Showing posts with label INTERNAL CONTROLS. Show all posts
Showing posts with label INTERNAL CONTROLS. Show all posts

Wednesday, October 28, 2015

IT CONTROLS AND HACKERS

By John Kyriazoglou*
The main purpose of IT Controls is to ensure the safe and secure operation of information systems and the protection from harm or other potential damage of the organization’s I.T. assets and data maintained by these systems. These objectives are achieved by a set of policies, procedures, practices, methods, techniques and technological measures, collectively called ‘controls’.
IT systems and infrastructure controls are classified as General IT Controls, i.e., controls applying to the whole of an organization’s Information Systems activity, and as IT Application Controls, which are specific to a given application, such as payroll processing, general ledger accounting, accounts receivable, etc. Both of these types of controls, within any type of organization (private, public, etc.), must operate within the greater framework of corporate governance and internal controls system, to fulfill their purpose to the fullest.
Sometimes the boundary line between these control types  (General IT Controls, IT Application Controls) is rather arbitrary, particularly in client/server, web-based and cloud computing applications, most of which may run on several computers.
What is important and crucial is for IT management, systems development professionals and other stakeholders (auditors, fraud examiners, etc.) is to realize that a comprehensive and effective combination of both of these control types (General IT Controls and IT Application Controls) arer required to ensure, as much as possible, an adequately safe and secure processing environment. We need to be proactive, plan and prepare both ourselves and our organizations for possible attacks, frauds committed, and errors occurring to information systems, disasters to IT facilities, and unusual events.
We should probably note that modern intruders to IT systems and networks do not publish their tools, successful or failed attacks or profits. They act with anonymity, quietly, in a step-by-step approach, from both inside and outside the organization, across the planet, and they usually cover their trail.
The players now include terrorists, white collar criminals, hackers, open source. The global underground cyber criminal community is actually trying to do better than what we do. Ten years ago, people sold you user IDs and passwords. Now the menu includes your CVs, ATM and credit cards with pin numbers, whole e-mail inboxes. They will ship information to anywhere in the world for money.
There is an army of them with new skills and capabilities.
There are: mappers, scanners, hackers, crackers, password sniffers, readers and shooters with van Eck tools, programmers who write code to enter network and application systems without leaving a trail, moles (personnel) employed to work in an organization much before it is attacked, vendors who sell illegal and improper hardware and software, social engineers who get passwords and other sensitive information by various means, etc.
They need to be controlled by society on the one hand, by the enactment of rules, regulations, laws, ethics codes, etc., and by organizations on the other hand, by devising and implementing overall corporate and detail IT controls.
Corporate and IT control issues are quite complex and may be included in corporate and business strategic and operational concerns, rather than on their own ground, as such. Detail IT controls require far more than the latest methods, practices and software tools or technology. Organizations must understand very precisely what IT entities, data, media, systems, services, and assets they are trying to protect, and why, before selecting any general or specific IT control solutions.
We also must note that according to recent international data breaches cases data privacy and protection shortcomings can do irreparable harm to companies’ balance sheets, not to mention their brands, credibility and customer trust and relationships.
IT management, IT professionals, IT auditors, Internal auditors, fraud experts, etc., must be always on their guard to protect their organizations, the data stored and reported by their IT systems, and the greater society, by using, implementing and improving IT controls and methods in a most efficient and effective way.
IT controls, operating within the greater IT Governance Practices Framework, can create value for an organization, as we have seen in several consulting projects for various clients.
It is our mission, moral duty, responsibility and job to do this. IT application systems are the life-blood of organizations. Quick dissemination of correct and timely information drives forward, enables and facilitates our national and global economies, benefiting everyone across the globe.
We need to work hard to achieve effective and working IT controls. As Menander (ancient Greek writer, 342-291 B.C.) has said: ‘He who labors diligently need never despair; for all things are accomplished by diligence and labor’.
We need to both plan and act. And as William Shakespeare has said: ‘Be great in act, as you have been in thought’.
We must be persistent in reaching the goal of controls, and be aware of what Friedrich Nietzsce has said: ‘Many are stubborn in pursuit of the path they have chosen, few in pursuit of the goal’
Last but no least, we may require to be disciplined in our approach, because as Abraham Lincoln has said: ‘Be sure you put your feet in the right place, then stand firm’.
For more specific details on IT Controls as well as Business Management Controls see the following books by John Kyriazoglou:

1. Book ‘IT Strategic & Operational Controls’, 2010, IT Governance, U.K.
2. Book ‘Business Management Controls: A Guide’, 2012, IT Governance U.K.

3. Book ‘Business Management Controls: Toolkit’, 2012, IT Governance U.K.      

Wednesday, December 10, 2014

New Book: Corporate Wellness: Management and Evaluation Toolkit

New Book: Corporate Wellness: Management and Evaluation Toolkit
I am glad to announce that this toolkit was just published and is available for your review and potential use at:

It contains material related to occupational stress and corporate wellness.
It contains:
1. A set of management improvement plans (with over 72 actions).
2. A stress policy.
3. Several stress performance measures.
4. Occupational Stress Audit Evaluation Questionnaires (Four audit questionnaires with over 87 questions to evaluate the stress level of people at all levels of your company, in terms of: Personal Happiness; Personal Stress; etc.).
5. Corporate Wellness Audit Questionnaires (18 audit questionnaires with over 90 questions to evaluate the Corporate Wellness of your company, in terms of: Tone at the Top; Understanding of the organization by the board; Operational philosophy; etc.).
6. Over 72 improvement actions.
7. An evaluation method that calculates an index for the person or entity taking going through the evaluation questions.

You may also check out the following documents for your business use.
1. Auditing and Improving Business Performance
2. Audit Report Model and Sample

Thank you,
John Kyriazoglou, CICA, B.A (Hon-University of Toronto),

Business Thinker, Consultant and Author of several books

Monday, August 26, 2013

Free E-BOOK: How To Improve Your Production


HOW TO IMPROVE YOUR PRODUCTION: Summary

By John Kyriazoglou

 

This book (in 2 parts) contains a wealth of general information on production systems, methods, policies, procedures, controls and management tools and offers several practical recommendations you may consider and use to improve your production operation.

 

Part 1 of this book, in summary, describes the main types of production controls, such as:

1. Production Policies and Procedures,

2. Production Management Duties and Responsibilities,

3. Manufacturing Process Controls,

4. Quality Management Controls, 

5. Standardization Procedures,

6. Production Performance Management Controls, and

7. Production Performance Measures for several areas (innovation, inventory control, manufacturing, production cost, etc.).




 
Title of Book: ‘How to Improve Your Production: Part I’
http://bookboon.com/en/how-to-improve-your-production-part-i-ebook




Part 2 of this book, presents additional items that facilitate, complement and support Part 1, such as:

1. Detail examples of various policies and procedures on purchasing, quality, health and safety, etc.

2. The steps of a methodology for establishing the production function and production policies and procedures.

3. Several audit programs and checklists.



 
Title of Book: ‘How to Improve Your Production: Part II’
http://bookboon.com/en/how-to-improve-your-production-part-ii-ebook
 



Wednesday, May 23, 2012

Business Management Controls for Small-Size Companies


Business Management Controls for Small-Size Companies


         By John Kyriazoglou*



‘Rule number 1: Never lose money. Rule number 2: Never forget rule number 1.’

                   Warren Buffet, CEO of Berkshire Hathaway

Abstract

This article deals with the business management controls for small-size companies. A business performance model for small companies of five dimensions (C1P4 Model (C one, four Ps), ‘C1’ for customers, ‘P1’ for people, ‘P2’ for property, ‘P3’ for production and ‘P4’ for performance) is introduced and five general recommendations with specific controls for each performance dimension are presented.
Key words: Small Business Controls, Internal Controls, Small Business Performance Model

1. Introduction



Managing a business, small, medium or large-size is quite a difficult, complicated and strenuous task. Whether you are the owner, major shareholder, CEO, Board Director or other corporate functionary, you must understand how your company works in all its strategic and operational aspects: governance, corporate management, risk assessment, compliance, strategy, operations, etc. You need to establish controls and comprehend, fully, their manifestations and impact, and employ the right internal control framework and its components to suit the specific aspects of the organization you lead, direct and manage.

In managing a small-size company, it is a matter of business life complements by my consulting experience that controlling a small business does not get any easier and in fact it is also to be considered a rather cumbersome task. Especially in the case of a sole company owner whereby the owner and the management of the business is usually the same person, the problem becomes worse.


Here are some recommendations and guidelines, as an example, to help with the aspects of controlling and managing more effectively a small-size business entity, on the basis of a business performance model of five dimensions: C1P4 Model (C one, four Ps), ‘C1’ for customers, ‘P1’ for people, ‘P2’ for property, ‘P3’ for production and ‘P4’ for performance.

2. Recommendations, Guidelines and Specific Controls



2.1. Business Performance Model Dimension C1: CUSTOMERS



Recommendation 1: Make your customer your number 1 priority.

This can be achieved by the following controls:

1. Identifying, attracting, increasing and maintaining your customers.

2. Establishing excellent customer sales and support function.

3. Developing and implementing your customer service policy.

4. Ensuring that you are selling, delivering and servicing highest-quality products and services.

5. Maintaining your effective sales ledger and other support systems.

6. Monitoring and reviewing your customer sales and support strategy and operations.

7. Improving your customer sales and support performance.



2.2. Business Performance Model Dimension P1: PERSONNEL



Recommendation 2: Manage your personnel properly and fairly.

This can be achieved by the following controls:

1. Screening of personnel during the hiring process,

2. Maintaining valid employment contracts and employee documentation (job application, job description, resume, records of participation in training events, salary history, records of disciplinary action and documents related to employee performance reviews, coaching, and mentoring),

3. Establishing authorization controls (for purchases, expenses, invoices, payments, contracts, investments, hiring and firing of personnel, transaction processing, file and records management activities, archiving of critical records, reports, and data, etc.), and implementing segregation of duties (where possible) or compensating controls (as required and if possible).

4. Communicating constantly your company’s ethics and values to all parties, and practicing what you preach,

5. Rewarding all your employees on performance,

6. Responding, resolving and punishing, if needed, all violators to your standards of practice,

7. Making decisions on accurate facts and data and by understanding of all your business functions and actions of individuals.



2.3. Business Performance Model Dimension
P2.: PROPERTY



Recommendation 3: Manage and protect your property with due care.

This can be achieved by the following:

1. Money and other financial assets can be managed and protected by establishing and implementing financial management controls, such as:

(a) Appointing a Financial Manager,

(b) Executing basic accounting and bookkeeping procedures (Chart of Accounts, General Ledger, Trial Balance, and Financial Statements),  

(c) Managing your Liabilities by noting down all payments and maintaining invoices, cheques and other payment documents,

(d) Managing Petty Cash, Payments, Accounts Receivable, Accounts Payable and Payroll, and

(e) Developing and monitoring your budget.

2. Physical property (buildings, plants, machinery, furniture, computers, etc.) can be managed and protected by establishing and implementing controls, such as:

(a) Security guards and protection systems,

(b) Asset Registers, and

(c) Taking Inventories,

3. Intangible assets (information systems, knowledge repositories, patents, etc.) can be managed and protected by establishing and implementing business management controls, such as:

(a) Registration of Patents, Copyrights and Trademarks,

(b) IT Governance controls (IT Manager, IT Security Policy, Password Controls, Computer Security Incident Controls, IT Backup and Disaster Recovery Plan, and Security and Safety Controls for Personal and other Computers holding corporate data, and valid maintenance contracts with bona-fide contractors for all hardware and systems),

(c) Business Continuity controls (Business Continuity Plan, IT Continuity Plan, IT Backup and Restore Policy and Procedures and Vital Records Package, and

4. Business Records can be protected by establishing effective policies and procedures to manage your business data. Keeping business records can be easy if they are organized well. Understand the nature of your business and then appoint people to maintain your business records.






Recommendation 4: Execute excellent production policies and procedures to satisfy the needs and expectations of your customers and optimize your production process.

This can be achieved by the following controls:

1. Developing, making or purchasing and pricing properly and a competitive basis your products and services,

2. Establishing effective purchasing procedures to avoid fraud and maintaining your purchase records (purchase ledger, invoices, checks, bank statements, bills payable and credit purchase slips, etc.) very well.
3. Executing effective inventory procedures and maintaining proper inventory records, and

4. Streamlining your production process by efficient procedures, and by maintaining proper manufacturing and production files (e.g., Bill of Materials (BOM) File, Master Production Schedule (MPS), Materials and vendors contingency list, and Equipment Operational Description File).





2.5. Business Performance Model Dimension P4: PERFORMANCE



Recommendation 5: Implement your business performance management controls with due care and an open mind.

This can be achieved by the following controls:

1. Implementing a performance management system by getting and deploying a Business Dashboard system or by a system suited to your purposes,

2. Establishing and executing a Continuous Business Management Monitoring Plan,

3. Monitoring and reviewing your operational data such as: customer sales and support strategy and operations, financial performance, production performance, etc.

4. Improving your financial, customer sales and support, and production performance.

5. Executing effective compliance and risk programs to ensure adherence to both to internal and external regulations,

6. Ensuring that a qualified auditor (usually external) examines and evaluates all your operational controls, besides your financial reports, at least annually, and

7. Improving your overall performance monitoring process.



3. Conclusion



Consider all these and customize them to your purposes and business environment. 

My experience is that controls are definitely required to ensure that you are profitable and that your small company survives and prospers.



My favorite watchdogs, however, are the budget, cash flow and expenses. The topic of the budget may be boring, but the need for budgeting is indispensable. It gives you immediate warnings that your company is doing well or not.



Your objective should be to have a system of controls in place that will give you excellent warnings when your business is approaching its financial limits that, if exceeded, could do serious harm to your small company.



And of course always and always watch your customers. Excel in providing excellent service and high-quality products to them and the rest will fall in place.











*Author’s Credentials



John Kyriazoglou, CICA, B.A (Hon-University of Toronto), is an International IT and Management Consultant, member of the Institute for Internal controls, founder and supporter of a number of cultural associations, and author of several books in a multitude of topics.

In the domain of internal controls his books include:

(1) ‘IT Strategic & Operational Controls’, www.itgovernance.co.uk (main author)

(2) ‘Addendum to the IT Strategic & Operational Controls’, containing audit checklists and programs, www.itgovernance.co.uk (main author)

(3) ‘Corporate Strategic & Operational Controls’, with Dr. Frank Nasuti, Ph.D., CPA, CICA, CFE, as the co-author, http://www.theiic.org/publicationsbookstore/bookstore2.html




SSRN Free Publications: http://ssrn.com/author=1315434




Thursday, December 1, 2011

CORPORATE COMPLIANCE AUDIT PROGRAMS AND CHECKLISTS


CORPORATE COMPLIANCE AUDIT PROGRAMS AND CHECKLISTS

By John Kyriazoglou* (author’s credentials at the end of this document)

The following audit program and checklists are designed to be used my managers, auditors and compliance staff in the process of establishing, controlling, reviewing, assessing and auditing the corporate compliance area and its particular components (compliance policies and procedures, corporate policies and procedures, ethics aspects, etc.).

The following audit programs and checklists, as detailed in the following paragraphs, should reviewed and customized before they are used in any corporate environment:

1. Corporate governance and internal controls systems audit program,

2. Assessment of the compliance controls framework,

3. Corporate policies and procedures checklist,

4. Records management system checklist,

5. Financial management system checklist,

6. Corporate fraud management system checklist,

7. Internal audit checklist, and

8. Ethics management checklist



1 Corporate governance and internal controls system audit program

1. Assess Board and senior executive management responsibility for the oversight and monitoring of corporate governance and internal controls.

Consider: Board and senior management should ensure that policies, procedures and systems are current and well documented. Management should establish an effective system of internal controls. Corporate, compliance, risk management and internal controls should cover the IT environment as well as the other business functions. Board and senior management should adopt and enforce appropriate policies and procedures to manage compliance, all risks (enterprise, IT, investments, etc.), and should re-evaluate and improve these controls every year or two.





2. Assess senior executive management practices.

Consider: Reporting effectiveness to the Board of Directors. Periodic review and updating of policies, standards, procedures and practices. Instituting controls to ensure that management information and detailed data are reliable and the reporting cycle is adequate, and that operating procedures are efficient and effective. Regular review of compliance issues, risks, segregation of duties, personnel controls, information security, software development and acquisition, outsourcing, insurance issues, internal and external audit results, service level agreements and performance measurements including issues and corrective action plans, ensuring that procedures are in effect to assure continuity of business, etc.

3. Does the internal controls framework identify all the required control components?

Consider: Control environment, risk assessment control activities information and communication monitoring.

4. Do the key functions of internal controls relate to all critical elements of governance?

Consider: Definition and establishment of objectives, standards and procedures. Definition of management responsibilities. Measurement of inputs, outputs and performance in relation to objectives. Critical review of the whole process. Reporting of both financial and non-financial results, compliance and performance. Taking corrective action, as necessary.

5. Do internal controls contain all types of controls?

Consider: Preventive controls (e.g. division of duties, authorization levels), detective controls (e.g. stock verification, bank reconciliation), directive controls (e.g. policies, procedures, training).

6. Are there adequate and effective financial controls in place at the detailed level, as required?

7. Are there adequate and effective customer service controls in place at the detailed level, as required?

8. Are there adequate and effective production/manufacturing controls in place at the detailed level, as required?

9. Are there adequate and effective information and communications controls in place at the detailed level, as required?

10. Are there adequate and effective asset management controls in place at the detailed level, as required?

11. Are there adequate and effective sales management controls in place at the detailed level, as required?

12. Are there adequate and effective management reporting controls in place at the detailed level, as required?



13. Are there adequate and effective internal audit controls in place at the detailed level, as required?

14. Are there adequate and effective human resource management controls in place at the detailed level, as required?

15. Are there adequate and effective research and innovation controls in place at the detailed level, as required?

16. Is there a formal and well-established performance management system for all functions of the organization?

Consider: The performance management system should promote and accelerate the rate of successful changes, increase the predictive and early warning capabilities to management, provide a holistic perspective to the management of the organization, link to the reward and other incentive systems of the organization, link and align on an integrated mode to the objectives and measures of the other corporate levels of the organization, such as: division, department, business unit, process, function, project, teams, etc.

17. Are critical performance data shared across all levels of the organization?

18. Are strategic performance data reviewed at the appropriate levels of the organization, and actions taken as necessary?

19. Are the approved personnel empowered to have access to whatever critical performance data is required to make balanced decisions?

20. Is the accountability and follow-through process based on critical performance data?

21. Is the psychological resistance of staff (management, line staff, etc.) managed and resolved accordingly?

22. Is there an active audit committee in place?

23. Is there an internal audit function in place?

24. Is there a compliance function in place with all its constituent components (compliance officer, compliance committee, policies, procedures, action plan, etc.)?

25. Are corrective and improvement measures taken when performance issues and compliance breaches occur?



2. Assessment of the compliance controls framework

Assess the organizational structure to ensure that it is neither so simple that it cannot adequately monitor the entity’s activities nor so complex that it inhibits the flow of necessary information.

1. Does the compliance monitoring system of the organization cover all business functions?

2. What is the management’s attitude towards compliance with laws and regulations?

3. Does the management of the organization specify the level of competence needed for particular jobs, and translate the desired levels of competence into requisite knowledge, cultural characteristics and skills?

4. Does the Board or governing council provide an effective oversight function to ensure that the management of the organization does not override system controls?

5. Is the philosophy and operating style of management compliance-related?

6. Does the assignment of responsibility, delegation of authority and establishment of related policies and procedures provide a basis for effective accountability and control?

7. Are human resources policies the basis for recruiting and retaining competent people to enable the plans of the organization to be carried out and its goals and objectives to be achieved?

8. Does the Board, the senior executives and the management of the organization have a clear understanding of all strategic components, and convey the message that integrity and ethical values of the organization cannot and should not be compromised by anyone?

Consider: Clear understanding of the values, mission and vision, and performance targets of the organization. Full understanding of the general goals and specific objectives of the organization and how they fit in the framework of corporate strategy. Provision of adequate information for risk identification and resolution. Clear understanding of the role played by policies and procedures in achieving effective controls and compliance.



3. Corporate policies and procedures checklist

1. Have compliance rules, guidelines, policies and procedures been formally established and communicated to all levels and functions of the organization?

2. Is there an approved performance policy, system and evaluation process in place?

3. Is there an approved human resources management policy, set of procedures, a system and an evaluation process in place?

4. Is there an approved financial and cost management policy, and a set of related procedures in place?

5. Is there an approved asset management, disposition and protection system in place?

6. Is there an approved IT policy and a set of related procedures covering all areas, such as strategy, security, contingency planning and disaster recovery, information systems development and operation, database and data privacy protection, web services, etc.?

7. Is there an approved research and innovation system in place?

8. Is there a Management Reporting System (MRS) in place?

9. Is there a quality management system in place?

10. Is there a risk management system in operation?

11. Is there an ethics code and policy in place?

12. Is there a compliance policy in place?

13. Is there a corporate social responsibility policy in place?

14. Is there an anti-fraud policy in place?

4. Records management system Checklist

1. Have operational guidelines and manuals been formally established, communicated to all levels and functions of the organization, and used in every-day work by all personnel?

2. Does the record-keeping system (for both manual and computerized files, media and data) of the organization produce complete and accurate results?

3. Is there an adequate documentation and effective audit trail for all transactions and activities?



4. Is there an approved segregation of duties policy, and a set of related procedures in operation?

5. Is there an approved employee rotation policy for critical jobs/tasks in operation?

6. Have levels of authorization been defined for all levels of management and all transactions and activities?

7. Are adequate asset protection and disposition controls in operation?

8. Are effective financial and cost management controls in operation?

9. Is there an active security committee, policy and procedures (for all elements: data, plants, installations, offices, infrastructure, systems, records, files, etc.) in operation at all levels?

10. Is there an active performance and compliance management, measurement and exception reporting system in place?



5. Financial management system checklist

1. Does the organization have a system for recording and tracking commitments, obligations and expenditures, and reconciling financial data?

2. Does the organization have controls that prevent incurring obligations in excess of funds available within a budget cost category?

3. Does the organization have a mechanism to ensure that periodic audits of the financial management area are undertaken?

4. Does the organization adjust financial plans in the light of the actual operating budget?

5. Does the organization monitor the reliability and confidentiality of financial data used in mission critical budgetary decisions?

6. Does the organization guard against breaches in confidentiality and loss of budget data integrity?

7. Does the organization use an operating budget to control project funds?

8. Does the organization link strategic goals, objectives and operational performance targets to budget performance activities?



6. Corporate fraud management system checklist

1. Does the organization have, within the corporate ethics policy, a statement with respect to fraud?

Consider: fraud definition, fraud hot-line, applicability to all employees, management, Board members, external contractors, media communications procedure for a disciplinary interview, employee services termination procedure, obligations of employees during notice periods and upon termination of employment, complaints procedure, conflict resolution, insurance claims, police contacting issues, investigation of fraud and corruption, theft and threats policy, obligations of external contractors, investigating procedure by the use of external approved investigators or expert internal audit personnel, and the protection procedure for the information sources.

2. Who is responsible for the issue of this statement?

3. Has this policy statement been approved and ratified by the Board or other top management committee?

4. Is this statement widely publicized in the organization?

5. Is this statement reviewed and improved annually?

6. Is the policy statement linked to internal controls?

7. Who (manager, function, etc.) is responsible for ownership and administration of the fraud policy?

8. How are fraud risks monitored, e.g. through risk registers?

9. Is there a budget for investigative costs on potential fraud issues?

10. Does the organization specify roles and responsibilities within the fraud policy (e.g. for the audit committee, the Board, the HR function, a Fraud Liaison Officer, etc.)?

11. What is the procedure for reporting suspicions of fraud?

12. What guidance is provided on dealing with incoming mail (such as anonymous letters, e-mails, etc.)?

13. Who are the first points of contact for reporting suspected dishonesty?

14. Does the organization have a whistle-blowing policy, which sets out the principles for protection of employees when reporting suspicions?



15. Does the organization keep a register of fraud?

16. Who is responsible for maintenance of this register (e.g. a Fraud Officer)?

17. What are the access rights to the fraud register?

18. Is the fraud register held securely?

19. Who is responsible for the investigation (e.g. internal audit)?

20. Who oversees the investigation?

21. Do written reports have to be submitted and to whom?

22. Are employees suspended from work pending an investigation?

23. Are all reasonable means of recovering any identified loss pursued?



7. Internal audit checklist

1. Is there an internal audit department?

Consider: terms of reference, organization chart, independence, expertise in IT.

2. Is there an internal IT audit function?

Consider: IT audit plan, adequacy of resources, suitability of resources, including qualifications, experience, technical competence and training.

3. Is there an internal audit policy document?

Consider: standards regarding review objectives, work plan, documentation, conclusions, report format, manager review.

4. Are all compliance issues subject to independent review by an internal audit function?

Consider: involvement in reviewing system developments, existing systems, computer operations, security and control issues use of audit software, etc.







8. Ethics management checklist

1. Does a code of ethics exist for all personnel, including IT?

2. Has an anti-fraud policy and associated procedures been put into operation for the organization?

3. Are confidentiality statements signed by all IT personnel and all critical users?

4. Do explicit corporate rules cover issues, such as:

Personal use of computer services,

proprietary rights to computer programs,

proprietary rights to data,

confidentiality of passwords,

physical access to restricted areas,

management of visitors,

use of terminals,

personal use of media and supplies,

disclosure of privileged information,

maintenance of professional relationships,

reporting mechanism for conflict situations,

penalties and rewards for violators,

clear assignments of accountability,

controls over data and files,

Data Protection Act,

data classification system?

5. Is there a centralized ethics control function?

6. Are proper international ethics standards used in the design and implementation of the code of ethics of the organization?





7. Is there an ethics program and appointed staff in implementation or operation?

8. Have all staff undertaken, or are there schedules for, ethics training?



*Author’s Credentials

John Kyriazoglou, CICA, M.S.,B.A(Hon), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’ ( to be published in 2/2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou.


Profiles





Blogs

Articles, Opinions, etc.: http://corporatecontrols.blogspot.com/