Information technology and its role in today’s business environment is an important component for the success of today’s organization. Although organizations are staffed with experienced personnel who are skilled in the technicalities of data systems, personnel computer systems and data access methods, it is important that all personnel have a strong understanding of control procedures that comprise the complex nature of today’s digital world.
Advancements in technology have raised the level of acknowledgement of threats in the cyber age. These threats touch both the business world and personal lives. Information technology is no longer a “back-office” function. Once considered a process area that was solely part of the Chief Information Officer’s domain, companies must now acknowledge that whether the threats are internal or external, they are very real and can and will cause harm to many organizations in many ways. As a result, it is imperative that professionals across the company understand and be prepared to deal with the multitude of ever-growing cyber threats.
This training serves as a primer for understanding the many advancements of information technology and its uses in today’s business environment. These advancements and uses of information technology can relate to financial, operational or compliance reporting methods. We will discuss the critical tie to COSO 2013 and delve into understanding the variance between General Controls and Application Controls as well as cover important concepts related to information technology and cyber risks.
Publication Date: August 2019
Designed For
Professionals working with information technology, IT professionals, Accountants, Finance and internal audit professionals, Legal and Compliance professionals.
Topics Covered
- Explore the definition of IT Systems
- Internal control benefits/risks of IT systems.
- ITGC most prevalent controls
- COSO's link to IT and GC
- The cyber link to ITGC
- Meaning/impact of data breaches and the importance of internal control
- Actions professionals and organizations can take towards prevention of cyber threats
Learning Objectives
- Describe the definition of IT Systems
- Identify internal control benefits/risks of IT systems
- Recognize and explore ITGC most prevalent controls
- Describe COSO's link to IT and GC
- Recognize and explore the cyber link to ITGC
- Recognize and apply the meaning/impact of data breaches and the importance of internal control
- Recognize and apply actions professionals and organizations can take towards prevention of cyber threats
- Identify an example of a processing application control
- Identify the steps in the SDLC process
- Recognize a type of ITGC that includes the backup of files, programs, and documentation at a secure off-site location
- Describe best practices for preventing data breaches correlates with the proper identification of critical assets
- Differentiate types of controls applied to all systems components, processes, and data for an organization or IT environment
- Identify an example of an input application control
- Describe node analysis
Level
Basic
Instructional Method
Self-Study
NASBA Field of Study
Information Technology (2 hours)
Program Prerequisites
None
Advance Preparation
None
Instructor
Lynn Fountain
Lynn Fountain has over 38 years of experience spanning public accounting, corporate accounting and consulting. 20 years of her experience has been working in the areas of internal and external auditing and risk management. She is a subject matter expert in multiple fields including internal audit, ethics, fraud evaluations, Sarbanes-Oxley, enterprise risk management, governance, financial management and compliance. Lynn has held two Chief Audit Executive (CAE) positions for international companies. In one of her roles as CAE, she assisted in the investigation of a multi-million-dollar fraud scheme perpetrated by a vendor that spanned 7 years and implicated 20 employees. The fraud was formally investigation by the FBI and resulted in 5 indictments estimating a $13M fraud loss.
Ms. Fountain is currently engaged in her own consulting and training practice. She is a highly sought-after trainer and international speaker. In addition, Ms. Fountain has assisted numerous companies with enterprise risk management frameworks, internal audit processes and financial accounting. She also serves as a discussion leader for the AICPA for numerous classes finance, accounting and risk management topics.
Ms. Fountain is the author of three separate technical books. Her first book released in 2015 by the Institute of Internal Auditors Foundation is entitled “Raise the Red Flag – The Internal Auditors Guide to Fraud Evaluations”. Her second book “Leading the Internal Audit Function” was released in October 2015 by Taylor & Francis Publications. This book serves as the initial launch for a series of leading practice internal audit and information technology publications. Her third book “Ethics and the Internal Auditor’s Dilemma” was released in December 2016.
Ms. Fountain obtained her BSBA from Pittsburg State University and her MBA from Washburn University in Kansas. She has her CPA, CGMA, CRMA credentials.