Ndhiemanisz’s Blog

Just another WordPress.com weblog

A.01 Internet Problem (Worksheet 12) February 3, 2010

Filed under: Auditing 2 — Windy Atmawardani Rachman @ 3:55 am

Windy Atmawardani Rachman (21207174)

SMAK01-7

Auditing 2


1. How does IT governance fit into an organization’s overall governance?

Answer :

IT governance fit into an organization’s overall governance by The certification has been specifically developed for professionals who have a significant management, advisory, or assurance role relating to the governance of IT. The certification promotes the advancement of professionals who wish to be recognized for their IT governance-related experience and knowledge.

The certification is also intended to support the growing business demands related to IT governance, increase the awareness and importance of IT governance good practices and issues and define the roles and responsibilities of the professionals performing IT governance work

Beside that This certification will benefit the individual, through recognition of their professional knowledge and competencies; skill-sets; abilities and experiences, and will enhance their professional standing. It will also add value to the enterprises they support through the demonstration of a visible commitment to excellence in IT governance practices.

Source: http://www.isaca.org/Template.cfm?Section=CGEIT_Certification&Template=/TaggedPage/TaggedPageDisplay.cfm&TPLID=16&ContentID=36126

2. The Executive Summary makes five recommendations for management with respect to IT. What are these recommendations?

Answer  :

Recommendations for management with respect to IT consist of :

  • Establish an overall cross-functional compliance team and a dedicated sub team managed by a director level person. The team should be supported by C-level executives and include executive from finance, IT, legal, marketing and affected business units.
  • Coordinate IT activities within the scope of an overall security and disaster recovery plan.
  • Have Finance or Audit take final responsibility to ensure compliance with SOX. Marketing should take the lead on customer data usage decisions affecting privacy as well as the Do Not Call Registry. IT is one input to the whole process.

Source : http://74.125.153.132/search?q=cache:Nhv8GFfqsaMJ:searchcio.techtarget.com/searchCIO/downloads/C_Braunstein_EDITED.ppt+How+does+IT+governance+fit+into+an+organization%E2%80%99s+overall+governance&cd=2&hl=id&ct=clnk&gl=id&client=firefox-a

3. How would an auditor likely view a company’s IT environment if the organization had implemented the above recommendations?

Answer :

An auditor likely view a company’s IT environment if the organization had implemented the above recommendations is a judgmental approach to assessing the effect IT has on the auditor’s study and evaluation of internal controls and the nature and extent of substantive testing may no longer be adequate. Such an approach allows auditors too much leeway to decide whether to perform tests of controls or bypass such tests and only perform substantive tests. SAS 941 provides auditors with much-needed guidance regarding the effect of IT on internal controls.

The standard requires tests of controls in certain situations, regardless of the level of control risk2 set by the auditor. The evaluation of internal controls is not complete until the auditor obtains a sufficient understanding of the controls’ design and determines whether critical internal controls are present in the automated environment, in operation and working as intended. Public Company Accounting Oversight Board (PCAOB) Standard No. 23 upholds SAS 94 and discusses the IT control objectives to consider in assessing internal controls for US Securities and Exchange Commission registrants.

Source : http://www.isaca.org/Template.cfm?Section=Home&CONTENTID=34376&TEMPLATE=/ContentManagement/ContentDisplay.cfm

Advertisement
 

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

 
Follow

Get every new post delivered to your Inbox.