欢迎来到淘文阁 - 分享文档赚钱的网站! | 帮助中心 好文档才是您的得力助手!
淘文阁 - 分享文档赚钱的网站
全部分类
  • 研究报告>
  • 管理文献>
  • 标准材料>
  • 技术资料>
  • 教育专区>
  • 应用文书>
  • 生活休闲>
  • 考试试题>
  • pptx模板>
  • 工商注册>
  • 期刊短文>
  • 图片设计>
  • ImageVerifierCode 换一换

    国外简约大气的PPT模板.ppt

    • 资源ID:27007227       资源大小:669KB        全文页数:38页
    • 资源格式: PPT        下载积分:15金币
    快捷下载 游客一键下载
    会员登录下载
    微信登录下载
    三方登录下载: 微信开放平台登录   QQ登录  
    二维码
    微信扫一扫登录
    下载资源需要15金币
    邮箱/手机:
    温馨提示:
    快捷下载时,用户名和密码都是您填写的邮箱或者手机号,方便查询和重复下载(系统自动生成)。
    如填写123,账号就是123,密码也是123。
    支付方式: 支付宝    微信支付   
    验证码:   换一换

     
    账号:
    密码:
    验证码:   换一换
      忘记密码?
        
    友情提示
    2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
    3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
    4、本站资源下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。
    5、试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。

    国外简约大气的PPT模板.ppt

    The Importance of IT Controls to Sarbanes-Oxley Compliance. 2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 2 Provide a high-level overview of Sarbanes-Oxley and the internal control certification requirements Discuss the importance of information technology in internal control over financial reporting Describe how the Sarbanes-Oxley section 404 rules impact information technology Provide an overview of the Cobit IT control framework Provide an example of a readiness program roadmap Summarize the importance and impact of IT controls to Sarbanes-Oxley complianceTodays Objectives 2003 Firm Name/Legal EntityImportance of IT Controls to Sarbanes-Oxley 3Setting the Stage2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 4Setting the Stage What is internal control? Internal control is broadly defined as a process, effected by an entitys board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: Effectiveness and efficiency of operations Reliability of financial reporting Compliance with applicable laws and regulations Internal control is now the Law The Sarbanes-Oxley Act of 2002 was created to restore investor confidence in the public markets Section 404 of the Act requires management to establish and maintain internal control and requires the independent auditors to evaluate Compliance deadline: Year-ends on or after November 15, 2004 Preparing for Sarbanes-Oxley compliance is a significant and challenging task There are many requirements, including the identification of significant financial statement accounts, processes and systems that support them and then documenting and testing them 2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 5Overview of Internal Control Certification RequirementsSection 302 Certification OverviewCEO and CFO to make specific certifications as of the end of each quarterly and annual reporting period, including: Report contains no untrue statements Report is fairly presented in all material respects Responsibility for design and maintenance of disclosure controls and procedures as well as internal controls over financial reporting Became effective in 2002 (amended in June 2003)Section 404 Certification OverviewCEO and CFO to certify as of the end of every annual reporting period: Their responsibility for establishing and maintaining effective internal controls over financial reporting Their assessment of internal controls, accompanied by the independent auditors attestation report Effective for annual periods ending after November 15, 2004 (small business and foreign filers July15, 2005).2003 Firm Name/Legal EntityImportance of IT Controls to Sarbanes-Oxley 6Understanding the Rules Impact to IT2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 7Understanding the Rules Impact to IT Management is required to assess the design and effectiveness of its internal control over financial reporting and provide an assertion to that effect in the published financial statements. The companys external auditors are required to express an opinion on managements assessment as well their own opinion on the companys internal controls. Auditor must perform a walkthrough of major classes of transactions for significant processes to understand process flows, and assess the design and effectiveness of controls including application and IT general controls. Evaluate the design effectiveness of IT controls to determine whether they are properly designed to achieve relevant assertions. Perform tests of the operating effectiveness of IT controls that are necessary to achieve relevant assertions.Key Compliance RequirementsImpact to IT Controls2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 8(paragraph 47)“The auditor should obtain an understanding of the design of specific controls by applying procedures that include tracing transactions through the information system relevant to financial reporting”(paragraph 73)“Most processes involve a series of tasks such as capturing input data, sorting and merging data, making calculations, updating transactions and master files, generating transactions, and summarizing and displaying or reporting data. The processing procedures relevant for the auditor to understand the flow of transactions generally are those activities required to initiate, authorize, record, process and report transactions.” The PCAOB rules are clear - auditors must understand how transactions flow through the system not around itUnderstanding the Rules Impact to IT contd2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 9(paragraph 69)“The auditor should identify each significant process over each major class of transactions affecting significant accounts or groups of accounts and Understand the flow of transactions, including how transactions are initiated, authorized, recorded, processed, and reported. Identify the points within the process at which a misstatement including a misstatement due to fraud related to each relevant financial statement assertion could arise. Identify the controls that management has implemented to address these potential misstatements. Identify the controls that management has implemented over the prevention or timely detection of unauthorized acquisition, use, or disposition of the companys assets. PCAOB statements applicable to Application Controls:Understanding the Rules Impact to IT contd2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 10(paragraph 40)“Determining which controls should be tested Generally, such controls include information technology general controls, on which other controls are dependent”(paragraph 50)“Some controls have a pervasive effect on the achievement of many objectives for example, information technology general controls over program development, program changes, computer operations, and access to programs and data” PCAOB statements applicable to IT General Controls:Understanding the Rules Impact to IT contd2003 Firm Name/Legal EntityImportance of IT Controls to Sarbanes-Oxley 11The Importance of Information Technology in Internal Control over Financial Reporting 2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 12 For most organizations, IT is pervasive and critical to the financial reporting process Financial and routine business applications are commonly used to initiate, authorize, record, process and report transactions Relevant IT controls include application controls - those that are embedded in financial and business applications general computer controls underlying infrastructure components that support the applications Statements made by the Public Company Accounting and Oversight Board (PCAOB) on the impact of IT (paragraph 75):“The nature and characteristics of a companys use of information technology in its information system affect the companys internal control over financial reporting”The Importance of Information Technology (IT) in Internal Control over Financial Reporting2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 13Application Controls SoDData integrityCompletenessValidationGeneral Computing ControlsInformation SecurityOperationsDatabase Impl. & SupportNetwork SupportBusiness ProcessClasses of Transactions SalesReturnsWrite offsSignificant Account Balance Balance Sheet (AR)IncomeStatementG/LInventoryOtherAR Mgt ProcessFCRPSales ProcessProcess StagesInitiateRecordProcessReport Application Impl. & Maint.System Software SupportThe Role of Information Technology in Internal Control over Financial Reporting contd2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 14 Account balance: Trade AR, Sales Classes of Transactions: Invoices, Sales orders Business Process: AR, Sales Order processes Process Stages: Initiate, record, process Application Controls: Access controls Built in limits for credit approval Restricted access to pricing table GCC Controls: Program change Operations Network & system securityLink Accounts and Assertions to IT: An Example Customerorder entry Accounts Receivable Invoice controls SAP, Oracle, Other ApplicationsGeneral computing controls cover security access, change management, operations, systems and network support, data retention, etc.Order ProcessingOrder & supplier controlsSalesSub-processCustomer controlsIT InfrastructureNetworksSystem SoftwareDatabases and InformationSecurityApplication controls cover authorized changes, segregation of duties, validity, completeness and timeliness of reporting of financial information.2003 Firm Name/Legal EntityImportance of IT Controls to Sarbanes-Oxley 15Cobit IT Control Framework Overview2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 16COBIT A Model for General Computer Controls The IT Governance Institute (www.ITGI.org) has recently published “revised” guidance for IT professionals on how to address Sarbanes-Oxley from an IT perspective April 2004 “Sarbanes-Oxley; The importance of information technology in the design, implementation and sustainability of internal control” The publication is the result of a joint effort of industry and auditors, with leadership from Deloitte and others The ITGI is a recognized global leader in IT governance, control and assurance with members in more than 100 countries2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 17 PCAOB designates COSO as the prescribed standard control framework and has become the control framework of choice for SOX compliance All 5 layers must be considered when evaluating internal control However, COSO does not provide specific guidance around IT control. CobiT is a widely accepted IT control framework (ITGI) CobiT provides 4 domains of IT control CobiT controls address the 5 layers of COSO With the development of this approach, organizations can be confident that they are taking an approach that reflects COSO requirementsControl EnvironmentRisk AssessmentControl ActivitiesInformation and CommunicationMonitoringCOSO ComponentsCobiT ObjectivesPlanning and OrganizationPlanning and OrganizationSection 302Section 302Delivery and SupportDelivery and SupportMonitoringMonitoringAcquisition and ImplementationAcquisition and ImplementationSection 404Section 404Information Technology controls should consider the overall governance framework to support the quality and integrity of informationCompetency in all 5 layers of COSOs framework are necessary to achieve an integrated control programControls in Information Technology are relevant to both Financial Reporting and Disclosure requirements of Sarbanes-OxleyCOBIT A Model for General Computer Controls contd2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 18 The ITGI publication provides guidance to IT professionals on how to meet the Sarbanes-Oxley challenge Detailed control objectives are provided for each CobiT domain and mapped to their respective COSO component Other control guidelines were reviewed and reconciled to this approach during the development process, including ISO17799, Common Criteria, ITIL, and SysTrust Organizations should assess their requirements on an individual basis and tailor their approach accordingly COSO Component CobiT Control Objectives Control Environment Risk Assessment Control Activities Information & Communication Monitoring Planning & Organization Define a strategic IT plan Define the information architecture Determine technological direction Define the IT organization and relationships Manage the IT investment Communicate management aims and direction Manage human resources Ensure compliance with external requirements Assess risks Manage projects Manage quality Acquisition & Implementation Identify automated solutions Acquire and maintain application software Acquire and maintain technology infrastructure Develop and maintain procedures Install and accredit systems Manage changes Delivery & Support Define and manage service levels Manage third-party services Manage performance and capacity Ensure continuous service Ensure systems security Identify and allocate costs Educate and train users Assist and advise customers Manage the configuration Manage problems and incidents Manage data Manage facilities Manage operations Monitoring Monitor the processes Assess internal control adequacy Obtain independent assurance Provide for independent audit COSO ComponentsCobiT ObjectivesCOBIT A Model for General Computer Controls contd2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 19 The CobiT SOA framework identified a sub-set of these areas for the purpose of focusing on SOA requirements Company level: Planning & Organizing / Monitoring COBIT A Model for General Computer Controls contdPlanning & Organization IT Strategic Planning IT organization and relationships Management of human resources Educate and train users Information architecture Communication of mgmt aims and direction Assessment of risks Manage the IT investment Manage projectsMonitoring Compliance with external requirements Management of quality Ensure continuous service Performance and capacity Monitoring Adequacy of internal controls Independent assurance Internal audit Activity level: Acquisition and Implementation / Delivery and Support Program Development (SDLC) Program Changes Computer Operations (scheduling, backup, problem management) Access to programs and data (applications, database, operating system, network)2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 20Top 5 List 404 IT Controls RequirementsSecurity Application and platform based Focused on applications that may impact financials and supporting infrastructure Requires secure operating systems, database, network, firewalls and infrastructure Auditors will look for excessive access; lack of segregation of duties; inadequate approval of access; they will be testing key processes to determine that they are effectiveChange Control Need to ensure that procedures are in place to control and ensure proper approval of changes to production Technical controls must tightly limit and control developer access to productionDisaster Recovery Focus will be on basic backup and recoverability of financial dataIT Governance Focus will be on determining of there are clear policies, procedures, and communications within IT Are there clear segregation of duties? Is there the appropriate “tone at the top” of the IT organization?Development And Implementation Activities Proper controls need to be built in before a new system or system changes go in the production environment Auditors may evaluate new financial systems; data conversion and testing are critical2004 Deloitte & Touche LLPImportance of IT Controls to Sarbanes-Oxley 21Most Common IT Control Gaps To RemediateChange control processes not fully in place (especially in dis

    注意事项

    本文(国外简约大气的PPT模板.ppt)为本站会员(asd****56)主动上传,淘文阁 - 分享文档赚钱的网站仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知淘文阁 - 分享文档赚钱的网站(点击联系客服),我们立即给予删除!

    温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。




    关于淘文阁 - 版权申诉 - 用户使用规则 - 积分规则 - 联系我们

    本站为文档C TO C交易模式,本站只提供存储空间、用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。本站仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知淘文阁网,我们立即给予删除!客服QQ:136780468 微信:18945177775 电话:18904686070

    工信部备案号:黑ICP备15003705号 © 2020-2023 www.taowenge.com 淘文阁 

    收起
    展开