Governance Risk and Compliance
Required Reading
Slides, class discussion notes, and hyperlinks for GRC 1 IM341, Fall 2024.
IM341 Course Overview
Information Processing Systems: Based on business process analysis, foundational content for the course.
Example Processes:
Order to Cash
Procure/Purchase to Pay
Business Process Analysis: Understanding organizational operations, methods, locations, timings, and rationales.
Documentation of Systems/Processes: Introduction to documenting processes using Data Flow Diagrams (DFDs) and Flowcharts.
Governance, Risk and Compliance (GRC): Overview of data analysis and modeling for transaction processing using SQL and QBE.
Importance of Business Understanding
Source: Audit Board
Organization Goals ➡️ Business Processes ➡️ Information Processes: Information processes designed using instruction-based technologies.
Effective Management of Processes: Managing processes, people, and technology to generate value.
GRC Overview:
Governance: Managing processes, technology, and systems.
Risk Management: Identifying and controlling risks associated with technology.
Compliance: Adhering to legal and regulatory requirements based on industry and organizational structure.
Foundational Knowledge for GRC
Essential understandings for managing risk:
Understanding the organization, its processes, information processes, and information technology.
Familiarization with key risk management terms and concepts.
Awareness of guidance for risk management.
Understanding key processes in risk management.
IT Governance
Definition: A framework ensuring IT investments align with business objectives.
IT Governance Aspects: Often termed as IT or I&T governance (Information & Technology).
Key Points:
Business issue rather than solely technological.
Involves processes for informing, directing, managing, and monitoring activities to achieve organizational goals.
I&T/IT Governance Objectives
Align IT strategy with business strategy.
Integrate IT into enterprise risk management.
Manage IT performance and ensure value delivery.
Maintain regulatory compliance and internal controls.
Broadly encompasses risk management and compliance.
Components of a Governance System (COBIT 2019)
Understanding requirements:
Knowledge of the organization and IT space.
Familiarity with risks including business, IT, and cyber risks.
Ability to evaluate and manage technology investments and processes.
IT Regulatory Environment
Security Frameworks: Includes Sarbanes-Oxley Act, FERPA, and others.
Each regulation comes with compliance documentation detailing requirements.
Examples of Regulations and Compliance
Data Breach Laws: All U.S. states mandate notification of breaches involving personally identifiable information (PII).
GDPR: Requires protection of personal data of EU residents.
HIPAA: Governs healthcare data.
CCPA: Mirrors GDPR, protecting data of California residents.
Risk Management Concept
Risk: Measure of potential loss or damage when a threat exploits a vulnerability.
Sources of risk outlined: economic, compliance, fraud, reputation, operational, etc.
Guidance for IT Governance
Refer to standards and frameworks for managing IT compliance and risks.
Standards provide methods for compliance, while frameworks offer general guidance and flexibility for implementation.
Overview of IT Governance/Risk-Control Frameworks
Key Groups: ISO, NIST, COSO, COBIT, ITIL, ISACA.
Provides a basis for understanding IT governance and associated risks.
Types of Risks in IT
Differentiation between I&T Risk, Audit Risk, and Enterprise Risk, emphasizing their impact on business objectives.
Understanding Vulnerabilities and Threats
Vulnerability: A weakness in information systems that may be exploited.
Examples range from poor user knowledge to configuration errors.
Threat: Any condition that could exploit vulnerabilities, potentially leading to asset loss.
Risk Management Process
Identify Risk Factors: Identify vulnerabilities and potential threats.
Assess Risk: Measure likelihood and potential impact of identified risks.
Implement Controls: Decide on control measures and document them effectively.
COSO Enterprise Risk Management (ERM)
Designed to identify and manage risk within organizational appetite.
Goes beyond identifying risks to include preventing associated threats.
IT General Controls (ITGC)
Framework ensuring reliability of information systems across their lifecycle.
Include access controls, change management, and operational procedures.
Business Continuity and Disaster Recovery Plans
DRP: Outlines strategies for recovering from disruptions.
Hot and Cold Sites: Options for data recovery.
Backup Methods: Full, differential, and incremental backups for data preservation.
Application Controls Types
Input, processing, and output controls ensure data integrity and reliability in systems.
Use of validation edits and control techniques for data entry reliability.
Security vs Compliance
Compliance does not equate to security; organizations must manage both to avoid vulnerabilities.
Security Goals: Protect information assets against unauthorized access and risks.
Encryption and Data Protection
Encryption: Process of securing data using encryption algorithms and keys.
Hashing: One-way function to validate data integrity.
Conclusion: Evolving Cybersecurity Landscape
Organizations need adaptable strategies for emerging threats in a constantly evolving cybersecurity environment.