Example: confidence

IT GENERAL CONTROLS What are IT General …

5/11/20111IT GENERAL CONTROLS &THE PREVENTION OF FRAUDEd Tobias, CISA, CIA, CFEMay 11, 2011 AGENDAWhat are IT GENERAL CONTROLS ?5 Areas for ReviewCase Study What are IT GENERAL CONTROLS (ITGC)?What is a control ? Process developed by management Provides reasonable assurance: Operations effective & efficient Reliable financial reporting Compliance laws & regulations What are IT GENERAL CONTROLS (ITGC)? Used to manage risks control someone s behavior Examples: Policies & procedures Approvals Reconciliations SoD(Segregation of Duties)What are IT GENERAL CONTROLS (ITGC)?

5/11/2011 1 IT GENERAL CONTROLS & THE PREVENTION OF FRAUD Ed Tobias, CISA, CIA, CFE May 11, 2011 A What are IT General Controls? GENDA 5 Areas for Review

Tags:

  General, Control, It general controls, It general

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of IT GENERAL CONTROLS What are IT General …

1 5/11/20111IT GENERAL CONTROLS &THE PREVENTION OF FRAUDEd Tobias, CISA, CIA, CFEMay 11, 2011 AGENDAWhat are IT GENERAL CONTROLS ?5 Areas for ReviewCase Study What are IT GENERAL CONTROLS (ITGC)?What is a control ? Process developed by management Provides reasonable assurance: Operations effective & efficient Reliable financial reporting Compliance laws & regulations What are IT GENERAL CONTROLS (ITGC)? Used to manage risks control someone s behavior Examples: Policies & procedures Approvals Reconciliations SoD(Segregation of Duties)What are IT GENERAL CONTROLS (ITGC)?

2 What are IT GENERAL CONTROLS (ITGC)? Process developed by management Provides reasonable assurance that: Operations effective & efficient Reliable financial reporting Compliance laws & regulations Used to manage technology risksWhat are IT GENERAL CONTROLS (ITGC)?What s the difference???5/11/20112 What are IT GENERAL CONTROLS (ITGC)? ITGC affect everythingbased on technology Passwords Program Changes / System updates Roles / SoD Backups / Recovery 3rd-party providersWhat are IT GENERAL CONTROLS (ITGC)? ITGC are partof the entire system of internal controlWhat are IT GENERAL CONTROLS (ITGC)?

3 3 main technology areas:1. System (servers)2. Network3. Applications What are IT GENERAL CONTROLS (ITGC)? ITGC provide assurance that information systems are working as intended Rely on the information Legal / regulatory compliance Effective / efficient operationsWhat are IT GENERAL CONTROLS (ITGC)?Center for Internet Security Applying ITGC consistently Protects against 85%+of top vulnerabilities reported by: NIST FBI SANS Institute Computer Security InstituteWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud .. Financial statements schemes Asset misappropriation schemes Fraudulent disbursements Theft of assets/inventory Bribery / Conflicts of interest5/11/20113 What are IT GENERAL CONTROLS (ITGC)?

4 Without effective ITGC, where is the fraud .. Theft of Intellectual Property Financial Institution Fraud Check & Credit Card Fraud Insurance Fraud Health Care Fraud Securities FraudWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud .. Consumer Fraud Identity Theft Computer / Internet Fraud Public Sector FraudWhat are IT GENERAL CONTROLS (ITGC)?Without effective ITGC, where is the fraud ..Almost everywheresince we use technology Store information Make decisions5 Areas for Review1. IT Entity-Level2. Change Management3.

5 Information Security4. Backup and Recovery5. 3rd-party IT Providers5 Areas for ReviewNormally done by IT Auditors Technology skills/background Can be performed by Operational/financial auditors IT Security / Compliance5 Areas for ReviewNeed to determine the key information technology risks Framework (NIST, COBIT) IT Management 5/11/201145 Areas for ReviewWhat 3-5 things keep them awake at night?5 Areas for Review1. IT Entity-Level Need to understand IT involvement Assess IT complexity Low COTS, 1 server, 1-15 users High ERP and/or customized, 4+ servers, 30+ users5 Areas for Review1.

6 IT Entity-Level Impact to the system? Mitigating CONTROLS ?5 Areas for Review1. IT Entity-Level Policies & procedures Acceptable Use Found in Employee Manual5 Areas for ReviewWhat about .. USB Thumb DrivesYour data has legs!5 Areas for ReviewWhat about .. SmartphonesYour data has legs!5/11/201155 Areas for ReviewWhat about .. Rogue wireless access pointsYour network is OPEN!5 Areas for Review Acceptable Use Information Security responsibilitiesYOUare responsible for your company s data!5 Areas for Review1. IT Entity-Level Annual Technology Plan Annual Budget Prioritization of IT projects 5 Areas for Review2.

7 Change Management All changes to system Properly authorized Securely implemented SoDis important!5 Areas for Review2. Change Management Vendor does changes Access always on? Logging access times? Review key reports before/after changes?5 Areas for Review2. Change Management Key Spreadsheets Locked down? Protected formulas? Restricted access?5/11/201165 Areas for ReviewImpact of Spreadsheet Errors Data entry error of $118,000 $11M severance error $30M spreadsheet error $644M misstatementStatistics from 2006 ACL White Paper Spreadsheets5 Areas for Review3.

8 Information Security Physical Security Passwords User IDs Roles in the system Administrators / Super Users Logging Encryption5 Areas for Review3. Information Security Wireless Access5 Areas for Review3. Information Security Physical Security5 Areas for Review3. Information Security Password best practices (NIST) Password length -8 Complex passwords 2/4 Upper / lower case Numeric (0-9) Special (!,@,#,$)5 Areas for Review3. Information Security Password best practices (NIST) Password history 90 days Suspended after 3 tries Change initial password Password history 8 5/11/201175 Areas for Review3.

9 Information Security Password best practices (NIST) Mitigating CONTROLS No dictionary words Regular training / awareness5 Areas for Review3. Information Security User IDs No sharing No generic IDs ( Clerk1) No default IDs/passwords 444 vendors, 1800+ passwords5 Areas for Review3. Information Security Roles in the system Simplify security administration Regularly reviewed?5 Areas for Review3. Information Security Administrators / Super Users Keys to the Kingdom 5 Areas for Review3. Information Security Administrators / Super Users Limited number Required for job duties Audit trail / logging Use only when necessary Periodic review5 Areas for Review3.

10 Information Security Logging Slows down system Critical changes/info Protected from Admins Regularly reviewed5/11/201185 Areas for Review3. Information Security Encryption Data at restWHY? Hacked Internal theft Backups are compromised5 Areas for Review3. Information Security Encryption Data in transitWHY? Packet sniffing -Wire theft War driving5 Areas for Review3. Information Security Wireless Access Wireless Access Policy Encryption MAC Address filtering5 Areas for Review4. Backup and Recovery Encrypted? Limited access5 Areas for Review5.


Related search queries