Redefining & Strengthening IT Governance Through Three Lines Of
Total Page:16
File Type:pdf, Size:1020Kb
Redefining & Strengthening IT Governance through Three Lines of Defense Presented by Ronke Oyemade, CISA, CRISC, PMP CEO, Principal Consultant, Strategic Global Consulting L.L.C Introduction • Brief Introduction of the Presenter. • Session Presentation: ‘Redefining & Strengthening IT Governance through Three Lines of Defense” This session takes a different and practical approach to strengthening IT Governance by applying the three lines of defense model. This approach adopts the use of Risk IT and Cobit as frameworks through which the three lines of defense model is implemented. The session gives an overview of the three lines of defense model, Risk IT and Cobit frameworks and provides practical application of them to the IT environment of a fictitious enterprise. • Benefits obtained from this session. Agenda 1. Use of IT and IT Risk 2. IT Governance: Overview and Importance 3. Overview of Three Lines of Defense, Risk IT and Cobit Framework 4. Three Lines of Defense Model 5. What is the relationship between Risk IT Framework and Cobit Framework 6. How do the Risk IT Framework and Cobit fit into the Three Lines of Defense Model 7. First Line of Defense 8. Second Line of Defense 9. Three Line of Defense Use of IT and IT risk • What is the importance of IT? • Why is IT Risk? What is IT risk? • IT risk is business risk and a component of overall risk universe of the enterprise. • IT-related risk is a component of other business risks IT risk as Business Risk Enterprise Risk StrategicStrategic RiskRisk EnvironmentalEnvironmental MarketMarket RiskRisk CreditCredit RiskRisk OperationalOperational ComplianceCompliance RiskRisk RiskRisk RiskRisk Compliance Risk ITIT Benefit/ValueBenefit/Value ITIT ProgrammeProgramme andand ITIT OperationsOperations andand EnablementEnablement RiskRisk ProjectProject DeliveryDelivery RiskRisk ServiceService DeliveryDelivery RiskRisk Types of IT risks ExamplesExamples ••TechnologyTechnology enablerenabler forfor newnew businessbusiness ITIT Benefit/Benefit/ ValueValue initiativesinitiatives EnablementEnablement ••TechnologyTechnology enablerenabler forfor efficientefficient operationsoperations ITIT ProgrammeProgramme andand ••ProjectProject qualityquality ProjectProject DeliveryDelivery ••ProjectProject RelevanceRelevance ••ProjectProject OverrunOverrun ITIT ProgrammeProgramme andand ••ProjectProject qualityquality ProjectProject DeliveryDelivery ••ProjectProject RelevanceRelevance ••ProjectProject OverrunOverrun IT Governance: Overview and Importance • Current economic crisis & governance • What is IT governance ? • Why is IT governance important? Overview of Three Lines of Defense, Risk IT and Cobit Framework • High-level overview of Three Lines of Defense, Risk IT and Cobit Framework Three Lines of Defense Model First Line of Defense Responsibility:Responsibility: BusinessBusiness operationsoperations performsperforms day-to-dayday-to-day riskrisk managementmanagement activityactivity Function:Function: AnAn establishedestablished riskrisk andand controlcontrol environmentenvironment Second Line of Defense Responsibility:Responsibility: OversightOversight functionsfunctions suchsuch asas finance,finance, HR,HR, Quality,Quality, andand RiskRisk Management,Management, definedefine policypolicy andand provideprovide assurance.assurance. Function:Function: StrategicStrategic management,management, policypolicy andand procedureprocedure setting,setting, functionalfunctional oversightoversight Third Line of Defense Responsibility:Responsibility: IndependenceIndependence assuranceassurance includesincludes internalinternal audit,audit, externalexternal auditaudit andand otherother independentindependent assuranceassurance providers,providers, offersoffers independentindependent challengechallenge toto thethe levelslevels ofof assuranceassurance providedprovided byby businessbusiness operationsoperations andand oversightoversight functions.functions. Function:Function: ProvidesProvides independentindependent challengechallenge andand assuranceassurance What is the relationship between Risk IT Framework and Cobit Framework Cobit processes manage all IT-related activities within an enterprise. These processes deal with events internal and externally. These events could pose a risk to the enterprise and need to be assessed and responses developed. This risk dimension and how to manage it is the main subject of the Risk IT Framework. Results from implementing the Risk IT Framework will have an impact on some of the IT processes and/or the input of the IT processes. How do the Risk IT Framework and Cobit fit into the Three Lines of Defense Model THREE LINES OF DEFENSE FRAMEWORKS FirstFirst LineLine ofof DefenseDefense RISKRISK ITIT Function:Function: AnAn establishedestablished riskrisk andand FRAMEWORKFRAMEWORK controlcontrol environmentenvironment COBITCOBIT SecondSecond LineLine ofof DefenseDefense FRAMEWORKFRAMEWORK Function:Function: StrategicStrategic management,management, policypolicy andand procedureprocedure setting,setting, functionalfunctional oversightoversight ThirdThird LineLine ofof DefenseDefense Function:Function: ProvidesProvides independentindependent challengechallenge andand assuranceassurance First Line of Defense THREE LINES OF DEFENSE FRAMEWORKS RISKRISK ITIT FRAMEWORK:FRAMEWORK: IdentifiesIdentifies andand assessesassesses ITIT riskrisk andand providesprovides riskrisk responsesresponses FirstFirst LineLine ofof DefenseDefense CobitCobit FRAMEWORK:FRAMEWORK: DefinesDefines andand implementsimplements controlscontrols toto mitigatemitigate keykey ITIT risksrisks What is Risk IT Framework? • Risk IT framework defines , and is founded on, a number of guiding principles for effective management of IT risk. Risk IT Framework - components RiskRisk GovernanceGovernance (RG)(RG) RiskRisk GovernanceGovernance :: RG1RG1 EstablishEstablish andand EnsuresEnsures thatthat ITIT riskrisk maintainmaintain aa commoncommon riskrisk managementmanagement practicespractices areare viewview embeddedembedded inin thethe Integrate with ERM RG2RG2 IntegrateIntegrate withwith ERMERM enterprise,enterprise, enablingenabling itit toto RG3RG3 MakeMake risk-awarerisk-aware securesecure optimaloptimal risk-adjustedrisk-adjusted businessbusiness decisionsdecisions return.return. Establish Make Risk- and aware RiskRisk EvaluationEvaluation (RE)(RE) Maintain a Business Common RE1RE1 CollectCollect datadata Decisions Risk View RE2RE2 AnalyseAnalyse riskrisk RE3RE3 MaintainMaintain riskrisk profileprofile Business Risk Response (RR) Risk Response (RR) Opportunities Analyze RR1RR1 ArticulateArticulate RiskRisk Manage Risk RR2RR2 ManageManage riskrisk Risk RR3RR3 ReactReact toto eventsevents Maintain Articulate React to COMMUNICATION Collect Risk Risk Events Data Profile RiskRisk EvaluationEvaluation :: RiskRisk ResponseResponse :: EnsureEnsure thatthat IT-relatedIT-related EnsureEnsure thatthat IT-relatedIT-related riskrisk risksrisks andand opportunitiesopportunities issues,issues, opportunitiesopportunities andand areare identified,identified, eventsevents areare addressedaddressed inin aa analyzedanalyzed andand cost-effectivecost-effective mannermanner andand inin presentedpresented inin businessbusiness lineline withwith businessbusiness prioritiespriorities termsterms Risk Governance (RG) processes RG1 Establish and maintain a common risk view RG2 Integrate with ERM RG3 Make risk-aware business decisions Risk Universe • Risk Universe defines boundaries of risk management activities and provides a structure for managing IT risk. • It considers overall business objectives , business processes and their dependencies throughout the enterprise and describes which IT applications and infrastructures support the business objectives through provision of IT services. • It also considers a life-cycle view of IT-related business activities,including transformation programmes, investments, projects and operations. IT Risk Assessment • A high level risk assessment performed to obtain initial view on overall IT risk • Reason for assessment: – Identification of potentially high-risk areas – Overview of major risk factors Enterprise IT Risk Assessment Form Part1 Entity Entity strategic role and objectives Assessment date Assessor(s) Major business processes IT infrastructure and applications supporting major business processes Important dependencies Part II – Risk Factor Assessment Overall l high-level IT risk rating Low Medium High Very High (based on results of the Entity is marginally Entity is dependent on Entity is very dependent on IT Entity is critically dependent assessment of all risk factors dependent on IT and/or IT and/or some IT risks and/or significant IT risk on IT and/or very significant IT below) IT risk is well controlled are not well controlled management deficiencies exist risk management issues exist Scoping of IT Risk Management Scoping includes activities to decide: • Which entities in the risk universe will be subject to risk management activities • The expected breadth and depth of risk management activities, including risk analysis and reporting Result of Enterprise IT Risk Assessment CorporateCorporate BusinessBusiness UnitUnit 11 BusinessBusiness UnitUnit 22 BusinessBusiness UnitUnit 33 MarketingMarketing R&DR&D MarketingMarketing SalesSales ManufacturingManufacturing SalesSales SalesSales ITIT SharedShared ServicesServices (Purchasing,(Purchasing, AccountingAccounting etc)etc) The chart above brings together all business lines , functional areas and risk importance. IT Risk Communication Expectation: