Assessing IT Business Application System Controls
On-Demand - 10 CPE Â
This on-demand class is designed for financial, business, and IT auditors who need a solid strategy for auditing business application systems.Â
Focusing on a risk-based approach to auditing business application transactions, you will review techniques that can be applied to all types of business application systems. You will learn how to assess key risks and controls in the application processing cycle and how to prioritize your audit approach to focus on the highest risk areas.
A primary focus during the session will be how to assess key aspects of a business application, including completeness and accuracy of input, processing and output, transaction authorizations, processing flow balancing and reconciliations. Testing will also be highlighted to provide for effective testing results.
Course Agenda:
IT Risks
·      IT Risk Definition
·      Information Security Objectives
·      Key Business Application Risks
Â
Performing Integrated Audits
·      Defining Integrated Auditing
·      Scoping Integrated Audits
·      Business and Application Controls
·      Integrated Audits - Challenges
·      COSO – Principle-11
Access Management
·      User Identification and Authentication
·      Single Sign-On
·      Authorization Controls
·      Separation of Duties
·      Audit Trail & Review
·      Log Management
Â
Change, Patch & Configuration Mgt                                             Â
·      Change Management                                                               Â
·      Patch Management
·      Security Configuration Management
Â
Business Application Systems
·      Business Application Audit Objectives
·      Batch, On-line, Web-facing and Real-time Models
·      Enterprise Resource Planning (ERP) Systems
Â
Business Application Transaction Risks
·      Determining Application Risks
·      Performing Walkthroughs
·      Automated & Manual Controls
·      IT Dependent Manual Controls
·      Application-Level IT General Controls
Â
Business Application Controls
·      Completeness & Accuracy of Input
·      Error Handling
·      Completeness & Accuracy of Processing
·      Completeness & Accuracy of Output
·      Output Retention & Disposal
·      Completeness & Accuracy of Masters
·      Completeness & Accuracy of Interfaces
Testing Business Application Controls
·      Testing Operating Effectiveness
·      Testing Automated Controls
·      Testing IT Dependent Manual Controls
·      Data Analytics & CAATs
                                                                                                             Â
End User Computing (EUC)
·      EUC / UDA Computing Risks                                                  Â
·      Spreadsheet Risk Factors                                                        Â
·      Evaluating End User Controls
·      Shadow IT / Shadow Cloud
Â
Course Curriculum
Featured Courses
View our other on-demand learning courses and get the continuing education hours you need!