The Importance Of Auditing IT Controls

Improved Essays
Are your policies and procedures something that sit on a shelf until the auditors and/or regulators ask to see them? Have they become akin to "Shelfware"? As I write this, my colleagues and I are very busy assisting companies with assessing risks, recommending security posture and well yeah, auditing IT controls too.

So what about policies and procedures? Where do they fit? Are they anything more than the product of “give the auditors what they want”? When was the last time or better yet, have you ever had meaningful dialogue around policies and procedures? Just in case you’ve forgotten, policies and procedures provide the framework within which your company operates.

Unfortunately far too many organizations "don 't know what they don 't know". There 's a presumption that the policy and procedure documentation will ultimately find its way back on the shelf unchanged (with the exception of a new signature) until the next time an auditor asks for it. So, why invest time and energy...and yes, money, into creating and re-engineering policy and procedure documentation? Below I have, at a high level, given a few of the primary reasons why creating or re-engineering policy and procedure documentation is critical to your business. We all have very busy professional lives so this is not intended to be a heavy technical read. Keep it simple right?! Please feel free to private message me with any comments or inquiries. I 'd be glad to discuss matters at a much deeper level if interested. Matters of Compliance - Whether your organization is interested in adopting or certifying to management and regulators to standards and guidelines such as ISO 270001, HIPAA, HITRUST CSF (Common Security Framework), PCI, COBIT or any other in a long list of compliance requirements, policies that reach across the entire organization such as an Information Security Policy, Access Control and Business Continuity, will be required (as an aside - COSO defines control activities as “the policies and procedures that help ensure management directives are carried out").
…show more content…
Many other policies while not required, do help establish a more robust control framework. Simply put, one 's organization can 't afford to be out of compliance. Policy and procedure documentation is often the first item requested (albeit sometimes not the first to be updated), and viewed as the foundation to a well-controlled organization. Tone at the Top - Cyber-security is a hot button topic...as it should be...but how much time is spent, after all the penetration tests, vulnerability scans, IDS …show more content…
It 's been my experience that many organizations underestimate the importance of well-planned and well written policies and procedures in their push towards confidentiality, integrity and availability...the ultimate goals of a sound information security framework. Policies and procedures are the critical underpinnings to a sustainable security posture. Specifically, the Information Security Policy, when well defined, is a set of instructions to help guide IT professionals define and enact security controls -including access and authentication methods. It will establish what the organization considers acceptable versus unacceptable behavior. Ultimately, when performed correctly, the exercise of creating the policy and procedure taxonomy, will communicate the tone at that the top to the rest of the organization. This communication will describe the cohesive strategy adopted, between IT and the rest of the organization...also known as aligning IT and the

Related Documents

  • Decent Essays

    Policy-based management: SQL server has a feature called policy-based management which is used to define and also implement policies in SQL server. It is used if we want to apply any policy against a table or database and then checks whether the database or table satisfies with the given policy. If target database objects are not satisfied with the policies then either a trigger should be fired or we can enforce it so that an administrator will come to know that there is some policy violation. It will manage one or more instances of SQL server.…

    • 391 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    Western Governors University A. Security Faults Describe three of the security faults in this scenario that caused a security breach. 1. Some accounts existed before the electronic health record(EHR) was deployed. Important steps were missed during the import of old accounts. I suggest using a clean base line for the brand new EHR system.…

    • 588 Words
    • 3 Pages
    Improved Essays
  • Decent Essays

    Information security policy is to protect the data and assets. We can apply policies to the users. What to access and what not to access. These security policies can protect the networks, computers, applications of the company.…

    • 342 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    Nt1310 Unit 9 Final Paper

    • 586 Words
    • 3 Pages

    Opening Statement Written policies provide a means of security within organization. It establishes the regulations that all faculty must adhere to in order to protect important company and client information. The organizational policies should be read by and signed by each employee as a consensus that all regulations will be followed once joining the organization. And, for those who are current employees, to keep abreast of any amendments made to current policy, so that all employees are in compliance. These policies should be kept in an accessible place for everyone to read, so no one will be left out of the loop.…

    • 586 Words
    • 3 Pages
    Improved Essays
  • Decent Essays

    Qcf Level 5 Unit 5

    • 220 Words
    • 1 Pages

    Based on the policy and produces in my children care (OOSH) out of school hours my staff roll is to encourage the children to learn and Ensure curriculum decision making contributes to each child learning and assist the children, assist with the implementation of the daily routines and use the daily routine times for the children learning. If I was to set goals the following information in my business plan would be forcing on the policy and produces such as the education program policy and Friendship with children and parents Policy and the staff arrangement policy in the work place These type policies provide information and the company values and adjective. Health and safety policy and produces the way the staff have to clean all equipment…

    • 220 Words
    • 1 Pages
    Decent Essays
  • Improved Essays

    1.1: The role of policies is to set out rules and directives in order to help staff in the setting to achieve their aims and objectives and are primarily there to assist them in making the right decisions. Policies will usually outline the requirements of what is necessary for staff to be aware of and what to abide by. They are also in keeping with the law and are set up in a way for both outside professional agencies and staff within the environment. They may also be there for parents to refer in order to keep themselves aware of the schools beliefs and values. Procedures on the other hand are the way these policies are carried out and they provide the staff with a guide of instructions based on how to go about their duties and be able to overcome certain issues.…

    • 670 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    Question: Question 12 Answer: Staff Policies and procedures are there to ensure staffâ€TMs health and welfare are protected and that there rights are supported. Some policies…

    • 613 Words
    • 3 Pages
    Improved Essays
  • Decent Essays

    Writing policies and procedures Ofsted do not require all of your policies and procedures in writing, however in doing so it helps you to demonstrate to Ofsted and prospective parents how your service works and how you meet the EYFS and Childcare requirements. Keep your policies and procedures clear and easy to understand. Each policy and procedure will contain different information but writing them should follow the general steps listed below. Step 1: Research Have a look in your EYFS pack and the Childcare register requirements to see what you must do to meet the current legislation.…

    • 435 Words
    • 2 Pages
    Decent Essays
  • Decent Essays

    Kyla, I have a similar situation at my workplace. Some policies are written by administrative staff and don’t cover all the aspects of tasks that are performed by staff. We too have a committee comprising of staff members, that routinely reviews policies and modifies them according to the situation. This practice has made workflow smoother and has increased staff involvement and satisfaction. In my experience, input from the staff, while developing a policy, makes it easy to follow and more effective.…

    • 81 Words
    • 1 Pages
    Decent Essays
  • Decent Essays

    Overregulation In Iraq

    • 392 Words
    • 2 Pages

    When I was stationed in Iraq I learned that during the transition from one command to another there should be a time that policies and procedures should remain the same until they can be evaluated to see if they work or need to be revised to be more efficient in completing the mission. I believe that taking over a department having numerous policies and procedures has more of an advantage than that of one with very few. If I were to inherit a department, I would prefer to take over a department with policies and procedures that were numerous. By having numerous policies and procedures it may regulate the officers too much but after reviewing and revising the policies and procedures of the department. Overregulation can simply be eased by revising…

    • 392 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    The policies are a guide on how issues should be dealt with in the organisation, Containing principles, morals and tasks for managers and…

    • 722 Words
    • 3 Pages
    Improved Essays
  • Improved Essays

    What is a policy? The dictionary defines policy as a deliberate system of principles to guide decisions and achieve rational outcomes. In other words a policy are set of rules of which we the people of the society are supposed to obey. If individuals do not follow the rules of a policy certain circumstances will play out. Every business has a policy no matter where you go, there are guidelines to follow.…

    • 1119 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    3. Marshalling resources behind the drive for good strategy execution and operating excellence. • An important element should be to give the great degree of standardizations to the local management align their own design and global strategy. • This will give a feeling of independence to the local management while the global standard will also be met. 4.…

    • 1492 Words
    • 6 Pages
    Improved Essays
  • Improved Essays

    Wasting money, time, effort and resource. If the organization security policy framework does not align with their objectives, the employees may try to find something else to help their security control, not using the current framework. Consequences when the framework doesn’t meet the requirements of organizational needs are they generally invest some money to…

    • 723 Words
    • 3 Pages
    Improved Essays
  • Decent Essays

    1. Public policy can be defined as steps that the government or any other organisation takes to achieve a certain goal. In this context, it is the government’s decision to act or not to act on an issue. Governments are able to get guidance and accountability from it. Various factors affect decision making, such as values.…

    • 871 Words
    • 4 Pages
    Decent Essays