulting from Inadequate Segregation of Duties
- Cybercrime
- Responsibilities to Detect Fraud
- Corporate Responsibility
- The Auditor’s Responsibility – Professional Guidance
- Future Plans by the Accounting Profession
Regarding Fraud
- The Corporate and Auditing Accountability,
Responsibility, and Transparency Act of 2002 (Sarbanes-Oxley Act)
- Forensic Auditing
- What is Computer Forensics?
- What Can Computer Forensics Do?
- Conducting the Forensic Investigation
a) Prosecution
|