WEBINAR: IT AUDIT, ENTERPRISE IT GOVERNANCE & RISK MANAGEMENT

November 10-11, 2021, 11:00 AM – 4:00 PM, DUBAI STANDARD TIME

Training Objectives

Learning Objectives

  • Highlight the strategic drivers for IT Governance, Audit and Risk.
  • Demonstrate the role of IT Governance, Audit & Risk in delivering value to the enterprise.
  • Highlight the impact of digital transformation initiatives on IT Governance, Audit & Risk Management functions in the enterprise.
  • Equip IT Audit and Risk Management professionals with the necessary knowledge and skills to add value to the enterprise in the face of tremendous change.
Register Now Download Brochure

Instructor of this course

Mr. Bernard Wanyama

CISA, CISM, CRISC, CGEIT
Founder & Managing Director of SYNTECH Associates Ltd
Instructor: Cyber Security, IT Audit, IT Risk Management
APMG Accredited Trainer for CISA & CISM Courses
Cyber Security Expert

More Detail

Audit and risk management professionals are required to provide assurance over complex, inter-connected information systems and processes in a fluid, environment of change - be it compliance requirements, disruption or digital transformation. 

This course will provide the strategic approach and knowledge necessary for IT Audit and Risk Management Professionals to thrive and add value to their organizations as they deal with evolving risks and emerging technologies.

Participants who complete the course will get an opportunity to:

  • Frame the role of IT Governance, Audit and Risk Management in supporting enterprises and industries that are undergoing rapid change and digital transformation.
  • Understand IT audit and assurance standards, guidelines and frameworks.
  • Understand how to plan and perform a risk-based IT audit.
  • Understand IT Risk Management Principles.
  • Discuss audit and control issues in different IT architecture components such as networks, databases, web application and cloud systems.
  • Discuss audit and control issues around cyber security.
  • Discuss risk, audit and control issues around emerging technologies such as cloud computing, virtualization, robotic process automation, machine learning and artificial intelligence.
  • Understand how to cultivate an atmosphere of shared responsibility for risk management across the enterprise.
  • Review case studies of major cyber security breaches to learn lessons for audit and risk functions.
  • 10.8 CPE hours.

C-Level Executives:

  • Chief IT Auditors, Chief Risk Officers, Chief Audit Executives, etc.

Directors, Heads, Partners, Managers, Officers & coordinators of:

  • IT Audit
  • IT Risk
  • IT Security Audit
  • Audit
  • Risk
  • Cyber security & Information Security.
  • Privacy

 

  • Group discussions focused on real-world case studies
  • Online Quizzes
  • Individual assignments
  • Using brainstorming techniques, images, graphics and video clips for quality learning
  • Feedback discussion of the previous day activities

Course Fee $300/Participant


WEBINAR: IT AUDIT, ENTERPRISE IT GOVERNANCE & RISK MANAGEMENT - Course Schedule

Day 1 - Wednesday 10 November, 2021
Opening Session (10:40 To 11:00)

Opening Remarks  & Introduction

Session One (11:00 AM To 1:00 PM)

IT Governance

  • Understand IT Governance
  • How Digital Transformation is Impacting Governance
  • Understand audit’s role in supporting IT Governance
  • Develop and analyze a risk management program
  • Identify Information Security roles and responsibilities

IT Governance Frameworks: the case of COBIT 2019
IT Resource Planning & Optimization
IT Benefits Realization
Quiz

Break
Session Two (01:20 PM To 03:20 PM)

IT Audit and Assurance Standards

  • IT Audit Framework
  • External Standards & Frameworks
  • Privacy & Regulatory Compliance

IT Systems Development Life Cycle

  • Identify and determine controls around a project management plan
  • Understand traditional and modern SDLC approaches to business application development
  • DevOps and DevSecOps
  • Continuous Development & Continuous Integration (CI/CD)
  • Understand key risks and controls relevant to application development

IT General Controls: Logical Security

  • Identity and Access Management
  • User Behaviour Analytics
  • Privileged Account Management
  • Multi Factor Authentication

IT General Controls: Resiliency

  • Business Continuity Planning (BCP)
  • Disaster Recovery (DR)

Quiz

End of Day Group Interactive Discussion
Day 2 - Thursday 11 November, 2021
Session One (11:00 AM To 01:00 PM)

IT Risk Management

  • Overview of Enterprise Risk Management
  • Principles of IT Risk Management
  • Frameworks & Standards
  • Develop and analyze a risk management program
  • Responsibilities and Accountability for IT Risk

IT Risk Identification

  • Collect event data, monitor risk and report exposures and opportunities
  • Understand organizational risks and how to mitigate them to provide assurance

IT Risk Assessment

  • Develop a risk assessment process and related mitigation strategies
  • Develop an audit or internal assessment plan

Risk Response and Mitigation

  • Risk Response Strategies
  • A consultative approach to developing effective risk response
  • Selection of appropriate, effective controls
  • Case Study

Quiz

Break
Session Two (01:20 PM To 03:20 PM)

End of day whiteboard working session
This will be a practical, interactive group exercise on “Planning and Executing a Risk - based IT General Controls Review” for a typical enterprise. The following tasks will be carried out:

  • Perform a Risk Assessment
  • Determining the Audit Scope
  • Testing IT General Controls on a sample web application using technical tools such as Nmap, Metasploit and Mimikatz
  • Documenting findings
Cumulative Exams
Course Program
Time Topic
Day 1
10:40 to 11:00Registration & Introduction
Day 1-2
11:00 to 13:00Session One
13:00 to 13:20Break
13:20 to 15:20Session Two
15:20 to 16:00End of Day Group Interactive Discussion