ITGC Assessment Workshop - In person at Bangalore Chapter office
About the Event
Dates of Training: Dec 2 & 3, 2023
Time of Training: 10 am to 6pm (6 hours each day)
Total Hours:12 hours
|
Day |
Activity - Day 1 |
Indicative Duration |
Agenda Items |
|
Day - 1 |
Introduction and ITGC Fundamentals |
1 Hour |
- Introduction to IT General Controls (ITGC) |
|
- Introduction to IT General Controls (ITGC) |
|||
|
- Practical Exercise: Identifying ITGC in various scenarios |
|||
|
Types of ITGC Controls and Walkthroughs |
2 Hours |
- Access Controls: Case study and walkthrough |
|
|
- Change Management Controls: Interactive walkthrough |
|||
|
- Operations Controls: Group activity on identifying controls |
|||
|
- Backup and Recovery Controls: Live simulation and walkthrough |
|||
|
Lunch Break |
1 Hour |
- (Break) |
|
|
Risk Assessment and Scoping ITGCs |
2 Hours |
- ITGC risk assessments: Hands-on exercise |
|
|
- Scoping ITGCs: Case-based group activity |
|||
|
- Practical Exercise: Determining scope based on business size and complexity |
|||
|
ITGC for Specific Applications - SAP Focus |
1 Hour |
- Overview of SAP controls environment |
|
|
- Case Study: SAP Access Control |
|||
|
- Group Discussion: Identifying key SAP ITGCs |
|||
|
Day - 2 |
Executing ITGC Audits - Test of Design (ToD) and Documentation |
1.5 Hours |
- ToD methodologies discussion |
|
- Hands-on group exercise to perform ToD on a simulated control |
|||
|
Executing ITGC Audits - Test of Operating Effectivness (ToE) and Documentation |
1.5 Hours |
- ToE concepts and practical demonstration |
|
|
- Case Study: Performing ToE on common ITGCs |
|||
|
Lunch Break |
1 Hour |
- (Break) |
|
|
ITGC for Specific Applications - Beyond SAP |
1 Hour |
- Overview of controls in other key applications |
|
|
- Case Study: Non-SAP application control assessment |
|||
|
ITGC Audits - Reporting and Communication |
2 Hours |
- Drafting ITGC Audit Findings: Demo and walkthrough |
|
|
- Communicating Results: Role-play exercises on presenting findings |
|||
|
- Action Plan Development: Workshop on formulating remediation strategies |
|||
|
Practical Aspects and Emerging Trends in ITGC Audits, IT Automated Controls Testing |
1 Hour |
- Insights into PBC Lists and usage in audits |
|
|
- Workshop: Automating ITGC Auditing processes |
|||
|
- Group discussion on continuous auditing and monitoring trends |
|||
|
Final Exercise and Wrap-up |
1 Hour |
- Comprehensive case study: From planning to reporting |
|
|
- Open Q&A Session: Addressing complex scenarios |
|||
|
- Final thoughts and closing remarks |
Training Methodology
The training shall cover:
- Practical use cases of ITGC and ITAC
- Some case studies,
- Drafting of risk control matrices
- Preparing the list of evidence required for validation.
- Assessment of evidence and controls
- Test of Design, Test of operating effectiveness
Trainer Profile
CA Narasimhan Elangovan
FCA, DipIFR(UK), CISA(USA), CDPSE (USA)
Director - Membership - ISACA Bangalore Chapter
CA Narasimhan Elangovan is a SOC 2 Auditor, a futurist, Cyber Security Auditor, and a Keynote Speaker.
His areas of practise include Cyber Security Audits, SOC 2 and ITGC attestations, auditing emerging technologies such as AI, Big Data, IoT.