IT Governance and Risk for the Non-IT Professional
Although Governance is a key corporate issue, discussion of IT Governance is often restricted to those with a strong IT background. The content of this course is pitched at those who are less familiar with technology but nevertheless have to make a contribution to the subject.
This course has been revised for 2009 and spends a significant amount of time examining the latest standards and guidance.
Suitability and duration
Suitability: Beginner
Duration: 2 days
Who should attend
Anyone who wishes to extend their knowledge into the field of IT Governance or anyone that needs to obtain a balanced overview of this subject in order to make a contribution to the Governance and Risk debate. This course does not require an IT background and is suitable for those that spend little time working with technology.
Benefits
Skills
After completion of this course, you will be able to:
- Understand how IT facilitates the delivery of organisational objectives
- Understand the structures and standards underpinning IT Governance
- Understand the boundaries imposed on information technology by UK law
- Understand the key risks involved in the arrangements for and support of IT services, software developments and how these can be managed
- Understand the major security related risks that occur in the delivery of IT services and how these can be reduced
Support Materials
This course is accompanied by a detailed manual that contains examples, explanations and reference materials to form a useful personal resource when you return to work.
Programme
IT Governance
- Connecting IT with the objectives of the organisation
- Dependence on IT for meeting the organisation’s objectives
- IT Governance and Governance at large – why pick on IT?
- How the Board and Management should address the challenge of IT Governance
Governance structures and standards
- ISO/IEC 38500:2008 – a new standard for the Corporate Governance of Information Communications and Technology
- COBIT, VAL-IT – established frameworks for control and value
- ITIL, ISO 20000– frameworks and standards for IT Operations
- ISO:27000; GTAG – standards and advisories on IT Security
IT and the law
- Data Protection Act / Freedom of Information Act
- Regulation of Investigatory Powers Act
- Surveillance and monitoring at work via electronic means
- Computer Misuse Act
- Other applicable legislation
IT performance risks
- Third party managed services, partnerships and outsourcing risks
- Service delivery and support best practices
- Contingency, disaster and business resumption planning
IT development risks
- IT Project Lifecycles – project risk; project management standards
- Software Lifecycles – software development risk; software development standards
IT security risks
- IT Security Policies and their role in enforcing good governance
- Secure and insecure systems – everyday security problems and common sense solutions
Integrating IT into the audit mix
- IT Auditing roles in support of the organisations governance activities
Course designed, developed and presented by MindGrove.