SlideShare une entreprise Scribd logo
LOGO
CISA Review Course
Iyad Mourtada, CIA, CMA, CFE, CPLP
Introduction to IT Governance
wps.cn/moban
Company Logo
IT Value
Delivery
Stakeholders
Value Drivers
Performance
Measurement
Risk
Management
Strategic
Alignment
IT GOVERNANCE
CORPORATE
GOVERNANCE
Company Logo
Audit Role in IT Governance:
- Improve the quality and effectiveness of
the IT governance Implementation.
- Ensure compliance with IT governance
initiatives implemented
CORPORATE
GOVERNANCE
Company Logo
Information Security Governance
•IS Governance should be integrated with IT
Governance
•The focus should be on
• Integrity of information
• Continuity of services
• Information assets protection
CORPORATE
GOVERNANCE
Enterprise Architecture
Organizations should in structured
way document its IT assets in to
facilitate understanding,
management and planning for IT
investments
• Performance
• Business
• Service component
• Technical
• Data
Company Logo
CORPORATE
GOVERNANCE
IS Roles & Responsibilities
•Systems analysis
•Security Architect
•Application programming
•Systems programming
•Network management
Company Logo
Segregation of Duties Within IS
- Security administration and change management
- Computer operations and system development
- System development and System design
- System development and systems maintenance
- Segregated
- Segregated
- Segregated
wps.cn/moban
Risk
Management
Risk Definitions
“Risk is the possibility that an event will
occur and adversely affect the
achievement of objectives.”
COSO ERM – Integrated Framework (Jersey City, NJ: AICPAs, 2004), P5
“Risk [is] the possibility of an event
occurring that will have an impact on
the achievement of objectives. Risk is
measured in terms of impact and
likelihood”
IPPF (Altamonte Springs, FL: IIA, 2011), p.43
Business Objectives
Strategic Objectives
Operations Objectives
Reporting Objectives
Compliance Objectives
COSO ERM – Integrated Framework (Jersey City, NJ: AICPAs, 2004),
P5
Risks
Company Logo
- Personnel Risk
- Information Security Risk
- Outsourcing Risk
- Operational Risk
- Financial Risk
- Compliance Risk
- Business Process Risk
Fraud
Lawsuits
Penalties and fines
Increased market share
New product
development
Increased revenue
Creating
shareholder
value
+
−
V
A
L
U
EPreserving
shareholder
value
ValueandRisk
Enterprise Risk Management (ERM) as an essential tool for good corporate governance, Rahaju Pal,
Deloitte - Enterprise Risk Services ,September 2010
Estimating Annual Losses
Company Logo
Single Loss Expectancy =
Asset Value $ X Exposure factor %
Annual Loss Expectancy =
Single Loss Expectancy X Annual rate of Occurrence
Impact and Probability
Managing Risk
Control
Share/Transfer Mitigate & Control
Accept (Mointor)
High Risk
Medium Risk
Medium Risk
Low Risk
Low
High
High
I
M
P
A
C
T
PROBABILITY
Business Process Reengineering
Company Logo
- Business Efficiency
- Improved Techniques
- New Requirements
BPR project is strategic in nature
Principles for BPR
Company Logo
- Think Big
- Incremental
- Hybrid Approach
BPR Implementation Steps
Company Logo
- Envision
- Initiate
- Diagnose
- Redesign
- Reconstruct
- Evaluate
Role of IS in BPR
Company Logo
- Enable the new process though automation
- Provide IT Project Management Tools
- Provide IT Support
- Help in integrating business processes with the
IT systems.
Business Process Documentation
Company Logo
- Process Maps
- Risk Assessment
- Benchmarking
- Roles and Responsibilities
- Tasks and Activities
- Process Controls and Data Process Restrictions
Business Process Documentation
Company Logo
- Process Maps
- Risk Assessment
- Benchmarking
- Roles and Responsibilities
- Tasks and Activities
- Process Controls and Data Process Restrictions
Question1:
Company Logo
What is the main purpose of the IT Steering
Committee?
A.Implement the New IT System
B.Review vender contracts
C.Identify business issues and objectives
D.Develop the IT Plan and Strategy
Question2:
Company Logo
Which of the following strategies is used in
business process reengineering with the big
thinking approach?
A.Bottom-up
B.Business Impact Analysis
C.Outsourcing
D.Top-Down
Question3:
Company Logo
An organization implements IT governance to ensure
that it aligns its IT strategy with:
A.IT Objectives
B.Enterprise Objectives.
C.Audit Objectives.
D.Control Objectives.
Question4:
Company Logo
Security Administrator performs a very
important role in:
A. Creating the security policy
B.Testing Security System
C. Maintaining access rules
D. Ensuring data integrity

Contenu connexe

Tendances

CA PPM Rationalizaiton
CA PPM RationalizaitonCA PPM Rationalizaiton
CA PPM Rationalizaiton
David Messineo
 
Technosoft Consultancy_Company Profile
Technosoft Consultancy_Company ProfileTechnosoft Consultancy_Company Profile
Technosoft Consultancy_Company Profile
Jittesh Purrohit
 
Ramco Systems- Overview
Ramco Systems- OverviewRamco Systems- Overview
Ramco Systems- Overview
Niraj Pradhan
 

Tendances (20)

Oracle_SmartERP - SCM RoundTable, What's Keeping You Up at Night
Oracle_SmartERP - SCM RoundTable, What's Keeping You Up at NightOracle_SmartERP - SCM RoundTable, What's Keeping You Up at Night
Oracle_SmartERP - SCM RoundTable, What's Keeping You Up at Night
 
The Protiviti View: RPA governance as enabler for value and acceptance of Rob...
The Protiviti View: RPA governance as enabler for value and acceptance of Rob...The Protiviti View: RPA governance as enabler for value and acceptance of Rob...
The Protiviti View: RPA governance as enabler for value and acceptance of Rob...
 
Best Practices for Designing and Building Integrations
Best Practices for Designing and Building IntegrationsBest Practices for Designing and Building Integrations
Best Practices for Designing and Building Integrations
 
CA PPM Rationalizaiton
CA PPM RationalizaitonCA PPM Rationalizaiton
CA PPM Rationalizaiton
 
Ramco BPO Services - A Proven End-to-End Solution for HR & Payroll Outsourcing
Ramco BPO Services - A Proven End-to-End Solution for HR & Payroll OutsourcingRamco BPO Services - A Proven End-to-End Solution for HR & Payroll Outsourcing
Ramco BPO Services - A Proven End-to-End Solution for HR & Payroll Outsourcing
 
Komia Overview
Komia OverviewKomia Overview
Komia Overview
 
Technosoft Consultancy_Company Profile
Technosoft Consultancy_Company ProfileTechnosoft Consultancy_Company Profile
Technosoft Consultancy_Company Profile
 
Martin Huddleston: No Service Management, No Security
Martin Huddleston: No Service Management, No SecurityMartin Huddleston: No Service Management, No Security
Martin Huddleston: No Service Management, No Security
 
Ramco Systems- Overview
Ramco Systems- OverviewRamco Systems- Overview
Ramco Systems- Overview
 
Streamline Capital Planning in Healthcare, Higher Ed, and Transportation wit...
 Streamline Capital Planning in Healthcare, Higher Ed, and Transportation wit... Streamline Capital Planning in Healthcare, Higher Ed, and Transportation wit...
Streamline Capital Planning in Healthcare, Higher Ed, and Transportation wit...
 
Transforming IT Services
Transforming IT ServicesTransforming IT Services
Transforming IT Services
 
Sustainable Architectures
Sustainable Architectures Sustainable Architectures
Sustainable Architectures
 
Managed Services Primer (HRMS)
Managed Services Primer (HRMS)Managed Services Primer (HRMS)
Managed Services Primer (HRMS)
 
SaaS vs BPO: Operational Considerations of the SaaS Service Delivery Model
SaaS vs BPO: Operational Considerations of the SaaS Service Delivery ModelSaaS vs BPO: Operational Considerations of the SaaS Service Delivery Model
SaaS vs BPO: Operational Considerations of the SaaS Service Delivery Model
 
11 Actions that will make your SIAM Programme successful
11 Actions that will make your SIAM Programme successful11 Actions that will make your SIAM Programme successful
11 Actions that will make your SIAM Programme successful
 
Reachwell Brochure
Reachwell BrochureReachwell Brochure
Reachwell Brochure
 
Hofincons, Technology and Consulting
Hofincons, Technology and ConsultingHofincons, Technology and Consulting
Hofincons, Technology and Consulting
 
Managing risks and opportunities in strategic fm outsourcing 3
Managing risks and opportunities in strategic fm outsourcing 3Managing risks and opportunities in strategic fm outsourcing 3
Managing risks and opportunities in strategic fm outsourcing 3
 
Full Overview Superior Group
Full Overview Superior GroupFull Overview Superior Group
Full Overview Superior Group
 
Overview superior group
Overview superior groupOverview superior group
Overview superior group
 

En vedette

En vedette (20)

CISA Review Courses - Slides Part2
CISA Review Courses - Slides Part2CISA Review Courses - Slides Part2
CISA Review Courses - Slides Part2
 
Mastering the Certified Professional in Learning and Performance (CPLP) Exam
Mastering the Certified Professional in Learning and Performance (CPLP) ExamMastering the Certified Professional in Learning and Performance (CPLP) Exam
Mastering the Certified Professional in Learning and Performance (CPLP) Exam
 
UserCertificateWithSignatures
UserCertificateWithSignaturesUserCertificateWithSignatures
UserCertificateWithSignatures
 
Intro to COBIT 5.0
Intro to COBIT 5.0Intro to COBIT 5.0
Intro to COBIT 5.0
 
Fraud Awareness Program - OpenThinking
Fraud Awareness Program - OpenThinkingFraud Awareness Program - OpenThinking
Fraud Awareness Program - OpenThinking
 
Mastering Enterprise Risk Management Inside Your Organization
Mastering Enterprise Risk Management Inside Your OrganizationMastering Enterprise Risk Management Inside Your Organization
Mastering Enterprise Risk Management Inside Your Organization
 
Financial Orchestra - PICPA Middle East Conference
Financial Orchestra - PICPA Middle East Conference Financial Orchestra - PICPA Middle East Conference
Financial Orchestra - PICPA Middle East Conference
 
PMP Preparation - 02 FAQ
PMP Preparation - 02 FAQPMP Preparation - 02 FAQ
PMP Preparation - 02 FAQ
 
50 qts مقابلة عمل planning
50 qts مقابلة عمل planning50 qts مقابلة عمل planning
50 qts مقابلة عمل planning
 
Financial Statement Fraud
Financial Statement FraudFinancial Statement Fraud
Financial Statement Fraud
 
Fraud Awareness Workshop 2015
Fraud Awareness Workshop 2015Fraud Awareness Workshop 2015
Fraud Awareness Workshop 2015
 
PMP Preparation - 08 Quality Management
PMP Preparation - 08 Quality ManagementPMP Preparation - 08 Quality Management
PMP Preparation - 08 Quality Management
 
The New Basics of Marketing - HBR
The New Basics of Marketing - HBRThe New Basics of Marketing - HBR
The New Basics of Marketing - HBR
 
PMP Preparation - 03 Framework
PMP Preparation - 03 FrameworkPMP Preparation - 03 Framework
PMP Preparation - 03 Framework
 
PMP integration review
PMP integration reviewPMP integration review
PMP integration review
 
PMP Preparation - 06 Time Management
PMP Preparation - 06 Time ManagementPMP Preparation - 06 Time Management
PMP Preparation - 06 Time Management
 
PMP Preparation - 11 Risk Management
PMP Preparation - 11 Risk ManagementPMP Preparation - 11 Risk Management
PMP Preparation - 11 Risk Management
 
Emergency management
Emergency managementEmergency management
Emergency management
 
PMP Preparation - 05 Scope Management
PMP Preparation - 05 Scope ManagementPMP Preparation - 05 Scope Management
PMP Preparation - 05 Scope Management
 
CISA Review Course Slides - Part1
CISA Review Course Slides - Part1CISA Review Course Slides - Part1
CISA Review Course Slides - Part1
 

Similaire à CISA Part2

The IQ Business Group
The IQ Business GroupThe IQ Business Group
The IQ Business Group
mbeck94
 
The IQ Business Group
The IQ Business GroupThe IQ Business Group
The IQ Business Group
kejensen810
 
CORPORATE PROFILE - ASOCON Pvt Ltd
CORPORATE PROFILE - ASOCON Pvt LtdCORPORATE PROFILE - ASOCON Pvt Ltd
CORPORATE PROFILE - ASOCON Pvt Ltd
Asocon Pvt. Limited
 
Intellinet Overview
Intellinet OverviewIntellinet Overview
Intellinet Overview
mclevenger
 
Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1
frankkulendran
 

Similaire à CISA Part2 (20)

Business Integra Profile 2008
Business Integra Profile 2008Business Integra Profile 2008
Business Integra Profile 2008
 
How to optimization your business...?
How to optimization your business...?How to optimization your business...?
How to optimization your business...?
 
How to enhance Profitability
How to enhance ProfitabilityHow to enhance Profitability
How to enhance Profitability
 
Improve business values and efficiency by IT
Improve business values and efficiency by ITImprove business values and efficiency by IT
Improve business values and efficiency by IT
 
E Team Data Management Offerings
E Team Data Management OfferingsE Team Data Management Offerings
E Team Data Management Offerings
 
Mann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRCMann-India_SAP_Service-Offering_GRC
Mann-India_SAP_Service-Offering_GRC
 
The IQ Business Group
The IQ Business GroupThe IQ Business Group
The IQ Business Group
 
The IQ Business Group
The IQ Business GroupThe IQ Business Group
The IQ Business Group
 
ADM Target Operating Models
ADM Target Operating ModelsADM Target Operating Models
ADM Target Operating Models
 
It risk advisory brochure 2013
It risk advisory brochure 2013It risk advisory brochure 2013
It risk advisory brochure 2013
 
It risk advisory brochure 2013
It risk advisory brochure 2013It risk advisory brochure 2013
It risk advisory brochure 2013
 
It risk advisory brochure 2013
It risk advisory brochure 2013It risk advisory brochure 2013
It risk advisory brochure 2013
 
It risk advisory brochure 2013
It risk advisory brochure 2013It risk advisory brochure 2013
It risk advisory brochure 2013
 
CORPORATE PROFILE - ASOCON Pvt Ltd
CORPORATE PROFILE - ASOCON Pvt LtdCORPORATE PROFILE - ASOCON Pvt Ltd
CORPORATE PROFILE - ASOCON Pvt Ltd
 
Intellinet Overview
Intellinet OverviewIntellinet Overview
Intellinet Overview
 
Intellinet Overview
Intellinet OverviewIntellinet Overview
Intellinet Overview
 
S&OP RFP 101: Evaluating Your ERP Vendor’s Solution vs. the Best-of-Breed
S&OP RFP 101: Evaluating Your ERP Vendor’s Solution vs. the Best-of-BreedS&OP RFP 101: Evaluating Your ERP Vendor’s Solution vs. the Best-of-Breed
S&OP RFP 101: Evaluating Your ERP Vendor’s Solution vs. the Best-of-Breed
 
JISommerResume
JISommerResumeJISommerResume
JISommerResume
 
ERP Implementation by Indiba Consultancy
ERP Implementation by Indiba ConsultancyERP Implementation by Indiba Consultancy
ERP Implementation by Indiba Consultancy
 
Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1Dci Pmo+Ecm+Erp Training+Embedded Sm1
Dci Pmo+Ecm+Erp Training+Embedded Sm1
 

Plus de Iyad Mourtada, CMA, CIA, CFE, CCSA, CRMA, CPLP

Plus de Iyad Mourtada, CMA, CIA, CFE, CCSA, CRMA, CPLP (20)

The Experience 2020 - Iyad Mourtada
The Experience 2020 - Iyad MourtadaThe Experience 2020 - Iyad Mourtada
The Experience 2020 - Iyad Mourtada
 
Digital Business Strategy Workshop
Digital Business Strategy Workshop Digital Business Strategy Workshop
Digital Business Strategy Workshop
 
OpenThinking Show - Fraud Case Files
OpenThinking Show - Fraud Case FilesOpenThinking Show - Fraud Case Files
OpenThinking Show - Fraud Case Files
 
CPLP Course 2014
CPLP Course 2014CPLP Course 2014
CPLP Course 2014
 
ASTD Competency Model 2013
ASTD Competency Model 2013ASTD Competency Model 2013
ASTD Competency Model 2013
 
Fraud prevention and detection within open data environment
Fraud prevention and detection within open data environmentFraud prevention and detection within open data environment
Fraud prevention and detection within open data environment
 
Fraud Game Template
Fraud Game TemplateFraud Game Template
Fraud Game Template
 
How ethical you are?
How ethical you are?How ethical you are?
How ethical you are?
 
How to lie, cheat and steal your way to success
How to lie, cheat and steal your way to successHow to lie, cheat and steal your way to success
How to lie, cheat and steal your way to success
 
Business Swimming Lessons
Business Swimming Lessons Business Swimming Lessons
Business Swimming Lessons
 
Passing the Torch
Passing the Torch Passing the Torch
Passing the Torch
 
How Accountants Cooked the Books
How Accountants Cooked the BooksHow Accountants Cooked the Books
How Accountants Cooked the Books
 
Why Auditors Do Not Discover Fraud
Why Auditors Do Not Discover FraudWhy Auditors Do Not Discover Fraud
Why Auditors Do Not Discover Fraud
 
What Color is your Business Strategy?
What Color is your Business Strategy?What Color is your Business Strategy?
What Color is your Business Strategy?
 
Business Swimming Lessons - Iyad Mourtada
Business Swimming Lessons - Iyad MourtadaBusiness Swimming Lessons - Iyad Mourtada
Business Swimming Lessons - Iyad Mourtada
 
Business Game
Business GameBusiness Game
Business Game
 
Visual Language - OpenThinking
Visual Language  - OpenThinkingVisual Language  - OpenThinking
Visual Language - OpenThinking
 
Contemporary Consulting - OpenThinking
Contemporary Consulting - OpenThinking Contemporary Consulting - OpenThinking
Contemporary Consulting - OpenThinking
 
Disruptive Innovation - OpenThinking
Disruptive Innovation - OpenThinking  Disruptive Innovation - OpenThinking
Disruptive Innovation - OpenThinking
 
Into to Fraud Examination
Into to Fraud ExaminationInto to Fraud Examination
Into to Fraud Examination
 

Dernier

NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
Khaled Al Awadi
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
seri bangash
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
AnaBeatriz125525
 

Dernier (20)

Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to Know
 
Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024Equinox Gold Corporate Deck May 24th 2024
Equinox Gold Corporate Deck May 24th 2024
 
Hyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseHyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings release
 
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...NewBase   24 May  2024  Energy News issue - 1727 by Khaled Al Awadi_compresse...
NewBase 24 May 2024 Energy News issue - 1727 by Khaled Al Awadi_compresse...
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob Badgett
 
FEXLE- Salesforce Field Service Lightning
FEXLE- Salesforce Field Service LightningFEXLE- Salesforce Field Service Lightning
FEXLE- Salesforce Field Service Lightning
 
PitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for StartupsPitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for Startups
 
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
Byrd & Chen’s Canadian Tax Principles 2023-2024 Edition 1st edition Volumes I...
 
LinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptxLinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptx
 
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
Unleash Data Power with EnFuse Solutions' Comprehensive Data Management Servi...
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
 
IPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best ServiceIPTV Subscription UK: Your Guide to Choosing the Best Service
IPTV Subscription UK: Your Guide to Choosing the Best Service
 
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdfInnomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
 
How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?
 
Unlock Your TikTok Potential: Free TikTok Likes with InstBlast
Unlock Your TikTok Potential: Free TikTok Likes with InstBlastUnlock Your TikTok Potential: Free TikTok Likes with InstBlast
Unlock Your TikTok Potential: Free TikTok Likes with InstBlast
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
 
Creative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team PresentationsCreative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team Presentations
 
12 Conversion Rate Optimization Strategies for Ecommerce Websites.pdf
12 Conversion Rate Optimization Strategies for Ecommerce Websites.pdf12 Conversion Rate Optimization Strategies for Ecommerce Websites.pdf
12 Conversion Rate Optimization Strategies for Ecommerce Websites.pdf
 
Pitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deckPitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deck
 
Stages of Startup Funding - An Explainer
Stages of Startup Funding - An ExplainerStages of Startup Funding - An Explainer
Stages of Startup Funding - An Explainer
 

CISA Part2

Notes de l'éditeur

  1. Risk begins with strategy formulation an objective settings
  2. Risk is related to preserving shareholders value as well as create value. Upside and downside