Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is...

17
Hussam Khattab MBA, CISA, CGEIT, PMP, COBIT2019 President, ISACA Amman Chapter

Transcript of Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is...

Page 1: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Hussam KhattabMBA, CISA, CGEIT, PMP, COBIT2019

President, ISACA Amman Chapter

Page 2: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Internal Audit “Internal Auditing is an independent, objective assurance and

consulting activity designed to add value and improve an organization’s operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management,

control and governance processes”

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 2

Page 3: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Internal Audit • Promotes organizational improvement• Provides risk-based assurance• Aligns with the strategies, objectives and risks of the

organization• Proactive and future-focused• Communicates effectively

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 3

Page 4: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

In middle of cybersecurity incidents and risks,

Where Should Internal Audit Stand?

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 4

Page 5: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Starts from the Top:• Have a cybersecurity expertise on the Board• Make cybersecurity a constant Board agenda item• Define & establish a cybersecurity roadmap• Regularly review cybersecurity strategies for effectiveness• Monitor & evaluate

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 5

Page 6: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Internal Audit • Understand the business crown jewels – Key processes and

products.• Understand the underlying IT environment.• Assess the current risks.• Identify threats and vulnerabilities

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 6

Page 7: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Key Questions: • Is cybersecurity on the current, previous and future audit

plans?• How frequently do we audit cybersecurity?• Does Internal Audit have cybersecurity audit skills?• Are cybersecurity issues communicated in business language?

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 7

Page 8: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value
Page 9: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Reference:NIST Cybersecurity V1.1

Page 10: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value
Page 11: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Reference:www.isaca.org

Page 12: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value
Page 13: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value
Page 14: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Areas to Assess: • Penetration testing & vulnerability assessment; frequency,

remediation & reporting• Effectiveness of patch management procedures• Review for critical security systems configurations• Review for end points controls• Training & awareness program

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 14

Page 15: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

Areas to Assess: • Access controls; logical & physical• Third party management• Detection capabilities• Business Continuity planning & disaster recovery• Data backup arrangements• Incident Response planning

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 15

Page 16: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value

“Internal Auditors are Partners of Management”

Cybersecurity and resilience Symposium - Amman- Jordan, 15-17 October 2019 16

Page 17: Hussam Khattab - icao.int · President, ISACA Amman Chapter. Internal Audit “Internal Auditing is an independent, objective assurance and consulting activity designed to add value