Tuesday, 24 July 2012

Amendments in ISCA

Hey friends,

Hope u are doing well !!!!

Following are the amendments in ISCA and are applicable for Nov - 2012 exam :

Chapter - 5 : Risk Management Process :


Risk Management Process:  (Latest Amendment)
The process of Information Risk Management typically involves the following steps:
Step 1: Identification of Information Assets
Step 2: Valuation of Information Assets
Step 3: Identifying the potential threats & Vulnerabilities
Step 4: Information Risk Assessment
Step 5: Developing Strategies for Information Risk Management

The detail of each step is given as follows:

Step 1: Identification of Information Assets
ü  Identify the information assets supporting critical business operations that need to be protected.
The assets could fall under different groups which are:
a)    Conceptual / Intangible Assets :
1.    Data and Information:
ü  Business and related information contained in various storage devices such as hard disks or in transit may be subject to unauthorized disclosure, copying, theft, corruption or damage.
2.    Software:
ü  Application software (application packages for accounting, payroll, sales etc.) and system software (operating system, utility programs, compiler, communication software, DBMS etc.):
ü  Such programs may be susceptible to intentional or unintentional unauthorized modification by persons internal or external to the organization or by faulty technology processes.

b)   Physical / Tangible Assets :
Ø  People (e.g. skilled users, analysts, programmers etc.)
Ø  Hardware (e.g. mainframes, minicomputers, microcomputers, storage media, printers)
Ø  Networking devices (e.g. communication lines, concentrators, hubs and switches etc.)
Ø  Facilities: The computing and communication equipments such as servers could require special environment such as air-conditioned, dust free, humidity controlled facilities.
Ø  Documentation (e.g. printed forms, manuals, system and database documentation, IS policies & procedures)


Step 2: Valuation of Information Assets
ü  The information classification process focuses on business risk and data valuation.
ü  Information systems resources should be classified or categorized according to their sensitivity. In other words, information classification should be done based based upon their critical value it possess.
Ø  Critical info :  Startegic plans , formulas , trade secrets etc.
Ø  Less critical info : list of customers, details of employees’ salaries, etc
ü  With the loss of information relating to trade secrets, formulas , new product information organisation’s credibility might be questioned.
ü  Thus in order to ensure cost-effective controls, it is beneficial to classify the entire organizational information. Also it helps in avoiding the cost of over-protecting and under protecting the information.
The assets so identified and grouped may be categorized into different classes, which are:
a)    Top secret:  
·         This indicates the highest classification wherein the compromise of the confidentiality, integrity and availability can endanger the existence of the organization.   
·         Access to such information may be restricted to either a few named individuals in the organization or to a set of identified individuals.

b)    Secret:
·         Information in this category is strategic to the survival of the organization.
·         Unauthorized disclosure could cause severe damage to the organization and stakeholders.
c)    Confidential:
·         Information in this category also needs high levels of protection but unauthorized disclosure may cause significant loss or damage.
·         Such information is highly sensitive and should be well protected.

d)    Sensitive:
·         Such information requires higher classification as compared to unclassified information.
·         Disclosure may cause serious impact.

e)    Unclassified:
·         Information that does not fall in any of the above categories finds place here.
·         This also implies that the nature of the information is such that its unauthorized disclosure would not cause any adverse impact on the organization.
·         Such information may also be made freely available to the public.
Another type of classification, popular in commercial organizations, can be:
Public, Sensitive, Private and Confidential.

Step 3: Identifying the potential threats & Vulnerabilities:
·         Threat can be defined as an event that contributes to the interruption or destruction of any service, product or process.
·         Common classes of threats are:
ü  Errors , Malicious damage/attack
ü  Fraud , Theft , Equipment/software failure
·         Threats occur because of vulnerabilities associated with use of information resources.
·         Vulnerability is the weakness in the system safeguards that exposes the system to threats.
·         It may be weakness in a

ü  information system,
ü  cryptographic system (security systems),
ü  Hardware Design
ü  Internal control
·         Examples of vulnerabilities are:
ü  Lack of user knowledge , Lack of security functionality
ü  Poor choice of passwords , Untested technology
ü  Transmission over unprotected communication medium

Threats Computer systems could affect the confidentiality, integrity or availability of system information or resources.

a)    Confidentiality :
Ø  It involves the protection of the organization’s sensitive information from disclosure to unauthorized persons and processes.

b)    Integrity :
Ø  It involves protection against any intentional / accidental unauthorized modification, which may result in serious consequences to the business.
Ø  e.g: Computer virus may cause corruption of data/program thereby causing loss of transactions or state of integrity of such transactions.
c)    Availability :
Ø  It emphasis on whether the information systems and processes critical for conduct of business are available to authorized users as and when required.
Ø  E.g. Denial-of-service attack.

Step 4: Information Risk Assessment :
Ø  Once the assets and corresponding potential threats have been identified, the systems are reviewed for weaknesses that can be exploited and the likelihood of those being exploited.
This can be done by :
a)    Vulnerability Assessment :
ü  Vulnerability is the weakness in the system safeguards that exposes the system to threats.
ü  Sometimes the threat viewed in isolation may be misleading unless the vulnerabilities are taken into consideration. In most cases the threats attempt to exploit the vulnerabilities to cause loss or harm to the assets.
ü  For example, a hacker would look for loopholes in the architecture of the firewall to compromise the controls and gain unauthorized access to the networks.

b)    Probability or Likelihood Assessment :
ü  Likelihood is the chance of a threat happening.
ü  A likelihood assessment considers the presence, tenacity and strength of threats, as well as, the effectiveness of safeguards.
ü  In general, the greater the likelihood of a threat occurring, the greater is the risk.
ü  To some extent, the nature and value of information assets affect the likelihood of occurrence of a threat. If the asset is of high value, e.g. proprietary software packages, it is a prime target for piracy attempts.
ü  Periodically, the likelihood of occurrence of a threat needs to be reassessed due to changes occurring in the structure, direction, and environment of an organization.

c)    Impact Analysis :
ü  The threat that is successful in causing harm or loss to an asset results in an impact.
ü  Impact may be either in monetary or non – monetary terms. e.g. loss of profit & loss of goodwill .

Step 5: Developing Strategies for Information Risk Management
·         Once risks have been identified and assessed, appropriate corrections shall be made to the system, if required.
·         Immediate action may not be taken to correct some identified vulnerabilities but the process will at least analyse these vulnerabilities, document and recognize them for risk management decisions.
The strategies to manage the risk fall into one or more of these four major categories:
a)    Risk Avoidance:
ü  It means not doing an activity that involves risk.
ü  It involves losing out on the potential gain that accepting the risk might have provided.  
ü  E.g. not using Internet / public network on a system connected to organisation’s internal network, instead using a stand-alone PC for Internet usage.

b)    Risk Mitigation / Reduction:
ü  It involves implementing controls to protect IT infrastructure and to reduce the severity of the loss or the likelihood of the loss from occurring.
ü  E.g. Using Anti –virus s/w for Virus attack.

c)    Risk Transfer:
ü  It involves causing another party to accept the risk i.e. sharing risk with partners or insurance coverage.

d)    Risk Retention / Acceptance:  ( Do nothing stratergy – Residual Risk)
ü  It means formally acknowledging that the risk exists and monitoring it. These risks are called residual risks.
ü  Risk management aims to identify, select and implement the controls that are necessary to reduce residual exposures to acceptable levels.
o   The goals and mission of an organization should be considered in selecting any of these risk management strategies.
o   It may not be practical to address all identified risks, hence prioritization is required.
o   In prioritization process the risks with the greatest loss and the greatest probability of occurrence are handled first, and risks with lower probability of occurrence and lower loss are handled later. Practically this process can be difficult to be handeled. 

Understanding the Relationships Between IS Risks and Controls
*      Risks that threaten the IS cannot be altogether eliminated but, through appropriate decisions and actions can be mitigated. ( Link : Residual risk )
*      Any threat to the system or its components could result in a loss to the company as a consequence of exploitation of the vulnerabilities.
*      A control is a check or restraint on a system which is designed to enhance its security.
*      Controls can act to reduce :
o    threat
o   vulnerability to a threat
o   detect &  recover from an impact of a threat

*      The objective of IS controls is to :
ü  prevent the threats from exploiting the vulnerabilities of the assets or the safeguards.
ü  Timely detect and trigger corrective action ( if threats can’t be prevented)
*      In the event of failure of a control, threats could cause harm to the assets resulting in an actual impact.
*      IS Auditor should be able to  evaluate whether available controls are adequate and appropriate to mitigate the IS risks.
*      In the case of deficiency , auditor should report such weaknesses to the auditee management along with appropriate recommendations.
*      Hence it is important for the IS auditor to understand the relationship between risks and controls.
The following rules apply in determining the use of new controls:
o   If control would reduce risk more than needed, then see whether a less expensive alternative exists.
o   If control does not reduce risk sufficiently, then look for more controls or a different control.
o   If control would cost more than the risk reduction provided, then find something else.
o   If control provides enough risk reduction and is cost-effective also, then use it



Thursday, 10 May 2012

FDI Criteria..

DOCUMENTATION FOR FOREIGN DIRECT INVESTMENT (FDI) REPORTING
What is FDI?

FDI refers to Foreign Direct Investment in `equity share or fully and mandatorily convertible preference shares or fully and mandatorily convertible debentures’ (FDI Instruments) of an Indian company by non resident entities.

Reporting requirements under FDI scheme as per extant RBI guidelines

Indian companies are required to report the details of the amount of consideration received for issuance of FDI instruments. Advance reporting format along with KYC report on the Non-resident investor need to be reported through Authorised Dealer Category – I Bank (AD Bank) to RBI within 30 days from the date of receipt of consideration.
Indian Companies are also required to issue the FDI instruments / refund the advance consideration to the Non-resident investor within 180 days from the date of the receipt of consideration. In case of issue of FDI instrument the same is required to be reported in form FC-GPR through AD Bank to RBI within 30 days from date of issue of instruments.

Documentation for reporting of inward remittance received for issuance of FDI Instruments

Advance reporting form (Annexure II) duly filled & signed by the client
Certified copies of FIRC/s, evidencing receipt of remittance. Purpose of FIRC should be in line with the transaction.
KYC report on Non-resident investor from the overseas bank remitting the amount

Note:- In case the inward remittance for FDI instruments has been received through the AD bank other than The Hongkong and Shanghai Banking Corporation Limited, India (HSBC), then FIRC and KYC report need to be issued by the concerned AD bank. Client will be required to request the concerned AD bank to issue FIRC & KYC report and such requests need to be routed through HSBC.
Documentation for form FC-GPR - Issuance of FDI instruments

Form FC-GPR (Annexure I) duly filled & signed by Managing Director/Director/Secretary.
Certificate from company secretary as per guidelines
Certificate from Category I Merchant Banker or Chartered accountant for valuation of FDI Instrument as per the RBI guidelines
Certified copies of FIRC’s
Unique Identification numbers allotted for all the remittances received as considerations for issuance of shares/debentures. In absence of the same, RBI acknowledged copy of the advance reporting submitted earlier is required.

Instructions for filling up Annexure II & Annexure I

Instructions for filling up Annexure II & Annexure I has been stated in the enclosed attachments.

Common discrepancies in Advance Reporting form (Annexure II)

Annexure II incompletely filled: Annexure II needs to filled correctly with the relevant details. No field should be left blank.
Missing FIRC/s copies: Please attach the attested copies of FIRC/s with the Annexure II.
Incorrect purpose in FIRC: Customers should advise the remitter to correctly state the purpose of remittance as "Application money for equity shares/preference shares/debentures under Automatic/Approval Route".

Common discrepancies in form FC-GPR (Annexure I)

Description of main business activity & NIC code: Indian company (beneficiary) needs to ensure that description of main business activity mentioned in the form is in line with the activity mentioned in the memorandum of association. NIC code should be as per attach list.
Date of reporting of inflows (refer point 4 (d) of form FC-GPR): This is date of reporting to RBI i.e. date of RBI acknowledgement on the Annexure II
Valuation method: Discounted Cash Flow (DCF) method needs to be followed for valuation of shares of unlisted Indian companies. DCF method needs to be followed even for the newly formed companies. In case of listed companies price of shares issued shall be on the basis of SEBI guidelines.
Amount mentioned on FIRCs does not tally with the total amount of FDI instrument issued: This may be due to issuance of FDI instrument for partial amount of application money received. Client needs to provide clarification on status of balance funds.

Monday, 19 March 2012

Direct Tax Highlights of Budget 2012-13 List


Direct Tax Highlights of Budget 2012-13 List

  • Turnover limit for compulsory tax audit for SMEs raised from Rs.60 lakh to Rs.1 crore
  • Income tax exemption limit raised from Rs.1,80,000 to Rs.2,00,000; upper limit of 20 per cent tax slab raised from Rs.8 lakh to Rs.10 lakh
  • White paper on Black Money to be introduced in the current session of Parliament
  • Interest from savings bank accounts deductible upto Rs.10,000; deduction of upto Rs.5,000 for preventive health check-up
  • General Anti Avoidance Rule being introduced to counter aggressive tax avoidance
  • Withholding tax rate on interest on ECB reduced from 20% to 5% for 3 years for specified sectors
  • TCS on cash purchase of immovable property above specified limit
  • Cascading effect of DDT in a multi-layer corporate structure removed
  • A number of measures proposed to deter generation and use of unaccounted money
  • STT reduced from 0.125% to 0.1%
  • 82 Double Taxation Avoidance Agreements and 19 Tax Information Exchange Agreements finalised: FM
  • Tax @ 30% on unexplained credit or investment (slab rate benefit not available)
  • TCS on cash purchase of bullion and jewellery
  • No change in corporate tax rate and tax structures
  • Senior citizens without business income exempt from advance tax
  • Re-opening of tax assessments upto 16 years in case of overseas assets
  • 15% rate for dividends from foreign companies extended for FY 2012-13

Friday, 16 March 2012

Budget 2012 - 13 Highlights..........


Budget in Detail

Union Budget 2012-13
Budget 2012-13:
• Income up to 2 lakhs - Nil
-- Rs. 2-5 lakhs - - 10 per cent
-- Rs. 5 lakhs -10 lakhs - 20 per cent
-- Rs. 10 lakhs and above - 30 per cent
• GST will be operational by August 2012
• Excise duty hiked from 10 per cent to 12 per cent
• Service Tax hiked from 10 per cent to 12 per cent
• Basis Exemption Limit 2 Lakhs
• STT cut to 0.1%.
• No change in corporate tax,DTC Deferred Further
• Global crude oil prices have crossed $115 per barrel
• Food and fertiliser subsidy largest expenditure.
• Fiscal deficit rose due to subsidy.
• Decided to fully provide for food subsidy in the budget
• FRBM implementation back on track
• Aadhar-enabled payment of select government schemes in 50 districts
• Rs 30,000 cr divestment target in FY 13
• To bring down subsidy to 1.7 % of GDP in the next 3 years
• To roll out computerized scheme for fertilizer subsidy transfer
• The Nandan Nilekani panel recommendation on direct transfer of subsidy accepted
• FY13 subsidy to be under 2% of GDP
•
• Find ways to expedite implementation of decision, prompt delivery and good governance with transparency, while curbing black money and corruption
• Remove bottlenecks in agriculture, energy, transport, coal, power and national highways
• Ensure rapid rise in private investment
• Frame policies that trigger domestic demand recovery
• Direct cash subsity to LPG, Kerosene
• Efforts to arrive at broadbased consensus with state governments on allowing FDI in multibrand retail up to 51 per cent
• Direct transfer of subsidy for kerosene initiated
• Direct Tax Code (DTC) Bill to be enacted at the earliest
• To introduce Rajiv Gandhi [ Images ] Equity Scheme for retail investors
• Tax incentive for new investors, These make sense when you consider that the share of household savings delpoyed in capital markets has come down sharply.
• Changes in IPO norms to increase participation in small towns
• Plan outlay for agriculture raised by 18% to Rs 20208 crore in FY 13
• Rs 300 crore for intensified irrigation program
• Retail stocks rally as Budget commits to multi-brand FDI
• Telecom towers made eligible for viability gap funding
• Agriculture credit target raised to Rs 5.75 lakh crore in FY13
• Agriculture allocation increased to Rs 5,75,000 crore.
• To allocate Rs 10,000 cr for NABARD to refinance RRBs.
• To allocate Rs 10,000 crore for NABARD for refinancing RRBs
• Government to set up Rs 5,000 crore venture fund for MSME sector
• To allow ECB borrowing to part-finance power projects.
• Agriculture credit target to be raised by Rs 1,00,000 crore to Rs 5,75,000 crore.
• Kisan credit cards can now be used for ATM machines.
• Change in IPO guidleines to promote small town participation
• Will allow external commercial borrowing for power, housing road construction companies
• To make 8,800 km of highways in FY13; outlay raised
• Plan outlay raised 18% to Rs 20,208 cr for agriculture
• Irrigation, dams to be eligible for special funding
• Telecom towers made eligible for viability gap funding
• Fuel supply constraints have hit power supplies nationally
• Current account deficit 3.6 percent in 2011-12; this put pressure on exchange rate.
• Advance Pricing Agreements in DTC to be in Finance Bill
• Corporate market reforms to be initiated.
• Allocation for national highways up 14 per cent. 8,800 km of highways to be developed under National Highway Development Project in 2012-13.
• Encourage small and medium artisans. Powerloom mega clusters to be set up.
• Foreign loans for low-cost housing projects.
• Foreign loan cap raised for airlines.
• To allow ECB funding to finance working capital needs of airlines for 1 year
• External commercial borrowings to the extent of $ 1 billion to be allowed for aviation sector for next year.
• Addressing malnutrition, black money and corruption in public life among five priorities in the year ahead.
• Budget to provide Rs 15,888 crore for recapitalisation of PSU banks, regional rural banks.
• Government examining new ways of providing subsidies for LPG, kerosene.
• Tax exemption on individual share investment below Rs 10 lakh.
• Govt to create Financial Holding company to meet financial needs of PSU banks.
• Income Tax deduction of 50 per cent on investments of up to Rs 50,000 in savings scheme named after Rajiv Gandhi.
• 3-year lock-in period exemption under Rajiv Gandhi scheme.
• Increase in investments in infrastructure through PPP.
• Coal India advised to sign FSA with power plants
• Infrastructure investment in 12th Plan to go up to Rs 50 lakh crore; half of it to come from private sector.
• To allow qualified FII into domestic corporate bonds
• Rs 15890 crore for recapitalisation of PSU banks
• Extend RRB capitalisation for 2 years
• Propose Central KYC depository
• Full exemption from basic customs duty for equipment for road and highway construction
• Full exemption from basic customs duty on natural gas, LNG, uranium for generation of electricity for two years.
• Customs duty on import of parts of aircraft, tyres and testing equipment fully exempted
• Excise duty on handmade and semi-mechanised matches reduced from 10 to 6 per cent
• Increase excise duty on some cigarettes
• Solar energy plants exempted from Customs Duty
• Excise duty on all processed food brought down to merit rate of 6 per cent..

Thursday, 15 March 2012

Changes in ISCA Syllabus ( CA Final)

Friends,


There are few amendments in ISCA Syllabus .  These were made by CA Institute in January 2012.
Any ways , these amendments are not applicable for May 2012 attempt.


Updated version of "ISCA - Made easy" - a book on this syllabus , authored by me , will be soon available in the market...

ACE Strategic Management - Study Material for CA Inter (Paper 6B) by CA CS Praveen Jain

  Hello Everyone! 👋 I'm thrilled to share that I’ve just launched my 18th book as an author! 📘✨ And what better day to announce this ...