39
Using COBIT 5 for Assurance as Frame- work for your IT Audit Hans Henrik Berthing, CPA, CGEIT, CRISC, CISA, CIA, Verifica & Aalborg University

Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Embed Size (px)

Citation preview

Page 1: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Using COBIT 5 for Assurance as Frame-work for your IT AuditHans Henrik Berthing, CPA, CGEIT, CRISC, CISA, CIA, Verifica & Aalborg University

Page 2: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Hans Henrik Berthing

Married with Louise and dad for Dagmar and Johannes

CPA, CRISC, CGEIT, CISA and CIA

Expert reviewer Cobit 5 for Sarbannes Oxley

Partner and owner for Verifica

Financial Audit, since 1994 and IT Assurance since 1996

Member of FSR IT Advisory Board & ISACA IT Assurance Task Force

CISA, CRISC & CISM review instructor (>80% passing)

Instructor, facilitator and speaker

Associated professor Aalborg University (Auditing, Risk & Compliance)

Page 3: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Learning Objective

After this presentation you will have learned how to use Cobit 5 for assurance as a framework for

your planning and reporting of your IT Audit. You will learn how you will be able as an audit to use

Cobit 5 for assurance as a framework and reference for your IT audit reporting for those who are

accountable for IT Governance

Subhead

Cobit 5 for Assurance

IT Assurance Framework

Cobit Assurance Workprogram

Page 4: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Cobit 5 for Assurance

An ISACA Framework

Page 5: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Figure 1—COBIT 5 Product Family

Page 6: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 for Assurance Overview

Page 7: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 for Assurance Overview

Page 8: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Prerequisite Knowledge

COBIT 5 for Assurance builds on COBIT 5. Most key concepts of COBIT 5 are repeated and elaborated on in this publication, making it a fairly standalone book—in essence, not requiring any prerequisite knowledge. However, an understanding of COBIT 5 at the foundation level will accelerate comprehension of this publication.

Should readers wish to know more about COBIT 5 concepts beyond what is required for assurance purposes, they are referred to the COBIT 5 framework publication.

COBIT 5 process details described therein. If readers wish to know more about the process capability assessment approach, they are referred to the COBIT Assessment Programme guides.

Page 9: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Assurance proces

Page 10: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Scope of COBIT 5 for Assurance

Page 11: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Comparison of Assurance Engag. Types

Page 12: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 Enterprise Enablers

Page 13: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Principles, Policies and Frameworks in ITAF

Page 14: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

ISACA Code of Professional Ethics

1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective

governance and management of enterprise information systems and technology, including: audit, control, security and

risk management.

2. Perform their duties with objectivity, due diligence and professional care, in accordance with professional standards.

3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and

not discrediting their profession or the association.

4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is

required by legal authority. Such information shall not be used for personal benefit or released to inappropriate parties.

5. Maintain competency in their respective fields and agree to undertake only those activities they can reasonably expect

to complete with the necessary skills, knowledge and competence.

6. Inform appropriate parties of the results of work performed including the disclosure of all significant facts known to them

that, if not disclosed, may distort the reporting of the results.

7. Support the professional education of stakeholders in enhancing their understanding of the governance and

management of enterprise information systems and technology, including: audit, control, security and risk

management.

Page 15: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Processes for Gov. of Enterprise IT

Page 16: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Align, Plan and Organise

Page 17: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

APO and Build, Acquire and Implement

Page 18: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Core Organisational Structures

Page 19: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Generic COBIT 5-based Assurance Engagement Approach

Page 20: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Determine scope of the assurance initiative (phase A)

Stakeholders? And their stakes?

¨Overall enterprise objectives?

Business requirements and associated risk and opportunities?

Organisational structure? - Roles and responsibilities?

Governing policies and procedures?

Applicable laws, regulations and contractual agreements?

Management practices and associated activities are in place?

Mgmt reporting (status, performance, actions) is in place?

Past issues have arisen and corrective actions have been taken?

Management hope to obtain as a result of the assurance initiative?

Current issues and concerns?

Page 21: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Phase A-1 to A-3

Page 22: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Example: Audit of an Internet banking system

3.2.1 Assurance Topic: The topic covered by this document is: Internet banking.

3.2.2 Goals of the Assurance Engagement: The goal of the review is to provide assurance over

whether Internet banking is secure, i.e., are the bank and its clients protected against fraudulent

transactions and is client confidentiality maintained?

3.2.3 Scoping: The scope of the assurance engageent is expressed in function of the seven

COBIT 5 enablers, as per the following table.

Some enabler instances are standard COBIT 5, i.e., they are described in varying degrees of

detail in the COBIT 5 framework or COBIT 5: Enabling Process. This would include COBIT 5

processes mainly, but also the enabler examples included in this or similar publications.

Page 23: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Example: Scope

Page 24: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Example: Scope

Page 25: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Assurance Engagement Scoping Summary

Page 26: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Understand enablers, set suitable Assessment criteria and perform the Assessment (phase b)

Reference all seven enablers. Building an understanding of the subject matter over which

assurance needs to be provided. The subject matter is expressed in terms of the COBIT 5

enablers.

Obtaining agreement over the assessment criteria that will be used during the assurance

engagement

Assessing the design and outcomes of the enablers

Page 27: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Appropriate auditing techniques

Enquire and confirm:

- eg: Search for exceptions/deviations and examine them.

Observe:

- eg: Observe and describe the processes.

Reperform and/or recalculate:

- eg: Reperform transactions, control procedures, etc.

Review automated evidence collection:

- eg: Collect sample data.

Page 28: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Understand enablers, set suitable Assessment criteria and perform the Assessment (phase b)

Reference all seven enablers. Building an understanding of the subject matter over which

assurance needs to be provided. The subject matter is expressed in terms of the COBIT 5

enablers.

Obtaining agreement over the assessment criteria that will be used during the assurance

engagement

Assessing the design and outcomes of the enablers

Page 29: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Understand enablers, set suitable Assessment criteria and perform the Assessment (phase b)

4.1 Introduction

4.2 Achievement of Goals

4.3 Enabler: Principles, Policies and Frameworks

4.4 Enabler: Processes

4.5 Enabler: Organisational Structures

4.6 Enabler: Culture, Ethics and Behaviour

4.7 Enabler: Information

4.8 Enabler: Services, Infrastructure and Applications

4.9 Enabler: People, Skills and Competencies

Page 30: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

4.2 Achievement of Goals

Page 31: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

4.3 Enabler: Principles, Policies and Frameworks

Page 32: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Generic approach for communicating on an Assurance initiative (phase c)

Page 33: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 ProcessAssurance Programs

Example

Page 34: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 Process Assurance Programs

Conducting assurance over a process.

Aligned with generally accepted auditing standards and practices and are based upon the overall

assurance engagement approach

Divided into three phases:

Determining the scope of the assurance initiative

Understanding enablers, setting suitable assessment criteria and performing the assessment

Communicating and reporting the results of the assessment

Page 35: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

COBIT 5 Process Assurance Programs

Fully aligned with COBIT 5:

Reference all seven enablers.

COBIT 5 goals are cascaded to ensure that detailed objectives of the assurance engagement

can be put into the enterprise and IT context

Enable linkage of the assurance objectives to enterprise and IT risk and benefits.

Comprehensive yet flexible.

The assurance professional can decide to not cover a set of enablers or some enabler instances

Issue of what is or is not covered will be quite transparent to the assurance engagement user.

For each step, a short description is included

Assurance professionals will have to use their own professional judgment

Page 36: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Evaluate, Direct and Monitor

Provide assurance over the EDM01 process:

Ensures:

A consistent and integrated approach aligned with the enterprise governance approach is

provided.

IT-related decisions are made in line with the enterprise’s strategies and objectives.

IT-related processes are overseen effectively and transparently.

Compliance with legal and regulatory requirements is confirmed.

The governance requirements for board members are met.

Page 37: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Phase A—Determine Scope of the Assurance Initiative

Page 38: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Phase B—Understand Enablers, Set Suitable Assessment Criteria and Perform the Assessment

Page 39: Using COBIT 5 for Assurance as Frame- work for your IT Audit · PDF fileUsing COBIT 5 for Assurance as Frame-work for ... COBIT 5 at the foundation level will accelerate ... COBIT

Question