REGIONAL TRAINING CENTRE, BANGALORE Information System Audit and COBIT Level II Level of Participants: AAOs/AOs/ Sr.AOs Day1 Session I & II Session Title: Introduction to Information System Development Life Cycle Session Learning Session Overview Course Structure Objectives This session is First, the course is inaugurated by Stages of Information System dedicated to Principal Director or any officer Development Life Cycle viz.Initiation, introduction of authorised by Principal Director. Systems Concept Development, Planning, Information Requirements Analysis, Design, Systems In this session the participants are Development, Integration and Test, Development Life introduced to Information System Implementation and Operations & Cycle to Development Life Cycle, which Maintenance. participants. are the policies and procedures that govern software development and modification as a software product goes through each phase of its life cycle. Session III & IV Session Title: Controls in IT Environment This session is Controls in IT environment IT Controls, General Controls viz. system intended for reflect the policies, procedures software acquisition and maintenance, acquainting and practices organization access security, and applications system participants with structures designed to ensure that developments. Application Controls viz. Controls in IT organistaions business objectives completeness, accuracy and validity of Environment. are met. In the session transactions, Input controls, forensic participants will be familairised controls etc. with various controls in IT environment. Teaching methods used Lecture. Time required Lecture. Learning objective: 10 min Session Overview: 15 min Subject Discussion: 140 min Total: 165 minutes Inauguration: 10 min Learning objective: 10 min Session Overview: 15 Subject Discussion: 130 min Total: 165 minutes Faculty Day2 Session I & II Session Title: Business Continuity Planning and Security Aspects Session Learning Objectives At the end of the session, the participants will gain insights on Business Continuity Planning and Security Aspects. Session Overview Business Continuity Planning refers to an organizations ability to recover from a disaster and resume operations. Audit of business continuity planning is to discover how closely an organizations disaster recovery readiness aligns to organisations actual objectives. Security aspects involve protection systems from unauthorized access and disclosure. Session III & IV Session Title: How to Conduct and IS Audit This session is Information System audit intended to process contains basic steps viz. acquaint Planning, Audit Objectives, participants with Studying and Evaluation the knowledge of controls, Evaluation of Evidence basic step in and Reporting and follow up. conducting and Information system audit. Course Structure Teaching methods used Business Continuity Planning and Disaster Lecture. Recovery. Risk assessment, Vulnerability, threats, documentation, backups and backup plans, evaluation of plans, security drills. Security Issues, Risk management, security controls, administrative controls, access controls etc. Time required Planning, Understanding the organization, Lecture. defining the IT environment, materiality, performing the risk assessment, formalizing the audit plan, Auditing of controls, evaluation of evidence, Questionnaires, Evaluation of controls, use of CAATs, Documentation and Reporting, Recommendations. Learning objective: 10 min Session Overview: 15 min Subject Discussion: 140 min Total: 165 minutes Learning objective: 10 min Session Overview: 15 min Subject Discussion: 140 min Total: 165 minutes Faculty Day3 Session I & II Session Title: Introduction to IDEA Session Learning Session Overview Course Structure Teaching methods Objectives used At the end of the In this session the participants are Basis of Data Structures, IDEA an Lecture, Computer session, the introduced to the software IDEA. overview. display, Demo and participants will IDEA (Interactive Data Extraction Exercises be introduced to and Analysis) is a CAAT tool IDEA software which is helpful for Auditors, Financial Managers Investigators and Accountants. Session III & IV Session Title: IDEA, importing files, Field Statistics, Control Total and History At the end of the Using IDEA software data can be Participants will be familiarized with Lecture, Computer session, the imported from wide range of file the knowledge of using history logs and display, Demo participants will formats and analyze the data. In this field statistics of IDEA software. Exercises acquire the session participants will be History Logs, Field Statistics, Control knowledge on familiarized with the knowledge of Totals Importing files to importing various file formats into IDEA and using idea also participants will be the IDEA tools familiarized with the knowledge of viz. Field using history logs and field Statistics, Control statistics of IDEA software. Total, History Logs. Time required Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 minutes Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 minutes Faculty Day 4 Session I & II Session Title: Essentials of Data Downloading, Record Extraction, Field Summarization, File Stratification, Check Duplicates, Indexing and summarizing Session Learning Session Overview Course Structure Teaching methods Time required Faculty Objectives used At the end of the Data downloading is the first part of Data Downloading, Record Extraction, Lecture, Demo, Learning objective: session, the using with IDEA software, In the Filed Summarization, Field Practical 10 min participants will session, participants will be Stratification using IDEA software. Exercises Session Overview: Acquire the familiarized with the knowledge of Checking Duplicates, Duplicate Key 15 min knowledge of data downloading with IDEA. Also Extraction, Duplicate key exclusion, Practice of Course Record Extraction, IDEA program has excellent Indexing, Sorting Material:120 min Field utilities available for checking Exercises: 20 min Summarization, Duplicates, Indexing, and Sorting Total 165 minutes Field etc. participants will be familiarized Stratification, with the use of these tools in idea. Check Duplicates, Indexing and Summarizing etc. using IDEA software. Session III & IV Session Title: Creation and Appending of Virtual Fields, joining and appending databases At the end of the IDEA software has excellent tools Field manipulation, virtual fields, Lecture, Computer Learning objective: session, the for creating additional virtual fields Appending virtual fields, editing virtual display, demo and 10 min participants will in imported databases. These virtual fields, manipulating virtual fields, Exercises Session Overview: acquire the fields can be manipulated to do a joining databases, appending databases, 15 min knowledge of better analysis of imported matching fields etc. Practice of Course creation and databases. Also participants will be Material:120 min appending of acquainted with the knowledge of Exercises: 20 min virtual fields, joining and appending databases. Total 165 minutes joining and appending databases Day5 Session : I & II Session Title: @functions in IDEA At the end of the IDEA software is providing sessions participants various @functions for will acquire the manipulating imported knowledge of using databases. These functions are the @functions in idea grouped into different categories viz. Text, functions, numeric functions, date and time functions etc. the sessions will be utilised for familiarising participants with the usage of functions. Session III & IV Session Title: Use of IDEA in Financial Audit Session Learning Session Overview Objectives At the end of the Conducting financial audit sessions participants generally requires auditing will be introduced to accounts payable, accounts the analysis that is part receivable, fixed assets, general of financial audit ledger, payroll, sales & receipts, using IDEA. purchase & payments accounts etc. In the session participants will be introduced to the methods of conducting financial audit. @Functions, Text functions, numeric functions, data and time functions, comparison functions. Using functions in extraction, filed manipulation, criteria etc. Course Structure Lecture, Computer display, demo and Exercises Teaching methods used Gap detection, finding duplicates, field Lecture, Computer manipulation, functions summarization, display, demo and stratification tools in use for Financial audit. Exercises Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 minutes Time required Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 min Faculty Day6 Session : Use of IDEA in Value for Money Audit At the end of the Value for money of audit is IDEA tools for Value for Money audit sessions participants used to assess the effectiveness will be introduced to and efficiency of utilization of the analysis that is part funds. IDEA software can be of Value for Money effectively utilized for Audit using IDEA conducting a value for money software. audit. In the session participants will be familirised with the tools for IDEA for conducting Value for Money Audit. Session III & IV Session Title: Use of IDEA in fraud investigation Session Learning Session Overview Objectives At the end of the IDEA software provides sessions participants auditors with tools that can will be introduced to identify unexpected or the commons analysis unexplained patterns in data that are part of Fraud that may indicate fraud. Investigation Audit IDEA software can be using IDEA Software utilised to do analytical test s and data analysis reports for the purpose of fraud detection. In this session, participants will be familiarised with the usage of IDEA for fraud investigation audit. Course Structure Lecture, Computer display, demo and Exercises Teaching methods used IDEA functions and tools viz. Check Lecture, Computer Duplicates, Duplicate key extraction, display, demo and duplicate key detection, Duplicate key Exercises exclusion, Check for gaps, aging will be utilized for the use of Fraud Investigation audit. Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 minutes Time required Learning objective: 10 min Session Overview: 15 min Practice of Course Material:120 min Exercises: 20 min Total 165 minutes Faculty Day7 Session : I & II Session Title: COBIT In this session participants will be introduced to the COBIT framework. COBIT is the IT control framework developed by ITGI (IT Governance Institute) divides it control objectives broadly into 4 domains. Participants will be acquainted with the business orientation of the framework with specific reference to value for investment in IT. Session III & IV Session Title: Assignments Session Learning Session Overview Objectives At the last session of Participants will be asked to the COBIT and IS do assignments and do Audit training presentations relating to programme, COBIT and IS Audit from participants required selected topics or any topics to demonstrate any of their choice. topics assigned to them. Last, Valediction ceremony by Principal Director and Distribution of Certificates. Various domains of COBIT, Control objectives, control practices, IT processes, Maturity models, Understanding the interrelationship between business goals, governance drivers, IT processes and it goals. Lecture. Learning objective: 10 min Session Overview: 15 min Subject Discussion: 140 min Total: 165 minutes Course Structure Teaching methods used Presentation by Participants Time required Participants asked to prepare assignments and do a demo of the assignment allotted to them. Participants Assignments: 140 min Valediction and Distribution of Certificates: 25 min Total 165 min Faculty Note: - The assessment test will be an exercise created for the purpose . And the participants will be asked to do a demo presentation. TIMING Lectures: Session I & II Session III & IV Breaks: First Tea Break: Second Tea Break: Lunch Break: 10:00 AM to 01:00 PM 02:00 PM to 05:00 PM 11:30 AM to 11:45 AM 03:30 PM to 03:45 PM 01:00 PM to 02:00 PM