Governance Risk and Compliance

Required Reading

  • Slides, class discussion notes, and hyperlinks for GRC 1 IM341, Fall 2024.

IM341 Course Overview

  • Information Processing Systems: Based on business process analysis, foundational content for the course.

    • Example Processes:

      • Order to Cash

      • Procure/Purchase to Pay

  • Business Process Analysis: Understanding organizational operations, methods, locations, timings, and rationales.

  • Documentation of Systems/Processes: Introduction to documenting processes using Data Flow Diagrams (DFDs) and Flowcharts.

  • Governance, Risk and Compliance (GRC): Overview of data analysis and modeling for transaction processing using SQL and QBE.

Importance of Business Understanding

  • Source: Audit Board

  • Organization Goals ➡️ Business Processes ➡️ Information Processes: Information processes designed using instruction-based technologies.

  • Effective Management of Processes: Managing processes, people, and technology to generate value.

    • GRC Overview:

      • Governance: Managing processes, technology, and systems.

      • Risk Management: Identifying and controlling risks associated with technology.

      • Compliance: Adhering to legal and regulatory requirements based on industry and organizational structure.

Foundational Knowledge for GRC

  • Essential understandings for managing risk:

    • Understanding the organization, its processes, information processes, and information technology.

    • Familiarization with key risk management terms and concepts.

    • Awareness of guidance for risk management.

    • Understanding key processes in risk management.

IT Governance

  • Definition: A framework ensuring IT investments align with business objectives.

    • IT Governance Aspects: Often termed as IT or I&T governance (Information & Technology).

    • Key Points:

      • Business issue rather than solely technological.

      • Involves processes for informing, directing, managing, and monitoring activities to achieve organizational goals.

I&T/IT Governance Objectives

  • Align IT strategy with business strategy.

  • Integrate IT into enterprise risk management.

  • Manage IT performance and ensure value delivery.

  • Maintain regulatory compliance and internal controls.

  • Broadly encompasses risk management and compliance.

Components of a Governance System (COBIT 2019)

  • Understanding requirements:

    • Knowledge of the organization and IT space.

    • Familiarity with risks including business, IT, and cyber risks.

    • Ability to evaluate and manage technology investments and processes.

IT Regulatory Environment

  • Security Frameworks: Includes Sarbanes-Oxley Act, FERPA, and others.

    • Each regulation comes with compliance documentation detailing requirements.

Examples of Regulations and Compliance

  • Data Breach Laws: All U.S. states mandate notification of breaches involving personally identifiable information (PII).

    • GDPR: Requires protection of personal data of EU residents.

    • HIPAA: Governs healthcare data.

    • CCPA: Mirrors GDPR, protecting data of California residents.

Risk Management Concept

  • Risk: Measure of potential loss or damage when a threat exploits a vulnerability.

    • Sources of risk outlined: economic, compliance, fraud, reputation, operational, etc.

Guidance for IT Governance

  • Refer to standards and frameworks for managing IT compliance and risks.

    • Standards provide methods for compliance, while frameworks offer general guidance and flexibility for implementation.

Overview of IT Governance/Risk-Control Frameworks

  • Key Groups: ISO, NIST, COSO, COBIT, ITIL, ISACA.

  • Provides a basis for understanding IT governance and associated risks.

Types of Risks in IT

  • Differentiation between I&T Risk, Audit Risk, and Enterprise Risk, emphasizing their impact on business objectives.

Understanding Vulnerabilities and Threats

  • Vulnerability: A weakness in information systems that may be exploited.

    • Examples range from poor user knowledge to configuration errors.

  • Threat: Any condition that could exploit vulnerabilities, potentially leading to asset loss.

Risk Management Process

  1. Identify Risk Factors: Identify vulnerabilities and potential threats.

  2. Assess Risk: Measure likelihood and potential impact of identified risks.

  3. Implement Controls: Decide on control measures and document them effectively.

COSO Enterprise Risk Management (ERM)

  • Designed to identify and manage risk within organizational appetite.

  • Goes beyond identifying risks to include preventing associated threats.

IT General Controls (ITGC)

  • Framework ensuring reliability of information systems across their lifecycle.

    • Include access controls, change management, and operational procedures.

Business Continuity and Disaster Recovery Plans

  • DRP: Outlines strategies for recovering from disruptions.

    • Hot and Cold Sites: Options for data recovery.

  • Backup Methods: Full, differential, and incremental backups for data preservation.

Application Controls Types

  • Input, processing, and output controls ensure data integrity and reliability in systems.

  • Use of validation edits and control techniques for data entry reliability.

Security vs Compliance

  • Compliance does not equate to security; organizations must manage both to avoid vulnerabilities.

    • Security Goals: Protect information assets against unauthorized access and risks.

Encryption and Data Protection

  • Encryption: Process of securing data using encryption algorithms and keys.

    • Hashing: One-way function to validate data integrity.

Conclusion: Evolving Cybersecurity Landscape

  • Organizations need adaptable strategies for emerging threats in a constantly evolving cybersecurity environment.