|
Dr. Dan Kneer Advisory Group |
CobiT and IT Frameworks and StandardsYes we all want to have world-class IT audit shops. And one way to get there is to audit “to” the gold standards. Ironically, many audit shops have no real audit benchmark as to “sound” auditing. (We’re not saying that they don’t perform good audits … but they may have no measurement or yardstick.) The true gold standard is the CobiT (Control Objectives for IT). Additionally, audit research, and practice, shows that the American Institute of Certified Public Accountants (AICPA) Statement on Auditing Standards (SASs) also provide a strong guidance, and linkage among the components of an audit. Given the exposure in public accounting, the SASs want to “get it right”… for all parties concerned. Other great standards exist such as the Institute of Internal Auditors (IIA) Global Technology Audit Guide (GTAG) and Guide to the Assessment of IT Risk (GAIT), the Auditing Standards (AS's) from the Public Company Accounting Oversite Board (PCAOB), the Committee of Sponsored Organizations (COSO) and COSO-ERM, Criteria of Control Board (CoCo) - Canada, Basel II, BS 7799 (UK) and even the ISOs. But what do they mean? What is their purpose? Are they point solutions or do they work together? How can they be used to streamline my Governance, Compliance, and Operational activities? Wouldn’t it be great to compare and contrast to “best of the best” auditing standards/frameworks, and then percolate our own “best practices” audit methodology? If these are the type of questions facing you, then this course is for you! We will provide an overview of several common IT Standards and Frameworks. We will examine how they came about, the issues and challenges that each standard is trying to address, and discuss the advantages and disadvantages of each. Finally, we will explore how they can be used synergistically to reduce or eliminate one-off solutions and streamline operations and compliance activities. Frameworks and Standards to be discussed include: SASs, CobiT, GTAG, COSO, Val IT, IT Infrastructure Library (ITIL), International Organization for Standardization (ISO) 17799 / 27001 / 27002, Capability Maturity Model (CMM), Health Insurance Portability and Accountability Act (HIPAA), PCI Security Standards Council, Gramm-Leach-Bliley Act (GLB), e-Discovery and more! |
|
Copyright © 2009 Dr. Dan Kneer Advisory Group.
All rights reserved. Last Updated: 30 July 2010 |