SlideShare uma empresa Scribd logo
1 de 16
Baixar para ler offline
IT KNOWLEDGE
CA Professional Stage - Knowledge Level, ICAB
Tutor: Mohammad Abdul Matin
Chapter 5
Internal Control in Computer
Based Business System
Chapter Outline
 Control, IT Internal Control, IT Internal Audit
 Responsibility of Control
 Control Objectives and Techniques
 Control over Acquisition, Implementation and Changes
 Risk Assessment
 Business Continuity Plan
 Overview of ERP
Control Objectives for IT (COBIT)
 Developed in 1996 as generally accepted information
technology control objectives for day-to-day use.
 COBIT 4.1 has around 34 high level processes and
covers 201 control objectives in four domains:
– Planning & Organization
– Acquisition & Implementation
– Delivery & Support
– Monitoring & Evaluation
Control Objectives for IT (COBIT)
 A complete COBIT package contains:
Executive Summary: Summary, principles, concepts, synopsis of
the framework, etc.
Framework: Defines the different (34) high level and other IT
processes in four domains. Also defines the Information criteria.
Control Objectives: Defines the (210) control objectives in the
form of statements throughout the high level processes.
Management & Implementation Guidelines: Composed of
Maturity Models to help defining and comparing expectations,
CSFs, KPIs, Key Goals Indicators, industry norms, etc.
Control Objectives for IT (COBIT)
IT Assurance Guide: Tools to assess if the IT controls linked to the
respective control objectives are achieving results. Compatible
with ISACA’s (Information System Audit and Control Association)
and ITAF’s (Information Technology Assurance Framework)
standards.
Audit Trails
Logs that are designed to record activity at the system
application and user levels to provide detective control
related to security, issue finding, etc.
 Audit Trail Objectives:
– Detecting unauthorized access
– Facilitating reconstruction of failure events or problems
– Establishing personal accountability
Controls – IS Selection, Acquisition
 Strategic Master Plan
A strategic master plan to ensure appropriateness and priority
 Project Control
Project Management, resource and time planning with responsibilities
 Data Processing Schedule
Backend tasks to be distributed and scheduled to maximize resource
usage
 System Performance Measurement
Throughput and time based utilization measurements
 Post-Implementation Review
Compare the cost and benefit between plan and implementation
Post Implementation Review (PIR)
 Post Implementation Review (PIR) of an initiative is
performed to mainly assess if the following were met as per
expectation / plan:
– Business Objectives (budget, deadline, benefits, etc.)
– User Expectations (friendliness, workload, reliability, etc.)
– Technical Requirements (expandability, ease of operation,
interconnectivity with external systems, etc.)
 PIR is typically performed after any project is completed, has
become stable and not being significantly changed/modified
as a result of errors or realizations.
 PIR should be performed by independent IS
consultant/team who had not been involved in the original
initiative/project/development.
Business Continuity Planning (BCP)
Key Objectives of a BCP
– Safety of people at the time of a disaster
– Continue critical business operations
– Minimize the duration of disruption of regular operations
– Minimize immediate damage or losses (data and equipment)
– Establishing management succession and emergency powers
– Facilitate effective coordination of recovery tasks
– Reduce the complexity in recovery
– Identify critical lines of business and supporting functions
Business Continuity Planning (BCP)
Eight Phases of Developing a BCP
i. Pre-planning activities
ii. Vulnerability assessment
iii. Business impact analysis
iv. Definitions of requirements
v. Plan development
vi. Testing program
vii. Maintenance program
viii. Plan testing and implementation
Enterprise Resource Planning (ERP)
 ERP system is a fully integrated business management
system covering different functional areas of an
enterprise.
 ERP systems can be general or industry specific.
Components integrated within a ERP system can vary
depending on the organizational needs and priority.
 Examples of ERP systems: SAP, Oracle EBS, Dynamics AX,
IFS, Glovia, Infor, Sage, etc.
Enterprise Resource Planning (ERP)
 Benefits of a ERP System
– Integrated Financial Systems
– Standardized Processes
– Shared, Real-time Information
 Implementation of ERP Systems
– Corporate culture
– Process change
– Management support
– Project Manager competence
– The ERP Team
– Project Methodology
– Training
– Commit to the change
ERP Example: SAP
 World’s most used tier one ERP system developed by
SAP AG, a German company.
 SAR R/3 System Architecture:
– Presentation layer
– Application layer
– Database layer
 Can run on many different O/S and Database platforms
 Can be distributed into multiple systems for load
management and other objectives.
Common SAP R/3 Functional Modules
Exam Questions
 What is control? What are the purposes of internal
control? Explain the five key components required for
effective internal control.
 What is Audit Trail? Explain its objectives.
 Describe Post Implementation Review (PIR).
 Why is information system security important?
 Explain “vulnerability management” and “threat
management” in management of IT security
 What is disaster recovery plan? Describe major areas of
a disaster recovery planning document.
 What is ERP? Explain SAP as a ERP system.
Thank You

Mais conteúdo relacionado

Mais procurados

ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsMohammad Abdul Matin Emon
 
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyMohammad Abdul Matin Emon
 
ICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITMohammad Abdul Matin Emon
 
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureMohammad Abdul Matin Emon
 
Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Yasir Khan
 
Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Yasir Khan
 
DEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISDEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISHiren Selani
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubKaushal Trivedi
 
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...Arnab Roy Chowdhury
 
Erp case study
Erp case studyErp case study
Erp case studyUMaine
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)Muhammad Azmy
 
Bua 235 bpm-chap 7
Bua 235 bpm-chap 7Bua 235 bpm-chap 7
Bua 235 bpm-chap 7UMaine
 
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshMohammad Abdul Matin Emon
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Hendri Eka Saputra
 
The IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessThe IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessArnab Roy Chowdhury
 

Mais procurados (20)

ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
 
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT StrategyICAB - ITA Chapter 1 class 1-2 - IT Strategy
ICAB - ITA Chapter 1 class 1-2 - IT Strategy
 
ICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of ITICAB - ITK Chapter 3 class 5 - Management of IT
ICAB - ITK Chapter 3 class 5 - Management of IT
 
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology ArchitectureICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
ICAB - ITK Chapter 2 Set 2 - Information Technology Architecture
 
ERP for IT
ERP for ITERP for IT
ERP for IT
 
Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1Information System Architecture and Audit Control Lecture 1
Information System Architecture and Audit Control Lecture 1
 
Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2Information System Architecture and Audit Control Lecture 2
Information System Architecture and Audit Control Lecture 2
 
System planning
System planningSystem planning
System planning
 
3c 2 Information Systems Audit
3c   2   Information Systems Audit3c   2   Information Systems Audit
3c 2 Information Systems Audit
 
DEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MISDEVELOPMENT PROCESS OF MIS
DEVELOPMENT PROCESS OF MIS
 
IT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit ClubIT General Controls Presentation at IIA Vadodara Audit Club
IT General Controls Presentation at IIA Vadodara Audit Club
 
The organization structure, managers and activities
The organization structure, managers and activities The organization structure, managers and activities
The organization structure, managers and activities
 
Unit Iii
Unit IiiUnit Iii
Unit Iii
 
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...The organizational structure, managers and activities Ppt - Unitedworld Schoo...
The organizational structure, managers and activities Ppt - Unitedworld Schoo...
 
Erp case study
Erp case studyErp case study
Erp case study
 
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
 
Bua 235 bpm-chap 7
Bua 235 bpm-chap 7Bua 235 bpm-chap 7
Bua 235 bpm-chap 7
 
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in BangladeshICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
ICAB - ITA Chapter 1 class 5-6 - IT in Enterprise in Bangladesh
 
Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)
 
The IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of BusinessThe IT - IS and its influence Ppt - Unitedworld School of Business
The IT - IS and its influence Ppt - Unitedworld School of Business
 

Destaque

ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIMohammad Abdul Matin Emon
 
Chinese AAT Project progress updated
Chinese AAT Project progress updatedChinese AAT Project progress updated
Chinese AAT Project progress updatedAAT Taiwan
 
Chic Paintings, by Janet Hill
Chic Paintings, by Janet HillChic Paintings, by Janet Hill
Chic Paintings, by Janet Hillmaditabalnco
 
Zimele presentation IT strategy
Zimele presentation  IT strategyZimele presentation  IT strategy
Zimele presentation IT strategySam Mandebvu
 
Decision making
Decision makingDecision making
Decision makingOnline
 
Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)William Jordan
 
Ethics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sEthics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sBabasab Patil
 
Internal control system
Internal control systemInternal control system
Internal control systemMadiha Hassan
 
Financial Management Lesson Notes
Financial Management Lesson NotesFinancial Management Lesson Notes
Financial Management Lesson NotesEkrem Tufan
 
Financial statement analysis
Financial statement analysisFinancial statement analysis
Financial statement analysisAnuj Bhatia
 
The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016Peak Sales Recruiting
 

Destaque (14)

ICAB - ITA Chapter 1 class 3 - IT Strategy
ICAB - ITA Chapter 1 class 3 - IT StrategyICAB - ITA Chapter 1 class 3 - IT Strategy
ICAB - ITA Chapter 1 class 3 - IT Strategy
 
ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDIICAB - ITA Chapter 1 class 4 - E Commerce & EDI
ICAB - ITA Chapter 1 class 4 - E Commerce & EDI
 
Chinese AAT Project progress updated
Chinese AAT Project progress updatedChinese AAT Project progress updated
Chinese AAT Project progress updated
 
Aat in german
Aat in germanAat in german
Aat in german
 
Chic Paintings, by Janet Hill
Chic Paintings, by Janet HillChic Paintings, by Janet Hill
Chic Paintings, by Janet Hill
 
Zimele presentation IT strategy
Zimele presentation  IT strategyZimele presentation  IT strategy
Zimele presentation IT strategy
 
Decision making
Decision makingDecision making
Decision making
 
Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)Chic Paints Ltd (3) (1)
Chic Paints Ltd (3) (1)
 
Ethics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom sEthics fraud & internal control ppt @ dom s
Ethics fraud & internal control ppt @ dom s
 
Internal control system
Internal control systemInternal control system
Internal control system
 
Financial Management Lesson Notes
Financial Management Lesson NotesFinancial Management Lesson Notes
Financial Management Lesson Notes
 
Financial statement analysis
Financial statement analysisFinancial statement analysis
Financial statement analysis
 
The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016The Top 10 Sales Conferences of 2016
The Top 10 Sales Conferences of 2016
 
Financial management
Financial managementFinancial management
Financial management
 

Semelhante a ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems

CONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceCONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceYalcin Gerek
 
Conig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceConig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceYalcin Gerek
 
Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Tej Kiran
 
Inroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxInroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxnagarajan740445
 
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxRamanaBulusu1
 
Information technology for managers
Information technology for managersInformation technology for managers
Information technology for managersDebashish Sahu
 
Aim PPT For Oracle HRMS
Aim PPT For Oracle HRMSAim PPT For Oracle HRMS
Aim PPT For Oracle HRMSRajiv reddy
 
Elico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions Singapore
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachMohammad Reda Katby
 
Oracle AIM Methodology
Oracle AIM MethodologyOracle AIM Methodology
Oracle AIM MethodologyFeras Ahmad
 
Use COBIT for IT SAVINGS
Use COBIT for IT SAVINGSUse COBIT for IT SAVINGS
Use COBIT for IT SAVINGSSanjiv Arora
 

Semelhante a ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems (20)

Aim crisp handout
Aim crisp handoutAim crisp handout
Aim crisp handout
 
CONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information GovernanceCONIG® v1.5 Converged Information Governance
CONIG® v1.5 Converged Information Governance
 
Conig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information GovernanceConig® v1.5 Converged Information Governance
Conig® v1.5 Converged Information Governance
 
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...Diskusi buku: Securing an IT Organization through Governance, Risk Management...
Diskusi buku: Securing an IT Organization through Governance, Risk Management...
 
Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)Enterprise Resource Planning(ERP)
Enterprise Resource Planning(ERP)
 
Inroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptxInroduction to ERP system core functions and challenages.pptx
Inroduction to ERP system core functions and challenages.pptx
 
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptxERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
ERP SYSTEM POST IMPLEMENTATION AUDIT_TRNG_May,2023 - Part-1.pptx
 
Information technology for managers
Information technology for managersInformation technology for managers
Information technology for managers
 
ERP 04
ERP 04ERP 04
ERP 04
 
Aim PPT For Oracle HRMS
Aim PPT For Oracle HRMSAim PPT For Oracle HRMS
Aim PPT For Oracle HRMS
 
Oracle Aim Methodology
Oracle Aim MethodologyOracle Aim Methodology
Oracle Aim Methodology
 
Elico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation ApproachElico Solutions' Odoo ERP Project Management Implementation Approach
Elico Solutions' Odoo ERP Project Management Implementation Approach
 
Audit rizkie hafizzah
Audit rizkie hafizzahAudit rizkie hafizzah
Audit rizkie hafizzah
 
Erp 2
Erp 2Erp 2
Erp 2
 
Chapter 1 erp
Chapter 1 erpChapter 1 erp
Chapter 1 erp
 
Principal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic ApproachPrincipal 4 Enabling A Holistic Approach
Principal 4 Enabling A Holistic Approach
 
Mba ii ewis u iv erp
Mba ii ewis u iv erpMba ii ewis u iv erp
Mba ii ewis u iv erp
 
Rabelani dagada wbs erp
Rabelani dagada wbs erpRabelani dagada wbs erp
Rabelani dagada wbs erp
 
Oracle AIM Methodology
Oracle AIM MethodologyOracle AIM Methodology
Oracle AIM Methodology
 
Use COBIT for IT SAVINGS
Use COBIT for IT SAVINGSUse COBIT for IT SAVINGS
Use COBIT for IT SAVINGS
 

Último

BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxBIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxSayali Powar
 
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...HetalPathak10
 
How to Uninstall a Module in Odoo 17 Using Command Line
How to Uninstall a Module in Odoo 17 Using Command LineHow to Uninstall a Module in Odoo 17 Using Command Line
How to Uninstall a Module in Odoo 17 Using Command LineCeline George
 
Employablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxEmployablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxryandux83rd
 
ICS 2208 Lecture Slide Notes for Topic 6
ICS 2208 Lecture Slide Notes for Topic 6ICS 2208 Lecture Slide Notes for Topic 6
ICS 2208 Lecture Slide Notes for Topic 6Vanessa Camilleri
 
Objectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxObjectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxMadhavi Dharankar
 
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...Nguyen Thanh Tu Collection
 
Unraveling Hypertext_ Analyzing Postmodern Elements in Literature.pptx
Unraveling Hypertext_ Analyzing  Postmodern Elements in  Literature.pptxUnraveling Hypertext_ Analyzing  Postmodern Elements in  Literature.pptx
Unraveling Hypertext_ Analyzing Postmodern Elements in Literature.pptxDhatriParmar
 
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptx
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptxDecoding the Tweet _ Practical Criticism in the Age of Hashtag.pptx
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptxDhatriParmar
 
How to Manage Buy 3 Get 1 Free in Odoo 17
How to Manage Buy 3 Get 1 Free in Odoo 17How to Manage Buy 3 Get 1 Free in Odoo 17
How to Manage Buy 3 Get 1 Free in Odoo 17Celine George
 
Sulphonamides, mechanisms and their uses
Sulphonamides, mechanisms and their usesSulphonamides, mechanisms and their uses
Sulphonamides, mechanisms and their usesVijayaLaxmi84
 
DBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfDBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfChristalin Nelson
 
Comparative Literature in India by Amiya dev.pptx
Comparative Literature in India by Amiya dev.pptxComparative Literature in India by Amiya dev.pptx
Comparative Literature in India by Amiya dev.pptxAvaniJani1
 
An Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPAn Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPCeline George
 
Indexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfIndexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfChristalin Nelson
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Celine George
 

Último (20)

BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptxBIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
BIOCHEMISTRY-CARBOHYDRATE METABOLISM CHAPTER 2.pptx
 
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...
Satirical Depths - A Study of Gabriel Okara's Poem - 'You Laughed and Laughed...
 
How to Uninstall a Module in Odoo 17 Using Command Line
How to Uninstall a Module in Odoo 17 Using Command LineHow to Uninstall a Module in Odoo 17 Using Command Line
How to Uninstall a Module in Odoo 17 Using Command Line
 
Employablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxEmployablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptx
 
Chi-Square Test Non Parametric Test Categorical Variable
Chi-Square Test Non Parametric Test Categorical VariableChi-Square Test Non Parametric Test Categorical Variable
Chi-Square Test Non Parametric Test Categorical Variable
 
ICS 2208 Lecture Slide Notes for Topic 6
ICS 2208 Lecture Slide Notes for Topic 6ICS 2208 Lecture Slide Notes for Topic 6
ICS 2208 Lecture Slide Notes for Topic 6
 
Objectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxObjectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptx
 
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...
31 ĐỀ THI THỬ VÀO LỚP 10 - TIẾNG ANH - FORM MỚI 2025 - 40 CÂU HỎI - BÙI VĂN V...
 
Unraveling Hypertext_ Analyzing Postmodern Elements in Literature.pptx
Unraveling Hypertext_ Analyzing  Postmodern Elements in  Literature.pptxUnraveling Hypertext_ Analyzing  Postmodern Elements in  Literature.pptx
Unraveling Hypertext_ Analyzing Postmodern Elements in Literature.pptx
 
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptx
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptxDecoding the Tweet _ Practical Criticism in the Age of Hashtag.pptx
Decoding the Tweet _ Practical Criticism in the Age of Hashtag.pptx
 
How to Manage Buy 3 Get 1 Free in Odoo 17
How to Manage Buy 3 Get 1 Free in Odoo 17How to Manage Buy 3 Get 1 Free in Odoo 17
How to Manage Buy 3 Get 1 Free in Odoo 17
 
Sulphonamides, mechanisms and their uses
Sulphonamides, mechanisms and their usesSulphonamides, mechanisms and their uses
Sulphonamides, mechanisms and their uses
 
DBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfDBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdf
 
prashanth updated resume 2024 for Teaching Profession
prashanth updated resume 2024 for Teaching Professionprashanth updated resume 2024 for Teaching Profession
prashanth updated resume 2024 for Teaching Profession
 
Comparative Literature in India by Amiya dev.pptx
Comparative Literature in India by Amiya dev.pptxComparative Literature in India by Amiya dev.pptx
Comparative Literature in India by Amiya dev.pptx
 
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
Mattingly "AI & Prompt Design" - Introduction to Machine Learning"
 
An Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPAn Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERP
 
Faculty Profile prashantha K EEE dept Sri Sairam college of Engineering
Faculty Profile prashantha K EEE dept Sri Sairam college of EngineeringFaculty Profile prashantha K EEE dept Sri Sairam college of Engineering
Faculty Profile prashantha K EEE dept Sri Sairam college of Engineering
 
Indexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfIndexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdf
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17
 

ICAB - ITK Chapter 5 Set 2 - Internal Control in IT Systems

  • 1. IT KNOWLEDGE CA Professional Stage - Knowledge Level, ICAB Tutor: Mohammad Abdul Matin Chapter 5 Internal Control in Computer Based Business System
  • 2. Chapter Outline  Control, IT Internal Control, IT Internal Audit  Responsibility of Control  Control Objectives and Techniques  Control over Acquisition, Implementation and Changes  Risk Assessment  Business Continuity Plan  Overview of ERP
  • 3. Control Objectives for IT (COBIT)  Developed in 1996 as generally accepted information technology control objectives for day-to-day use.  COBIT 4.1 has around 34 high level processes and covers 201 control objectives in four domains: – Planning & Organization – Acquisition & Implementation – Delivery & Support – Monitoring & Evaluation
  • 4. Control Objectives for IT (COBIT)  A complete COBIT package contains: Executive Summary: Summary, principles, concepts, synopsis of the framework, etc. Framework: Defines the different (34) high level and other IT processes in four domains. Also defines the Information criteria. Control Objectives: Defines the (210) control objectives in the form of statements throughout the high level processes. Management & Implementation Guidelines: Composed of Maturity Models to help defining and comparing expectations, CSFs, KPIs, Key Goals Indicators, industry norms, etc.
  • 5. Control Objectives for IT (COBIT) IT Assurance Guide: Tools to assess if the IT controls linked to the respective control objectives are achieving results. Compatible with ISACA’s (Information System Audit and Control Association) and ITAF’s (Information Technology Assurance Framework) standards.
  • 6. Audit Trails Logs that are designed to record activity at the system application and user levels to provide detective control related to security, issue finding, etc.  Audit Trail Objectives: – Detecting unauthorized access – Facilitating reconstruction of failure events or problems – Establishing personal accountability
  • 7. Controls – IS Selection, Acquisition  Strategic Master Plan A strategic master plan to ensure appropriateness and priority  Project Control Project Management, resource and time planning with responsibilities  Data Processing Schedule Backend tasks to be distributed and scheduled to maximize resource usage  System Performance Measurement Throughput and time based utilization measurements  Post-Implementation Review Compare the cost and benefit between plan and implementation
  • 8. Post Implementation Review (PIR)  Post Implementation Review (PIR) of an initiative is performed to mainly assess if the following were met as per expectation / plan: – Business Objectives (budget, deadline, benefits, etc.) – User Expectations (friendliness, workload, reliability, etc.) – Technical Requirements (expandability, ease of operation, interconnectivity with external systems, etc.)  PIR is typically performed after any project is completed, has become stable and not being significantly changed/modified as a result of errors or realizations.  PIR should be performed by independent IS consultant/team who had not been involved in the original initiative/project/development.
  • 9. Business Continuity Planning (BCP) Key Objectives of a BCP – Safety of people at the time of a disaster – Continue critical business operations – Minimize the duration of disruption of regular operations – Minimize immediate damage or losses (data and equipment) – Establishing management succession and emergency powers – Facilitate effective coordination of recovery tasks – Reduce the complexity in recovery – Identify critical lines of business and supporting functions
  • 10. Business Continuity Planning (BCP) Eight Phases of Developing a BCP i. Pre-planning activities ii. Vulnerability assessment iii. Business impact analysis iv. Definitions of requirements v. Plan development vi. Testing program vii. Maintenance program viii. Plan testing and implementation
  • 11. Enterprise Resource Planning (ERP)  ERP system is a fully integrated business management system covering different functional areas of an enterprise.  ERP systems can be general or industry specific. Components integrated within a ERP system can vary depending on the organizational needs and priority.  Examples of ERP systems: SAP, Oracle EBS, Dynamics AX, IFS, Glovia, Infor, Sage, etc.
  • 12. Enterprise Resource Planning (ERP)  Benefits of a ERP System – Integrated Financial Systems – Standardized Processes – Shared, Real-time Information  Implementation of ERP Systems – Corporate culture – Process change – Management support – Project Manager competence – The ERP Team – Project Methodology – Training – Commit to the change
  • 13. ERP Example: SAP  World’s most used tier one ERP system developed by SAP AG, a German company.  SAR R/3 System Architecture: – Presentation layer – Application layer – Database layer  Can run on many different O/S and Database platforms  Can be distributed into multiple systems for load management and other objectives.
  • 14. Common SAP R/3 Functional Modules
  • 15. Exam Questions  What is control? What are the purposes of internal control? Explain the five key components required for effective internal control.  What is Audit Trail? Explain its objectives.  Describe Post Implementation Review (PIR).  Why is information system security important?  Explain “vulnerability management” and “threat management” in management of IT security  What is disaster recovery plan? Describe major areas of a disaster recovery planning document.  What is ERP? Explain SAP as a ERP system.