IT Governance, Risk, and Compliance:

Control Environment


May 11, 2012  10:37 PM

What Every IT Manager Should Know About Service Delivery and Support – Part III



Posted by: Robert Davis
COBIT, Control Environment, Ethics, Infrastructure, Integrity, ISO, ITSM, Service Delivery, Systems, Yahoo

For most individuals, integrity values are a personal issue that should reflect organizationally enforced edicts. Within an entity’s control environment, managerial integrity should represent “the quality or state of being of sound moral principles.” Specifically,...

May 8, 2012  10:10 PM

What Every IT Manager Should Know About Service Delivery and Support – Part II



Posted by: Robert Davis
COBIT, Control Environment, Infrastructure, ISO, ITSM, Service Delivery, Systems

Contributing foundational control environment factors are values and attitudes. Values and attitudes represent a view of what is desirable or undesirable behavior. Behavior refers to “the way one acts,” especially to actions that can be observed. Circularly, individual and group behavior is...


May 4, 2012  11:35 PM

What Every IT Manager Should Know About Service Delivery and Support – Part I



Posted by: Robert Davis
COBIT, Control Environment, Control Techniques, Infrastructure, ISO, ITSM, Service Delivery, Service Support, Systems

The control environment is an important component of an entity’s control structure or system that directly impacts IT governance. Literally, an entity’s control environment sets the “


October 11, 2011  7:51 PM

Auditing Information Security Governance – Part VI



Posted by: Robert Davis
Certified Information Systems Auditor, Certified Information Technology Professional, Certified Internal Auditor, Certified Internal Controls Auditor, Certified Public Accountant, COBIT, Control Environment, External Audit, Information Security Governance, Internal Audit, ISG, IT Audit

Primary drivers for ISG assurance planning is the verification of governance existence, adequacy, and risk management. However, as with standard IT audits, a general control environment, information systems, and control procedures understanding should be obtained during engagement planning to...


September 20, 2011  8:33 PM

Common Risk Determinants for an IT Architecture – Part VIII



Posted by: Robert Davis
COBIT, Control Environment, IT Architecture, Project Management, Risk Management, Risk Mitigation, Risk Tolerance

At the departmental-level, value delivery risks are generally an inducement for the entity’s executive management to designate an IT managerial group (e.g. IT Portfolio Management Committee) or individual (e.g. Chief Information Officer) to oversee


September 16, 2011  9:24 PM

Common Risk Determinants for an IT Architecture – Part VII



Posted by: Robert Davis
COBIT, Control Environment, IT Architecture, Project Management, Risk Management, Risk Mitigation, Risk Tolerance

As a logical assumption, IT project management is a primary governance point for the entity’s ITG program. Therefore, derivatively, management’s CE due diligence regarding IT project governance policies will significantly reduce systems and infrastructure life cycle risks. At the...


September 13, 2011  8:56 PM

Common Risk Determinants for an IT Architecture – Part VI



Posted by: Robert Davis
Audit Oversight Committee, COBIT, Control Environment, Due Diligence, IT Architecture, Project Management, Risk Management, Risk Mitigation, Risk Tolerance

An entity's oversight committee should provide internal and external controls due diligence. In this regard, entity oversight committees normally delegate responsibility, accountability, and authority to an audit oversight committee that: evaluates project controls, interfaces...


September 9, 2011  8:31 PM

Common Risk Determinants for an IT Architecture – Part V



Posted by: Robert Davis
COBIT, Control Environment, IT Architecture, Project Management, Risk Management, Risk Mitigation, Risk Tolerance

IT project governance can only be effective if those influencing project decisions are adequately informed. Project management policies, procedures, rules, and individual responsibilities should be distributed to all affected parties. Furthermore, the risk awareness program...


September 6, 2011  7:35 PM

Common Risk Determinants for an IT Architecture – Part IV



Posted by: Robert Davis
COBIT, Control Environment, IT Architecture, Project Management, Risk Management, Risk Mitigation, Risk Tolerance

Fundamentally, IT policies and procedures should be deployed based on assessed effectiveness and efficiency in addressing managements’ risk appetite. Supporting CE


September 2, 2011  9:23 PM

Common Risk Determinants for an IT Architecture – Part III



Posted by: Robert Davis
COBIT, Control Environment, IT Architecture, ITG, Project Management

Controlled environments provide a structured method for effective IT project management. Partially reflecting the COBIT framework; systems and infrastructure delivered to the core business processes through procurement...