Download: IS audit and cobit - Regional Training Centre,Bangalore

advertisement
REGIONAL TRAINING CENTRE, BANGALORE
Information System Audit and COBIT
Level II
Level of Participants: AAOs/AOs/ Sr.AOs
Day1
Session I & II
Session Title: Introduction to Information System Development Life Cycle
Session Learning Session Overview
Course Structure
Objectives
This session is First, the course is inaugurated by Stages
of
Information
System
dedicated
to Principal Director or any officer Development Life Cycle viz.Initiation,
introduction
of authorised by Principal Director.
Systems Concept Development, Planning,
Information
Requirements
Analysis,
Design,
Systems
In this session the participants are Development, Integration and Test,
Development Life introduced to Information System Implementation and Operations &
Cycle
to Development Life Cycle, which Maintenance.
participants.
are the policies and procedures
that govern software development
and modification as a software
product goes through each phase
of its life cycle.
Session III & IV
Session Title: Controls in IT Environment
This session is Controls in IT environment IT Controls, General Controls viz. system
intended
for reflect the policies, procedures software acquisition and maintenance,
acquainting
and
practices
organization access security, and applications system
participants with structures designed to ensure that developments. Application Controls viz.
Controls in IT organistaions business objectives completeness, accuracy and validity of
Environment.
are met. In the session transactions, Input controls, forensic
participants will be familairised controls etc.
with various controls in IT
environment.
Teaching methods
used
Lecture.
Time required
Lecture.
Learning
objective: 10 min
Session
Overview: 15
min
Subject
Discussion: 140
min
Total: 165
minutes
Inauguration: 10
min
Learning
objective: 10 min
Session
Overview: 15
Subject
Discussion: 130
min
Total: 165
minutes
Faculty
Day2
Session I & II
Session Title: Business Continuity Planning and Security Aspects
Session Learning
Objectives
At the end of the
session,
the
participants will
gain insights on
Business
Continuity
Planning
and
Security Aspects.
Session Overview
Business Continuity Planning
refers to an organizations ability
to recover from a disaster and
resume operations. Audit of
business continuity planning is
to discover how closely an
organizations disaster recovery
readiness aligns to organisations
actual
objectives.
Security
aspects
involve
protection
systems
from unauthorized
access and disclosure.
Session III & IV
Session Title: How to Conduct and IS Audit
This session is
Information
System
audit
intended to
process contains basic steps viz.
acquaint
Planning, Audit Objectives,
participants with
Studying
and
Evaluation
the knowledge of
controls, Evaluation of Evidence
basic step in
and Reporting and follow up.
conducting and
Information
system audit.
Course Structure
Teaching methods
used
Business Continuity Planning and Disaster Lecture.
Recovery. Risk assessment, Vulnerability,
threats, documentation, backups and
backup plans, evaluation of plans, security
drills. Security Issues, Risk management,
security controls, administrative controls,
access controls etc.
Time required
Planning, Understanding the organization, Lecture.
defining the IT environment, materiality,
performing
the
risk
assessment,
formalizing the audit plan, Auditing of
controls,
evaluation
of
evidence,
Questionnaires, Evaluation of controls, use
of CAATs, Documentation and Reporting,
Recommendations.
Learning objective:
10 min
Session Overview: 15
min
Subject Discussion:
140 min
Total: 165 minutes
Learning objective:
10 min
Session Overview: 15
min
Subject Discussion:
140 min
Total: 165 minutes
Faculty
Day3
Session I & II
Session Title: Introduction to IDEA
Session Learning Session Overview
Course Structure
Teaching methods
Objectives
used
At the end of the In this session the participants are Basis of Data Structures, IDEA an Lecture, Computer
session,
the introduced to the software IDEA. overview.
display, Demo and
participants will IDEA (Interactive Data Extraction
Exercises
be introduced to and Analysis) is a CAAT tool
IDEA software
which is helpful for Auditors,
Financial Managers Investigators
and Accountants.
Session III & IV
Session Title: IDEA, importing files, Field Statistics, Control Total and History
At the end of the Using IDEA software data can be Participants will be familiarized with Lecture, Computer
session,
the imported from wide range of file the knowledge of using history logs and display, Demo
participants will formats and analyze the data. In this field statistics of IDEA software. Exercises
acquire
the session participants will be History Logs, Field Statistics, Control
knowledge
on familiarized with the knowledge of Totals
Importing files to importing various file formats into
IDEA and using idea also participants will be
the IDEA tools familiarized with the knowledge of
viz.
Field using history logs and field
Statistics, Control statistics of IDEA software.
Total,
History
Logs.
Time required
Learning objective:
10 min
Session Overview:
15 min
Practice of Course
Material:120 min
Exercises: 20 min
Total 165 minutes
Learning objective:
10 min
Session Overview:
15 min
Practice of Course
Material:120 min
Exercises: 20 min
Total 165 minutes
Faculty
Day 4
Session I & II
Session Title: Essentials of Data Downloading, Record Extraction, Field Summarization, File Stratification, Check Duplicates, Indexing and summarizing
Session Learning Session Overview
Course Structure
Teaching methods Time required
Faculty
Objectives
used
At the end of the Data downloading is the first part of Data Downloading, Record Extraction,
Lecture, Demo,
Learning objective:
session,
the using with IDEA software, In the Filed Summarization, Field
Practical
10 min
participants will session, participants will be Stratification using IDEA software.
Exercises
Session Overview:
Acquire
the familiarized with the knowledge of Checking Duplicates, Duplicate Key
15 min
knowledge
of data downloading with IDEA. Also Extraction, Duplicate key exclusion,
Practice of Course
Record Extraction, IDEA program has excellent Indexing, Sorting
Material:120 min
Field
utilities available for checking
Exercises: 20 min
Summarization,
Duplicates, Indexing, and Sorting
Total 165 minutes
Field
etc. participants will be familiarized
Stratification,
with the use of these tools in idea.
Check Duplicates,
Indexing
and
Summarizing etc.
using
IDEA
software.
Session III & IV
Session Title: Creation and Appending of Virtual Fields, joining and appending databases
At the end of the IDEA software has excellent tools Field manipulation, virtual fields, Lecture, Computer Learning objective:
session,
the for creating additional virtual fields Appending virtual fields, editing virtual display, demo and
10 min
participants will in imported databases. These virtual fields, manipulating virtual fields, Exercises
Session Overview:
acquire
the fields can be manipulated to do a joining databases, appending databases,
15 min
knowledge
of better
analysis
of
imported matching fields etc.
Practice of Course
creation
and databases. Also participants will be
Material:120 min
appending
of acquainted with the knowledge of
Exercises: 20 min
virtual
fields, joining and appending databases.
Total 165 minutes
joining
and
appending
databases
Day5
Session : I & II
Session Title: @functions in IDEA
At the end of the IDEA software is providing
sessions participants various
@functions
for
will
acquire
the manipulating
imported
knowledge of using databases. These functions are
the @functions in idea grouped
into
different
categories viz. Text, functions,
numeric functions, date and
time functions etc. the sessions
will be utilised for familiarising
participants with the usage of
functions.
Session III & IV
Session Title: Use of IDEA in Financial Audit
Session Learning
Session Overview
Objectives
At the end of the Conducting financial audit
sessions participants generally requires auditing
will be introduced to accounts payable, accounts
the analysis that is part receivable, fixed assets, general
of financial audit ledger, payroll, sales & receipts,
using IDEA.
purchase & payments accounts
etc. In the session participants
will be introduced to the
methods of conducting financial
audit.
@Functions, Text functions, numeric
functions, data and time functions,
comparison functions. Using functions in
extraction, filed manipulation, criteria etc.
Course Structure
Lecture, Computer
display, demo and
Exercises
Teaching methods
used
Gap detection, finding duplicates, field Lecture, Computer
manipulation, functions summarization, display, demo and
stratification tools in use for Financial audit. Exercises
Learning objective:
10 min
Session Overview: 15
min
Practice of Course
Material:120 min
Exercises: 20 min
Total 165 minutes
Time required
Learning objective:
10 min
Session Overview:
15 min
Practice of Course
Material:120 min
Exercises: 20 min
Total 165 min
Faculty
Day6
Session : Use of IDEA in Value for Money Audit
At the end of the Value for money of audit is IDEA tools for Value for Money audit
sessions participants used to assess the effectiveness
will be introduced to and efficiency of utilization of
the analysis that is part funds. IDEA software can be
of Value for Money effectively
utilized
for
Audit using IDEA conducting a value for money
software.
audit. In the session participants
will be familirised with the
tools for IDEA for conducting
Value for Money Audit.
Session III & IV
Session Title: Use of IDEA in fraud investigation
Session Learning
Session Overview
Objectives
At the end of the IDEA software provides
sessions participants auditors with tools that can
will be introduced to identify
unexpected
or
the commons analysis unexplained patterns in data
that are part of Fraud that may indicate fraud.
Investigation
Audit
IDEA software can be
using IDEA Software
utilised to do analytical test s
and data analysis reports for
the
purpose
of
fraud
detection. In this session,
participants
will
be
familiarised with the usage
of IDEA
for fraud
investigation audit.
Course Structure
Lecture, Computer
display, demo and
Exercises
Teaching methods
used
IDEA functions and tools viz. Check Lecture, Computer
Duplicates, Duplicate key extraction, display, demo and
duplicate key detection, Duplicate key Exercises
exclusion, Check for gaps, aging will be
utilized for the use of Fraud Investigation
audit.
Learning
objective: 10
min
Session
Overview: 15
min
Practice of
Course
Material:120
min
Exercises: 20
min
Total 165
minutes
Time required
Learning
objective: 10
min
Session
Overview: 15
min
Practice of
Course
Material:120
min
Exercises: 20
min
Total 165
minutes
Faculty
Day7
Session : I & II
Session Title: COBIT
In
this
session
participants will be
introduced to the
COBIT framework.
COBIT is the IT control
framework developed by ITGI
(IT
Governance
Institute)
divides it control objectives
broadly into 4 domains.
Participants will be acquainted
with the business orientation of
the framework with specific
reference
to
value
for
investment in IT.
Session III & IV
Session Title: Assignments
Session Learning
Session Overview
Objectives
At the last session of Participants will be asked to
the COBIT and IS do assignments and do
Audit
training presentations relating to
programme,
COBIT and IS Audit from
participants required selected topics or any topics
to demonstrate any
of their choice.
topics assigned to
them.
Last, Valediction ceremony
by Principal Director and
Distribution of Certificates.
Various domains of COBIT, Control
objectives, control practices, IT processes,
Maturity models, Understanding the
interrelationship between business goals,
governance drivers, IT processes and it
goals.
Lecture.
Learning objective:
10 min
Session Overview: 15
min
Subject Discussion:
140 min
Total: 165 minutes
Course Structure
Teaching methods
used
Presentation by
Participants
Time required
Participants asked to prepare assignments
and do a demo of the assignment allotted to
them.
Participants
Assignments: 140
min
Valediction and
Distribution of
Certificates: 25 min
Total 165 min
Faculty
Note: - The assessment test will be an exercise created for the purpose . And the participants will be asked to do a demo presentation.
TIMING
Lectures:
Session I & II
Session III & IV
Breaks:
First Tea Break:
Second Tea Break:
Lunch Break:
10:00 AM to 01:00 PM
02:00 PM to 05:00 PM
11:30 AM to 11:45 AM
03:30 PM to 03:45 PM
01:00 PM to 02:00 PM
Download