2/20/2013. Information Governance Matters: Real-World Lessons. Real-World Events. Information

Size: px
Start display at page:

Download "2/20/2013. Information Governance Matters: Real-World Lessons. Real-World Events. Information"

Transcription

1 Information Governance Matters: Real-World Lessons Peter Sloan Deborah Juhnke, CRM Real-World Events Information 1

2 Real-World Consequences Information Governance is an integrated approach to: Ensuring information compliance and Controlling information risk, while Maximizing information value. Information compliance is meeting legal requirements for: Records creation, retention, management, disposition Information Compliance Preserving & collecting relevant information for litigation Information protection 2

3 Control Risk Maximize Value Achieve Compliance Internal control is a process, effected by an entity s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance. COSO Internal Control Integrated Framework, Executive Summary at 20 (September 2012) Internal Control Framework Control Environment Risk Assessment Control Activities Information & Communication Monitoring Activities COSO Internal Control Integrated Framework, Executive Summary at (September 2012) 3

4 Establishing Enterprise Strategic Tactical Enterprise Objective: To maximize information value while satisfying information compliance requirements and controlling information risks. Assess Analyze Act Audit 4

5 Identify Strategic Define Tactical Establish Program Elements Audit for Accountability Assess Analyze Act Audit Identify Strategic Reducing Unnecessary Information Managing Records Protecting Information Preserving Information Strategic Objective: Reducing Unnecessary Information 5

6 Strategic Objective: Reducing Unnecessary Information Dispose of information not required for legal compliance or business need (Control Risk) Reduce creation of unnecessary information (Control Risk) Realize cost-savings through decreasing the amount of unnecessary information (Maximize Value) Define Tactical Performing Root Cause Analysis Identifying Desired End State Prioritizing Tasks Developing Tactics Tactical : Control volume of Control volume of unstructured data in network drives Control volume of off-site paper 6

7 Establish Program Elements Seeking Entry Points Developing Program not Project Enabling Decision making Addressing Culture Information Management Information Asset Map Records Retention Schedule File Plan Policies Processes Training & Guidance People Technology Information Governance Integrated Information Governance Matrix Integrated Information Governance Policies Aligned Personnel & Technology 7

8 Audit for Accountability Establishing Individual Responsibility Collecting Metrics Providing Continued Support Seeking Continued Improvement Metrics: Total volume of Average volume of per user Age of Identify Strategic Define Tactical Establish Program Elements Audit for Accountability Unnecessary Information Root Cause Analysis Records Management Desired End State Information Protection Prioritization Preservation Tactics Seek Entry Points Individual Responsibility Program not Project Metrics Enable Decision making Continued Support Address Culture Continued Improvement Assess Analyze Act Audit 8

9 Real World Lessons Good enough today won t be good enough tomorrow Risk reveals importance Process is paramount Auditing is necessary Accountability must be clear Thank you! Peter Sloan peter.sloan@huschblackwell.com Deborah Juhnke, CRM deborah.juhnke@huschblackwell.com 9

INTEGRATING ISO 9000 METHODOLOGIES WITH PROJECT QUALITY MANAGEMENT

INTEGRATING ISO 9000 METHODOLOGIES WITH PROJECT QUALITY MANAGEMENT INTEGRATING ISO 9000 METHODOLOGIES WITH PROJECT QUALITY MANAGEMENT M a r ch 2015 OBJECTIVE ISO and Project Quality Management Process Are they different or the same? ISO 9000 QMS FAMILY ISO 9000:2005 Vocabulary

More information

R. Scott Murchison, CRM Kaizen InfoSource LLC SVP, Information Management Services

R. Scott Murchison, CRM Kaizen InfoSource LLC SVP, Information Management Services R. Scott Murchison, CRM Kaizen InfoSource LLC SVP, Information Management Services What records & information management (RIM) is Why RIM is important Building a compliant RIM program 2 3 A field of management

More information

Internal Control at OSU COSO & Enterprise Risk Management. Oregon State University Board of Trustees Executive & Audit Committee Educational Session

Internal Control at OSU COSO & Enterprise Risk Management. Oregon State University Board of Trustees Executive & Audit Committee Educational Session Internal Control at OSU COSO & Enterprise Risk Management Oregon State University Board of Trustees Executive & Audit Committee Educational Session OSU Internal Control Model - COSO The COSO framework

More information

CGEIT Certification Job Practice

CGEIT Certification Job Practice CGEIT Certification Job Practice Job Practice A job practice serves as the basis for the exam and the experience requirements to earn the CGEIT certification. This job practice consists of task and knowledge

More information

CARNEGIE MELLON UNIVERSITY

CARNEGIE MELLON UNIVERSITY CARNEGIE MELLON UNIVERSITY 1 Integrated Risk Management for the Enterprise Brett Tucker December 2018 Carnegie Mellon University Software Engineering Institute Carnegie Mellon University Pittsburgh, PA

More information

Cascading the BSC Using the Nine Steps to Success

Cascading the BSC Using the Nine Steps to Success Cascading the BSC Using the Nine Steps to Success The Balanced Scorecard Institute uses a proven, disciplined framework, Nine Steps to Success, to systematically develop, implement, and sustain a strategic

More information

Gleim CIA Review Updates to Part Edition, 1st Printing June 2018

Gleim CIA Review Updates to Part Edition, 1st Printing June 2018 Page 1 of 15 Gleim CIA Review Updates to Part 1 2018 Edition, 1st Printing June 2018 Study Unit 3 Control Frameworks and Fraud Pages 66 through 69 and 76 through 77, Subunit 3.2: In accordance with the

More information

The Ins and Outs: Audits Under FDICIA. Jennifer Gureckis and Kaylyn Landry BerryDunn February 27, 2018

The Ins and Outs: Audits Under FDICIA. Jennifer Gureckis and Kaylyn Landry BerryDunn February 27, 2018 The Ins and Outs: Audits Under FDICIA Jennifer Gureckis and Kaylyn Landry BerryDunn February 27, 2018 Presenters Jennifer Gureckis, CPA Kaylyn Landry, CPA Objectives Overview of Internal Controls over

More information

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II S P E A K E R : D O T T. FA B I O A C C A R D I C O U R S E O F B U S I N E S S A U D I T I N G U N I V E R

More information

Global Records and Information Management Risk: Proactive and Practical Approaches to Effective Records Management. September 16, 2014

Global Records and Information Management Risk: Proactive and Practical Approaches to Effective Records Management. September 16, 2014 Global Records and Information Management Risk: Proactive and Practical Approaches to Effective Records Management September 16, 2014 Maura Dunn, MLS, CRM Lee Karas, MBA Agenda Drivers for your Records

More information

SUPPLY CHAIN AND OPERATING RISK

SUPPLY CHAIN AND OPERATING RISK SUPPLY CHAIN AND OPERATING RISK 1 Supply Chain Management The management of the flow of goods and services from point of origin to point of consumption Movement and storage of raw materials work-in-process

More information

Enterprise Risk Management Montana State Fund

Enterprise Risk Management Montana State Fund Enterprise Risk Management Montana State Fund Report to the Board January 28, 2011 Presented by: Mary Peter, Director of Enterprise Risk Management Enterprise Risk Management (ERM) Defined An integrated

More information

ISMS AUDIT CHECKLIST

ISMS AUDIT CHECKLIST 4.1 REQUIREMENT REFER TO BS ISO / IEC 27001 : 2005 Has the organisation developed a documented ISMS based on the PDCA model? Checked at Stage 1 for development and Stage 2/surveillance for implementation,

More information

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance

From Dictionary.com. Risk: Exposure to the chance of injury or loss; a hazard or dangerous chance Sharon Hale and John Argodale May 28, 2015 2 From Dictionary.com Enterprise: A project undertaken or to be undertaken, especially one that is important or difficult or that requires boldness or energy

More information

SAMPLE BEC SuperfastCPA Review Notes

SAMPLE BEC SuperfastCPA Review Notes BEC 2018 SuperfastCPA Review Notes Table of Contents Corporate Governance 1 Internal Control Frameworks 1 Enterprise Risk Management Frameworks 6 Other Regulatory Frameworks and Provisions 10 Economic

More information

COSO ERM: Integrating with Strategy and Performance. Michael Parkinson

COSO ERM: Integrating with Strategy and Performance. Michael Parkinson COSO ERM: Integrating with Strategy and Performance Michael Parkinson Content The COSO Frameworks Risk (Enterprise) Risk Management The COSO risk management framework A few highlights Questions for management

More information

Creating an IWMS Implementation Plan

Creating an IWMS Implementation Plan Creating an IWMS Implementation Plan Overview The increased information available through an Integrated Workplace Management System (IWMS) impacts every part of an organization and can dramatically increase

More information

Implementation Practices for the Archiving and Compliance Infrastructure

Implementation Practices for the Archiving and Compliance Infrastructure Implementation Practices for the Archiving and Compliance Infrastructure Gary Zasman, Network Appliance WW Practice Director Co-chair 100 Year Archive and ILM PS SNIA Legal Notice The material contained

More information

Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control

Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control IIA IIA-CIA-Part1 Certified Internal Auditor - Part 1, The Internal Audit Activity's Role in Governance, Risk, and Control https://killexams.com/pass4sure/exam-detail/iia-cia-part1 Question: 555 During

More information

SUPPLIER SURVEY FORM Instructions

SUPPLIER SURVEY FORM Instructions SUPPLIER SURVEY FORM Instructions 1. The following Supplier Survey was developed by Vishay Measurements Group, Inc. to assess and document the capability of its supplier base. 2. The Supplier Survey is

More information

COSO ERM: Integrating with Strategy and Performance. Paul J. Sobel COSO Chairman Chief Risk Officer Georgia-Pacific

COSO ERM: Integrating with Strategy and Performance. Paul J. Sobel COSO Chairman Chief Risk Officer Georgia-Pacific COSO ERM: Integrating with Strategy and Performance Paul J. Sobel COSO Chairman Chief Risk Officer Georgia-Pacific 1 Focus of Presentation Why the COSO ERM Framework was Updated 10 Key Things to Know about

More information

REPORT 2015/077 INTERNAL AUDIT DIVISION

REPORT 2015/077 INTERNAL AUDIT DIVISION INTERNAL AUDIT DIVISION REPORT 2015/077 Advisory engagement to assist the International Trade Centre in its efforts to develop a risk management framework 29 July 2015 Assignment No. VE2014/350/01 CONTENTS

More information

Information System Audit Engr. Abdul-Rahman Mahmood MS, PMP, MCP, QMR(ISO9001:2000)

Information System Audit Engr. Abdul-Rahman Mahmood MS, PMP, MCP, QMR(ISO9001:2000) Information System Audit Engr. Abdul-Rahman Mahmood MS, PMP, MCP, QMR(ISO9001:2000) armahmood786@yahoo.com alphasecure@gmail.com alphapeeler.sf.net/pubkeys/pkey.htm http://alphapeeler.sourceforge.net pk.linkedin.com/in/armahmood

More information

Session 7: Corporate Governance

Session 7: Corporate Governance Session 7: Corporate Governance New York Bankers Association-Community Bank Auditors Group 2016 Internal Audit Training-June 6-8, 2016 MEMBER OF ALLINIAL GLOBAL, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS

More information

Enterprise SM VOLUME 2, SECTION 2.6: TROUBLE AND COMPLAINT HANDLING

Enterprise SM VOLUME 2, SECTION 2.6: TROUBLE AND COMPLAINT HANDLING VOLUME 2, SECTION 2.6: TROUBLE AND COMPLAINT HANDLING 2.6 TROUBLE AND COMPLAINT HANDLING [C.3.4.2, M.3.7] 2.6.1 TROUBLE AND COMPLAINT ORGANIZATION AND RESOURCES [L.34.2.3.6] The Level 3 Team provides a

More information

Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, :45 p.m. 4:45 p.m.

Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, :45 p.m. 4:45 p.m. Enterprise Risk Management: Aligning Risk with Strategy & Performance June 26, 2017 3:45 p.m. 4:45 p.m. Presented by: Marc Winkler Director P&G Associates 646 Highway 18 East Brunswick, NJ 08816 P: 877-651-1700

More information

PMO Services Checklist

PMO Services Checklist PMO Services Checklist by IMPACTbyLaura.com Services Checklist This resource is a list of possible services and categories that you can consider when determining how you will drive IMPACT with your PMO.

More information

Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018

Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018 Page 1 of 16 Gleim CPA Review Updates to Business Environment and Concepts 2018 Edition, 1st Printing March 2018 The content of BEC Study Unit 2, Subunit 2, has undergone extensive edits due to the 2017

More information

Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013

Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013 Mapping ISO/IEC 27001:2005 -> ISO/IEC 27001:2013 Carlos Bachmaier http://excelente.tk/ - 20140218 2005 2013 In 2005 0 Introduction 0 Process approach PDCA In 2013 0 No explicit process approach ISMS part

More information

Correlation matrices between ISO 9001:2008 and ISO 9001:2015

Correlation matrices between ISO 9001:2008 and ISO 9001:2015 Correlation matrices between ISO 9001:2008 and ISO 9001:2015 ISO 9001:2015 ISO 9001:2008 1 Scope 1 Scope 1.1 General 4 Context of the organization 4 Quality management system 4.1 Understanding the organization

More information

Efficiency First Program

Efficiency First Program Efficiency First Program Short-Term Impact; Long-Term Results Presented to: Discussion Points About AOTMP Your Telecom Environment The Efficiency First Framework Our Approach The Efficiency First Program

More information

Forensic Technology: Considerations for Information Governance

Forensic Technology: Considerations for Information Governance Forensic Technology: Considerations for Information Governance ARMA Twin Cities Presentation April 6, 2016 Forensic Technology: Considerations for Information Governance Information Governance and Records

More information

IT Audit at Brown. A collaboration between the Information Technology and Internal Audit Teams

IT Audit at Brown. A collaboration between the Information Technology and Internal Audit Teams IT Audit at Brown A collaboration between the Information Technology and Internal Audit Teams Page 1 Agenda Objective Risk Management Overview Internal Audit at Brown IT Audit at Brown Frequently Asked

More information

Emerging Trends in Auditing ERM COSO ERM 2017

Emerging Trends in Auditing ERM COSO ERM 2017 Emerging Trends in Auditing ERM COSO ERM 2017 AGENDA Our Agenda for today will Include; Introducing COSO ERM 2017. Organizational Bias Risk - Aware Culture Risk Portfolio View. Risk Appetite & Tolerance.

More information

Understanding the Challenge and Incredible Potential of IT Governance

Understanding the Challenge and Incredible Potential of IT Governance Understanding the Challenge and Incredible Potential of IT Governance REALIZING THE MOST VALUE FROM TECHNOLOGY THROUGH BUSINESS GOV ERNANC E O F IT Governance defined gov er nance noun (ˈgə-vər-nən(t)s)

More information

Successful ERM Program Standards. Definitions of Enterprise Risk Management (ERM)

Successful ERM Program Standards. Definitions of Enterprise Risk Management (ERM) 1 Successful ERM Program Standards Enterprise Risk Management Vendor Management Business Continuity IT GRC Internal Audit Regulatory Compliance Manager William C. Hord V.P. of Enterprise Risk Management

More information

Applying Technology to Information Governance

Applying Technology to Information Governance Applying Technology to Information Governance Eric Robinson, KrolLDiscovery February 24, 2017 1 The Bots are Coming! Or, are they???? 2 Overview What is Information Governance (IG) How to Develop IG Programs

More information

A Discussion About Internal Controls February 2016

A Discussion About Internal Controls February 2016 A Discussion About Internal Controls February 2016 What we will cover today 001 Introductions 002 Defining Internal Controls 003 COSO Internal Controls Integrated Framework 004 Approach to Designing Internal

More information

Implementing Benefits Realization at Farm Credit Canada. Jacob van der Merwe Project Portfolio Manager November 8, 2011

Implementing Benefits Realization at Farm Credit Canada. Jacob van der Merwe Project Portfolio Manager November 8, 2011 Implementing Benefits Realization at Farm Credit Canada Jacob van der Merwe Project Portfolio Manager November 8, 2011 Learning Objectives Learn how FCC developed its Benefits Realization methodology and

More information

CHHS Master Data Management Strategy

CHHS Master Data Management Strategy CHHS Master Data Management Strategy Master Data Management (MDM) will provide the California Health and Human Services Agency (CHHS) and its Departments with a 360-degree view of CHHS clients, providers,

More information

Quality Manual Revision: C Effective: 03/01/10

Quality Manual Revision: C Effective: 03/01/10 TABLE OF CONTENTS DESCRIPTION SECTION PAGE INTRODUCTION 1.0 1 APPROVAL SIGNATURE PAGE 1.1 1 AMENDMENT RECORD 1.2 2 SCOPE 2.0 3 EXCLUSIONS 2.1 3 CORPORATE POLICY 3.0 3 QUALITY MANAGEMENT SYSTEM 4.0 4 GENERAL

More information

Audit by Design: Moving Beyond Continuous Auditing - a Vision for Future Models

Audit by Design: Moving Beyond Continuous Auditing - a Vision for Future Models Audit by Design: Moving Beyond Continuous Auditing - a Vision for Future Models Kendall Tieck, VP Internal Audit, Workday, Inc. Professional Strategies S31 If you look in the rear view mirror too long

More information

ISO Changing the Conversation Mark T. Gasser Nicholas E. Fioravante

ISO Changing the Conversation Mark T. Gasser Nicholas E. Fioravante ISO 55000 Changing the Conversation Mark T. Gasser Nicholas E. Fioravante NFMT 2015 ADENGA Introduction and Overview of the Standard Business Case for Asset Management An Asset Management Program Lesson

More information

Statewide Technology Cooperative Contracting Program

Statewide Technology Cooperative Contracting Program DATA, INFORMATION, AND KNOWLEDGE MANAGEMENT Statewide Technology Cooperative Contracting Program Transforming Traditional Procurement to Knowledge-Driven Sourcing in Texas EXECUTIVE SUMMARY The competitiveness

More information

Information Technology Investment Management: A Framework for State Government

Information Technology Investment Management: A Framework for State Government Association for Information Systems AIS Electronic Library (AISeL) SAIS 2007 Proceedings Southern (SAIS) 3-1-2007 Information Technology Investment Management: A Framework for State Government James B.

More information

Work Group: Risk and Review Host: Fox Blocks. Work Group: Risk and Review. Host: Fox Blocks

Work Group: Risk and Review Host: Fox Blocks. Work Group: Risk and Review. Host: Fox Blocks WG Core Members 1. ALN Facilitator: Rob Leibrandt, Camcode 2. Sponsor: Mike Kennaw, Fox Blocks 3. Marlene Millemaci, Deloitte 4. Marsha Campbell, Deloitte 5. Jack Kelly, OMB (ret.) 6. Richard Culbertson,

More information

Machined Integrations, LLC

Machined Integrations, LLC QUALITY MANUAL Machined Integrations, LLC ISO9001: 2008 Electronically Controlled by Quality Representative, Rev2, January 2014 Page 2 of 25 TABLE OF CONTENTS SECTION ELEMENT PAGE No A Revision and Approval

More information

Risk Assessments & Internal Controls

Risk Assessments & Internal Controls Risk Assessments & Internal Controls Kelly A. Nueske Managing Director Enterprise Risk Services ~ Internal Audit & Compliance 1 Nature of Risk R = risk is relative because perception of downside and upside

More information

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting

Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting Enterprise Risk Management Discussion American Gas Association Risk Management Committee Meeting July 17, 2017 Objectives Provide perspective on the evolution of Enterprise Risk Management (ERM) New 2017

More information

Logistics Community of Interest 2001 General Supply Series Competency-Based Learning Map and Training Strategy. Page 1

Logistics Community of Interest 2001 General Supply Series Competency-Based Learning Map and Training Strategy. Page 1 Page 1 General Supply Competency-Based Learning Map Overview The United States Marine Corps (USMC) Logistics Community of Interest (COI) developed this competency-based learning map to support 2001 general

More information

Breakout Session A. Asset Management Best Practices and What Trends You Should Know (ISO 55000: Asset Management)

Breakout Session A. Asset Management Best Practices and What Trends You Should Know (ISO 55000: Asset Management) Breakout Session A Asset Management Best Practices and What Trends You Should Know (ISO 55000: Asset Management) Life Science Leader magazine February 2014 Where is the time/energy of FDA? Inspections

More information

Marketing Best Practice Records Management. Kemal Hasandedic MBII GDDM MRMA National President RMAA

Marketing Best Practice Records Management. Kemal Hasandedic MBII GDDM MRMA National President RMAA Marketing Best Practice Records Management Kemal Hasandedic MBII GDDM MRMA National President RMAA RM an excellent product to Market Questions: 1. Why do we need to sell to senior management? 2. What are

More information

Fraud Risk Management

Fraud Risk Management Fraud Risk Management Fraud Risk Management Overview 2017 Association of Certified Fraud Examiners, Inc. Discussion Questions 1. Does your organization follow a specific risk management model? If so, which

More information

Charter for Enterprise Risk Management

Charter for Enterprise Risk Management for Enterprise Risk Management Prepared by: Shannon Sinclair Version: 1.2 Document Id: Date: Release Date TABLE OF CONTENTS TABLE OF CONTENTS... i 1. Background... 1 2. Objectives... 1 3. Scope... 2 3.1

More information

Service Lifecycle Management (SLM): The New Competitive Frontier

Service Lifecycle Management (SLM): The New Competitive Frontier Service Lifecycle Management (SLM): The New Competitive Frontier Part 1 Setting the Stage Whitepaper by: Michael R. Blumberg, CMC President Service Lifecycle Management (SLM): The New Competitive Frontier,

More information

In our ever-changing, developing, and expanding world, we are faced with an abundance

In our ever-changing, developing, and expanding world, we are faced with an abundance Natalie DeAngelo 534 Records Management 11/26/12 Records Retention Program- Museum In our ever-changing, developing, and expanding world, we are faced with an abundance of information that needs to be

More information

Completing the ERM Circle

Completing the ERM Circle Completing the ERM Circle A Role for Continuous Controls Monitoring Andrew Simpson MBA, CISA Chief Operating Officer CaseWare RCM Inc. Agenda Definitions COSO Integrated ERM Framework Self Assessments

More information

RSA ARCHER MATURITY MODEL: AUDIT MANAGEMENT

RSA ARCHER MATURITY MODEL: AUDIT MANAGEMENT RSA ARCHER MATURITY MODEL: AUDIT MANAGEMENT OVERVIEW Internal Audit (IA) plays a critical role in mitigating the risks an organization faces. Audit must do so in a world of increasing risks and compliance

More information

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM)

Agenda. Enterprise Risk Management Defined. The Intersection of Enterprise-wide Risk Management (ERM) and Business Continuity Management (BCM) The Intersection of Enterprise-wide Risk (ERM) and Business Continuity (BCM) Marc Dominus 2005 Protiviti Inc. EOE Agenda Terminology and Process Introductions ERM Process Overview BCM Process Overview

More information

Internal Controls. Presented by Donna Maskil-Thompson SPP RE Workshop 03/15/2016. Property of KC Board of Public Utilities - PUBLIC

Internal Controls. Presented by Donna Maskil-Thompson SPP RE Workshop 03/15/2016. Property of KC Board of Public Utilities - PUBLIC Internal Controls Presented by Donna Maskil-Thompson SPP RE Workshop 03/15/2016 Property of KC Board of Public Utilities - PUBLIC - 2016 1 Internal Controls The policies, procedures, practices and organizational

More information

CONTENTS. Part I BUSINESS PROCESSES AND INFORMATION SYSTEMS FOUNDATION 1. Part II TECHNOLOGY FOR BUSINESS PROCESSES AND INFORMATION SYSTEMS 65

CONTENTS. Part I BUSINESS PROCESSES AND INFORMATION SYSTEMS FOUNDATION 1. Part II TECHNOLOGY FOR BUSINESS PROCESSES AND INFORMATION SYSTEMS 65 CONTENTS Part I BUSINESS PROCESSES AND INFORMATION SYSTEMS FOUNDATION 1 Chapter 1 Introduction to Information Systems 2 Synopsis 3 Introduction 4 The Textbook s Three Themes 4 Challenges and Opportunities

More information

City of Saskatoon Updated Internal Audit Plan SPCF Public Meeting. Date of Submission: March 29, 2016 Date of Meeting: April 4, 2016

City of Saskatoon Updated Internal Audit Plan SPCF Public Meeting. Date of Submission: March 29, 2016 Date of Meeting: April 4, 2016 City of Saskatoon 2016 Updated Internal Audit Plan SPCF Public Meeting Date of Submission: March 29, 2016 Date of Meeting: April 4, 2016 Table of Contents Context - Updating Internal Audit Plan 3 Introduction

More information

Integrated Clause-byclause Guidance

Integrated Clause-byclause Guidance Integrated Clause-byclause Guidance ISO 9001:2015, ISO 14001:2015 & ISO 45001:2018 Table of Contents 1 INTRODUCTION... 4 2 IMPLEMENTATION & DEVELOPMENT... 5 2.1 MANAGING THE CHANGE... 6 2.2 TOP MANAGEMENT

More information

Strengthening Your Enterprise Risk Management Process

Strengthening Your Enterprise Risk Management Process Strengthening Your Enterprise Risk Management Process Belinda Mumma, Senior Consultant, Enterprise Risk Management Services bmumma@sollievo.com (866) 605-5664 x3400 Discussion Topics Definition of Enterprise

More information

This resource is associated with the following paper: Assessing the maturity of software testing services using CMMI-SVC: an industrial case study

This resource is associated with the following paper: Assessing the maturity of software testing services using CMMI-SVC: an industrial case study RESOURCE: MATURITY LEVELS OF THE CUSTOMIZED CMMI-SVC FOR TESTING SERVICES AND THEIR PROCESS AREAS This resource is associated with the following paper: Assessing the maturity of software testing services

More information

Records Management Policy

Records Management Policy Records Management Policy Responsible Officer Author Business Planning & Resources Director Corporate Office Date effective from December 1999 Date last amended December 2015 Review date October 2018 1

More information

Federal Segment Architecture Methodology Overview

Federal Segment Architecture Methodology Overview Federal Segment Architecture Methodology Background In January 2008, the Federal Segment Architecture Working Group (FSAWG) was formed as a sub-team of the Federal CIO Council s Architecture and Infrastructure

More information

Requirements Analysis and Design Definition. Chapter Study Group Learning Materials

Requirements Analysis and Design Definition. Chapter Study Group Learning Materials Requirements Analysis and Design Definition Chapter Study Group Learning Materials 2015, International Institute of Business Analysis (IIBA ). Permission is granted to IIBA Chapters to use and modify this

More information

COBIT. IT Governance CEN 667

COBIT. IT Governance CEN 667 COBIT IT Governance CEN 667 1 Project proposal (week 4) Goal of the projects are to find applicable measurement and metric methods to improve processes: For 27000 series of standards 27001 and 27004 For

More information

Quality Manual Template ISO 9001:2015 Quality Management System

Quality Manual Template ISO 9001:2015 Quality Management System Quality Manual Template Table of Contents 1 INTRODUCTION... 5 2 QUALITY MANAGEMENT PRINCIPLES... 6 3 REFERENCES & DEFINITIONS... 6 4 CONTEXT OF THE ORGANIZATION... 8 4.1 ORGANIZATIONAL CONTEXT... 8 4.2

More information

Standards for Establishing

Standards for Establishing RIM FUNDAMENTALS 2012 ARMA International www.arma.org Standards for Establishing Records and Information Management Programs Virginia A. Jones, CRM, FAI Organizations that don t already have a records

More information

Improving your finance function effectiveness

Improving your finance function effectiveness April 2016 Financial Accounting Advisory Services Improving your finance function effectiveness Establishing a Center of Expertise framework for your teams Finance functions in many companies are evolving

More information

ERM Retooled: Driving Performance by Revising and Enhancing Risk Management Governance Wipfli LLP

ERM Retooled: Driving Performance by Revising and Enhancing Risk Management Governance Wipfli LLP ERM Retooled: Driving Performance by Revising and Enhancing Risk Management Governance 2018 Wipfli LLP In September 2017, the Committee of Sponsoring Organizations (COSO) a committee that provides guidance

More information

CITIBANK N.A JORDAN. Governance and Management of Information and Related Technologies Guide

CITIBANK N.A JORDAN. Governance and Management of Information and Related Technologies Guide CITIBANK N.A JORDAN Governance and Management of Information and Related Technologies Guide 2018 Table of Contents 1. OVERVIEW... 2 2. Governance of Enterprise IT... 3 3. Principles of Governance of Enterprise

More information

Advancing analytics and automation within internal audit

Advancing analytics and automation within internal audit Advancing analytics and automation within internal audit A look into the current maturity stages of internal audit analytics and how internal audit departments are further developing their analytics programs

More information

Logistics Solutions for the Warfighter

Logistics Solutions for the Warfighter Logistics Solutions for the Warfighter Marine Corps Logistics Command Albany, Georgia Name of Presenter: Mr. Arthur Tringali Code: P307 Future Plans Date Presented: 13 February 2015 Due Diligence Brief

More information

IIA ACFE Conference April 17, 2015

IIA ACFE Conference April 17, 2015 IIA ACFE Conference April 17, 2015 Summary of Presentation Forensic Audit / Internal Audit Forensic Audit Role Forensic Audit Methodology Pragmatic examples of how forensic audit can benefit the risk assessment

More information

716 West Ave Austin, TX USA

716 West Ave Austin, TX USA FRAUD-RELATED INTERNAL CONTROLS GLOBAL Headquarters the gregor building 716 West Ave Austin, TX 78701-2727 USA Figure 2.1 COSO defines an internal control as a process, effected by an entity s board of

More information

Community Bankers Conference

Community Bankers Conference 3rd Annual Regional and Community Bankers Conference The Federal Reserve Bank of Boston Disclaimer NEVER WRONG DON T COMPLETELY RELY UPON Recent Developments in Audit Practice SOX, FDICIA 112, Other Robert

More information

A Vision of an ISO Compliant Company by Bruce Hawkins, MRG, Inc.

A Vision of an ISO Compliant Company by Bruce Hawkins, MRG, Inc. A Vision of an ISO 55000 Compliant Company by Bruce Hawkins, MRG, Inc. ISO 55000 refers to a series of three standards outlining the purpose, requirements, and implementation guidance for an Asset Management

More information

Information governance for the real world

Information governance for the real world Information governance for the real world 1 2 Information governance is the activities and technologies that organizations employ to maximize the value of their information while minimizing associated

More information

ABOUT APQC's OPEN STANDARDS BENCHMARKING MEASURE LIST

ABOUT APQC's OPEN STANDARDS BENCHMARKING MEASURE LIST ABOUT APQC's OPEN STANDARDS BENCHMARKING MEASURE LIST The APQC Open Standards Benchmarking measure list concisely lists all of the measures currently available for a specific survey. These measures are

More information

ISACA Systems Implementation Assurance February 2009

ISACA Systems Implementation Assurance February 2009 ISACA Pressures Today Pressure to increase realization of value from IT spending Pressure to deliver on IT projects at a time when resources/budgets are constrained Pressure from risk of technology-based

More information

Enterprise Architecture: The Strategic Tool for Innovation in Tough Times

Enterprise Architecture: The Strategic Tool for Innovation in Tough Times Enterprise Architecture: The Strategic Tool for Innovation in Tough Times Presented By: Mr. Robert (Bob) Weisman MSc, PEng, PMP, CD CEO/Principal Consultant, Build The Vision Inc. Robert.weisman@buildthevision.ca

More information

Why CIP? AIIM International's Certified Information Professional designation was designed to allow information professionals to:

Why CIP? AIIM International's Certified Information Professional designation was designed to allow information professionals to: Why CIP? Over the past decade, there has been a perfect storm of change driven by consumerization, cloud, mobile, and the Internet of Things. It has changed how we think about enterprise information and

More information

Establishing an Agile Portfolio to Align IT Investments with Business Needs. Agile 2008 Experience Report

Establishing an Agile Portfolio to Align IT Investments with Business Needs. Agile 2008 Experience Report Establishing an Agile Portfolio to Align IT Investments with Business Needs Joseph C. Thomas DTE Energy Steven W. Baker DTE Energy Agile 2008 Experience Report Discussion Topics Context and History Legacy

More information

Compliance Operations Update

Compliance Operations Update Compliance Operations Update The Reliability Assurance Initiative Earl Shockley, Senior Director of Compliance Operations 2013 NERC Standards and Compliance Fall Workshop September 26, 2013 Table of Contents

More information

Boards and internal audit: Working together to strengthen risk management

Boards and internal audit: Working together to strengthen risk management Boards and internal audit: Working together to strengthen risk management Growing demands on boards The role of the board has always been an important and demanding one, but today s board members face

More information

More than 2000 organizations use our ERM solution

More than 2000 organizations use our ERM solution 5 STEPS TOWARDS AN ACTIONABLE RISK APPETITE Contents New Defining Pressures Risk Appetite and Risk Tolerance Benefits The 5 Best of Practices Risk Assessments Benefits of an Actionable Risk Appetite More

More information

IT Services Management Service Brief

IT Services Management Service Brief IT Services Management Service Brief Business Impact Analysis Prepared by: Rick Leopoldi June 19, 2002 Copyright 2002. All rights reserved. Duplication of this document or extraction of content is strictly

More information

1. Definition & Mission

1. Definition & Mission 1. Definition & Mission 1.1 Internal Auditing is an independent, objective assurance and consulting activity that is guided by a philosophy of adding value to improve the operations of. 1.2 Group Internal

More information

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010

Catching Fraud During a Recession Through Superior Internal Controls. FICPA s 25 th Annual Accounting Show. J. Stephen Nouss September 29, 2010 Catching Fraud During a Recession Through Superior Internal Controls FICPA s 25 th Annual Accounting Show J. Stephen Nouss September 29, 2010 1 Session Objectives Fraud Facts (2008 Association of Certified

More information

Fear, Uncertainty, Doubt

Fear, Uncertainty, Doubt Fear, Uncertainty, Doubt However, ERM = Manageable OK, Back to The Bonadio Group Standard Enterprise Risk Management An Overview on Key Controls We Will Cover Why ERM ERM COSO basics Tangible benefits

More information

Your business will become an e-business. Be prepared for the challenges. business value today and tomorrow. information how and when you need it

Your business will become an e-business. Be prepared for the challenges. business value today and tomorrow. information how and when you need it we re the bricks behind the clicks Your business will become an e-business. Be prepared for the challenges. e-business is more than a storefront. It s a business. It s no longer enough to merely bolt-on

More information

Roche Group Records Management Directive V2.0

Roche Group Records Management Directive V2.0 Roche Group Records Management Directive V2.0 Version: 2.0 Issue Date: 1-Mar-2017 Document Information Document Owner Document Location Geographical Scope Associated Documents Head of COREMAP Group Intranet/CONDOR

More information

Summary of 47 project management processes (PMBOK Guide, 5 th edition, 2013)

Summary of 47 project management processes (PMBOK Guide, 5 th edition, 2013) Summary of 47 project management processes (PMBOK Guide, 5 th edition, 2013) Integration Management: processes & activities needed to properly coordinate all aspects of the project to meet stakeholder

More information

September 17, 2012 Pittsburgh ISACA Chapter

September 17, 2012 Pittsburgh ISACA Chapter September 17, 2012 Pittsburgh ISACA Chapter What is COBIT? Control Objectives for Information and related Technologies ISACA s guidance on the enterprise governance and management of IT. Builds on more

More information

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining)

Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Comparison of the PCAOB s Auditing Standards No. 5 and No. 2 (Certain key differences are highlighted by underlining) Topic AS No. 5 AS No. 2 Objective of ICFR Audit Planning the ICFR Audit Integration

More information

Certified Information Professional 2016 Update Outline

Certified Information Professional 2016 Update Outline Certified Information Professional 2016 Update Outline Introduction The 2016 revision to the Certified Information Professional certification helps IT and information professionals demonstrate their ability

More information

A step towards strengthening governance

A step towards strengthening governance A step towards strengthening governance Resolution No.1, 2017 of the Chairman of ADAA March 2018 kpmg.com/ae kpmg.com/om What is the Resolution about? Setting the context GCC regulations are constantly

More information