UNIVERSITY OF VIRGINIA BOARD OF VISITORS MEETING OF THE AUDIT, COMPLIANCE, AND RISK COMMITTEE DECEMBER 9, 2016

Size: px
Start display at page:

Download "UNIVERSITY OF VIRGINIA BOARD OF VISITORS MEETING OF THE AUDIT, COMPLIANCE, AND RISK COMMITTEE DECEMBER 9, 2016"

Transcription

1 UNIVERSITY OF VIRGINIA BOARD OF VISITORS MEETING OF THE AUDIT, COMPLIANCE, AND RISK COMMITTEE DECEMBER 9, 2016

2 AUDIT, COMPLIANCE, AND RISK COMMITTEE (Open Session) Friday, December 9, :45-1:45 p.m. Board Room, The Rotunda Committee Members: Frank E. Genovese, Chair Mark T. Bowles L. D. Britt, M.D. Frank M. Conner III Babur B. Lateef, M.D. James B. Murray Jr. William H. Goodwin Jr., Ex-officio Adelaide Wilcox King, Faculty Consulting Member AGENDA PAGE I. REMARKS BY THE COMMITTEE CHAIR (Mr. Genovese) 1 II. DISCUSSION A. Auditor of Public Accounts Audit and Management Report 2 (Ms. Melody Bianchetto, VP Finance, to introduce Mr. Eric Sandridge, Director of Higher Education Programs, Auditor of Public Accounts; Mr. Sandridge to report) B. Audit Department Report (Mr. Genovese to introduce Ms. Carolyn D. Saint; Ms. Saint to report) Summary of Audit Reports, Departmental Activities, 3 and Plan Status C. University Compliance (Mr. Genovese to introduce Mr. Gary S. Nimax; Mr. Nimax to report) Report on Medical Center Compliance and Privacy 8 Officer Search D. Enterprise Risk Management (ERM) Report (Mr. Genovese 9 to introduce Mr. James S. Matteo; Mr. Matteo to report) III. CLOSED SESSION Discussion of IT security matters as provided for in (A)(19) of the Code of Virginia.

3 UNIVERSITY OF VIRGINIA BOARD OF VISITORS AGENDA ITEM SUMMARY BOARD MEETING: December 9, 2016 COMMITTEE: AGENDA ITEM: ACTION REQUIRED: Audit, Compliance, and Risk I. Remarks by the Committee Chair None BACKGROUND: Mr. Frank Genovese, the Committee Chair, will open the meeting and provide an overview of the agenda. 1

4 UNIVERSITY OF VIRGINIA BOARD OF VISITORS AGENDA ITEM SUMMARY BOARD MEETING: December 9, 2016 COMMITTEE: AGENDA ITEM: ACTION REQUIRED: Audit, Compliance, and Risk II.A. Auditor of Public Accounts Audit and Management Report None BACKGROUND AND DISCUSSION: The Auditor of Public Accounts of the Commonwealth conducts an annual audit of the University and the Medical Center and reports findings to the Board. Ms. Bianchetto will introduce Mr. Eric M. Sandridge, who will report on findings for the fiscal year audit. Mr. Sandridge is the Director of Higher Education Programs for the Virginia Auditor of Public Accounts and has served in that position since His responsibilities include management of the office s Higher Education Programs Specialty Team and project management oversight for audits of various agencies and institutions of the Commonwealth. Mr. Sandridge has served as audit director for the Virginia Community College System, Old Dominion University, Virginia Commonwealth University, Norfolk State University, University of Virginia, and the Department of Alcoholic Beverage Control annual audits. Mr. Sandridge also coordinates required federal audits at the Commonwealth s institutions of higher education, which support Virginia s statewide Single Audit report. He received his B.B.A. in Finance from the College of William and Mary and is a Certified Public Accountant and a Certified Government Financial Manager. 2

5 UNIVERSITY OF VIRGINIA BOARD OF VISITORS AGENDA ITEM SUMMARY BOARD MEETING: December 9, 2016 COMMITTEE: AGENDA ITEM: ACTION REQUIRED: Audit, Compliance, and Risk II.B. Audit Department Report: Summary of Audit Reports, Departmental Activities, and Plan Status None DISCUSSION: For purposes of supporting the Committee s oversight of the Audit Department, Ms. Carolyn Devine Saint, Chief Audit Executive, will summarize the Audit Department s activities for FY 2017 year to date. 3

6 Assurance and Advisory Projects: Completed FY 2017 To Date Subject Curry School of Education Darden Fund Transfers Distributed IT Systems Current State Assessment FY2016 Inventories (UVA Bookstore, Pharmacy) Action Plan Implementation Status Follow Ups Epic Phase 2 Implementation Project Health Check (2 nd Report) Integrated Assurance: Athletics Compliance Security Enhancement Plan (SecureUVA) Project Health Check (1 st report) Subject Epic 1 Phase 2 Implementation Project Health Check w/clinical Readiness and Database Security Areas of Focus IT System Security: Privileged Access Fiscal Stewardship (Data-driven Internal Controls Analytics): Focus on Research Compliance Integrated Assurance Athletics (NCAA) Compliance Assessment NCAA Football Attendance Certification Security Enhancement Plan (SecureUVA) Project Health Check continues SCADA 2 Consultation continues Ufirst (HR Transformation) Project Health Check Office of the President: Travel and Expenses Ivy Cloud 3 Project Health Check w/ Security and Governance Focus Subject Report to BOV ACR Committee: December 2016 Audit Department Plan Status UVA Division, Health System, Health System Health System Assurance and Advisory Projects: In Progress 4 UVA Division Health System Health System Pan-University Pan-University Pan-University Current View of Risk- Prioritized Future Projects (Remainder of FY17) 340B Drug Discount Program Epic Phase 2 Implementation Project Health Check Continues through Implementation (6/30/17) UVA Division Health System Health System 1 Epic is UVA Health System s Electronic Medical Records system. Phase 2 implements Epic s scheduling and revenue cycle modules, and certain clinical modules. 2 SCADA=Supervisory Control and Data Access. SCADA is a system for remote monitoring and control that operates with coded signals over communication channels. 3 UVA Data Science Institute s cloud computing environment for highly sensitive, secure data for researchers

7 Current View of Risk- Prioritized Future Projects Cont d (Remainder of FY17) Subject UVA Division IT Change Controls Special Collections Library Procedures and Controls Integrated Assurance: Environmental Health & Safety Compliance Strategic Investment Fund Expenditures Monitoring UFirst HR Transformation Project Health Check Continues through Implementation Health System Pan-University Pan-University Pan-University 5

8 Audit Department Dashboards: Types of Audit Projects Performed Through November 30, % 13% 4% 4% 17% 33% Agreed Upon Procedures Audit Consultation Follow Ups Pilot Audit Project Health Check Action Plan Completion Status Through November 30, 2016 by Priority Rating Priority Priority Legacy (Unrated) 25 2 Closed Open Details of Open Priority 1 and 2 Action Plans: Priority 1 Action Plan 1: Financial Outreach and Compliance Department s reassessment of Internal Controls Questionnaire and review of significant fiscal processes and associated key controls has been pushed back until new University Comptroller is hired and on boarded. Due Date Extended Until Onboarding of New Comptroller. Priority 1 Action Plan 2: University Registrar s office is evaluating completeness and accuracy of all schools undergraduate and graudate requirements. Due Date to Complete the Review Extended Until 12/31/2016. Two Priority 2 Open Action Plans relate to administrative/fiscal matters in the Curry School s Sheila Johnson Center. A third Priority 2 Open Action Plan relates to a recommendation to ensure Curry School adopts consistent practices for requiring background checks for students in unpaid positions throughout the school, including those involving students interacting with minors as part of their core function. 6

9 Audit Department Value Scorecard: Data as of November 30, 2016 Measures People: Leadership & Relationship Acumen Internal Team Team Participation in Introduction to Transactional Competence (ITC) Program Target: 100% participation Year to Date Metric Achievement Status Training hours per audit in non-technical differentiator competencies Target: 20 Hours External Stakeholders Audit Satisfaction Scores Target: Above Average Developing Survey Tool Collaboration on Cross Functional Projects and Committees Target: 3/year People: Industry & Technical Competence CPE Hours Earned on Priority Skills Target: 20 Hours Certifications Held by Each Auditor Target: 1/auditor Active Participation in Professional Associations Target: 1/auditor Audit Process: Efficient & Effective Audit Process Staff Utilization Target: 80% 74% Individual audit project actual to budget hours variance Target: 10% or less Completion of Lean Project on Audit Processes Target: 1/year Costs contained/recovered and revenue enhancements identified ($); Target: Establish baseline in 2016/17 Plan: Relevance to Risks that Matter Most Audit resources dedicated to higher or emerging risk areas Target: 75% Recommendations Made Target: Establish baseline in 2016/2017 $0 to date 7

10 UNIVERSITY OF VIRGINIA BOARD OF VISITORS AGENDA ITEM SUMMARY BOARD MEETING: December 9, 2016 COMMITTEE: AGENDA ITEM: ACTION REQUIRED: Audit, Compliance, and Risk II.C. University Compliance: Report on Medical Center Compliance and Privacy Officer Search None DISCUSSION: Mr. Gary Nimax, Assistant Vice President for Compliance, will report on the search for the Medical Center s new Compliance and Privacy Officer. A national search is underway to fill the vacant position on a permanent basis. Mr. Nimax will provide a report on the status of the search and a timeline for completion. 8

11 UNIVERSITY OF VIRGINIA BOARD OF VISITORS AGENDA ITEM SUMMARY BOARD MEETING: December 9, 2016 COMMITTEE: AGENDA ITEM: ACTION REQUIRED: Audit, Compliance, and Risk II.D. Enterprise Risk Management (ERM) Report None BACKGROUND AND DISCUSSION: Mr. James Matteo, Associate Vice President and Treasurer, will report on actions taken toward accomplishing the three key priorities for the ERM program, as first identified at the Committee s February 2016 meeting. The effort consists of three near-term priorities designed to: (1) reposition and enrich the program; (2) enhance board reporting; and (3) onboard ERM at the Health System. The University has taken several significant steps to reposition the program including the adoption of an Enterprise Risk Management Charter and the establishment of a network of individuals to advance risk management efforts at the Division and Health System. A Risk Management Council was formed to provide guidance in support of the global ERM effort and Risk Management Networks, comprised of representatives from major business units, in both the Division and Health System. These networks help identify inherent and emerging risks, serve as a connection between executive-level and department risk management activities, and seek to raise risk awareness among units across the University. At the Division, we have completed a risk identification effort designed to gather risks and update the University s existing risk list. From the risks identified, we worked with executive leadership to create a new key risk list for the Division. We will report on the Division s key risks using an updated risk reporting format. Reporting will be presented in two parts: 1) a key risk dashboard to provide a high-level risk overview; and 2) a key risk update intended to provide a more detailed discussion on a key risk or risks. At this meeting, we will present a key risk update on the SecureUVA program designed to enhance information technology security for the Division. 9

12 Additionally, significant progress has been made to onboard the Health System. We have completed the risk identification effort for the Health System and are working with executive leadership to finalize the Health System s key risk list. 10

Board of Visitors Audit, Compliance, and Risk Committee September 16, 2016

Board of Visitors Audit, Compliance, and Risk Committee September 16, 2016 Board of Visitors Audit, Compliance, and Risk Committee September 16, 2016 1 Audit Department Activities 2 September 2016 Audit Department Status Assurance and Advisory Projects: Completed FY 2017 To Date

More information

UNIVERSITY OF VIRGINIA BOARD OF VISITORS. Meeting of the Audit, Compliance, and Risk Committee

UNIVERSITY OF VIRGINIA BOARD OF VISITORS. Meeting of the Audit, Compliance, and Risk Committee UNIVERSITY OF VIRGINIA BOARD OF VISITORS Meeting of the Audit, Compliance, and Risk Committee March 1, 2018 AUDIT, COMPLIANCE, AND RISK COMMITTEE Thursday, March 1, 2018 10:45 11:30 a.m. Upper West Oval

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel and Corporate

More information

NERC Staff Organization Chart Budget 2019

NERC Staff Organization Chart Budget 2019 NERC Staff Organization Chart Budget 2019 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Officer Senior Vice President, General Counsel and Corporate

More information

NERC Staff Organization Chart Budget 2018

NERC Staff Organization Chart Budget 2018 NERC Staff Organization Chart Budget 2018 President and CEO Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel and Corporate

More information

2018 Government Professional Accounting Seminar

2018 Government Professional Accounting Seminar 2018 Government Professional Accounting Seminar Thursday September 6, 2018 7:30 a.m. - Registration and Networking 8:00 a.m. 4:50 p.m. (Early Registration by Tuesday, July 31, 2018; Regular by Friday,

More information

Memorandum of Understanding between the Central LHIN and the Toronto Central LHIN to establish a Joint ehealth Program

Memorandum of Understanding between the Central LHIN and the Toronto Central LHIN to establish a Joint ehealth Program Memorandum of Understanding between the Central LHIN and the Toronto Central LHIN to establish a Joint ehealth Program Purpose This Memorandum of Understanding (MOU) defines the terms of a joint ehealth

More information

Audit and Compliance Committee - Agenda

Audit and Compliance Committee - Agenda Audit and Compliance Committee - Agenda Board of Trustees Audit and Compliance Committee April 17, 2018, 1:30 2:30 p.m. President s Board Room Conference Call-In Phone #1-800-442-5794, passcode 463796

More information

Security and Privacy Governance Program Guidelines

Security and Privacy Governance Program Guidelines Security and Privacy Governance Program Guidelines Effective Security and Privacy Programs start with attention to Governance. Governance refers to the roles and responsibilities that are established by

More information

MNsure Privacy Program Strategic Plan FY

MNsure Privacy Program Strategic Plan FY MNsure Privacy Program Strategic Plan FY 2018-2019 July 2018 Table of Contents Introduction... 3 Privacy Program Mission... 4 Strategic Goals of the Privacy Office... 4 Short-Term Goals... 4 Long-Term

More information

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION Cathy Bates Senior Consultant, Vantage Technology Consulting Group January 30, 2018 Campus Orientation Initiative and Project Orientation Project

More information

KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT)

KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT) KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT) 1. DIRECTOR, LEARNING & DEVELOPMENT - LOWER KABETE Reporting to the Director General, Campus Directors will be responsible for

More information

Article II - Standards Section V - Continuing Education Requirements

Article II - Standards Section V - Continuing Education Requirements Article II - Standards Section V - Continuing Education Requirements 2.5.1 CONTINUING PROFESSIONAL EDUCATION Internal auditors are responsible for maintaining their knowledge and skills. They should update

More information

NERC Staff Organization Chart Budget 2017

NERC Staff Organization Chart Budget 2017 NERC Staff Organization Chart Budget 2017 President and CEO Administrative Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel

More information

Policies and Procedures Date: February 28, 2012

Policies and Procedures Date: February 28, 2012 No. 5200 Rev.: 1 Policies and Procedures Date: February 28, 2012 Subject: Information Technology Security Program 1. Purpose... 1 2. Policy... 1 2.1. Program Elements... 1 2.2. Applicability and Scope...

More information

NERC Staff Organization Chart Budget 2017

NERC Staff Organization Chart Budget 2017 NERC Staff Organization Chart Budget 2017 President and CEO Administrative Associate Director to the Office of the CEO Senior Vice President and Chief Reliability Senior Vice President, General Counsel

More information

RESUME. David Lynwood Deal

RESUME. David Lynwood Deal Resume David Lynwood Deal 1 RESUME 1608 Meadowview Lane Martinsville, Virginia 24112 (276) 252-8820 (Home) (276) 656-0258 (Work) email: ddeal@patrickhenry.edu David Lynwood Deal Education: June 1978 April

More information

Memphis Chapter. President s Message. This annual event is designed to provide students with a

Memphis Chapter. President s Message. This annual event is designed to provide students with a Memphis Chapter F E B R U A R Y 2 0 1 5 Remember: Update your IIA profile for the most up-to-date news. RSVP for the Annual Student Day February 24, 2015 This annual event is designed to provide students

More information

A Global Look at IT Audit Best Practices

A Global Look at IT Audit Best Practices A Global Look at IT Audit Best Practices 2015 IT Audit Benchmarking Survey March 2015 Speakers Kevin McCreary is a Senior Manager in Protiviti s IT Risk practice. He has extensive IT audit and regulatory

More information

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors Page 1 of 6 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: June 1, 2018 Contact for More Information: HIPAA Privacy Officer Board Policy Administrative

More information

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED. Assistant Deputy Minister (Review Services) Reviewed by in accordance with the Access to Information Act. Information UNCLASSIFIED. Security Audits: Management Action Plan Follow-up December 2015 1850-3-003

More information

Threat and Vulnerability Assessment Tool

Threat and Vulnerability Assessment Tool TABLE OF CONTENTS Threat & Vulnerability Assessment Process... 3 Purpose... 4 Components of a Threat & Vulnerability Assessment... 4 Administrative Safeguards... 4 Logical Safeguards... 4 Physical Safeguards...

More information

Information Security Governance and IT Governance

Information Security Governance and IT Governance Information Security Governance and IT Governance Overview NC State is redesigning its IT governance process (see external document, NC State IT Governance Redesign at http://go.ncsu.edu/it-governance-redesign-final

More information

IT Town Hall Meeting. IT Town Hall - October 6,

IT Town Hall Meeting. IT Town Hall - October 6, IT Town Hall Meeting Scott F. Midkiff Vice President for Information Technology and CIO Professor of Electrical and Computer Engineering Virginia Tech midkiff@vt.edu IT Town Hall - October 6, 2014 1 Agenda

More information

Subject: University Information Technology Resource Security Policy: OUTDATED

Subject: University Information Technology Resource Security Policy: OUTDATED Policy 1-18 Rev. 2 Date: September 7, 2006 Back to Index Subject: University Information Technology Resource Security Policy: I. PURPOSE II. University Information Technology Resources are at risk from

More information

UNC Campus Security Initiatives Update. Business Affairs Committee May 9, 2017

UNC Campus Security Initiatives Update. Business Affairs Committee May 9, 2017 UNC Campus Security Initiatives Update Business Affairs Committee May 9, 2017 UNC Campus Security Initiative In August 2013, President Ross asked for a review of current security practices, an assessment

More information

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT Mitigation Framework Leadership Group (MitFLG) Charter DRAFT October 28, 2013 1.0 Authorities and Oversight The Mitigation Framework Leadership Group (MitFLG) is hereby established in support of and consistent

More information

System Chief Business Officer - B. J. Crain The Texas A&M University System Position Description--January 13, 2010

System Chief Business Officer - B. J. Crain The Texas A&M University System Position Description--January 13, 2010 System Chief Business Officer - B. J. Crain Position Description--January 13, 2010 Dual reporting to the Chancellor and President of Texas A&M University with consideration to an executive oversight committee*

More information

STRATEGIC PLAN. USF Emergency Management

STRATEGIC PLAN. USF Emergency Management 2016-2020 STRATEGIC PLAN USF Emergency Management This page intentionally left blank. Organization Overview The Department of Emergency Management (EM) is a USF System-wide function based out of the Tampa

More information

University of Dublin Trinity College

University of Dublin Trinity College University of Dublin Trinity College Library & Information Policy Committee Minutes of the meeting held on Monday 8 th November 2011 at 15.15 in the Henry Jones Room, Old Library. Present: Apologies: Professor

More information

Our Mission: To provide technology resources for the County and set the vision for future technology investments

Our Mission: To provide technology resources for the County and set the vision for future technology investments Jack Belcher, Chief Information Officer 2100 CLARENDON BLVD., SUITE 612, ARLINGTON, VA 22201 703-228-3220 cio@arlingtonva.us Our Mission: To provide technology resources for the County and set the vision

More information

Report of the Nominating Committee

Report of the Nominating Committee Volume 7, 31 March 2011 In This Issue: Report of the Nominating Committee Slate of 2011-2012 Board of Directors New COBIT Case Study: Grupo Bancolombia New COBIT Process Assessment Model: The Market Need

More information

SCHEME OF DELEGATION (Based on the model produced to the National Governors Association)

SCHEME OF DELEGATION (Based on the model produced to the National Governors Association) SCHEME OF DELEGATION (Based on the model produced to the National Association) THE PURPOSE OF A SCHEME OF DELEGATION: A scheme of delegation (SoD) is the key document defining which functions have been

More information

Table of Contents. Preface xvii PART ONE: FOUNDATIONS OF MODERN INTERNAL AUDITING

Table of Contents. Preface xvii PART ONE: FOUNDATIONS OF MODERN INTERNAL AUDITING Table of Contents Preface xvii PART ONE: FOUNDATIONS OF MODERN INTERNAL AUDITING Chapter 1: Significance of Internal Auditing in Enterprises Today: An Update 3 1.1 Internal Auditing History and Background

More information

ISACA International Perspective

ISACA International Perspective ISACA International Perspective 11 th October 2013 Allan Boardman ISACA International Vice President and Board Director Member of ISACA s Strategic Advisory Council Member of the IT Governance Institute

More information

2016 NCCA Standards Revisions Recap and Takeaways: What You Need to Know

2016 NCCA Standards Revisions Recap and Takeaways: What You Need to Know 2016 NCCA Standards Revisions Recap and Takeaways: What You Need to Know Certification programs must stay up to date with the latest revisions to the NCCA Standards for certification. Written by Dr. Jim

More information

Drive Your Career Forward IIA Certifications and Qualifications

Drive Your Career Forward IIA Certifications and Qualifications Drive Your Career Forward IIA Certifications and Qualifications Mapping Your Path for Growth Professional development is a journey. Demonstrating your knowledge, acumen, and leadership ability are key

More information

Certification Commission for Healthcare Information Technology. CCHIT A Catalyst for EHR Adoption

Certification Commission for Healthcare Information Technology. CCHIT A Catalyst for EHR Adoption Certification Commission for Healthcare Information Technology CCHIT A Catalyst for EHR Adoption Alisa Ray, Executive Director, CCHIT Sarah Corley, MD, Chief Medical Officer, NextGen Healthcare Systems;

More information

SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION

SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION POSITION: CHIEF OPERATING OFFICER FUNCTION: Responsible for all aspects of the SLV POA day-to-day operations. In this capacity,

More information

Our Vision Professional Community

Our Vision Professional Community Our Vision Professional Community Destination resort - the preferred provider of information about lean software and system development." www.leanssc.org Mission To promote and create awareness of Lean

More information

DHS Overview of Sustainability and Environmental Programs. Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs

DHS Overview of Sustainability and Environmental Programs. Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs DHS Overview of Sustainability and Environmental Programs Dr. Teresa R. Pohlman Executive Director, Sustainability and Environmental Programs DHS Mission DHS Organization Getting to Know DHS Mission: Secure

More information

Article I - Administrative Bylaws Section IV - Coordinator Assignments

Article I - Administrative Bylaws Section IV - Coordinator Assignments 3 Article I - Administrative Bylaws Section IV - Coordinator Assignments 1.4.1 ASSIGNMENT OF COORDINATORS To fulfill the duties of the Fiscal Control and Internal Auditing Act (30 ILCS 10/2005), the Board

More information

Student Union Social Programming Board Constitution

Student Union Social Programming Board Constitution Student Union Social Programming Board Constitution Preamble The Social Programming Board (SPB) is an Executive Entity of the Student Union at Washington University in Saint Louis, charged with providing

More information

Texas Commission on Fire Protection

Texas Commission on Fire Protection 2017 Texas Commission on Fire Protection OVERVIEW, REVENUE, DATA MANAGEMENT PROJECT, PERFORMANCE MEASURES Page 1 of 9 Overview The Commission on Fire Protection is charged with developing and enforcing

More information

Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education

Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education Exploring the Maturity of Risk Management Process in Government: An Integrated ERM Model at the U.S. Department of Education FEDERAL STUDENT AID ENTERPRISE RISK MANAGEMENT GROUP Cynthia Vitters 1. ERM

More information

CMA Certification. What it Can Mean for You

CMA Certification. What it Can Mean for You CMA Certification What it Can Mean for You Institute of Management Accountants (IMA) Vision The world s leading association for management accounting and finance professionals Building Your Career CMA

More information

Annual Report for the Utility Savings Initiative

Annual Report for the Utility Savings Initiative Report to the North Carolina General Assembly Annual Report for the Utility Savings Initiative July 1, 2016 June 30, 2017 NORTH CAROLINA DEPARTMENT OF ENVIRONMENTAL QUALITY http://portal.ncdenr.org Page

More information

Our Mission: To provide technology resources for the County and set the vision for future technology investments

Our Mission: To provide technology resources for the County and set the vision for future technology investments Jack Belcher, Chief Information Officer 2100 CLARENDON BLVD., SUITE 612, ARLINGTON, VA 22201 703-228-3220 cio@arlingtonva.us Our Mission: To provide technology resources for the County and set the vision

More information

UCSB IT Forum. April 15, 2014

UCSB IT Forum. April 15, 2014 UCSB IT Forum April 15, 2014 Agenda 1. Announcements 2. IT Governance a. Enterprise IT Governance Overview b. History of Campus IT Governance c. New Approach 3. Discussion ANNOUNCEMENTS IT Needs Assessment

More information

University of Texas Arlington Data Governance Program Charter

University of Texas Arlington Data Governance Program Charter University of Texas Arlington Data Governance Program Charter Document Version: 1.0 Version/Published Date: 11/2016 Table of Contents 1 INTRODUCTION... 3 1.1 PURPOSE OF THIS DOCUMENT... 3 1.2 SCOPE...

More information

ERO Enterprise Strategic Planning Redesign

ERO Enterprise Strategic Planning Redesign ERO Enterprise Strategic Planning Redesign Mark Lauby, Senior Vice President and Chief Reliability Officer Member Representatives Committee Meeting February 10, 2016 Strategic Planning Redesign Current

More information

Project Management Professional (PMP) Exam Preparation elearning Course

Project Management Professional (PMP) Exam Preparation elearning Course Project Management Professional (PMP) Exam Preparation elearning Course Course Code: PMC001CL Duration: 4 Days, 35 Hours Format: elearning Certification Exam: PMI s PMP Exam Certification Track: N/A Course

More information

13.f Toronto Catholic District School Board's IT Strategic Review - Draft Executive Summary (Refer 8b)

13.f Toronto Catholic District School Board's IT Strategic Review - Draft Executive Summary (Refer 8b) AGENDA ADDENDU TE REGULAR EETING OF TE AUDIT COITTEE COITTEE PUBLIC SESSION Tuesday, June 6, 2017 6:30 P.. Pages 13. Staff Reports 13.f Toronto Catholic District School Board's IT Strategic Review - Draft

More information

Document Number: HITSP 08 N 378 Date: December 17, 2008 Report from the HITSP Education, Communication and Outreach (HITSP-ECO) Committee

Document Number: HITSP 08 N 378 Date: December 17, 2008 Report from the HITSP Education, Communication and Outreach (HITSP-ECO) Committee 0 Document Number: HITSP 08 N 378 Date: December 17, 2008 Report from the HITSP Education, Communication and Outreach (HITSP-ECO) Committee Co-Chairs: Walter G. Suarez, MD, Institute for HIPAA/HIT Education

More information

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13

Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 Texas Reliability Entity, Inc. Strategic Plan for 2017 TEXAS RE STRATEGIC PLAN FOR 2017 PAGE 1 OF 13 I. Vision A highly reliable and secure bulk power system in the Electric Reliability Council of Texas

More information

MINUTES COMMITTEE ON GOVERNANCE Conference Call April 7, 2010

MINUTES COMMITTEE ON GOVERNANCE Conference Call April 7, 2010 MINUTES COMMITTEE ON GOVERNANCE Conference Call April 7, 2010 A conference call of the Committee on Governance was held April 7, 2010. Chair Dianna Morgan called the meeting to order at 1:03 p.m. Present

More information

FramewOrk to DeSign and implement ifc

FramewOrk to DeSign and implement ifc Marketing Partner Hotel Radisson GRT, 15 Leveraging COSO internal COntrOLS FramewOrk to DeSign and implement ifc 8 CPE Hours Networking Opportunities Qualified CIA Faculty about the Seminar The COSO Internal

More information

OF ACCOUNTANTS IAASB CAG MEETING MARCH 7, 2011

OF ACCOUNTANTS IAASB CAG MEETING MARCH 7, 2011 INTERNATIONAL FEDERATION OF ACCOUNTANTS IAASB CAG MEETING MARCH 7, 2011 HISTORY OF THE IIA 1941 Founded in New York City 1944 First chapter outside the US chartered in Toronto 1948 First chapters outside

More information

Multi-Region Registered Entity Coordinated Oversight Program

Multi-Region Registered Entity Coordinated Oversight Program Multi-Region Registered Entity Coordinated Oversight Program Ken McIntyre, Vice President and Director of Standards and Compliance Compliance Committee Open Meeting February 7, 2018 Coordinated Oversight

More information

Chief Compliance Officer s (CCO s) Role in Cybersecurity Thursday, February 22 10:00 a.m. 11:00 a.m.

Chief Compliance Officer s (CCO s) Role in Cybersecurity Thursday, February 22 10:00 a.m. 11:00 a.m. Chief Compliance Officer s (CCO s) Role in Cybersecurity Thursday, February 22 10:00 a.m. 11:00 a.m. Increased use of technologies such as mobile devices, social media and cloud computing has increased

More information

Number of CPE Hours Required for CCSA, CFSA, CGAP, CRMA. Specialty Certification CPE Requirements. Required Attestations at Time of CPE Reporting

Number of CPE Hours Required for CCSA, CFSA, CGAP, CRMA. Specialty Certification CPE Requirements. Required Attestations at Time of CPE Reporting Volume 16 Issue 5 Changes to Continuing Professional Education (CPE) Requirements and Reporting Processes to be Implemented in 2012 On Tuesday, November 15, 2011, the Global Board approved the implementation

More information

OSC Guidance and Training for Internal Audit and Internal Control Practitioners. Tina Kim John Buyce

OSC Guidance and Training for Internal Audit and Internal Control Practitioners. Tina Kim John Buyce OSC Guidance and Training for Internal Audit and Internal Control Practitioners Tina Kim John Buyce Training Requirements for Auditors and Internal Control Professionals Yellow Book: Chapter 3 General

More information

IT Governance Framework at KIT

IT Governance Framework at KIT [unofficial English version; authoritative is the German version] IT Governance Framework at KIT 1. Recent situation and principle objectives Digitalization increasingly influences our everyday life at

More information

Strategic Plan for years Updated - 8/9/14 Review & re-approved

Strategic Plan for years Updated - 8/9/14 Review & re-approved The Mid-Florida Chapter of APICS will continue to utilize a Continuous Improvement concept, along with the C-BAR as tools to better manage the chapter. Vision: Mission: Mid-Florida Chapter of APICS will

More information

CASA External Peer Review Program Guidelines. Table of Contents

CASA External Peer Review Program Guidelines. Table of Contents CASA External Peer Review Program Guidelines Table of Contents Introduction... I-1 Eligibility/Point System... I-1 How to Request a Peer Review... I-1 Peer Reviewer Qualifications... I-2 CASA Peer Review

More information

RISK BASED INTERNAL AUDIT (16 CPE) COSO ERM Framework - Risk Assessment Process

RISK BASED INTERNAL AUDIT (16 CPE) COSO ERM Framework - Risk Assessment Process RISK BASED INTERNAL AUDIT (16 CPE) COSO ERM Framework - Risk Assessment Process Date 24-25 September 2018 Time: 09:00 17:00 Location Hotel Grand, Tirana, Albania Course director: Mr. Konstantinos P. Triantafyllidis,

More information

Overview of ABET Kent Hamlin Director Institute of Nuclear Power Operations Commissioner TAC of ABET

Overview of ABET Kent Hamlin Director Institute of Nuclear Power Operations Commissioner TAC of ABET Overview of ABET Kent Hamlin Director Institute of Nuclear Power Operations Commissioner TAC of ABET 1 st National Meeting on Improving Education and Training For Chinese Nuclear Power Industry Personnel

More information

Standards: Enabler of Sustainability

Standards: Enabler of Sustainability Standards: Enabler of Sustainability An Academic-Industry Workshop May 17, 2017 Mary H. Saunders Vice President, Government Relations and Public Policy Business Drivers of Sustainability Standards Use

More information

Audit Challenges and Best Practices in a Research University Environment

Audit Challenges and Best Practices in a Research University Environment NSAA Annual Conference Jeffrey Huskamp Vice President and CIO University of Maryland, College Park Carnegie Doctoral/Research University Extensive 18 th ranked public university (US News) Celebrated 150

More information

Present. 5th May - Chennai. Internal. auditing. today: Beginning Auditor Tools and Techniques. 6 CPE hours.

Present. 5th May - Chennai. Internal. auditing. today: Beginning Auditor Tools and Techniques. 6 CPE hours. Present 5th May - Chennai Internal auditing today: Beginning Auditor Tools and Techniques 6 CPE hours www.achromicpoint.com About the Seminar To become a successful auditor, a strong base of knowledge

More information

State of South Carolina Interim Security Assessment

State of South Carolina Interim Security Assessment State of South Carolina Interim Security Assessment Deloitte & Touche LLP Date: October 28, 2013 Our services were performed in accordance with the Statement on Standards for Consulting Services that is

More information

Programs that Work. March 7,

Programs that Work. March 7, Programs that Work March 7, 2017 www.workforcedqc.org @workforcedqc Panelists Jenna Leventoff, Workforce Data Quality Campaign Kermit Kaleba, National Skills Coalition David W. Ramsay, Office of Research

More information

Recommendation from SACSCOC January 15, 2013 Probation Sanction Letter [1]:

Recommendation from SACSCOC January 15, 2013 Probation Sanction Letter [1]: Principle 1.1 Principle of Integrity The institution operates with integrity in all matters. Recommendation from SACSCOC January 15, 2013 Probation Sanction Letter [1]: Principle 1.1 (Integrity) The institution

More information

Critical Infrastructure Protection Version 5

Critical Infrastructure Protection Version 5 Critical Infrastructure Protection Version 5 Tobias Whitney, Senior CIP Manager, Grid Assurance, NERC Compliance Committee Open Meeting August 9, 2017 Agenda Critical Infrastructure Protection (CIP) Standards

More information

ASHRAE. Strategic Plan STARTING

ASHRAE. Strategic Plan STARTING 1 ASHRAE Strategic Plan STARTING 2014 O StrategicPlan STARTING 2014 Figure 1: The Strategic Plan on a Page VISION ASHRAE will be the global leader, the foremost source of technical and educational information,

More information

PECB Certified ISO Lead Auditor. Master the Audit of Occupational Health and Safety Management System (OHSMS) based on ISO 45001

PECB Certified ISO Lead Auditor. Master the Audit of Occupational Health and Safety Management System (OHSMS) based on ISO 45001 Certified Lead Auditor Master the Audit of Occupational Health and Safety Management System (OHSMS) based on Why should you attend? is the first global Occupational Health and Safety Management System

More information

Plenary Session: Branch Cybersecurity Controls Thursday, February 22 1:15 p.m. 2:15 p.m.

Plenary Session: Branch Cybersecurity Controls Thursday, February 22 1:15 p.m. 2:15 p.m. Plenary Session: Branch Cybersecurity Controls Thursday, February 22 1:15 p.m. 2:15 p.m. Cybersecurity is a top priority for the financial services industry. Firms dedicate significant resources every

More information

Drive Your Career Forward IIA Certifications and Qualifications

Drive Your Career Forward IIA Certifications and Qualifications CCSA CRMA CFSA CGAP Don t miss out on the CIA Application Fee Waiver in August! More information is available on the back cover. Drive Your Career Forward IIA Certifications and Qualifications Mapping

More information

Public Safety Canada. Audit of the Business Continuity Planning Program

Public Safety Canada. Audit of the Business Continuity Planning Program Public Safety Canada Audit of the Business Continuity Planning Program October 2016 Her Majesty the Queen in Right of Canada, 2016 Cat: PS4-208/2016E-PDF ISBN: 978-0-660-06766-7 This material may be freely

More information

DIPLOMA COURSE IN INTERNAL AUDIT

DIPLOMA COURSE IN INTERNAL AUDIT DIPLOMA COURSE IN INTERNAL AUDIT Course Objective: Internal Audit is an assurance and consulting service that reviews the efficiency and effectiveness of the internal control.. It assists management at

More information

Office of Internal Audit

Office of Internal Audit Office of Internal Audit March 16, 2017 Dr. Kirk Calhoun, President UT Health Northeast 11937 U. S. Hwy 271 Tyler, TX 75708 Dr. Calhoun: We have completed the Security Control Standards as part of our

More information

Taking the Mystery Out of Counting CPE. Opening Remarks

Taking the Mystery Out of Counting CPE. Opening Remarks Taking the Mystery Out of Counting CPE Kristen Kociolek Assistant Director U.S. Government Accountability Office Harriet Richardson City Auditor Palo Alto, CA Opening Remarks MODERATOR R. Kinney Poynter

More information

FROM TACTIC TO STRATEGY:

FROM TACTIC TO STRATEGY: FROM TACTIC TO STRATEGY: The CDW-G 2011 Cloud Computing Tracking Poll 2011 CDW Government LLC TABLE OF CONTENTS Introduction 3 Key findings 4 Planning for the cloud 16 Methodology and demographics 19 Appendix

More information

Position Description IT Auditor

Position Description IT Auditor Position Title IT Auditor Position Number Portfolio Performance and IT Audit Location Victoria Supervisor s Title IT Audit Director Travel Required Yes FOR OAG HR USE ONLY: Approved Classification or Leadership

More information

Business Architecture Implementation Workshop

Business Architecture Implementation Workshop Delivering a Business Architecture Transformation Project using the Business Architecture Guild BIZBOK Hands-on Workshop In this turbulent and competitive global economy, and the rapid pace of change in

More information

INTERNAL AUDIT ACTIVITY REPORT

INTERNAL AUDIT ACTIVITY REPORT STATE OF NORTH CAROLINA COUNCIL OF INTERNAL AUDITING INTERNAL AUDIT ACTIVITY REPORT As Required by G.S. 143-747(c)(12) October 2015 Prepared By: Office of Internal Audit Office of State Budget and Management

More information

Get Exam Ready. Attention Potential HFMA Certification Candidates! HFMA Certification Candidate

Get Exam Ready. Attention Potential HFMA Certification Candidates! HFMA Certification Candidate Get Exam Ready HFMA Certification Candidate Attention Potential HFMA Certification Candidates! Thursdays February 12, 2015 March 12, 2015 12:00 pm to 2:00 pm cst Course Instructor Christoph Stauder FHFMA,

More information

CCSA, CFSA, CGAP Transition FAQs

CCSA, CFSA, CGAP Transition FAQs CCSA, CFSA, CGAP Transition FAQs July 2018 Frequently Asked Questions (FAQ) Q. How is the Certified Government Auditing Professional (CGAP) certification changing? A. The CGAP certification will be repositioned

More information

Aboriginal Affairs and Northern Development Canada. Internal Audit Report Summary. Audit of Information Technology Security.

Aboriginal Affairs and Northern Development Canada. Internal Audit Report Summary. Audit of Information Technology Security. Aboriginal Affairs and Northern Development Canada Internal Audit Report Summary Audit of Information Technology Security Prepared by: Audit and Assurance Services Branch April 2015 NCR#7367040 - NCR#7358318

More information

354 & Index Board of Directors Responsibilities Audit Committee and Risk Committee Coordination, 244 Audit Committee Functions and Responsibilities, 2

354 & Index Board of Directors Responsibilities Audit Committee and Risk Committee Coordination, 244 Audit Committee Functions and Responsibilities, 2 Index Accounts Payable Process Review Procedures Assessments, 191 Actions to Resolve Risks COSO ERM Control Activities, 97 Activity Management COSO ERM Control Activities, 81 AICPA SAS No. 1 Internal Controls

More information

UNF Finance and Audit Committee January 15, 2013

UNF Finance and Audit Committee January 15, 2013 Item 6 UNF Finance and Audit Committee January 15, 2013 Issue Office of Internal Auditing Quarterly Report Proposed Action Presentation Background Information The purpose of this item is to present a report

More information

In 2017, the Auditor General initiated an audit of the City s information technology infrastructure and assets.

In 2017, the Auditor General initiated an audit of the City s information technology infrastructure and assets. REPORT FOR ACTION IT Infrastructure and IT Asset Management Review: Phase 1: Establishing an Information Technology Roadmap to Guide the Way Forward for Infrastructure and Asset Management Date: January

More information

General Information Technology Controls Follow-up Review

General Information Technology Controls Follow-up Review Office of Internal Audit General Information Technology Controls Follow-up Review May 19, 2015 Internal Audit Team Shannon B. Henry Chief Audit Executive Stacy Sneed Audit Manager Rod Isom Auditor Winston-Salem

More information

STRATEGIC PLAN

STRATEGIC PLAN STRATEGIC PLAN 2013-2018 In an era of growing demand for IT services, it is imperative that strong guiding principles are followed that will allow for the fulfillment of the Division of Information Technology

More information

ERO Enterprise IT Projects Update

ERO Enterprise IT Projects Update ERO Enterprise IT Projects Update Stan Hoptroff, Vice President, Chief Technology Officer and Director of Information Technology Technology and Security Committee Meeting November 6, 2018 Agenda ERO IT

More information

IMA and the CMA How They Can Help Your Career. Presented by: Honorable Kim R. Wallin, CMA, CFM, CPA John B. Pollara, CMA

IMA and the CMA How They Can Help Your Career. Presented by: Honorable Kim R. Wallin, CMA, CFM, CPA John B. Pollara, CMA IMA and the CMA How They Can Help Your Career Presented by: Honorable Kim R. Wallin, CMA, CFM, CPA John B. Pollara, CMA 1 IMA and Your Career WE NEED TO INSERT THE VIDEO HERE Agenda The Institute of Management

More information

SALARY $ $72.54 Hourly $3, $5, Biweekly $8, $12, Monthly $103, $150, Annually

SALARY $ $72.54 Hourly $3, $5, Biweekly $8, $12, Monthly $103, $150, Annually SALARY $49.72 - $72.54 Hourly $3,977.88 - $5,803.27 Biweekly $8,618.75 - $12,573.75 Monthly $103,425.00 - $150,885.00 Annually ISSUE DATE: 03/21/18 THE POSITION DIRECTOR OF CYBER SECURITY OPEN TO THE PUBLIC

More information

Facilities Master Plan Toronto Public Library Board Consultation

Facilities Master Plan Toronto Public Library Board Consultation STAFF REPORT INFORMATION ONLY Facilities Master Plan Toronto Public Library Board Consultation Date: May 28, 2018 20. To: From: Toronto Public Library Board City Librarian SUMMARY The purpose of this report

More information

Recertification Handbook

Recertification Handbook Recertification Handbook NACAS 3 Boar's Head Lane, Suite B Charlottesville, VA 22903 Phone 434-245-8425 Fax 434-245-8453 nacas.org/casp casp@nacas.org Congratulations on receiving the CASP designation!

More information

Implementation of Business Continuity Management System (BCMS) based on ISO 22301:2012 requirements

Implementation of Business Continuity Management System (BCMS) based on ISO 22301:2012 requirements Implementation of Business Continuity Management System (BCMS) based on ISO 22301:2012 requirements Summary This five-day intensive training course enables participants to develop the necessary expertise

More information