IT-audits according to COBIT. Experiences of the Regional Audit Court of Upper Austria

IT-audits according to COBIT Experiences of the Regional Audit Court of Upper Austria Regional Audit Court of Upper Austria ƒ Regional Audit Court ...
Author: Cuthbert Brown
2 downloads 1 Views 181KB Size
IT-audits according to COBIT Experiences of the Regional Audit Court of Upper Austria

Regional Audit Court of Upper Austria

ƒ Regional Audit Court is responsible for the audit of ƒ IT-organisations within the Administration of Upper Austria and of associated companies ƒ Computer centres

ƒ So far the Regional Audit Court has audited the IT of the Administration of Upper Austria including one big computer centre two times using the COBIT model (2001/2002 und 2008/2009)

EURORAI Susdal

May 17, 2013

page 1

1

IT - Department ƒ Tasks ƒ ƒ ƒ ƒ ƒ

development, IT-Strategy and IT-Standards procurement, provision and operation of the IT-infrastructure data security software development and -servicing IT-training and consulting

ƒ IT-expenses 2008: 24 Mio Euro ƒ 9.5 Mio Euro ƒ 14.5 Mio Euro

personnel expenses tangible expenses

ƒ App. 150 employees

EURORAI Susdal

May 17, 2013

page 2

2

IT - Department Control Objectives for Information and related Technology (Version 4 respectively 4.1)

ƒ internationally acknowledged standard for the overall steering and control of the IT ƒ developed by the Information Systems Audit and Control Association (ISACA)

ƒ procedure for an overall check and assessment of the IT and its processes ƒ COBIT is a process-oriented model and therefore independent of the technology used or the branch EURORAI Susdal

May 17, 2013

page 3

3

COBIT ƒ COBIT guarantees ƒ an overall assessment of the IT according to the requirements of a professional IT-System ƒ reliable application of the Information Technology ƒ due to use of generally applicable IT-process-oriented control objectives and audit-tools

ƒ fulfilment of IT-Governance Objectives ƒ constant alignment of the IT with business objectives and processes ƒ supporting the fulfilment of business objectives ƒ responsible and lasting use of IT-resources ƒ increasing the satisfaction of customers and associates ƒ minimizing IT-risks

EURORAI Susdal

May 17, 2013

page 4

4

COBIT ƒ COBIT is an internationally acknowledged standard for security, quality and compliance of Information Technology ƒ auditing is done by people who have acquired the competence within a special training by ISACA ƒ ISACA offers the following certifications: ƒ ƒ ƒ ƒ

CISA (Certified Information System Auditor) CISM (Certified Information Security Manager) CGEIT (Certified in the Governance of Enterprise IT) CRISC (Certified in Risk and Information Systems Control)

ƒ the process model COBIT 4 contains 4 domains with 34 ITprocesses; it can be broken down into 300 activities and controls EURORAI Susdal

May 17, 2013

page 5

5

COBIT - Principles

EURORAI Susdal

May 17, 2013

page 6

6

COBIT - Principles Confidentiality Availability Integrity Compliance Reliability Effectiveness Efficiency

Domains Technology/Application Information/Data Infrastructure Personnel

Plan & Organise Acquire & Implement Deliver & Support Monitor & Evaluate

Processes Activities

EURORAI Susdal

May 17, 2013

page 7

7

COBIT Framework

The structural design of COBIT is represented by the COBIT Framework. It contains three central areas which are essential for successful IT-Governance: IT processes Business Requirements concerning IT IT resources

and shows the various divisions (types, categories)

EURORAI Susdal

May 17, 2013

page 8

8

COBIT Domains and Control Objectives domain = cluster of main processes of a company C O N T R O L O B J E C T I V E S

ƒ Plan and Organise (10 processes) ƒ ƒ ƒ ƒ ƒ

compliance of company and IT-strategy optimal use of IT-resources in the company understanding within the organisation of the IT-objectives provision of the proper resources and the IT-environment assessment of the IT-risks

ƒ Acquire and Implement (7 processes)

EURORAI Susdal

ƒ ƒ ƒ ƒ ƒ

budget and time management regarding new projects procurement and implementation support of business objectives functionality of Change Management risks of adjustment to new systems May 17, 2013

page 9

9

COBIT Domains and Control Objectives C O N T R O L O B J E C T I V E S

ƒ Deliver and Support (13 processes) ƒ services delivered ƒ optimization of IT-cost ƒ productivity and security when using the system ƒ ƒ

security standards user trainings

ƒ confidentiality, integrity and availability of data

ƒ Monitor and Evaluate (4 processes)

EURORAI Susdal

ƒ ƒ ƒ ƒ ƒ

control system in order to identify problems as soon as possible effectiveness and efficiency of internal controls link to business objectives measuring and reporting of risks, controls and performance auditing the compliance with legal requirements ƒ

guaranteeing compliance

May 17, 2013

page 10

10

COBIT-Process-Model Business Requirements Geschäftsanforderungen

Domains Domänen

EURORAI Susdal

Domänen Domains

May 17, 2013

page 11

11

COBIT Results ƒ IT-Strategy ƒ missing overall strategy ƒ insufficient coordination with overall strategy of the Administration of Upper Austria ƒ unclear basic position (innovator or promoter of the established ways) ƒ unused synergies with other IT-organisations within the Administration of Upper Austria ƒ further emphasis on outcome-orientation ƒ no strategic controlling

ƒ Structures and Processes ƒ ƒ ƒ ƒ ƒ ƒ

existence of double structures suboptimal process design incomplete process map inefficient process steering inadequate project management specific problems with the implementation of the electronic file

EURORAI Susdal

May 17, 2013

page 12

12

COBIT Results ƒ IT – Technology ƒ partly not up-to-date (specific recommendations for improvement)

ƒ Security ƒ concrete security problems and appropriate recommendations for improvement

ƒ Service Quality ƒ customer survey was done ƒ better coordination of service quality and customer needs ƒ concrete recommendations for improvement concerning servicing and service desk ƒ response time partly too long

ƒ Personnel ƒ wages are not up to market value EURORAI Susdal

May 17, 2013

page 13

13

COBIT Contact Data ƒ COBIT versions ƒ ƒ ƒ ƒ ƒ ƒ

1996 1998 2000 2005 2007 2012

ƒ ISACA

COBIT COBIT COBIT COBIT COBIT COBIT

1 2 3 4 4.1 5

www.isaca.org

ƒ Certified COBIT auditors: ƒ ƒ ƒ ƒ ƒ

EURORAI Susdal

KPMG Ernst&Young IBM PricewaterhouseCoopers Swiss Life etc.

May 17, 2013

page 14

14

Thank you for your Attention! LRH, Promenade 31, 4020 Linz www.lrh-ooe.at

EURORAI Susdal

May 17, 2013

page 15

15

Suggest Documents