Name
Strayer University
IT Governance and Compliance Assessment
CIS 349 - Information Technology Audit and Control
Task Title: IT Governance and Compliance Assessment
Assignment Instructions:
You are tasked with conducting an IT governance and compliance assessment for a large
multinational corporation. This corporation operates in various regions and industries and relies
heavily on its IT infrastructure to support its operations.
Organization Selection: Choose the multinational corporation for your audit. Explain why you
selected this organization and provide a brief overview of its global operations and the
complexity of its IT infrastructure.
1. Audit Objectives: Outline the primary objectives of the IT governance and compliance
assessment. What are the key goals you aim to achieve with this audit? Consider factors
like IT governance effectiveness, compliance with industry regulations, and risk
management.
2. Regulations and Standards: Identify and explain the specific industry regulations,
international standards, and corporate governance frameworks applicable to the
organization. Describe how non-compliance with these standards can impact the
company's global operations.
3. Audit Scope: Specify the areas within the organization's IT infrastructure that will be
included in the audit (e.g., corporate policies, IT governance structure, data management
practices). Will the audit cover both on-premises and cloud-based elements?
4. Audit Team and Resources: Define the roles and responsibilities of the audit team
members. What qualifications and expertise should team members possess? Outline the
resources, tools, and software required for the audit.
5. IT Governance Assessment: Explain the methodologies or frameworks you will use to
assess the effectiveness of IT governance within the organization. What are the key
aspects to be evaluated, such as IT strategy alignment with business goals and board
oversight?
6. Compliance Assessment: Describe the audit procedures and methodologies that will be
employed to assess compliance with relevant regulations and standards. How will you
gather evidence and documentation during the audit?
7. Risk Management: Assess the organization's risk management practices, including
identification, assessment, and mitigation. Provide recommendations for improving the
company's risk management framework.
8. Data Management and Privacy: Evaluate the organization's data management practices
and compliance with data protection and privacy regulations (e.g., GDPR). What
measures and policies will be assessed, and what recommendations will be provided?
9. Documentation Standards: Explain the standards for documenting audit findings,
compliance status, and identified governance and compliance risks. Include examples of
documentation templates if applicable.
10. Storage of Audit Documentation: Outline where and how all audit documentation and
evidence will be securely stored for future reference, including backup copies.
Write clearly and concisely about topics related to information technology audit and control
using proper writing mechanics and technical style conventions.
Click=here=to view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 200 IT Governance and Compliance Assessment
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectation
s
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Define the
following items for
an organization
you are familiar
with: a) Scope;
b)Goals and
objectives;
c)Frequency of the
audit; d) Duration
of the audit.
Weight: 5%
Did not
submit or
incompletely
defined the
following
items for an
organization
you are
familiar with:
a) Scope; b)
Goals and
objectives; c)
Frequency of
the audit; d)
Duration of
the audit.
Insufficientl
y defined
the
following
items for an
organization
you are
familiar
with: a)
Scope; b)
Goals and
objectives;
c)
Frequency
of the audit;
d) Duration
of the audit.
Partially
defined the
following
items for an
organization
you are
familiar
with: a)
Scope; b)
Goals and
objectives;
c) Frequency
of the audit;
d) Duration
of the audit.
Satisfactoril
y defined
the
following
items for an
organization
you are
familiar
with: a)
Scope; b)
Goals and