Current Projects 

 

Audit/Assurance Programs

ISACA is currently updating the audit/assurance programs for COBIT 5. The first group of programs released was a series of programs for the COBIT 5 processes, based on the generic structure developed in the COBIT 5 for Assurance publication. The new audit/assurance programs are fully aligned with COBIT 5, and explicitly reference all seven enablers. The next group of programs below has been released.

This set of new audit/assurance programs and ICQs complements the book Security, Audit and Control Features SAP® ERP, 4th Edition. The set includes:

  • SAP ERP Revenue Business Cycle Audit/Assurance Program and ICQ
  • SAP ERP Expenditure Business Cycle Audit/Assurance Program and ICQ
  • SAP ERP Inventory Business Cycle Audit/Assurance Program and ICQ
  • SAP ERP Financial Accounting (FI) Audit/Assurance Program and ICQ
  • SAP ERP Managerial Accounting (CO) Audit/Assurance Program and ICQ
  • SAP ERP Human Capital Management Cycle Audit/Assurance Program and ICQ
  • SAP ERP BASIS Administration and Security Audit/Assurance Program and ICQ
  • SAP ERP Control Environment ICQ
  • Blank Audit/Assurance Program Template

View Programs >>


COBIT 5 for Business Benefits Realisation

ISACA is writing the COBIT 5 for Business Benefits Realisation professional guide, which will support and enhance the COBIT 5 family of products by focusing on governance and management dimensions of business benefits realisation and providing contextualized guidance for consultants, experts in governance, business management, IT professionals and other interested parties at all levels of the enterprise. Business benefits realisation is a requirement from stakeholders and governance bodies to ensure that IT-business activity achieves the benefits that are envisioned when key investment decisions are made. The COBIT 5 framework helps enterprises to create optimal value from information technology by maintaining a balance between realising benefits and optimising risk levels and resource use.


Critical Cyber Event Governance and Management: Board and Executive Guidance

This white paper will discuss the need for governance over critical cyber events as a necessary component of risk management, and will outline the benefits in terms of business reputation and incident cost reduction that result when cyber event management is effectively planned for.


Operational Risk Management/Basel Using COBIT 5

This will provide an update of the existing publication “IT Control Objectives Basel II” to align it with COBIT 5 and related publications. Concepts will be updated to reflect the current state of the technology, challenges, risk and necessary assurance practices. Publication is on hold pending the release of the updated COSO Enterprise Risk Management — Integrated Framework.


Privacy Principles and Program Management Guidance

This publication will offer uniform privacy guidance based on COBIT 5, including guidance on planning, implementing, and maintaining a comprehensive privacy program in an enterprise. The publication is scheduled to be available in the first quarter of 2016.