18.01.2013 Views

Enabling Processes

Enabling Processes

Enabling Processes

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Monitor, Evaluate and Assess<br />

210<br />

: ENABLING PROCESSES<br />

MEA02 Process Practices, Inputs/Outputs and Activities (cont.)<br />

Management Practice Inputs Outputs<br />

MEA02.04 Identify and report control deficiencies.<br />

Identify control deficiencies and analyse and identify<br />

their underlying root causes. Escalate control<br />

deficiencies and report to stakeholders.<br />

From Description Description To<br />

APO11.05 Root causes of quality<br />

delivery failures<br />

APO12.06 Risk-related root causes<br />

DSS06.01 � ���� ����� �������� ���<br />

recommendations<br />

� ������� �� ����������<br />

effectiveness reviews<br />

DSS06.04 Evidence of error<br />

correction and remediation<br />

Activities<br />

Control deficiencies All APO<br />

All BAI<br />

All DSS<br />

All MEA<br />

Remedial actions All APO<br />

All BAI<br />

All DSS<br />

All MEA<br />

1. Identify, report and log control exceptions, and assign responsibility for resolving them and reporting on the status.<br />

2. Consider related enterprise risk to establish thresholds for escalation of control exceptions and breakdowns.<br />

3. Communicate procedures for escalation of control exceptions, root cause analysis, and reporting to process owners and IT stakeholders.<br />

4. Decide which control exceptions should be communicated to the individual responsible for the function and which exceptions should be escalated.<br />

Inform affected process owners and stakeholders.<br />

5. Follow up on all exceptions to ensure that agreed-on actions have been addressed.<br />

6. Identify, initiate, track and implement remedial actions arising from control assessments and reporting.<br />

Management Practice Inputs Outputs<br />

From Description Description To<br />

MEA02.05 Ensure that assurance providers are<br />

Results of assurance Internal<br />

independent and qualified.<br />

Ensure that the entities performing assurance are<br />

independent from the function, groups or organisations<br />

in scope. The entities performing assurance should<br />

demonstrate an appropriate attitude and appearance,<br />

competence in the skills and knowledge necessary to<br />

perform assurance, and adherence to codes of ethics<br />

and professional standards.<br />

provider evaluations<br />

Activities<br />

1. Establish adherence to applicable codes of ethics and standards (e.g., Code of Professional Ethics of ISACA) and (industry- and geography-specific)<br />

��������� ���������� ����� �� ����� ��� ��������� ��������� �� ����� ��� ��� ������������� �������� ��� ��������� ��������� ������� ���������<br />

International Framework for Assurance Engagements (IAASB Assurance Framework).<br />

2. Establish independence of assurance providers.<br />

3. Establish competency and qualification of assurance providers.<br />

Management Practice Inputs Outputs<br />

MEA02.06 Plan assurance initiatives.<br />

From Description Description To<br />

���� ��������� ����������� ����� �� ���������� ����������<br />

and strategic priorities, inherent risk, resource<br />

BAI01.05 Programme audit plans High-level assessments Internal<br />

constraints, and sufficient knowledge of the enterprise. DSS01.02 Independent assurance Assurance plans EDM01.03<br />

plans<br />

All APO<br />

All BAI<br />

All DSS<br />

All MEA<br />

Activities<br />

Assessment criteria Internal<br />

�� ��������� ��� �������� ����� �� ��� ��������� ���������� ������ ��� ��� ������ �� ��� �������<br />

�� ������� � ���������� ���� ���������� ������ ���������� �� ������� ���������� �� �������� ���� ��� �������� �������� �� ����������<br />

�� ������� ��������� ��� ����� ��������� �� ��� ������� ���������� ��� �������� ��������� ���� ���� �� ��� ����� ��� ��� ������� �����������<br />

Personal Copy of: Mr. Dong Hong Wang

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!