Information Technology Risk and Controls 2Nd Edition
Total Page:16
File Type:pdf, Size:1020Kb
IPPF – Practice Guide Information Technology Risk and Controls 2nd Edition 120366 PRO-GTAG_1_COVER.indd 1 3/28/12 2:18 PM Building on Experience, Shaping the Future of Audit Technology As the world’s leading audit management software, TeamMate has revolutionized the audit industry, empowering audit departments of all sizes to do more with less. Introduced in 1994, TeamMate has a long standing commitment to advancing the audit profession. From consistently innovative product updates, to hosted solutions, and now mobile apps, we are dedicated to leveraging the latest technology for our clients. Don’t take our word for it... TeamMate’s outreach extends beyond our customers to support Check out what our and enrich the professional community through research projects, educational programs and initiatives such as our Open customers are saying at Audit Innovation Contest. TeamMateSuccess.com To learn about TeamMate, visit us on the web at CCHTeamMate.com or call 1.888.830.5559. Copyright © 2012 Wolters Kluwer Financial Services, Inc. All Rights Reserved. 2119-ARC-TM-GTAG-AD 12/15/11 120366 PRO-GTAG_1_COVER.indd 2 3/28/12 2:18 PM Global Technology Audit Guide (GTAG®) 1 Information Technology Risk and Controls 2nd Edition March 2012 120366 PRO-GTAG_1_TEXT.indd 1 3/28/12 2:17 PM 120366 PRO-GTAG_1_TEXT.indd 2 3/28/12 2:17 PM GTAG — Table of Contents EXECUTIVE SUMMARY .........................................................................................................................................2 1. INTRODUCTION ................................................................................................................................................3 2. INTRODUCTION TO THE BASIS OF IT-RELATED BUSINESS RISKS AND CONTROLS ...........................5 3. INTERNAL STAKEHOLDERS AND IT RESPONSIBILITIES ...........................................................................8 4. ANALYZING RISKS ...........................................................................................................................................10 5. ASSESSING IT — AN OVERVIEW ...................................................................................................................13 6. UNDERSTANDING THE IMPORTANCE OF IT CONTROLS ........................................................................16 7. IT AUDIT COMPETENCIES AND SKILLS ......................................................................................................22 8. USE OF CONTROL FRAMEWORK ...................................................................................................................23 9. CONCLUSION ...................................................................................................................................................25 10. AUTHORS & REVIEWERS .............................................................................................................................26 11. APPENDIX: IT CONTROL FRAMEWORK CHECKLIST ..............................................................................27 1 120366 PRO-GTAG_1_TEXT.indd 1 3/28/12 2:17 PM GTAG — Executive Summary Executive Summary This GTAG helps chief auditing executives (CAEs) and internal auditors keep pace with the ever-changing and sometimes complex world of IT by providing resources written for business executives — not IT executives. Both management and the Board have an expectation that the internal audit activity provides assurance around all-impor- tant risks, including those introduced or enabled by the implementation of IT. The GTAG series helps the CAE and internal auditors become more knowledgeable of the risk, control, and governance issues surrounding technology. The goal of this GTAG is to help internal auditors become more comfortable with general IT controls so they can talk with their Board and exchange risk and control ideas with the chief information officer (CIO) and IT management. This GTAG describes how members of governing bodies, executives, IT professionals, and internal auditors address significant IT-related risk and control issues as well as pres- ents relevant frameworks for assessing IT risk and controls. Moreover, it sets the stage for other GTAGs that cover in greater detail specific IT topics and associated business roles and responsibilities. This guide is the second edition of the first installment in the GTAG series — GTAG 1: Information Technology Controls — which was published in March 2005. Its goal was, and is, to provide an overview of the topic of IT-related risks and controls. 2 120366 PRO-GTAG_1_TEXT.indd 2 3/28/12 2:17 PM GTAG — Introduction • Who is responsible? Everyone. However, control 1. Introduction ownership and responsibilities must be defined and disseminated by management. Otherwise, no one is The purpose of this GTAG is to explain IT risks and controls responsible, and results could be quite severe. in a format that allows CAEs and internal auditors to under- stand and communicate the need for strong IT controls. It is • When should IT risks and controls be assessed? organized to enable the reader to move through the frame- Always. IT is a rapidly changing environment that work for assessing IT controls and to address specific topics promotes process and organizational change. New based on need. This GTAG provides an overview of the risks emerge at a rapid pace. Controls must present key components of IT control assessment with an emphasis continuous evidence of their effectiveness, and that on the roles and responsibilities of key constituents within evidence must be assessed and evaluated constantly. the organization who can drive governance of IT resources. • How much control is enough? Management must Some readers already may be familiar with some aspects of decide based on risk appetite, tolerance and manda- this GTAG, but some segments will provide new perspectives tory regulations. Controls are not the objective; on how to approach IT risks and controls. One goal of this controls exist to help meet business objectives. GTAG, and others in the series, is that IT control assess- Controls are a cost of doing business and can ment components can be used to educate others about what be expensive, but not nearly as expensive as the IT risk and controls are and why management and internal possible consequences of inadequate controls. audit should ensure proper attention is paid to fundamental IT risks and controls to enable and sustain an effective IT control environment. IT controls are essential to protect assets, customers, part- ners, and sensitive information; demonstrate safe, efficient, Although technology provides opportunities for growth and and ethical behavior; and preserve brand, reputation, and development, it also represents threats, such as disruption, trust. In today’s global market and regulatory environment, deception, theft, and fraud. Research shows that outside these things are too easy to lose. A CAE can use this guide attackers threaten organizations, yet trusted insiders are a as a foundation to assess an organization’s framework and far greater threat. Fortunately, technology also can provide internal audit practices for IT risk and control, compliance, protection from threats, as this guide will demonstrate. and assurance. It also can be used to meet the challenges Executives should know the right questions to ask and what of constant change, increasing complexity, rapidly evolving the answers mean. For example: threats, and the need to improve efficiency. • Why should I understand IT risks and controls? Two words: assurance and reliability. Executives IT controls do not exist in isolation. They form an inter- play a key role in assuring information reliability. dependent continuum of protection, but they also may be Assurance comes primarily from an interdependent subject to compromise due to weak links. IT controls are set of business controls as well as from evidence that subject to error and management override, range from controls are continuous and sufficient. Management simple to highly technical, and exist in a dynamic envi- must weigh the evidence provided by controls and ronment. IT controls have two significant elements: the audits and conclude that it provides reasonable automation of business controls (which support business assurance. management and governance) and control of the IT envi- ronment and operations (which support the IT applications • What is to be protected? Trust should be protected and infrastructures). The CAE needs to consider and assess because it ensures business and efficiency. Controls both elements. The CAE may view the automated busi- provide the basis for trust, although they often ness controls as those controls where both business and IT are unseen. Technology provides the foundation audit skills work together in an integrated audit capacity. for many — perhaps most — business controls. The CAE may want to separate the general IT controls or Reliability of financial information and processes — general computer controls (GCCs) based on the technical now mandated for many organizations— is all about skills and competencies necessary to assess more technical trust. applications, infrastructure, and operations. For example, • Where are IT controls applied? Everywhere. IT an enterprise resource planning (ERP) application requires includes technology components, processes, people, more technical knowledge to understand and assess controls organization, and architecture, as well as the infor- over the ERP database structures, user