Transcription of IT GENERAL CONTROLS What are IT General …
1 5/11/20111IT GENERAL CONTROLS &THE PREVENTION OF FRAUDEd Tobias, CISA, CIA, CFEMay 11, 2011 AGENDAWhat are IT GENERAL CONTROLS ?5 Areas for ReviewCase Study What are IT GENERAL CONTROLS (ITGC)?What is a control ? Process developed by management Provides reasonable assurance: Operations effective & efficient Reliable financial reporting Compliance laws & regulations What are IT GENERAL CONTROLS (ITGC)? Used to manage risks control someone s behavior Examples: Policies & procedures Approvals Reconciliations SoD(Segregation of Duties)What are IT GENERAL CONTROLS (ITGC)?
2 What are IT GENERAL CONTROLS (ITGC)? Process developed by management Provides reasonable assurance that: Operations effective & efficient Reliable financial reporting Compliance laws & regulations Used to manage technology risksWhat are IT GENERAL CONTROLS (ITGC)?What s the difference???5/11/20112 What are IT GENERAL CONTROLS (ITGC)? ITGC affect everythingbased on technology Passwords Program Changes / System updates Roles / SoD Backups / Recovery 3rd-party providersWhat are IT GENERAL CONTROLS (ITGC)? ITGC are partof the entire system of internal controlWhat are IT GENERAL CONTROLS (ITGC)?
3 3 main technology areas:1. System (servers)2. Network3. Applications What are IT GENERAL CONTROLS (ITGC)? ITGC provide assurance that information systems are working as intended Rely on the information Legal / regulatory compliance Effective / efficient operationsWhat are IT GENERAL CONTROLS (ITGC)?Center for Internet Security Applying ITGC consistently Protects against 85%+of top vulnerabilities reported by: NIST FBI SANS Institute Computer Security InstituteWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud .. Financial statements schemes Asset misappropriation schemes Fraudulent disbursements Theft of assets/inventory Bribery / Conflicts of interest5/11/20113 What are IT GENERAL CONTROLS (ITGC)?
4 Without effective ITGC, where is the fraud .. Theft of Intellectual Property Financial Institution Fraud Check & Credit Card Fraud Insurance Fraud Health Care Fraud Securities FraudWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud .. Consumer Fraud Identity Theft Computer / Internet Fraud Public Sector FraudWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud ..Almost everywheresince we use technology Store information Make decisions5 Areas for Review1. IT Entity-Level2. Change Management3.
5 Information Security4. Backup and Recovery5. 3rd-party IT Providers5 Areas for ReviewNormally done by IT Auditors Technology skills/background Can be performed by Operational/financial auditors IT Security / Compliance5 Areas for ReviewNeed to determine the key information technology risks Framework (NIST, COBIT) IT Management 5/11/201145 Areas for ReviewWhat 3-5 things keep them awake at night?5 Areas for Review1. IT Entity-Level Need to understand IT involvement Assess IT complexity Low COTS, 1 server, 1-15 users High ERP and/or customized, 4+ servers, 30+ users5 Areas for Review1.
6 IT Entity-Level Impact to the system? Mitigating CONTROLS ?5 Areas for Review1. IT Entity-Level Policies & procedures Acceptable Use Found in Employee Manual5 Areas for ReviewWhat about .. USB Thumb DrivesYour data has legs!5 Areas for ReviewWhat about .. SmartphonesYour data has legs!5/11/201155 Areas for ReviewWhat about .. Rogue wireless access pointsYour network is OPEN!5 Areas for Review Acceptable Use Information Security responsibilitiesYOUare responsible for your company s data!5 Areas for Review1. IT Entity-Level Annual Technology Plan Annual Budget Prioritization of IT projects 5 Areas for Review2.
7 Change Management All changes to system Properly authorized Securely implemented SoDis important!5 Areas for Review2. Change Management Vendor does changes Access always on? Logging access times? Review key reports before/after changes?5 Areas for Review2. Change Management Key Spreadsheets Locked down? Protected formulas? Restricted access?5/11/201165 Areas for ReviewImpact of Spreadsheet Errors Data entry error of $118,000 $11M severance error $30M spreadsheet error $644M misstatementStatistics from 2006 ACL White Paper Spreadsheets5 Areas for Review3.
8 Information Security Physical Security Passwords User IDs Roles in the system Administrators / Super Users Logging Encryption5 Areas for Review3. Information Security Wireless Access5 Areas for Review3. Information Security Physical Security5 Areas for Review3. Information Security Password best practices (NIST) Password length -8 Complex passwords 2/4 Upper / lower case Numeric (0-9) Special (!,@,#,$)5 Areas for Review3. Information Security Password best practices (NIST) Password history 90 days Suspended after 3 tries Change initial password Password history 8 5/11/201175 Areas for Review3.
9 Information Security Password best practices (NIST) Mitigating CONTROLS No dictionary words Regular training / awareness5 Areas for Review3. Information Security User IDs No sharing No generic IDs ( Clerk1) No default IDs/passwords 444 vendors, 1800+ passwords5 Areas for Review3. Information Security Roles in the system Simplify security administration Regularly reviewed?5 Areas for Review3. Information Security Administrators / Super Users Keys to the Kingdom 5 Areas for Review3. Information Security Administrators / Super Users Limited number Required for job duties Audit trail / logging Use only when necessary Periodic review5 Areas for Review3.
10 Information Security Logging Slows down system Critical changes/info Protected from Admins Regularly reviewed5/11/201185 Areas for Review3. Information Security Encryption Data at restWHY? Hacked Internal theft Backups are compromised5 Areas for Review3. Information Security Encryption Data in transitWHY? Packet sniffing -Wire theft War driving5 Areas for Review3. Information Security Wireless Access Wireless Access Policy Encryption MAC Address filtering5 Areas for Review4. Backup and Recovery Encrypted? Limited access5 Areas for Review5.