Thursday, May 28, 2009
Friday, May 8, 2009
PPF Professional Practice Framework from IIA
Describe basic principles that represent the practice of internal auditing as it should be;
Provide a framework for performing and promoting a broad range of value-added internal audit activities;
Establish the basis for the evaluation of internal audit performance; and
Foster improved organizational processes and operations.
Internal Auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.
Principles Internal auditors are expected to apply and uphold the following principles:
Integrity The integrity of internal auditors establishes trust and thus provides the basis for reliance on their judgment.
Objectivity Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating, and communicating information about the activity or process being examined. Internal auditors make a balanced assessment of all the relevant circumstances and are not unduly influenced by their own interests or by others in forming judgments.
Confidentiality Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless there is a legal or professional obligation to do so.
Competency Internal auditors apply the knowledge, skills, and experience needed in the performance of internal auditing services.
Provide a framework for performing and promoting a broad range of value-added internal audit activities;
Establish the basis for the evaluation of internal audit performance; and
Foster improved organizational processes and operations.
Internal Auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.
Principles Internal auditors are expected to apply and uphold the following principles:
Integrity The integrity of internal auditors establishes trust and thus provides the basis for reliance on their judgment.
Objectivity Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating, and communicating information about the activity or process being examined. Internal auditors make a balanced assessment of all the relevant circumstances and are not unduly influenced by their own interests or by others in forming judgments.
Confidentiality Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless there is a legal or professional obligation to do so.
Competency Internal auditors apply the knowledge, skills, and experience needed in the performance of internal auditing services.
Wednesday, May 6, 2009
End Of Audit Tips
Auditors will arrange an exit meeting to discuss status and findings,
When exceptions are detailed, determine remediation deliverables.
Examine in detail the audit report in a timely manner.
Ask for input when implementing changes
Communicate remediation target dates. The corrective action deadlines may vary depending on the severity of the noncompliance.
Ask for feedback on how the level of support provided to auditors
When exceptions are detailed, determine remediation deliverables.
Examine in detail the audit report in a timely manner.
Ask for input when implementing changes
Communicate remediation target dates. The corrective action deadlines may vary depending on the severity of the noncompliance.
Ask for feedback on how the level of support provided to auditors
Monday, May 4, 2009
How To Help Auditors
Be professional at all times. All differences of opinions can be resolved.
Avoid being judgmental.
Follow all documented and required procedures.
Make sure that you understand the purpose of the audit.
Ask questions or discuss compliance problems, if attention required.
Be flexible - any potential problem not within the scope of the audit - evaluate the potential risks of the problem if left unaddressed.
Communicate with the auditor as often is needed.
Avoid being judgmental.
Follow all documented and required procedures.
Make sure that you understand the purpose of the audit.
Ask questions or discuss compliance problems, if attention required.
Be flexible - any potential problem not within the scope of the audit - evaluate the potential risks of the problem if left unaddressed.
Communicate with the auditor as often is needed.
Saturday, May 2, 2009
Audit Survival Tactics
Know what you are being audited for. Make sure you contact the auditor assigned to your audit before he/she comes into your facility. Be clear with the auditor on what will be audited, and what kind of support you will have to provide
Do your own pre-audit. Use internal audit program. Look for accountability from management to assure that all issues found during your internal audit are corrected using good “root-cause” corrective actions.
Use the same checklists or requirements that auditors may use
List previous findings. Examine findings from all your previous audits. Make sure everything which was found previously has ceased to be a problem.
Make sure everyone in your area knows the appropriate procedures.
Provide documented objective proof for compliance to your policies and procedures.
Do your own pre-audit. Use internal audit program. Look for accountability from management to assure that all issues found during your internal audit are corrected using good “root-cause” corrective actions.
Use the same checklists or requirements that auditors may use
List previous findings. Examine findings from all your previous audits. Make sure everything which was found previously has ceased to be a problem.
Make sure everyone in your area knows the appropriate procedures.
Provide documented objective proof for compliance to your policies and procedures.
Friday, May 1, 2009
Tips Before an Audit
• Establish the authority of the audit team to increase the cooperation.
• Check the scope, area focus, frequency, resources, both IT and internal.
• Communicate your audit plans.
• Just what is the objective? Be it regulatory compliance, QA, adherence to policies?
• Share audit plans, purposes, and scope of the audits with audit staff.
• Determine what standards, policies, and procedures will be used for comparisons.
• Document in detail what documentation and reports you will use
• Have a wonderful and exciting opening meeting with the auditees.
• Check the scope, area focus, frequency, resources, both IT and internal.
• Communicate your audit plans.
• Just what is the objective? Be it regulatory compliance, QA, adherence to policies?
• Share audit plans, purposes, and scope of the audits with audit staff.
• Determine what standards, policies, and procedures will be used for comparisons.
• Document in detail what documentation and reports you will use
• Have a wonderful and exciting opening meeting with the auditees.
Thursday, April 30, 2009
PCI Security Milestones
Best practices for protecting against the highest risk factors and escalating threats facing cardholder data security:
· Milestone One: If you don’t need it, don’t store it
· Milestone Two: Secure the perimeter
· Milestone Three: Secure applications
· Milestone Four: Monitor and control access to your systems
· Milestone Five: Protect stored cardholder data
· Milestone Six: Finalize remaining compliance efforts, and ensure all controls are in place
· Milestone One: If you don’t need it, don’t store it
· Milestone Two: Secure the perimeter
· Milestone Three: Secure applications
· Milestone Four: Monitor and control access to your systems
· Milestone Five: Protect stored cardholder data
· Milestone Six: Finalize remaining compliance efforts, and ensure all controls are in place
Thursday, April 23, 2009
PCI Compliance Standards
PCI Data Security Standard (PCI DSS) from PCI Security Standards Council (TM)
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security
Wednesday, April 22, 2009
IT Security Matrix for Compliance
Create a matrix of controls on top and security layers on the left. When listing security layer or element, also identify whether it is a preventive or detective control. Control listings and security architecture maps should help.
Use clear, green, yellow, and red to identify which layers/control types meet completely, partially, or not meet the control requirements on top. The deliverable will be a control assessment.
In some cases, two or more controls may provide a partial protection individually, but together may meet fully the control requirements.
Check to see if there are unnecessary controls, and analyze to identify where a single layer may address a control cluster.
Use clear, green, yellow, and red to identify which layers/control types meet completely, partially, or not meet the control requirements on top. The deliverable will be a control assessment.
In some cases, two or more controls may provide a partial protection individually, but together may meet fully the control requirements.
Check to see if there are unnecessary controls, and analyze to identify where a single layer may address a control cluster.
Tuesday, April 21, 2009
Audit TCP/IP Infrastructure
•Review network policies and procedures
•Analyze network diagrams (layer 1 & 2), design, and walk-through, list of network equipment and IP address list
•Verify diagrams with Ping and Trace Route
•Review utilization, trouble reports and help desk procedures
•Probe systems using scanning tools
•Verify network vendor oversight, user support, and network technicians services
•Review software settings on network equipment
•Inspect computer room and network locations
•Evaluate back-up and operational procedures
•Analyze network diagrams (layer 1 & 2), design, and walk-through, list of network equipment and IP address list
•Verify diagrams with Ping and Trace Route
•Review utilization, trouble reports and help desk procedures
•Probe systems using scanning tools
•Verify network vendor oversight, user support, and network technicians services
•Review software settings on network equipment
•Inspect computer room and network locations
•Evaluate back-up and operational procedures
Monday, April 20, 2009
WLAN and Wireless Compliance
Review the FCC Part 15 regulatory requirements.
http://www.fcc.gov/oet/info/rules/part15/part15-91905.pdf
It covers various emission guidelines and regulations, focusing on unlicensed transmissions, such as low-power broadcasting. The 802.11x Wireless LAN (e.g. "Wi-Fi") 2.4 GHz, 5 GHz (U-NII) is under this regulation.
Include compliance requirements as appropriate in your WLAN and wireless compliance reviews, recommendations, and proposed documented policies, procedures, or internal standards.
http://www.fcc.gov/oet/info/rules/part15/part15-91905.pdf
It covers various emission guidelines and regulations, focusing on unlicensed transmissions, such as low-power broadcasting. The 802.11x Wireless LAN (e.g. "Wi-Fi") 2.4 GHz, 5 GHz (U-NII) is under this regulation.
Include compliance requirements as appropriate in your WLAN and wireless compliance reviews, recommendations, and proposed documented policies, procedures, or internal standards.
Third-party BCP Impact Audit Scope
Vendor contract obligations
Defined cut over procedures
Risks to shared facilities and overall availability
Data backups and storage
Hardware and applications availability
Access security controls
Facility and environmental controls
Time frames for acceptable off site processing
Defined cut over procedures
Risks to shared facilities and overall availability
Data backups and storage
Hardware and applications availability
Access security controls
Facility and environmental controls
Time frames for acceptable off site processing
Sunday, April 19, 2009
Security and Audit - Improve The Relatioship
Document everything. List your measures to reduce risk, and decisions to accept risk, when flexibility or potential benefits dictate it.
Good controls should be part of the process, not after thought insertions. They address compliance requirements and enhance security. Monitor through metrics.
Design and implement best practices that fit your infrastructure; then, track through measurable performance metrics.
Be prepared to prove your assessment of the effectiveness of controls framework and mitigating factors.
Good controls should be part of the process, not after thought insertions. They address compliance requirements and enhance security. Monitor through metrics.
Design and implement best practices that fit your infrastructure; then, track through measurable performance metrics.
Be prepared to prove your assessment of the effectiveness of controls framework and mitigating factors.
Saturday, April 18, 2009
Audit Healthcare Provider Fraud Schemes
Billing for services not performed
Documenting non-covered treatments as covered
Recording diagnosis and treatments based on what is covered
Performing more care than necessary
Coding for high pay than was performed
Misstating services performed
Pretending to be a health care worker to bill
Un-bundling services and coding
Documenting non-covered treatments as covered
Recording diagnosis and treatments based on what is covered
Performing more care than necessary
Coding for high pay than was performed
Misstating services performed
Pretending to be a health care worker to bill
Un-bundling services and coding
Thursday, April 16, 2009
Guess What's On Your Hard Drive
In addition to documents, graphics, and sound files, there are
Internet Browser History Files
Temporary Internet Files
Automatic Backup Files
Power Saver Functions
Data about your data files
Unique Identifiers
Virtual Memory and Swap Files
Temporary Files
Spooled Files
Plenty of data for forensics and privacy issues
Internet Browser History Files
Temporary Internet Files
Automatic Backup Files
Power Saver Functions
Data about your data files
Unique Identifiers
Virtual Memory and Swap Files
Temporary Files
Spooled Files
Plenty of data for forensics and privacy issues
Internal Audit Essential Objectives
Learn and know the business supported by processes
Adopt auditing appropriately to the environment
Upgrade audit skills inventory for effective performance
Adopt auditing appropriately to the environment
Upgrade audit skills inventory for effective performance
Wednesday, April 15, 2009
What Corporations Want from Internal Auditors
Appropriate scope of audit activities
Input in risk mitigation
Efficient and effective periodic internal control assessments
Value-added improvements in processes and error reductions
Help with cost reductions
Providing appropriate assistance in achieving compliance
Assistance in fraud prevention, detection, and evaluations
Help with financial statement assurance
Input in risk mitigation
Efficient and effective periodic internal control assessments
Value-added improvements in processes and error reductions
Help with cost reductions
Providing appropriate assistance in achieving compliance
Assistance in fraud prevention, detection, and evaluations
Help with financial statement assurance
Tuesday, April 14, 2009
Mistakes Responding to Auditors
Misreading what the auditor is asking or asking for
Not fully understanding the scope and implications of auditor inquiries
Forwarding documents to auditors with obvious errors
Responding with the wrong policy or procedure documents
Being distracted or confused by auditor's multiple requests
Not providing relevant info due to elimination of areas that are applicable to a request
Not having detail knowledge of the specific test area, and not asking for appropriate help
Attempting to respond to auditors by guessing or using intuition
Not fully understanding the scope and implications of auditor inquiries
Forwarding documents to auditors with obvious errors
Responding with the wrong policy or procedure documents
Being distracted or confused by auditor's multiple requests
Not providing relevant info due to elimination of areas that are applicable to a request
Not having detail knowledge of the specific test area, and not asking for appropriate help
Attempting to respond to auditors by guessing or using intuition
IFRS Impact on Audit
Analyze the adequacy and appropriateness of identification of gaps between US GAAP and IFRS
Determine whether proposed internal control changes are aligned with the identified gaps.
Review current policies and documented processes to assess alignment
Analyze whether information gathering processes will support the new data requirements
Evaluate any workarounds to meet compliance requirements, resulting from lack of adequate information system integration of data collection processes
Review transition plans for risks and adequacy of testing
Determine whether adequate backup plans exist, and how backward compatibility will be maintained (this could be the sticky one)
Determine whether proposed internal control changes are aligned with the identified gaps.
Review current policies and documented processes to assess alignment
Analyze whether information gathering processes will support the new data requirements
Evaluate any workarounds to meet compliance requirements, resulting from lack of adequate information system integration of data collection processes
Review transition plans for risks and adequacy of testing
Determine whether adequate backup plans exist, and how backward compatibility will be maintained (this could be the sticky one)
Subscribe to:
Posts (Atom)