What is ITGC and its purpose?
What is the ITGC “Control Environment”?
ITGC equiv to :
What is one primary goal of effective “Control Environment”?
What are 4 areas in the ITGC “Control Environment”?
(1) Strategic Planning
(2) Policies and Procedures
(3) Risk Mgmt
(4) HR Mgmt of IT Personnel
Under the ITGC “Control Environment”, what is included in “Strategic Planning”?
(1) IT Strategic Plan
- Ensure IT function aligned w/ entity’s strategies, goals, objectives
(2) Strategic approach to budgeting of IT, divided into 2 parts:
(a) Operational budget (employees, op exp)
(b) Capital budget (major IT capital projects, systems, hardware, software)
(3) Controls needed to ensure objectives are being met
- Ex: Report to BoD about IT function related to strategic planning
Under the ITGC “Control Environment”, what is included in “Policies and Procedures”?
- Describe how IT will be managed for effectiveness, efficiency and meet mgmt’s expectations
Under the ITGC “Control Environment”, what is included in “Risk Mgmt”?
Under the ITGC “Control Environment”, what is included in “HR Mgmt of IT Personnel”?
Involves IT working w/ HR on:
(1) IT Skill Set - ID proper competencies
(2) Hiring and Firing Policies
- Key elements would be to ID and document certifications and education needed for IT jobs
(3) Performance Evaluation
(4) Training and Professional Dev
IT Governance Institute (ITGI) defines IT governance as:
… to understand and manage risks w/ implementing new technologies, and addressing enterprise challenges and concerns such as:
(a) aligning IT and business strategy
(b) cascading strategy and goals down the enterprise
(c) providing org structure that facilitates implementation of strategy and goals
(d) insisting IT control framework be adopted and implemented
(e) measuring IT’s performance
- IT governance is responsibility of BODs and Exec Mgmt
- Integral part of enterprise governance and consists of leadership and org structures and processes that ensure org’s IT sustains and extends org’s strategy and objectives