SlideShare a Scribd company logo
British Columbia Auditor General audit
of Maturity of Computing Controls…
Strong general computing controls are government’s first
line of defence against potential threats.
The Auditor General looked at how good government’s
general computing controls were, and how good 148
agencies thought they were.
FEBRUARY 2016
The current COBIT 4.1 maturity model worked
superbly for this audit of IT management
systems.
The AG recommended that BC government
adopt a target maturity level of 3.
This means that each perspective of the
management system is defined and staff are
trained.
WHAT DOES IT SAY.
FEBRUARY 2016
Self-assessments were generally optimistic. No
surprises.
Most agencies rated themselves at a maturity level
of 3 or above. Central agencies and health sector
agencies rated themselves well into the 4s and 5s.
The AG found that 69% of the validated agencies
overstated their maturity level.
WHAT ELSE DOES IT SAY.
FEBRUARY 2016
The audit identified more than 600 outsourced
IT projects, which raises the importance of
general computing controls.
This raises the risks of: fraud, human error and
down-time.
I didn’t see analysis of instances where
outsourcing has led to higher maturity levels,
and lower risks.
WHAT ELSE DOES IT SAY.
FEBRUARY 2016
• This report justifies general computing
controls better than most.
• Perhaps central agencies, and the health
sector, have gone beyond a cost-effective
optimum, self-assessing controls well
above maturity level of 3.
• Always seek to validate self-assessments
to gain more insight.
The comments on these slides are the views of Tim Kirby, Sydney.
You should always read the report itself before putting any money on the line.
WHAT DOES IT MEAN.
Tim Kirby, Sydney CA, CIA, LA-EMS
au.linkedin.com/in/timkirbysydney
FEBRUARY 2016

More Related Content

PPT
E gov versus corruption - test of indexes
PDF
The Sick State of Healthcare Data Breaches
PDF
IRJET- Crime Prediction System
PDF
Etude PwC "Crime Survey 2014" sur la fraude dans le secteur pharmaceutique (o...
PPT
Welcome in Czechoslovakia. Any startups here?
PPTX
Measuring Web Content Readability & Consistency - with VisibleThread Clarity ...
PDF
Ret Barbosa
PDF
Content Maturity Model
E gov versus corruption - test of indexes
The Sick State of Healthcare Data Breaches
IRJET- Crime Prediction System
Etude PwC "Crime Survey 2014" sur la fraude dans le secteur pharmaceutique (o...
Welcome in Czechoslovakia. Any startups here?
Measuring Web Content Readability & Consistency - with VisibleThread Clarity ...
Ret Barbosa
Content Maturity Model

Viewers also liked (20)

PDF
Web2 journalsmanuscripteditingmuenning
PPTX
Best practices in website design
PDF
Measuring Marketing Governance Maturity
PPT
Sociální sítě - Workshop
PPT
The Case for a Web Audit: Your 360 Degree Performance Review
PDF
Data Governance Maturity Model Thesis
PDF
Best Practices for Structuring Your Web Content
PPT
WhiteHat Security Presentation
PPTX
Implementing the Four Pillars of the SharePoint Governance Maturity Model
PDF
Website Governance: Tips for Defining a Successful Strategy
DOC
Website Governance Document
PDF
Governance Maturity Assessment Report
PDF
A Practical Web Governance Framework
DOCX
Small business consultant performance appraisal
PDF
Content marketing maturity map & e-guide
PDF
Risk Management Maturity Model (RMMM)
PPTX
Web Governance: Where Strategy Meets Structure
PDF
Planning for Content Governance
PDF
Rethinking Website Design: Creating a Peak-Performing Website with Less Risk ...
PDF
It governance & cobit 5
Web2 journalsmanuscripteditingmuenning
Best practices in website design
Measuring Marketing Governance Maturity
Sociální sítě - Workshop
The Case for a Web Audit: Your 360 Degree Performance Review
Data Governance Maturity Model Thesis
Best Practices for Structuring Your Web Content
WhiteHat Security Presentation
Implementing the Four Pillars of the SharePoint Governance Maturity Model
Website Governance: Tips for Defining a Successful Strategy
Website Governance Document
Governance Maturity Assessment Report
A Practical Web Governance Framework
Small business consultant performance appraisal
Content marketing maturity map & e-guide
Risk Management Maturity Model (RMMM)
Web Governance: Where Strategy Meets Structure
Planning for Content Governance
Rethinking Website Design: Creating a Peak-Performing Website with Less Risk ...
It governance & cobit 5
Ad

Similar to BC OAG Maturity of Computer Controls in5slides (20)

DOCX
Student Name Brief #5 Use of Audit Software Review and Survey.docx
PPTX
T Kirby Presentation AES conference September 2016
PDF
Audit Committee
DOCX
Running head AN   EMPIRICAL STUDY ON ACCOUNTING AND AUDITING ENFO.docx
PPTX
VAGO access to Public Sector Info
PPT
Immigration Compliance and E-Verify for Federal contractors
PPTX
What The Heck Is CCM
PDF
SOX 2016 - PART I - COSO 2013
DOCX
1 2Cheat Sheet on Evidence and DocumentationACC491J.docx
PDF
Case Study Audit
PDF
N6.pdf
PDF
The effect of risk based audit approach on the implementation of internal co...
PDF
Grc sap next evaluation of internal audit
PDF
Cga Assignment Au1 Essay
PDF
Audit Report And Internal Control Evaluation
PDF
Solution Manual for Information Technology Auditing 3rd Edition by Hall
PDF
Pwc 2015 Technology Sector Sec Comment Letter Trends
DOCX
Acc 490 final exam
PDF
QUALITY ASSESSMENT OF ACCESS SECURITY CONTROLS OVER FINANCIAL INFORMATION
PDF
QUALITY ASSESSMENT OF ACCESS SECURITY CONTROLS OVER FINANCIAL INFORMATION
Student Name Brief #5 Use of Audit Software Review and Survey.docx
T Kirby Presentation AES conference September 2016
Audit Committee
Running head AN   EMPIRICAL STUDY ON ACCOUNTING AND AUDITING ENFO.docx
VAGO access to Public Sector Info
Immigration Compliance and E-Verify for Federal contractors
What The Heck Is CCM
SOX 2016 - PART I - COSO 2013
1 2Cheat Sheet on Evidence and DocumentationACC491J.docx
Case Study Audit
N6.pdf
The effect of risk based audit approach on the implementation of internal co...
Grc sap next evaluation of internal audit
Cga Assignment Au1 Essay
Audit Report And Internal Control Evaluation
Solution Manual for Information Technology Auditing 3rd Edition by Hall
Pwc 2015 Technology Sector Sec Comment Letter Trends
Acc 490 final exam
QUALITY ASSESSMENT OF ACCESS SECURITY CONTROLS OVER FINANCIAL INFORMATION
QUALITY ASSESSMENT OF ACCESS SECURITY CONTROLS OVER FINANCIAL INFORMATION
Ad

More from Tim Kirby (20)

PDF
BC OAG Protection of Drinking Water Audit in5slides
PPTX
ARPA-E Evaluation 2017
PPTX
BC OAG Ethics Management in5slides
PPTX
OAGNZ Report on Governance
PPTX
OAGNZ Report on Governance
PPTX
Dairy NZ Water Accord Report 2016
PPT
What others are saying about environmental accounting AIEA Conference Novembe...
PPTX
What auditors are saying about evaluation AES Conference September 2015
PPTX
Warming up to environmental regulation risk SOPAC March 2016
PPTX
UK NAO report on Sellafield in5slides
PPTX
US GAO Environmental Regulation Decision making
PPTX
Nsw Report on Native Vegetation 2011 13 in5slides
PDF
ASAE 3610 in5slides
PPTX
ANAO performance audit of the Strengthening Basin Communities in5slides
PPTX
IPCC Report on the Physical Science Basis for Climate Change in5slides
PPTX
OAG WA Audit Report on Pest Management in5slides
PPTX
Australian Govt Environmental Information Requirements in5slides
PPTX
CSEAR Silent and Shadow reporting in5slides
PPTX
OAGNZ Biosecurity Performance Audit in5slides
PPT
IPPF Practice Guide in5slides
BC OAG Protection of Drinking Water Audit in5slides
ARPA-E Evaluation 2017
BC OAG Ethics Management in5slides
OAGNZ Report on Governance
OAGNZ Report on Governance
Dairy NZ Water Accord Report 2016
What others are saying about environmental accounting AIEA Conference Novembe...
What auditors are saying about evaluation AES Conference September 2015
Warming up to environmental regulation risk SOPAC March 2016
UK NAO report on Sellafield in5slides
US GAO Environmental Regulation Decision making
Nsw Report on Native Vegetation 2011 13 in5slides
ASAE 3610 in5slides
ANAO performance audit of the Strengthening Basin Communities in5slides
IPCC Report on the Physical Science Basis for Climate Change in5slides
OAG WA Audit Report on Pest Management in5slides
Australian Govt Environmental Information Requirements in5slides
CSEAR Silent and Shadow reporting in5slides
OAGNZ Biosecurity Performance Audit in5slides
IPPF Practice Guide in5slides

Recently uploaded (20)

PPTX
Vocational Education for educational purposes
PDF
2026 RMHC Terms & Conditions agreement - updated 8.1.25.pdf
PPTX
AMO Pune Complete information and work profile
PDF
मुख्यमंत्राी सामूहिक विवाह कार्यक्रम, जनपद बाँदा
PPTX
GOVERNMENT-ACCOUNTING1. bsa 4 government accounting
PDF
Contributi dei parlamentari del PD - Contributi L. 3/2019
PDF
Item # 3 - 934 Patterson Final Review.pdf
PDF
The Role of FPOs in Advancing Rural Agriculture in India
PPTX
Weekly Report 17-10-2024_cybersecutity.pptx
PPT
generalgeologygroundwaterchapt11-181117073208.ppt
PPTX
STG - Sarikei 2025 Coordination Meeting.pptx
PDF
Item # 2 - 934 Patterson Specific Use Permit (SUP)
PPTX
Nur Shakila Assesmentlwemkf;m;mwee f.pptx
PPTX
Omnibus rules on leave administration.pptx
PPTX
Quiz - Saturday.pptxaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
PDF
ISO-9001-2015-gap-analysis-checklist-sample.pdf
PPTX
DFARS Part 249 - Termination Of Contracts
PDF
PPT Item #s 2&3 - 934 Patterson SUP & Final Review
PPTX
怎么办休斯敦大学维多利亚分校毕业证电子版成绩单办理|UHV在读证明信
PDF
Courtesy Meeting NIPA and MBS Australia.
Vocational Education for educational purposes
2026 RMHC Terms & Conditions agreement - updated 8.1.25.pdf
AMO Pune Complete information and work profile
मुख्यमंत्राी सामूहिक विवाह कार्यक्रम, जनपद बाँदा
GOVERNMENT-ACCOUNTING1. bsa 4 government accounting
Contributi dei parlamentari del PD - Contributi L. 3/2019
Item # 3 - 934 Patterson Final Review.pdf
The Role of FPOs in Advancing Rural Agriculture in India
Weekly Report 17-10-2024_cybersecutity.pptx
generalgeologygroundwaterchapt11-181117073208.ppt
STG - Sarikei 2025 Coordination Meeting.pptx
Item # 2 - 934 Patterson Specific Use Permit (SUP)
Nur Shakila Assesmentlwemkf;m;mwee f.pptx
Omnibus rules on leave administration.pptx
Quiz - Saturday.pptxaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
ISO-9001-2015-gap-analysis-checklist-sample.pdf
DFARS Part 249 - Termination Of Contracts
PPT Item #s 2&3 - 934 Patterson SUP & Final Review
怎么办休斯敦大学维多利亚分校毕业证电子版成绩单办理|UHV在读证明信
Courtesy Meeting NIPA and MBS Australia.

BC OAG Maturity of Computer Controls in5slides

  • 1. British Columbia Auditor General audit of Maturity of Computing Controls… Strong general computing controls are government’s first line of defence against potential threats. The Auditor General looked at how good government’s general computing controls were, and how good 148 agencies thought they were. FEBRUARY 2016
  • 2. The current COBIT 4.1 maturity model worked superbly for this audit of IT management systems. The AG recommended that BC government adopt a target maturity level of 3. This means that each perspective of the management system is defined and staff are trained. WHAT DOES IT SAY. FEBRUARY 2016
  • 3. Self-assessments were generally optimistic. No surprises. Most agencies rated themselves at a maturity level of 3 or above. Central agencies and health sector agencies rated themselves well into the 4s and 5s. The AG found that 69% of the validated agencies overstated their maturity level. WHAT ELSE DOES IT SAY. FEBRUARY 2016
  • 4. The audit identified more than 600 outsourced IT projects, which raises the importance of general computing controls. This raises the risks of: fraud, human error and down-time. I didn’t see analysis of instances where outsourcing has led to higher maturity levels, and lower risks. WHAT ELSE DOES IT SAY. FEBRUARY 2016
  • 5. • This report justifies general computing controls better than most. • Perhaps central agencies, and the health sector, have gone beyond a cost-effective optimum, self-assessing controls well above maturity level of 3. • Always seek to validate self-assessments to gain more insight. The comments on these slides are the views of Tim Kirby, Sydney. You should always read the report itself before putting any money on the line. WHAT DOES IT MEAN. Tim Kirby, Sydney CA, CIA, LA-EMS au.linkedin.com/in/timkirbysydney FEBRUARY 2016