Wednesday, August 29, 2012
Sources of System Risk
Information EFFECTIVENESS attributes
· Appropriate Amount
|
· Consistency
|
· Interpretability
|
· Objectivity
|
· Pertinence
|
· Relevance
|
· Timely Delivery
|
· Understandability
|
· Usability
|
Tuesday, August 28, 2012
Benefits of Virtualization
§ Increase uptime
§ Isolate applications to prevent problem moving across systems
§ Extend the life of older applications
§ Help move things to the cloud
§ Improve business continuity and disaster recovery
§ Flexibility and agility with multiple systems on a single platform
§ Reduced downtime
§ Reduced administration costs as faster provisioning
§ Increase space usage efficiency by reducing hardware units
§ Save energy
§ Reduce the data center footprint by consolidating servers
Monday, August 27, 2012
Bad Communication Tips
Sunday, August 26, 2012
Computer Tips
2. Create Folder without name by using RENAME on an existing folder and then typing 0160 on the numeric keyboard while holding ALT, then release ALT and hit ENTER. Really cool.
3. Forbidden Name of Folder ! "Con" Try it. You cannot create a folder named "Con."
4. Weird word trick. Just enjoy it. In MS Word, type =Rand(200,99), and hit ENTER.
5. Become buzz-word compliant!!!
6. Hardware: The parts of a computer system that can be kicked.
7. Computer dating is great for computers.
8. Viruses, unlike operating systems, rarely fail.
9. Prepare for disaster: Save Your Buffers !
10. Someone knocked over my recycle bin... There's icons all over my desktop...
11. The more I C+, the less I see.
12. Smith & Wesson, the original point and click interface.
13. Please press CTRL ALT DEL now for IQ test.
14. An application is never finished until the developer finds another job.
15. Eve used an Apple in Paradise. The rest is history.
16. How many times you need to hit CTRL to be in control?
17. If a train station is where the train stops, what is a work station?
18. Computers, like air conditioners, stop working when you open Windows.
19. Bad or missing mouse driver. Spank the cat [Y/N]?
20. Error: Keyboard not attached. Press F1 to continue.
Friday, August 24, 2012
Components of Best Practice Governance
Thursday, August 23, 2012
Why Request an Audit
2. Improve existing controls
3. Prevent fraud
4. Discover new money saving approaches
5. Operate more efficiently
6. Stop or prevent data breaches
Wednesday, August 22, 2012
Evaluation Criteria for Communication
Tuesday, August 21, 2012
On the lighter side
How do cannibal auditors honor their clients? They toast them.
What do you call an accountant with an opinion? An auditor
What did the auditor do at a vampire convention? Count Dracula
How expensive is cannibal auditor's consulting? They charge an arm and a leg.
How can you cook the books without burning down the office?
Why auditors appears so reserved? They have strong internal controls.
What does accountant do hitting the mid-life crisis? Gets a faster calculator.
Friday, August 17, 2012
Effective Motivation for Increased Productivity
- You can attempt to get blood out of a stone.
- You can attempt to motivate a stone to give blood.
- You can empower a stone to motivate itself to give blood.
- You can inspire a stone to empower itself to motivate itself to give blood.
- You can embolden a stone to inspire itself to empower itself to motivate itself to give blood.
- You can ennoble a stone to embolden itself to inspire itself to empower itself to motivate itself to give blood.
Characteristics of Processes
Wednesday, August 15, 2012
Estimating Costs of Automated Controls
Tuesday, August 14, 2012
Major IT Governance Areas
Monday, August 13, 2012
Goals of Process Improvement
Friday, August 10, 2012
Governance Process Principles
Thursday, August 9, 2012
Politics of Cost Cutting
Wednesday, August 8, 2012
Risk Treatment
Tuesday, August 7, 2012
Improving Judgment
Monday, August 6, 2012
Avoiding Drift from Established Procedures
- Perform detailed after-action reviews to improve processes.
- Foster a climate of open and candid dialogue.
- Focus on information “handed off” from one unit of the IT to another.
- Challenge silo thinking and work out inter-unit rivalries.
- Support transparency in the IT organizational units and systems.
- Avoid duck-tape approaches to small problems. Small problems may hide large ones.
Sunday, August 5, 2012
Change Strategy in Complex Systems
2. Inappropriate Starts = No Project Plan
3. Frustration = Lack of Resources
4. Slow change = Lack of Incentives
5. Errors Made = Lack of Skills
6. Confusion = Lack of Mission or vision
Saturday, August 4, 2012
Risk Factors in Complex Systems
- Inter-dependency among system components
- Connectedness of a each component to the number of other components of a system
- Diversity exists where different software packages perform same function (not good thing)
- Adaptation through fixes and upgrades allowing the system to handle new conditions
Risk Categories
Key Risk Governance Concepts
Wednesday, September 7, 2011
Monday, September 5, 2011
Monday, August 1, 2011
E-Governance
Why IT Governance
2. Rewards based on singular program accomplishments, without the broader strategic focus.
3. Lack of delivery strategies across program boundaries
4. Increased user pressure from cloud/internet functionality and ease of use expectations
5. Drive for a cost-efficient single, common service and delivery interface in meeting user needs
Information Technology Governance
It combines accountability with the assignment of decision-making responsibilities. Governance includes cross-level communications about processes and key IT investments. When fully employed, IT governance is aligned with business governance. Its key components include collaboration, modular and incremental development and implementation of strategic and tactical initiatives.
Wednesday, April 13, 2011
Dodd-Frank Act for Banks
• Abolishes the Office of Thrift Supervision:
• Stronger lending limits
• Improves supervision of holding company subsidiaries
• Intermediate Holding Companies
• Interest on business checking
• Charter Conversions
• New Offices of Minority and Women Inclusion at the fed financial agencies
Dodd-Frank Act for Extraction Industry
TRANSPARENCY FOR EXTRACTION INDUSTRY
Tuesday, April 12, 2011
Dodd-Frank Act
- Ends Too Big to Fail Bailouts
- Advance Warning Systems
- Transparency & Accountability for Exotic Instruments
- Executive Compensation and Corporate Governance
- Protects Investors
- Enforces Regulations on the Books
Saturday, February 26, 2011
Six Sigma Internal Audit
Friday, February 25, 2011
Key Sox Compliance Items
Develop action plans for ongoing maintenance and monitoring of internal controls in accordance policies and regulatory requirements, including the Sarbanes-Oxley Act.
Identify and implement internal controls process improvements
Recommend and implement process improvement solutions, including tools which enable these solutions.
Implement the Sarbanes-Oxley testing and evaluation plan and develop the ongoing procedures for maintenance and testing of company controls.
Provide metrics that measure effectiveness these of initiatives.
Ensure that all compliance and process improvement activities follow the appropriate change management, governance, and documentation requirements.
Conduct walk through(s) of processes and develop control guidance documentation and training materials.
Friday, January 28, 2011
Understand Information Systems Relevant to the Audit
• The nature and type of records and source documents
• The processing involved from the initiation of transactions to their final processing, including the nature of computer files and the manner in which they are accessed, updated, and deleted
• For financial audits, the process used to prepare the entity's financial statements and budget information, including significant accounting estimates, disclosures, and computerized processing.
FISCAM Federal Information System Controls Audit Manual Approach
Evaluation of entity-wide controls and their effect on audit risk.
Evaluation of general controls and their pervasive impact on business process application controls.
Evaluation of security management at all levels (entitywide, system, and business process application levels).
A control hierarchy (control categories, critical elements, and control activities) to assist in evaluating the significance of identified IS control weaknesses
Groupings of control categories consistent with the nature of the risk.
Experience gained in GAO’s performance and review of IS control audits, including field testing the concepts in this revised FISCAM.
Document Network Architecture
● firewalls, routers, and switches
● intrusion detection or prevention systems
● critical systems, such as Web and mail systems, file transfer systems, etc.
● network management systems
● connections to inter- and intra-agency sites
● connections to other external organizations
● remote access—virtual private network and dial-in
● wireless connections.
Plan the Information System Controls Audit
● Obtain an understanding of an entity and its operations and key business processes
● Obtain a general understanding of the structure of the entity’s networks
● Identify key areas of audit interest (files, applications, systems, locations)
● Assess IS risk on a preliminary basis
● Identify critical control points (for example, external access points to networks)
● Obtain a preliminary understanding of IS controls
● Perform other audit planning procedures
Tuesday, June 22, 2010
Thursday, May 13, 2010
How to delete Facebook Account
http://www.wikihow.com/Permanently-Delete-a-Facebook-Account
Someone posted 10 reasons that you won't be able to delete your Facebook account. Here is the link
http://www.businessinsider.com/10-reasons-youll-never-quit-facebook-even-if-you-think-you-want-to-2010-5#youre-not-going-to-go-back-to-waiting-an-hour-to-send-an-email-to-30-people-with-40-photos-attached-1
There is one reason that may override others: Employability and Marketability. Hey, it's just your life on the Internet. Enjoy the ride, no matter what you decide.
Thursday, April 29, 2010
OFAC Compliance - Not as Easy as it Appears
OFAC compliance is tricky as:
1. Rules and customs vary from country to country, confusing companies entering global operations without adequate requirements preparation.
2. OFAC rules, along with the names on the SDN list, change often;
3. Third-party service providers and their own vendors may end up dealing with those OFAC prohibits.
Sunday, December 6, 2009
Internet Security Standards Setting Bodies
International Telecommunications Union (ITU) X.273, Open Systems Network Layer Security, and X.509, Authetication Framework
International Standards Organization (ISO) ISO 17799
Institute of Electrical and Electronic Engineers (IEEE)
European Computer Manufacturers Association
Sunday, October 18, 2009
Business Lunch Tips for Auditors
Friday, October 16, 2009
Cut Your Public Audit Bill
Wednesday, October 14, 2009
Why Travel on Audits Light
#10:
Nobody can steal your luggage
#9:
Be more independent
#8: Extra time to get to the airport
#7:
Volunteer to be bumped, as no worry about luggage coming on the same flight
#6:
Catch public transportation, as no suitcases to roll around among lots of
people
#5: Don’t wait for getting luggage
#4: Avoid tipping
#3: Be environmental, as fewer luggage means less
weight to lift
#2: Avoid fees
#1:
“Lost Luggage
Friday, September 25, 2009
Photo Evidence Audit
- Document title
- Description
- Description writer
- Author
- Title
- Style
- Key Words
Tuesday, September 15, 2009
Lava Lamp for Auditors
If you wish to remember some facts, try intensely to forget them.
Auditing skills promote full employment for auditors.
If you laid all your sampling tests end to end, would they reach a conclusion?
Get your facts first, then you can properly arrange them.
An audit is just a flurry of activity without a program.
Audit opinions are plenty, implementations can be expensive.
Sunday, September 13, 2009
Develop Your Own Voice as Auditor
Stope over-analyzing what everyone else thinks! You cannot please everyone, and you cannot live in your head only all the time.
Search and Find Your Own Reasons to help others by auditing.
Audit your own goals, attitudes, resentments by asking yourself every question in the "book."
Write down your own reasons for passion to be an auditor. When you write things down you automatically reflect, and remember all those written "to do" lists that did get done.
Don't just file it, do something, act on your reasons to be great at auditing.
Don't worry about the dead ends. Just back up and move forward.
Saturday, September 12, 2009
Achieve Happiness As Auditor - Yes You Can
2. Don't forget to keep around a few annoying friends. It will sharpen your skills in dealing with incompatible people, and help you function in the world with people not like you.
3. Texting is for thumb people. Studies show that over 40% of what you write in emails is misunderstood.
4. Online friends don't exits in 3D real world. Only 7% of inter-personal exchange takes place through words, the rest, a mere 93% is non-verbal. We know that we exist, and who we are by seeing ourselves in the mirrors of other people's eyes.
5. No real friends, no spontenous criticism, and we miss it. Non-direct forms of communication are a great way to avoid being honest, by having the time to choose and craft words. We need quirks, humiliations and vulnerabilities that only real friendships provide.
6. Media Negativity Does Affect Us. After constant negative spins on just about everything, we feel at odds with the rest of the world. Like Mark Twain said, turn off all the news, and be happy. Almost no news will really affect your life, and what does affect, you won't be able to change anyway.
7. We feel less because we have less (friends). All these on-line friends don't place demands on us. BUT, we were wired to help and take care of others. We are a product of social interactions, so we need to be connected in real life, not through flat-screen monitors. Find a way to do something simple, but physical to help someone else. It really works.
Saturday, September 5, 2009
Scoring Risks
- The adequacy of internal controls
- The potential threats from transactions
- History of problems with system or application
- IT Architecture and Data Classification - is there a match
- The physical and logical security of information, equipment, and premises
- The adequacy of operating management oversight and monitoring
- Human resources, including the experience of management and staff, turnover, technical competence, management’s succession plan, and the degree of delegation
- Senior management oversight and appropriate governance
Great New Email Functions
- Undo sent message
- Snooze this message
- Reply to selected text
- Smart reply templates
- Attachment reminders
- Language-based filtering
- Usage trending
- Related message search
Friday, September 4, 2009
5 Key IT Skills Worth Having
2. Java
3. Lisp
4. C/C++
5. Unix form O/S familiarity
Knowing syntax to be able to read would be helpful for some IT Auditors
Thursday, September 3, 2009
Sign Your Should Charge More in Consulting Fees
They have new jobs after you finish this one.
You work and still get poverty assistance
Hey, any catch with your quote for the job?
Here you go, I have enough cash on me to pay you.
You have no friends among consultants.
You are hired without even telling them how much you charge
As you can't get all the work done, you live on cola and pizza
You get jobs from overseas outsourcers
Measuring Fraud Drivers - Yes, It Can Be Done
Envy Total thefts (robbery, burglary, larceny, and grand theft auto) per capita.
Wrath Number of violent crimes (murder, assault, and rape) per capita.
Sloth Expenditures on art, entertainment, and recreation compared with employment.
Gluttony Number of fast-food restaurants per capita.
Lust Number of STD cases reported per capita.
Pride Aggregate of the other six offenses—because pride is the root of all sin.
Feel free to put add these measures into a dashboard.
Web site Content Hell
- hit counters
- guestbooks
- stale links
- pages forever under construction
- pointless vanity pages
- advertisements from hell
- no email address for feedback
- unstable extensions
- broken HTML
- blinking text
- gratuitous animation
- marquees
- garish backgrounds
- unreadable text/background combinations
- "Best viewed with..."
- pop-up windows
- menus made entirely from image maps
- background MIDI, Flash, Shockwave
Becoming a Hacker
2. Don't bother trying to solve a previously solved problem: no glory
3. Hate boredom and repetitive work?
4. Love freedom without borders?
5. Forget attitude, impress with competence.
6. Get a really cool shirt at the next Def Con in Las Vegas (usually in August)
Wednesday, September 2, 2009
Compliance Program Key Elements
Monday, August 31, 2009
Involving Right Deparments in Compliance Issues
Accounting Irregularities Audit Committee, External/Internal Auditors, Compliance
Fraud Internal Audit, Loss Prevention, Risk Management, Compliance/Ethics
Workplace Violence Security, Operations, Legal, HR
Employee Theft (other than by head-hunters) Loss Prevention, HR
ETHICS The Federal Sentencing Guidelines for Organizations
Written standards of ethical workplace conduct
Means for an employee to anonymously report violations of ethics standards
Orientation or training on ethical workplace conduct
A specific office, phone line, e-mail, or Web site so that emps can get ethics advice
Evaluation of ethical conduct as part of regular performance appraisals
Discipline for employees who commit ethics violations
Sunday, August 30, 2009
Compliance Committee Key Issues
2. Review reports on internal controls
3. Examine all external reporting
4. Read internal audit reports
5. Evaluate internal audit activities, budget, staffing, and responsibilities
6. Consider all inquiries from external sources (including governmental)
7. Deal with all related party transactions and conflict of interests
8. Update conduct and ethics statements
9. Assess compliance program, including corporate communications.
10. Obtain input from Legal, Compliance, Board, and Internal Audit on compliance issues.
Friday, August 28, 2009
Deal with Human Component As Security Threat
Control the use of portable devices on the network
Trust employees, but not too much
Monitor network activity and audit who is doing what
Watch out for curious pokers into network and data security configurations
Determine your single point of failure
Physical security--no compensating controls here.
Wednesday, August 26, 2009
Audit Vulnerability
- Get raw info from people in crucial information flow areas.
- Get beyond surface concerns, and get to the real worries.
- Analyze information for gaps and inconsistencies,
- Determine where weakest links are
- Develop potential threats and their impacts list
- Communicate findings with change recommendations
- Focus on most likely threats and risks
Frequent QAR Findings In Internal Audit Departments
- Internal Audit Charter does not exist, is out of date, or not appropriate for the organization
- No on-going formal, consistent, self-assessments
- Limited input to the corporate governance and IT governance process and compliance assurance
- Hazy or improper reporting lines
- Too technically oriented IT audits, missing overall control framework contexts
- No effective continuing education opportunities and skills development
- Poor time tracking and remediation follow ups
- Lack of adequate formal audit planning and soliciting management's input on key risks
- Poor audit planning and approval documentation
Friday, August 21, 2009
Social Audit of Public Companies
2. Determine your culture's social and human focus initiatives and priorities
3. Link social obligations to corporate mission, culture, and responsibilities
4. Assess what problems you may be facing on a social audit-what you control, what don't
5. Determine the framework and methodology to use for audit
6. Determine the framework and methodology to use for comparison to actual practices.
7. Conclude on "integrated audit" Integrated here means key issues and peripheral concerns.
Friday, August 7, 2009
Total Risk Management Program
Specify boundary conditions and data input needed for predictive analysis
Select time scope for evaluation, and conditions to be measured
Establish an acceptable results range, and what is outside of it
List relevant predictors for the condition tested
Determine the cause for the risk condition
Measure conditions identify, and attempt to determine any value associated with it
Decide on the risk response to identified risk condition
Evaluate your "risk margin" and what risk to transfer
Choose between lowering threats (risks) and potential opportunities foregone.
Don't forget to have fun, while doing this.
Security When Facing Reduction In Force
- Check access and system logs often
- Secure weak spots, like "back door" facilities
- Inspect physical access controls, wake them up if you have to
- Examine existing change controls
- Timely remove asset access
- Inventory IT assets and track equipment returns
- Activate available audit trail recording features
Internal Risk Management
“Insider Threat” = Risk of actions of an Insider
Malicious Insider = Current or former employees or contractors who:
–intentionally exceeded or misused an authorized level of access to networks, systems or data,
and;
–affected the security of the organizations’ data, systems, or daily business operations
FMS Financial Management System
a. Collect, process, maintain, transmit, and report data about financial transactions
b. Support financial planning and budgeting
c. Store cost information
d. Aid in financial statement preparation
It is usually integrated with the main corporate application, or a module within it. If separate vendor used, it talks to main apps through some middle ware.
Thursday, August 6, 2009
Internal Audit Bread and Butter Issues
Strategic Management - map to corporate objectives
Decision Making - your employees can help with the budget
Executive Compensation - tax increases are coming?
Risk - fraud risk; risk management process
Analytics - the audit x-ray machine
Control Environment - stake claim to this turf
Automation - would be nice if it existed; now, just faster bicycles
IT Security - BCP, BRP, etc, etc...
Sunday, August 2, 2009
New Audit Tool - Free - Get It
The Dispute Finder Firefox Extension highlights disputed claims on web pages you browse and shows you evidence for alternative points of view. Watch the Videos to learn more.
Use this web interface to tell Dispute Finder what snippets to highlight and what evidence to present for alternative viewpoints. You can create a new disputed claim, mark new instances of a claim on the web, and add evidence that supports or opposes a claim.
http://disputefinder.cs.berkeley.edu/
Whatever you are evaluating, get the opposite opinion. This just came out, and they are planning additional upgrades
