Friday, May 8, 2009

PPF Professional Practice Framework from IIA

Describe basic principles that represent the practice of internal auditing as it should be;

Provide a framework for performing and promoting a broad range of value-added internal audit activities;

Establish the basis for the evaluation of internal audit performance; and

Foster improved organizational processes and operations.

Internal Auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.

Principles Internal auditors are expected to apply and uphold the following principles:

Integrity The integrity of internal auditors establishes trust and thus provides the basis for reliance on their judgment.

Objectivity Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating, and communicating information about the activity or process being examined. Internal auditors make a balanced assessment of all the relevant circumstances and are not unduly influenced by their own interests or by others in forming judgments.

Confidentiality Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless there is a legal or professional obligation to do so.

Competency Internal auditors apply the knowledge, skills, and experience needed in the performance of internal auditing services.

Wednesday, May 6, 2009

End Of Audit Tips

Auditors will arrange an exit meeting to discuss status and findings,
When exceptions are detailed, determine remediation deliverables.
Examine in detail the audit report in a timely manner.
Ask for input when implementing changes
Communicate remediation target dates. The corrective action deadlines may vary depending on the severity of the noncompliance.
Ask for feedback on how the level of support provided to auditors

Monday, May 4, 2009

How To Help Auditors

Be professional at all times. All differences of opinions can be resolved.
Avoid being judgmental.
Follow all documented and required procedures.
Make sure that you understand the purpose of the audit.
Ask questions or discuss compliance problems, if attention required.
Be flexible - any potential problem not within the scope of the audit - evaluate the potential risks of the problem if left unaddressed.
Communicate with the auditor as often is needed.

Saturday, May 2, 2009

Audit Survival Tactics

Know what you are being audited for. Make sure you contact the auditor assigned to your audit before he/she comes into your facility. Be clear with the auditor on what will be audited, and what kind of support you will have to provide


Do your own pre-audit. Use internal audit program. Look for accountability from management to assure that all issues found during your internal audit are corrected using good “root-cause” corrective actions.


Use the same checklists or requirements that auditors may use

List previous findings. Examine findings from all your previous audits. Make sure everything which was found previously has ceased to be a problem.

Make sure everyone in your area knows the appropriate procedures.

Provide documented objective proof for compliance to your policies and procedures.

Friday, May 1, 2009

Tips Before an Audit

• Establish the authority of the audit team to increase the cooperation.
• Check the scope, area focus, frequency, resources, both IT and internal.
• Communicate your audit plans.
• Just what is the objective? Be it regulatory compliance, QA, adherence to policies?
• Share audit plans, purposes, and scope of the audits with audit staff.
• Determine what standards, policies, and procedures will be used for comparisons.
• Document in detail what documentation and reports you will use
• Have a wonderful and exciting opening meeting with the auditees.

Thursday, April 30, 2009

PCI Security Milestones

Best practices for protecting against the highest risk factors and escalating threats facing cardholder data security:

· Milestone One: If you don’t need it, don’t store it

· Milestone Two: Secure the perimeter

· Milestone Three: Secure applications

· Milestone Four: Monitor and control access to your systems

· Milestone Five: Protect stored cardholder data

· Milestone Six: Finalize remaining compliance efforts, and ensure all controls are in place

Thursday, April 23, 2009

PCI Compliance Standards

PCI Data Security Standard (PCI DSS) from PCI Security Standards Council (TM)

Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters


Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks


Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications

Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data

Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes


Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security

Wednesday, April 22, 2009

IT Security Matrix for Compliance

Create a matrix of controls on top and security layers on the left. When listing security layer or element, also identify whether it is a preventive or detective control. Control listings and security architecture maps should help.

Use clear, green, yellow, and red to identify which layers/control types meet completely, partially, or not meet the control requirements on top. The deliverable will be a control assessment.

In some cases, two or more controls may provide a partial protection individually, but together may meet fully the control requirements.

Check to see if there are unnecessary controls, and analyze to identify where a single layer may address a control cluster.

Tuesday, April 21, 2009

Audit TCP/IP Infrastructure

•Review network policies and procedures
•Analyze network diagrams (layer 1 & 2), design, and walk-through, list of network equipment and IP address list
•Verify diagrams with Ping and Trace Route
•Review utilization, trouble reports and help desk procedures
•Probe systems using scanning tools
•Verify network vendor oversight, user support, and network technicians services
•Review software settings on network equipment
•Inspect computer room and network locations
•Evaluate back-up and operational procedures

Monday, April 20, 2009

WLAN and Wireless Compliance

Review the FCC Part 15 regulatory requirements.

http://www.fcc.gov/oet/info/rules/part15/part15-91905.pdf

It covers various emission guidelines and regulations, focusing on unlicensed transmissions, such as low-power broadcasting. The 802.11x Wireless LAN (e.g. "Wi-Fi") 2.4 GHz, 5 GHz (U-NII) is under this regulation.

Include compliance requirements as appropriate in your WLAN and wireless compliance reviews, recommendations, and proposed documented policies, procedures, or internal standards.

Third-party BCP Impact Audit Scope

Vendor contract obligations
Defined cut over procedures
Risks to shared facilities and overall availability
Data backups and storage
Hardware and applications availability
Access security controls
Facility and environmental controls
Time frames for acceptable off site processing

Sunday, April 19, 2009

Security and Audit - Improve The Relatioship

Document everything. List your measures to reduce risk, and decisions to accept risk, when flexibility or potential benefits dictate it.

Good controls should be part of the process, not after thought insertions. They address compliance requirements and enhance security. Monitor through metrics.

Design and implement best practices that fit your infrastructure; then, track through measurable performance metrics.

Be prepared to prove your assessment of the effectiveness of controls framework and mitigating factors.

Saturday, April 18, 2009

Audit Healthcare Provider Fraud Schemes

Billing for services not performed
Documenting non-covered treatments as covered
Recording diagnosis and treatments based on what is covered
Performing more care than necessary
Coding for high pay than was performed
Misstating services performed
Pretending to be a health care worker to bill
Un-bundling services and coding

Thursday, April 16, 2009

Guess What's On Your Hard Drive

In addition to documents, graphics, and sound files, there are

Internet Browser History Files
Temporary Internet Files
Automatic Backup Files
Power Saver Functions
Data about your data files
Unique Identifiers
Virtual Memory and Swap Files
Temporary Files
Spooled Files

Plenty of data for forensics and privacy issues

Internal Audit Essential Objectives

Learn and know the business supported by processes

Adopt auditing appropriately to the environment

Upgrade audit skills inventory for effective performance

Wednesday, April 15, 2009

What Corporations Want from Internal Auditors

Appropriate scope of audit activities
Input in risk mitigation
Efficient and effective periodic internal control assessments
Value-added improvements in processes and error reductions
Help with cost reductions
Providing appropriate assistance in achieving compliance
Assistance in fraud prevention, detection, and evaluations
Help with financial statement assurance

Role of an Internal Auditor

Tuesday, April 14, 2009

Mistakes Responding to Auditors

Misreading what the auditor is asking or asking for

Not fully understanding the scope and implications of auditor inquiries

Forwarding documents to auditors with obvious errors

Responding with the wrong policy or procedure documents

Being distracted or confused by auditor's multiple requests

Not providing relevant info due to elimination of areas that are applicable to a request

Not having detail knowledge of the specific test area, and not asking for appropriate help

Attempting to respond to auditors by guessing or using intuition

IFRS Impact on Audit

Analyze the adequacy and appropriateness of identification of gaps between US GAAP and IFRS

Determine whether proposed internal control changes are aligned with the identified gaps.

Review current policies and documented processes to assess alignment

Analyze whether information gathering processes will support the new data requirements

Evaluate any workarounds to meet compliance requirements, resulting from lack of adequate information system integration of data collection processes

Review transition plans for risks and adequacy of testing

Determine whether adequate backup plans exist, and how backward compatibility will be maintained (this could be the sticky one)