已阅读5页,还剩29页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
ANINTRODUCTIONTOINFORMATIONTECHNOLOGY(IT)SUPERVISION,KirkTyrell,CISAAssistantDirectorFinancialInstitutionsSupervisoryDivisionBankofJ.jm,CARTAC&CaribbeanGroupofBankingSupervisorsITWorkshopforRegionalBankExaminersJune2325,2009Georgetown,Guyana,1,WhatisITSupervision?,ahighlevelexaminationthatencompassesreviewandevaluation(whollyorin-part)ofautomatedinformationprocessingsystems,relatednon-automatedprocessesandtheinterfacesbetweenthem,2,WhatisITSupervision?(contd),DOESIncreaseprobabilityofdetectingpotentiallyseriousissuesReducesprobabilityofoccurrenceoffraud,breaches,etc.,DOESNOTGuaranteefulldetectionPreventfraud,breaches,etc.fromoccurring,Whatis.“isanafter-the-fact,detailedreviewofasystemand,intheworldofinformationsecurityisconsideredalineofdefense.”(ISACA),3,Classifications,InformationSystemsauditCollectandevaluateevidence,assesses/effectiveness/adequacyofcontrolsofISresources,etc,detect,correctandpreventundesirableeventsSpecializedauditsExamines3rdpartyrelationship,forensicaudits,etc.ForensicauditsAuditspecializedindiscovering,disclosingandfollowinguponfraudsandcrimes,4,ITSupervisionvs.ISAuditing,ReportingrelationshipScopeandfrequencyofreviewsMandate,5,ITSupervisionvs.ISAuditing,Reportingrelationship:ITSupervisionreportsareroutedtotheChiefSupervisorofBanksand/orsupervisorycouncilISauditreportsaremadetotheboardofdirectors,auditcommitteeorthepublicScopeandfrequencyofreviewsMandate,6,ITSupervisionvs.ISAuditing,ReportingrelationshipScopeandfrequencyofreviews:ITSupervisionscopeislimitedtohighlevelexaminationofcontrolsthatgovernthedevelopment,operation,maintenance,andsecurityofITsystems.Reviewsarenormallyscheduledatleastonceayear,exceptifatargetreviewisrequiredISAuditingscopeincludesamoredetailedreviewofcontrolsthatevaluateITfunctionsandsystembasedonsecurity,quality,fiduciary,servicesandcapacity.Thesereviewsarenormallyongoing/continuousoveranagreedauditcycleMandate,7,ITSupervisionvs.ISAuditing,ReportingrelationshipScopeandfrequencyofreviewsMandate:ITSupervisionisprimarilyconcernedwithensuringthatfinancialinstitutionsoperateinasafeandsoundmannerinordertoprotectdepositorsinterestandtheintegrityofthefinancialsystemISauditingisdesignedtomeetthesafeguardingneedsofshareholdersandotherstakeholders.,8,WhyisITSupervisionNecessary?,GrowingimportanceofITtofinancialinstitutionGrowthofoperationalriskIncreasedfocusfromtheinternationalregulatorycommunity,9,WhyisITImportanttoFIs?,RegulatorypressurestoimproveriskmanagementandcomplianceStrategictechnologyinvestmentforsurvivalandgrowthRelentlessglobalizationShiftsincustomerdemographicsIncreasedcompetition,10,ITSpendingWithinBanks,Source:ITSpendinginFinancialServices:AGlobalPerspectiveReportPublishedbyCelentJanuary2009,11,GrowthinOperationalRisk,12,ITSupervisionvs.BankingSupervision,SupplementstheworkoffinancialorsafetyandsoundnessexaminationsProvidesforanoverallriskassessmentofthefinancialinstitutionCrossoverofITriskintothetraditionalrisksareas,Financials,13,ChallengesImpactingITSupervision,RapidtechnologyinnovationAuditfatigueSkill,competenceandavailabilityofITsupervisorsChangingscopeofexaminationsNeedtosatisfymultiplestakeholdersLackofstandardizedcertificationprocessforITsupervision,14,ChallengesImpactingITSupervision,SiloedviewofcomplianceExistenceofBarrierstocomplianceCollectingaccurate,timelydata/evidenceisaprotractedmanualprocessProprietaryinterfacespreventdataintegration,evenwhereautomationofITsupervisorytoolsexists,15,SpecializedskillsforITSupervisors,16,StandardsandStandards-SettingBodies,VendororJurisdictionSpecific,IFAC,17,ObjectivesofITSupervision,ToassessafinancialinstitutionsITmanagementandoperationToensureaccuracyandreliabilityofinformationsystemITalignmentwiththefinancialinstitutionsbusinessUltimateobjectivesensurethesafetyandsoundness,18,MainAreasofInterest,InternalControlEnvironmental,BusinessandTransactionalProcesses,ApplicationSystems,TechnologyInfrastructure,AreSupportedby,ArePoweredby,ProcessControls,ApplicationControls,ITGeneralControls,EffectivenessEfficiencyConfidentialityIntegrityAvailabilityComplianceReliability,EntryLevelControls,19,ARisk-BasedApproach,20,Risk-BasedApproach-GatherInformationandPlan,KnowledgeofthefinancialinstitutionandindustryPrioryearsexaminationresult(i.e.ITandnon-ITreports)Regulatorystatutes,standards,industryrequirements,etc.Inherentriskassessments,21,Risk-BasedApproach-GatherInformationandPlan,ScopingWhattoinclude:InformationanditsflowITarchitectureApplicationsanddatabases(e.g.OS,API,DBOracle,Sybase,etc.),22,ARisk-BasedApproachtoITSupervision,Starthere,23,Risk-BasedApproach-UnderstandingofInternalControl,ControlenvironmentControlproceduresDetectionriskassessmentControlriskassessmentEquatetotalrisk,24,ARisk-BasedApproachtoITSupervision,Starthere,25,Risk-BasedApproach-PerformComplianceTests,TestpoliciesandproceduresOthersubstantiveauditprocedures,26,ARisk-BasedApproachtoITSupervision,Starthere,27,Risk-BasedApproach-PerformSubstantiveTests,AnalyticalproceduresDetailedtestsofaccountbalanceOthersubstantiveexaminationprocedures,28,ARisk-BasedApproachtoITSupervision,Starthere,29,Risk-BasedApproach-ConcludeExamination,PresentfindingstoinstitutionsmanagementCreaterecommendationsandcourseofactionWriteauditreport,30,ARisk-BasedApproachtoITSupervision,S
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026年社区家庭日活动合同
- 质检员年终工作总结(15篇)
- 创优整改实施方案
- 自身免疫性疾病课件
- 酒店前台年终工作总结
- 销售业务员年度工作总结
- 添加剂替代品研发进展-洞察与解读
- 桥梁巡视养护工岗前操作水平考核试卷含答案
- 速录师安全防护水平考核试卷含答案
- 水平定向钻机司机操作规程模拟考核试卷含答案
- 2025年郑州水务集团有限公司招聘80人笔试模拟试卷带答案解析
- 创伤急救模拟教学的团队协作模拟演练
- 2025年国有企业管理专员岗位招聘面试参考题库及参考答案
- 生猪屠宰兽医卫生检验人员理论考试题库及答案
- 国家开放大学学生成绩单
- 完整版全国行政区域身份证代码表(EXCEL版)TextMarkTextMark
- 基于CA6150普通车床的数控化改造
- 脑的动脉课件
- 离子的占位晶体磁晶各向异性课件
- 13.Arnold(阿诺德)渲染器
- 婚姻法教学精品课件
评论
0/150
提交评论