Showing posts with label CORPORATE CONTROLS. Show all posts
Showing posts with label CORPORATE CONTROLS. Show all posts

Thursday, December 15, 2016

Managing enterprises better in the 21st century

By John Kyriazoglou

1. Introduction

According to various sources1 ‘management control’ is a management function aimed at achieving defined goals within an established timetable, and usually understood to have three components:
(1) Setting standards,
(2) Measuring actual performance, and
(3) Taking corrective action.

In practical business terms, management controls, in a private company or public organizational environment, are used daily by managers and employees to accomplish the identified objectives of an organization (private company, public organization, or business entity, called ‘enterprise’ in this article).

Simply put, management controls are the operational methods that enable work to proceed as expected. 

Management is responsible for establishing and maintaining the business management control environment. Auditors play a role in a system of internal controls by performing evaluations and making recommendations for improved controls. Furthermore, every employee plays a role in either strengthening or weakening the specific company’s internal business management control system. Therefore, all employees need to be aware of the concept and purpose of internal business management controls.

How many, of these business management controls, however, does an enterprise need?


For more details, download the article from the following link:



Wednesday, October 28, 2015

IT CONTROLS AND HACKERS

By John Kyriazoglou*
The main purpose of IT Controls is to ensure the safe and secure operation of information systems and the protection from harm or other potential damage of the organization’s I.T. assets and data maintained by these systems. These objectives are achieved by a set of policies, procedures, practices, methods, techniques and technological measures, collectively called ‘controls’.
IT systems and infrastructure controls are classified as General IT Controls, i.e., controls applying to the whole of an organization’s Information Systems activity, and as IT Application Controls, which are specific to a given application, such as payroll processing, general ledger accounting, accounts receivable, etc. Both of these types of controls, within any type of organization (private, public, etc.), must operate within the greater framework of corporate governance and internal controls system, to fulfill their purpose to the fullest.
Sometimes the boundary line between these control types  (General IT Controls, IT Application Controls) is rather arbitrary, particularly in client/server, web-based and cloud computing applications, most of which may run on several computers.
What is important and crucial is for IT management, systems development professionals and other stakeholders (auditors, fraud examiners, etc.) is to realize that a comprehensive and effective combination of both of these control types (General IT Controls and IT Application Controls) arer required to ensure, as much as possible, an adequately safe and secure processing environment. We need to be proactive, plan and prepare both ourselves and our organizations for possible attacks, frauds committed, and errors occurring to information systems, disasters to IT facilities, and unusual events.
We should probably note that modern intruders to IT systems and networks do not publish their tools, successful or failed attacks or profits. They act with anonymity, quietly, in a step-by-step approach, from both inside and outside the organization, across the planet, and they usually cover their trail.
The players now include terrorists, white collar criminals, hackers, open source. The global underground cyber criminal community is actually trying to do better than what we do. Ten years ago, people sold you user IDs and passwords. Now the menu includes your CVs, ATM and credit cards with pin numbers, whole e-mail inboxes. They will ship information to anywhere in the world for money.
There is an army of them with new skills and capabilities.
There are: mappers, scanners, hackers, crackers, password sniffers, readers and shooters with van Eck tools, programmers who write code to enter network and application systems without leaving a trail, moles (personnel) employed to work in an organization much before it is attacked, vendors who sell illegal and improper hardware and software, social engineers who get passwords and other sensitive information by various means, etc.
They need to be controlled by society on the one hand, by the enactment of rules, regulations, laws, ethics codes, etc., and by organizations on the other hand, by devising and implementing overall corporate and detail IT controls.
Corporate and IT control issues are quite complex and may be included in corporate and business strategic and operational concerns, rather than on their own ground, as such. Detail IT controls require far more than the latest methods, practices and software tools or technology. Organizations must understand very precisely what IT entities, data, media, systems, services, and assets they are trying to protect, and why, before selecting any general or specific IT control solutions.
We also must note that according to recent international data breaches cases data privacy and protection shortcomings can do irreparable harm to companies’ balance sheets, not to mention their brands, credibility and customer trust and relationships.
IT management, IT professionals, IT auditors, Internal auditors, fraud experts, etc., must be always on their guard to protect their organizations, the data stored and reported by their IT systems, and the greater society, by using, implementing and improving IT controls and methods in a most efficient and effective way.
IT controls, operating within the greater IT Governance Practices Framework, can create value for an organization, as we have seen in several consulting projects for various clients.
It is our mission, moral duty, responsibility and job to do this. IT application systems are the life-blood of organizations. Quick dissemination of correct and timely information drives forward, enables and facilitates our national and global economies, benefiting everyone across the globe.
We need to work hard to achieve effective and working IT controls. As Menander (ancient Greek writer, 342-291 B.C.) has said: ‘He who labors diligently need never despair; for all things are accomplished by diligence and labor’.
We need to both plan and act. And as William Shakespeare has said: ‘Be great in act, as you have been in thought’.
We must be persistent in reaching the goal of controls, and be aware of what Friedrich Nietzsce has said: ‘Many are stubborn in pursuit of the path they have chosen, few in pursuit of the goal’
Last but no least, we may require to be disciplined in our approach, because as Abraham Lincoln has said: ‘Be sure you put your feet in the right place, then stand firm’.
For more specific details on IT Controls as well as Business Management Controls see the following books by John Kyriazoglou:

1. Book ‘IT Strategic & Operational Controls’, 2010, IT Governance, U.K.
2. Book ‘Business Management Controls: A Guide’, 2012, IT Governance U.K.

3. Book ‘Business Management Controls: Toolkit’, 2012, IT Governance U.K.      

Friday, December 14, 2012

OECD IT Security Guidelines


OECD IT Security Guidelines

John Kyriazoglou*
Establishing the IT security guidelines and standards (in general terms) for the specific organization should be done by the IT committee and ratified by the board. These standards could follow international guidelines and frameworks issued by organizations such as OECD, NIST (U.S.A.),  European Union, IATF, ISO (ISO/IEC 17799, ISO/IEC 27001, ISO 13335, ISO 15408), U.S. Federal Information Processing Standard (FIPS 140), etc.

I have used the following security principles of OECD in my IT security projects and particularly when large public or private organizations are involved.

PRINCIPLE 1: Awareness. Participants should be aware of the need for security of information systems and networks and what they can do to enhance security.

PRINCIPLE 2: Responsibility. All participants are responsible for the security of information systems and networks.

PRINCIPLE 3: Response. Participants should act in a timely and co‑operative manner to prevent, detect and respond to security incidents.

PRINCIPLE 4: Ethics. Participants should respect the legitimate interests of others.

PRINCIPLE 5: Democracy. The security of information systems and networks should be compatible with essential values of a democratic society.

PRINCIPLE 6: Risk assessment. Participants should conduct risk assessments.

PRINCIPLE 7: Security design and implementation. Participants should incorporate security as an essential element of information systems and networks.

PRINCIPLE 8: Security management. Participants should adopt a comprehensive approach to security management.

PRINCIPLE 9: Reassessment. Participants should review and reassess the security of information systems and networks, and make appropriate modifications to security policies, practices, measures and procedures.

 


John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto)

International IT and Management Consultant, author of several books



SSRN Free Publications: http://ssrn.com/author=1315434

 

 

Monday, September 10, 2012

Business Data Security Checklist


Business Data Security Checklist

 

John Kyriazoglou*

 

A business data security policy and related procedures should include protection controls and measures that cover the following issues:

1. Comprehensive due diligence of all critical staff, including external parties (outsourcing, external suppliers, sub-contractors, etc.). 

2. Authentication of all customers.

3. Non repudiation and accountability for all on-line transactions.

4. Segregation of duties.

5. Authorization controls.

6. Business data, transactions, records and information integrity.

7. Transactions audit trails.

8. Information confidentiality.

9. Appropriate disclosures for organizational services.

10. Data privacy.

11. Business continuity and contingency planning.

12. Security and other crises incident response planning.

13. Access controls: encryption, passwords, password control devices, tokens, user authentication devices, anti-hacking tools/techniques, digital signals origin identification, anti-tapping tools/techniques.

14. Data confidentiality.                             

15. Data integrity.

16. Anti-virus and e-crime detection software.

17. Time stamping.

18. Biometrics.

19. Digital signatures.

20. Smart cards.                            

 

 

John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto)

International IT and Management Consultant, author of several books



SSRN Free Publications: http://ssrn.com/author=1315434

 

 

Tuesday, May 29, 2012


WHISTLE BLOWING AND CORPORATE CRIME

By John Kyriazoglou*




Remember that 'whistleblowers' are considered as 'traitors' in many corporate and social environments as they are breaching the norms of the social group and destroying the cohesion and harmony and emotional contracting process of the social group they belong to (i.e. their own company group). 

You see 'whistleblowing' is a 'hard' control, and it, alone, cannot deal with corporate crimes, very well. If you want to study why people commit corporate crimes and protect the company from such events you must look at the whole  set of 'soft' issues, as well.

Hard controls are formal policies and procedures and how well or not they are designed and implemented. They relate to tangible things, usually well-defined, formalized and approved like organizational structure, assignment of authority and responsibility, corporate standards, policies and procedures, risk methodology, ethics code, compliance procedures, computerized systems, company books, registers, audit trail mechanisms, personnel controls like segregation of duties, taking vacation, job descriptions, confidentiality statements, etc.

These hard controls are implemented and used, in everyday business practice to carry out the activities of the organization, by various participants, i.e., people such as employees, managers, board members, customers, etc. These participants usually operate with their feelings, their beliefs, their trust and confidence, their motives, etc., collectively termed soft controls.

Soft controls are intangible things that have to do with behavioral aspects and social properties inherent in people (board members, executives, employees, etc.) and are utilized in applying hard controls in their daily business activities, and especially in business risk management, such as: tone at the top, understanding of the organization by the board, culture, structure of reporting relationships, morale, integrity and ethical values, operational philosophy, trust, Ethical climate, Empowerment, Corporate attitudes, Competences, Leadership, Employee motivation, Expectations, Openness and shared values, Information flow throughout the organization and emotional contracting.

I am afraid 'whistle blowing' will have to be complemented with improving all the other soft controls in order that corporate crimes are minimized at all.

John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto),

International IT and Management Consultant (with over 35 years of experience),

Editor-in-Chief for the Internal Controls Magazine, www.theiic.org

Author of several books:

(1) ‘IT Strategic and Operational Controls’, Publisher: www.itgovernance.co.uk


(2) ‘Addendum to IT Strategic & Operational Controls’

This book contains over 60 of IT audit programs and checklists in all IT audit areas.

Direct Link: www.itgovernance.co.uk/products/3143

(3) ‘Corporate Strategic and Operational Controls’, Publisher: www.theiic.org

with Dr. F. Nasuti and Dr. C. Kyriazoglou.


(4) ‘Implementing Management Controls for Small and Medium-Size Companies   

AMAZON Kindle Books:www.amazon.com


(5) ‘Business Management Controls: A Guide’, Publisher: www.itgovernance.co.uk

Expected to be published within 2012

(6) ‘Pearls of Wisdom of the 7 Sages of Ancient Greece

AMAZON Kindle Books:www.amazon.com




SSRN Free Publications: http://ssrn.com/author=1315434



Thursday, March 8, 2012

CORPORATE CONTROLS BOOK PUBLISHED


Announcement of New Book
Hi,
I am glad to announce my new book 'Corporate Strategic and Operational Controls', as described, in summary, next.
This book is about corporate controls (such as frameworks, terms of reference (charters), methodologies, management plans, policies, procedures, forms, performance measures, and audit programs and checklists) and how these controls: (a) enable, facilitate and support board members, management and staff to drive, control, manage and evaluate the organization’s social and economic performance, and (b) allow the organization’s stakeholders to monitor and assess the specific organization and both its outcomes and results. The book is structured in three parts and an appendix.

The first part (two chapters) identifies the basic concepts of controls and defines the control framework within which all organizations must operate.

Chapter 1: Introduction to Management, Regulations and Controls  

Chapter 2: Proposed Organizational Controls Framework

The second part (eight chapters) identifies the main organizational controls and defines the specific corporate control elements (policies, structures, procedures, measures, etc.) which could be utilized and improved by all organizations.

Chapter 3: Corporate Philosophy Controls, Chapter 4: Corporate Governance Controls

Chapter 5: Strategic Management Controls, Chapter 6: Financial Controls, Chapter 7: Administrative Controls, Chapter 8: Human Resource Controls, Chapter 9: Production Controls, Chapter 10: Information Technology (IT) Controls

The third part (three chapters) describes the elements required to design, implement and monitor strategic and operational control systems more efficiently and effectively.

Chapter 11: Designing Strategic and Operational Controls

Chapter 12: Implementing Strategic and Operational Controls with the BSC

Chapter 13: Monitoring and Review Controls.

The appendix contains various codes, examples of BSC implementations, strategic tools, a glossary and an extended bibliography.

The book also contains descriptions (examples) of: five performance  frameworks, ten terms of reference (charters) of corporate departments, nine methodologies, eleven management plans, twenty-three policies, eight procedures, five forms, over 140 performance  measures, and forty audit programs and checklists.

AUTHORS: John Kyriazoglou and Frank Nasuti, Ph.D.

                       with contribution by Christos Kyriazoglou, Ph.D.

ISBN: 978-0-557-77254-4

Publisher: The Institute for Internal Controls (U.S.A.)-Spring, 2012. www.theiic.org

Sincerely,

John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A(Hon-University of Toronto), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk)




Friday, January 27, 2012

Performance Measurement for Organizations (Greek)

Performance Measurement for Organizations (Greek)

Γιατί χρειάζεται Μέτρηση Απόδοσης σε Επιχειρήσεις και Οργανισμούς




                                          Του Ι. Κυριαζόγλου*



‘Παντού οι πόλεις όταν προκηρύσσουν διαγωνισμό για το κτίσιμο των ναών ή κολοσσών, ακούν τους τεχνίτες που αμιλλώνται συζητώντας για την εργολαβία και παρουσιάζουν τα επιχειρήματά τους και τα παραδείγματα, μετά διαλέγουν αυτόν που θα εκτελέσει το ίδιο έργο με τη χαμηλότερη δαπάνη, καλύτερη ποιότητα και ταχύτερα’.



                                  Πλούταρχος, Ηθικά Ηθικά 3, 498 Ε



Εισαγωγή

Ζούμε σε μια μεταβιομηχανική κοινωνία, την κοινωνία της γνώσης, των εικόνων, της πληροφορίας  και του γρήγορου θεάματος. Ο νέος τρόπος ζωής επιβάλλει ένα νέο σύνολο χαρακτηριστικών λειτουργίας της κοινωνίας μας, ακόμη και στην Ελλάδα.

Αυτό το σύνολο διέπεται από διάφορους παράγοντες και χαρακτηριστικά λειτουργίας, όπως: Παγκοσμιοποίηση αγορών, απελευθέρωση αγορών, οικονομία των υπηρεσιών, συνεχείς εξελίξεις στην τεχνολογία Πληροφορικής, Επικοινωνιών, Βιολογίας, Ιατρικής, Διοίκησης, κτλ., πλουραλισμός στην πληροφόρηση, αύξηση της επιρροής και εστίαση στις ανάγκες των πελατών και πολιτών, και αποδυνάμωση της προσέγγισης της κεντρικής οργάνωσης του παραδοσιακού κράτους σε ένα μοντέλο οργάνωσης πιο αποκεντρωτικό. Όλα αυτά αλληλοσυνδεόμενα, διαμορφώνουν ένα νέο κοινωνικό, οικονομικό, τεχνολογικό, ηθικό και πολιτικό πλαίσιο λειτουργίας της κοινωνίας, της οικονομίας, των επιχειρήσεων, των οργανισμών, των κοινοτήτων, των πολιτών, κτλ.

Αναδεικνύονται πιο σύνθετοι ρόλοι για το κράτος (κεντρική και περιφερειακές διοικήσεις, τοπική αυτοδιοίκηση, κτλ.), για τις επιχειρήσεις (μικρές, μεσαίες, μεγάλες) και για τους οργανισμούς (δημόσιου και ευρύτερου δημόσιου συμφέροντος), ως βασικοί συντελεστές στην κοινωνική και οικονομική ανάπτυξη, προοπτική, ευημερία και εξέλιξη σε όλους τους τομείς και πεδία εφαρμογής.



Γιατί χρειάζεται σύστημα απόδοσης



Ο διάσημος διανοητής σε θέματα διοίκησης επιχειρήσεων Charles Handy  υποστηρίζει ότι πρέπει να επανεξετάσουμε τις βασικές αρχές που διέπουν τις επιχειρήσεις και οργανισμούς, και να αναρωτηθούμε εκ νέου ποιος είναι ο βασικός στόχος του ‘επιχειρείν’. (Βλ. Επίσης την μελέτη της Διεθνούς Τράπεζας ‘Doing business in a more transparent world 2012’: www.doingbusiness.org).

Το ίδιο ισχύει και για το ρόλο του Ελληνικού κράτους, τόσο στο πλαίσιο της Ευρωπαϊκής Ένωσης, όσο και στο διεθνές περιβάλλον, με την προσέγγιση της ηλεκτρονικής διακυβέρνησης (e-government), της εξυπηρέτησης από ένα σημείο (one-stop shop services, όπως τα ΚΕΠ: www.kep.gov.gr) και της παραχώρησης αρμοδιοτήτων σε τοπικές αρχές (περιφέρειες, νομαρχίες, δήμοι, κτλ.).

Όλες αυτές οι νέες και ραγδαίως εφαρμοσμένες προσεγγίσεις πηγάζουν από την ανάγκη για ταχύτερη και αποτελεσματικότερη εξυπηρέτηση, πιο ορθολογική διαχείριση εταιρικών και άλλων πόρων για την ωφέλιμη επιβίωση και ανάπτυξη της επιχείρησης/οργανισμού και συνεχή βελτιστοποίηση της ποιότητας εξυπηρέτησης.

Έτσι δημιουργείται ένα πλαίσιο εξυπηρέτησης (Σχήμα 1) το οποίο βασίζεται στην κύρια αντίληψη ότι για την  επίτευξη των ανωτέρω, απαιτείται η σχεδίαση και υλοποίηση ενός νέου μοντέλου λειτουργίας (εταιριών και οργανισμών), το οποίο θα έχει ως κύριο συστατικό το Πλαίσιο Μέτρησης Απόδοσης.



Πλαίσιο Μέτρησης Απόδοσης
1. Οι Κοινωνικές Ανάγκες (Πελατών Πολιτών) για καλύτερες υπηρεσίες και προιόντα
2. Απαιτούν μια αποτελεσματική Στρατηγική της Επιχείρησης/Οργανισμού για καλύτερα αποτελέσματα (υπηρεσίες, προιόντα, απόδοση επιχείρησης)
3. Μέσω της Επίλυσης Προβλημάτων και της Βελτίωσης Παραγωγικών Διαδικασιών
4. Που επιτυγχάνονται πιο αποδοτικά με Μεθόδους, Κίνητρα, Εκπαίδευση  και Κατάρτιση του Προσωπικού
5. Και τα οποία (Αποτελέσματα) πρέπει να Μετρηθούν για να βελτιωθούν



Σχήμα 1: Πλαίσιο Αναγκών Μέτρησης Απόδοσης

Επίσης η απόδοση μιας επιχείρησης ή οργανισμού επηρεάζεται τόσο από το εσωτερικό περιβάλλον λειτουργίας και  τη συνολική δυνατότητα και διαθεσιμότητα των πόρων  της επιχείρησης / οργανισμού, όσο και από το εξωτερικό περιβάλλον της (νομικό, θεσμικό, κανονιστικό πλαίσιο, διεθνείς υποχρεώσεις, πρότυπα λειτουργίας, κοινωνία, κτλ.).



Στόχοι του συστήματος απόδοσης



Οι στόχοι του συστήματος μέτρησης απόδοσης καθορίζονται ως εξής:

1. Να βοηθήσει και να υποστηρίξει τη Διοίκηση, τα στελέχη και το προσωπικό επιχειρήσεων και οργανισμών να εκτελέσουν την στρατηγική και όλες τις απαιτούμενες εργασίες με τον πιο σωστό και αποτελεσματικό τρόπο, εντός ενός δημιουργικού επιχειρηματικού και ηθικού πλαισίου διακυβέρνησης.

2. Να ενισχύσει και να ενδυναμώσει τη σωστή διακυβέρνηση και την αποτελεσματική περάτωση όλων των λειτουργιών, συναλλαγών και δραστηριοτήτων της επιχείρησης ή του οργανισμού.

3. Να βελτιώσει την αποδοτικότητα της επιχείρησης / οργανισμού και την επισκόπηση της από όλα τα ενδιαφερόμενα μέρη (κοινωνικούς και θεσμικούς εταίρους, ρυθμιστικές και κανονιστικές αρχές, επιτροπές ελέγχου, μετόχους, κτλ.)

4. Να ενισχύσει και να ενδυναμώσει τη χρήση και την αξιοποίηση των πιο αποτελεσματικών συστημάτων μέτρησης απόδοσης με την ανταλλαγή πρακτικών εμπειριών από διαφορετικά επιχειρηματικά, κοινωνικά και οικονομικά περιβάλλοντα.









Συμπέρασμα



Ο νέος κόσμος του ανταγωνισμού λειτουργεί με κέντρο τον πελάτη/πολίτη και την ικανοποίηση των αναγκών του και διέπεται, στην πράξη, από τα εξής:

1. Μείωση κόστους. Οι επιχειρήσεις δεν μπορούν να αυξάνουν τις τιμές σε συνάρτηση με το κόστος. Πρέπει να ελέγχουν το κόστος και την τιμή των προϊόντων και υπηρεσιών, διότι ο πελάτης συνεχώς αναμένει καλύτερα προϊόντα και υπηρεσίες αλλά δεν είναι διατεθειμένος να υποστεί μεγάλη αύξηση στις τιμές. Τι ίδιο ισχύει και για τους πολίτες (πελάτες) σχετικά με τις κρατικές υπηρεσίες.

2. Άμεση απόδοση. Οι πελάτες/πολίτες ικανοποιούνται από ένα οικονομικό κλάδο, υπηρεσία ή προϊόν και αναμένουν το ίδιο και από τους άλλους κλάδους και υπηρεσίες. Οι επιχειρήσεις, οι οργανισμοί αλλά και οι κρατικές υπηρεσίες, δεν μπορούν παρά να παρέχουν άμεση απόδοση στις υπηρεσίες και τα προϊόντα που προσφέρουν στον πελάτη. 

3. Άριστη εξυπηρέτηση. Ο πελάτης/πολίτης απαιτεί να έχει άριστη εξυπηρέτηση και συνεχώς αυξάνει το επίπεδο αριστείας που αναμένει να του προσφερθεί. Οι επιχειρήσεις και οργανισμοί δεν πρέπει να θεωρήσουν ότι όταν παρέχουν μια καλή βασική εξυπηρέτηση, ο πελάτης/πολίτης θα είναι για πάντα ικανοποιημένος.

4. Καινοτομία. Ο πελάτης/πολίτης αναμένει καινοτόμα προϊόντα και υπηρεσίες από την συγκεκριμένη επιχείρηση, οργανισμό και δημόσια υπηρεσία. Αυτό σημαίνει ότι απαιτεί καλύτερη εξυπηρέτηση, με μείωση της σπατάλης του χρόνου του και με αξιοποίηση της νέας τεχνολογίας πληροφοριών και επικοινωνιών.



Το Πλαίσιο Μέτρησης Απόδοσης είναι το εργαλείο που συμβάλλει τα μέγιστα  στην αποδοτικότερη λειτουργία των επιχειρήσεων / οργανισμών τόσο του ιδιωτικού, όσο και του δημόσιου τομέα. Μέσω της μέτρησης και της αξιολόγησης της απόδοσής τους, οι επιχειρήσεις / οργανισμοί έχουν τη δυνατότητα να βελτιώνουν συνεχώς τα προϊόντα και τις υπηρεσίες τους και να αναπτύσσονται διαχρονικά.



*Βιογραφικά Στοιχεία



Ο Ι. Κυριαζόγλου, CICA, M.S.,B.A(Hon), είναι Σύμβουλος Επιχειρήσεων σε θέματα Οργάνωσης, Διοίκησης, Ελέγχου και Πληροφορικής με 35+ χρόνια διεθνούς εμπειρίας, και συγγραφέας πολλών άρθρων και βιβλίων όπως: ‘Έλεγχος Συστημάτων Πληροφορικής (www.anubis.gr, 2001), ‘Μέτρηση Απόδοσης για Επιχειρήσεις και Οργανισμούς’, Εκδόσεις ΙΩΝ, Αθήνα, 2005. (με δεύτερο συγγραφέα την κα Δ. Πολίτου), ‘Σκέψεις Αγάπης και Φιλίας’, ΥΑΔΕΣ, 2009, IT Strategic & Operational Controls, 2010, IT GOVERNANCE, U.K.(www.itgovernance.co.uk), ‘Corporate Controls’, 2012, www.theiic.org (με Dr. F. Nasuti & Dr. C. Kyriazoglou).



Blogs-Articles, Opinions, etc.: http://businessmanagementcontrols.blogspot.com/







Sunday, November 13, 2011

INFORMATION SENSITIVITY POLICY


INFORMATION SENSITIVITY POLICY

By John Kyriazoglou* (author’s credentials at the end of this document)

The primary objective of the Information Sensitivity Policy is to provide guidelines for the data classification issues of information collected and processed by information systems activities of an organization. This example may be used for educational purposes only and it should be amended to suit the particular organization’s legal and regulatory requirements and operating conditions, before it is put to effective use and is implemented in a real environment. The author assumes no responsibility whatsoever for the contents, suitability and accuracy of this policy.

An example of such a policy is described next.

  Company ‘XYZ-Fictitious Enterprise Corporation’ Information Sensitivity Policy

1. Purpose

The Information Sensitivity Policy of ‘XYZ-Fictitious Enterprise Corporation’ (referred to as Company, from now on), is intended to help management and staff of a corporate entity determine what information can be disclosed to non-employees, as well as the relative sensitivity of information that should not be disclosed outside of <Company Name> without proper authorization.

2. Coverage

The information covered in these guidelines includes, but is not limited to, information that is either stored or shared via any means. This includes: electronic information, information on paper, and information shared orally or visually (such as telephone and video conferencing).

3. Classification Definitions

All <Company> information is categorized into three main classifications: <Company> Public, or <Company> Confidential, or <Company> Restricted.

<Company> Public information is information that has been declared public knowledge by someone with the authority to do so, and can freely be given to anyone without any possible damage to < Company>.

<Company> Confidential contains all other information that is not public or restricted such as information stored in computer files and network servers, telephone directories, general corporate information, personnel information, etc., which is, however, critical to the every-day activities of the company.  

<Company> Restricted contains information that is more sensitive than other information, and should be protected in a more secure manner. This information includes: trade secrets, development programs, patents, copyrighted material, potential acquisition targets, and other information integral to the success of the company.

This classification, for all digital and non-digital information of the organization, should be carried out initially and reviewed and improved periodically by a management mechanism that includes: (a) Information Owners, (b) Information Systems Managers, and (c) Security Manager, with the support and advice of other corporate officers, such as data privacy officer, compliance officer, etc.

4. Encryption of Information

All <Company> Confidential and <Company> Restricted information should be encrypted in accordance with the Acceptable Encryption Policy. International issues regarding encryption are complex. Corporate guidelines on export controls on cryptography should be followed. For more details consult your manager and/or corporate legal services for further guidance.

5. Sensitivity Guidelines

The Sensitivity Guidelines below provide details on how to protect information at varying sensitivity levels.

5.1. <Company> Public: This relates to general corporate information, some personnel and technical information of a generalized nature.

Access: This information should be allowed to <Company> employees, contractors, and people with a business need to know. All accesses to this type of information should be authorized and recorded.

Distribution: Internal distribution of this information within <Company> should be carried out by standard inter-office mail, approved electronic mail and electronic file transmission methods. Distribution of this information outside of <Company’s> internal mail should be carried out by national mail and other public or private carriers, approved electronic mail and electronic file transmission methods. If this information is distributed in an electronic way, it should be sent to only approved recipients.

Storage: This information should be protected from loss. All electronic transmissions should have individual access controls where possible and appropriate.

Disposal/Destruction: Special disposal bins should be used for outdated paper information. Electronic data should be expunged, cleared and erased with specialized devices. Media should be physically destroyed.



5.2. <Company> Confidential: Business, financial, technical, and most personnel information.

Access: This information should be allowed to <Company> employees, contractors, and people with signed non-disclosure agreements who have a business need to know. All accesses to this type of information should be authorized and recorded.

Distribution: Internal distribution of this information within <Company> should be carried out by standard inter-office mail, approved electronic mail and electronic file transmission methods. Distribution of this information outside of <Company’s> internal mail should be carried out by national mail and other public or private carriers, approved electronic mail and electronic file transmission methods. If this information is distributed in an electronic way, it should be sent to only approved recipients.

Storage: This information should be protected from loss. All electronic transmissions should have individual access controls.

Disposal/Destruction: Special disposal bins should be used for outdated paper information. Electronic data should be expunged, cleared and erased with specialized devices. Media should be physically destroyed. All these actions should be authorized, recorded and reported.



5.3. <Company> Restricted: Trade secrets & marketing, operational, personnel, financial, source program code, & technical information integral to the success of <Company Name>.

Access: This information should be allowed to <Company> staff with signed non-disclosure agreements who have a specific board authorization. All accesses to this type of information should be recorded and reported.

Distribution within <Company>: This information should be delivered directly to the approved recipient upon their signatures. All envelopes should be stamped confidential. Electronic file transmissions should not be allowed.

Distribution outside of <Company> internal mail:  This information should be delivered directly, by approved private carriers, to the approved recipient upon their signatures. All envelopes should be stamped confidential. Electronic file transmissions should not be allowed.

Storage: Individual access controls to this information should be enforced for electronic information. Appropriate physical security measures should be used, and information should be encrypted and stored in a physically secured computer.

Disposal/Destruction: This information should be physically destroyed by paper shredders, and other specialized digital crunching devices. Digital media should be cleared and erased before disposal. All these actions should be authorized, recorded and reported.



6. Business Connections

Access to <Company> computers and information systems by business partners, competitors and unauthorized external personnel must be restricted so that, in the event of an attempt to access <Company> corporate information, the amount of information at risk is minimized. Connections may be set up to allow others (business partners, etc.) to see only what they need to see only when specifically authorized by the board. Unauthorized personnel should only have access to information classified as <Company> Public, upon recording their details and their needs for accessing this information. This involves setting up both applications and network configurations to allow access to only what is necessary. All these actions should be recorded and reported.



7. Penalties

The penalty for deliberate or inadvertent disclosure of any information by any staff member (management, board, professional staff, line employee, etc.) found to have violated this policy may include disciplinary action, up to and including termination of employment, possible civil and/or criminal prosecution to the full extent of the law.

8. Responsibility of management  

All <Company> personnel should use these guidelines in securing <Company> Restricted and <Company> Confidential information to the proper extent possible. All department heads are responsible to supervise the classification activities of all the information managed by their function. A register of such files should be maintained and reported to the senior management of the company. If a manager is not certain of the classification to be applied, he or she should contact a higher level of authority (such as CEO, Ethics Committee, Compliance Committee, Compliance Officer, Legal Department, etc.), as specified by the internal controls policy and practices of the company. 

9. Responsibility of staff  

If an employee is uncertain of the sensitivity of a particular piece of information, he/she should contact their manager. If an employee feels that their manager is not following these guidelines, he or she should contact a higher level of authority (such as CEO, Compliance Committee, Ethics Office, Compliance Officer, Legal Department, etc.), as specified by the internal controls policy and practices of the company. 

10. Responsibility of Compliance Officer  

It is the responsibility of the compliance officer to provide guidance to all personnel on the use of these guidelines, and ensure that these guidelines are complied with. The compliance officer should also report to both the compliance committee and the board, on the basis of the company’s reporting standards, all compliance related activities.

*Author’s Credentials

John Kyriazoglou, CICA, M.S.,B.A(Hon), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’ ( to be published in 2/2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou.


Profiles





Blogs

Articles, Opinions, etc.: http://corporatecontrols.blogspot.com/