Process alone can’t save us

Blindness to the need for technology is often found among the companies with the strongest set of business processes and policies.  “We don’t let our user install on our network” is one of my favorite quotations.  I heard these words spoken in the same room where a CEO offered to download my files by via web mail on his private laptop.   Configuration exceptions made for “special cases” is the tip of the iceberg and, but offers at least one concrete example for why we tools such as the products created by Tripwire and EMC.  The management or mismanagement of digital information is a part of every employee, document and product in the path of running business.  We need to understand tools because evidence of their proper use is a large component of our job.  Assessing a corporation’s control over information touches people process and technology, but our process for evaluation involves technology, tools and technique.

As an ISO child, applying properties with relation to document owner, use and retention is just a way of doing business.  I would not imagine it any other way.  As the Final Rule on section 17a-4 of the already signed Sarbanes-Oxley Act was delivered for public view, I was surprised at the amount of response to suggest this was a new way to practice information archive and classification.  There is a web site listing in eloquent summary that manner used by ISO9001 to organize a data retention program.  I’ve written to the author, and hope to get permission to say more about it.  The site is not offered directly by an accredited organization, the summary for concerns in the retention of documents is well stated and compressive.

The all-in-one notion of “Compliance Solutions” is forgivably appealing to executives desperate to pay compliance terrorist whatever ransom releases their hostage workforce.  The irony here is the workforce held hostage is likely the only means for technology compliance, and it won’t be accomplished through any single suite of solutions.  Even the term compliance tool is an oxymoron.  Is there a noncompliance tool?  Products like ACL earn the right to be called a tool for compliance.  My definition is a compliance tool is that it allows us to summarize metrics as they indicate the actual audit of application controls.  Consider Tripwire, EMC, ACL, Bindview, MKS and Serena.  They control change and configuration, providing all forms of evidence.  Clearly controls, but the tools have a technology functional core purpose.  The people who use them are what make a company compliant.  Strong infrastructure management resources align to logical data and function owners in service oriented architecture.  Success is achieved by domain experts who are actually capable of knowing the right tool when they find it.  Technology professionals know the pain of implementing battleship solutions that introduce excessive change to an already stressed or non adapting culture.  Even if one suite of products could control every known area of business and technology, certainly 90% would fail for lack of time to customize its use, or worse, the customization would break any digitally binding evidence built into the tool in the first place.

These points are common sense.

Application Development and Acquisition is a science.  Tools that align to regulation and standard have a common characteristic of long aligning to respected frameworks.  Consider the history of PMI, TQM and W3C, BSA, and the SEI institute.  They were big before the hype.  Consider the suite of technology implementation guides produced by ITIL® being re-released with greater attention to current technology requirements.  Note that the creators of our best weapons against computer abuse and fraud have been at this for a long time, were involved in creation of standards and legislation and grew up with the standards.

If any of this is new information, I suggest putting a foundation certificate in IT Service Management in front of all other tasks on your calendar this month.  The curriculum follows the first three titles in a substantial list of notable works, advancing general knowledge of frameworks and terminology.  Results from this knowledge include ability to discern compliance hype based in FUD, (Fear, Uncertainty and Doubt) from compliance theory, such as ITIL®, COBIT® and ISO 17799 derived security works.  ISACA, EXIM and InteQ offer excellent on line certification training.  The experiences of our company indicate a TSM certificate is achieved in four week-ends.  ISEB certification is not the only path to gaining knowledge.  The following series of book and CD resources are available for purchase at the TSO On-line Bookstore.

Consider the view in the ICT Infrastructure handbook of the manager’s role in the control over information and systems: An ICT Infrastructure Manager ensures that:

  • ICT plans are produced and circulated to the appropriate IT Service Management and Business Management on a regular basis
  • Changes to architectures, plans, designs, configurations are reviewed and approved
  • Any changes that impact on the ICT services are appropriately assessed and the risks and impact made clear
  • ICT components and services are adequately managed and administered
  • ICT components and services are appropriately monitored and that there is adequate funding for the necessary tools to support diagnostic and performance monitoring
  • There is adequate monitoring of security and supporting procedures
  • There are appropriate plans for recruitment, training and development of ICTIM staff
  • The quality and cost of ICT services are monitored and controlled to ensure that they are matched to business needs and are provided within budget
  • Appropriate regulations and standards are enforced
  • Regular audits and risk analysis of the ICT infrastructure are conducted
  • Relationships with suppliers and partners are developed accordingly, with compliance to contractual commitments
  • Regular reviews of ICTIM processes are performed
  • ICT Infrastructure Managers may play a key coordination role as part of a business change program and in crisis management[135].

For more information on tools and compliance, please check posts to my web site.  (www.pbandsp.com/tools)

Factors affecting world trade:

No matter what we buy or what we build, it is pointless to proceed without consideration for the financial, digital, and privacy mandates as required for World Trade.  The very definition of information, transaction and retainable data change with each passing day.  You might think the industry leaders have considered this since the beginning, albeit with varying moral intent, such that using established tools and vendors would guarantee safe trade and profit.  This is not so.  On any given day, news stories include headlines like today’s Computer World article  “Microsoft faces order to modify Windows in South Korea.”  This and many more articles regarding international policy can be found at: www.computerworld.com.

The statutes of European Digital Rights are available at EDRI: www.edri.org.

When looking to purchase technology products, those lacking evidence of alignment to international barriers to trade deserve lower rank or even complete elimination from vendor consideration.  Companies that are not actively involved in regulatory alignment simply won’t hold up in the global market.  Awareness of international legal requirement is not exclusively managed by larger corporations, or ignored by all non-public corporations.  It’s a factor that must be evaluated before inviting any vendor to provide either RFI or RFP.  Without consideration for legal exposure the product will not meet Common Criteria standards, will likely lack alignment to the PCI VISA standard which could result in loss of privilege to engage in e-commerce.  Digital Rights, both in Europe and the United States gain increasing regulation and granularity of definition, with changes occurring in the span of even writing this paper.

Important web sites for the study of European and International laws as affecting technology and information standards, consider adding these sites to your favorites:

Products that cannot conform to retention and restrictions as mandated by European Digital Rights will at the very least, need to demonstrate exactly how their services and inventory will steer clear of non-United States internet traffic.  One way or another, companies ignoring US and International Law will become both news and liability.  Remember, an Eagle spots prey from a thousand feet.  Hungry legal Eagles eat companies violating world trade and copyright law as a regular diet.  The notion of self contained requirements is pretty much long.

Birth announcement

I added a post it flag to a new pile.  It reads “Mount Recycle.”

The buddy system

Truth is, only Eagles and licensed pilots fly alone.  We simple farm animals need ITGI's Knowledge Network, all the resources from ISACA (especially COBIT® On-line), IIA Resources for Information Technology, and updates from PricewaterhouseCoopers CFOdirect Network®.  I rank attempts to Sarbanes-Oxley and SAS 70 compliance in the absence reading COSO[136] and AICPA guidelines with untied shoe laces while running with scissors.  These are our primary source of guidance, because they represent the people with a core mission to provide us with what we need to know.  Google™ may be the source of infinite answers, but these sources are true Oracles.  Google may win a Nobel Prize someday, but as for me, it is by definition “too much information[137]."

Reading PCAOB standards, audit guideline and practice frameworks, attending ISACA and IIA CPE events, and subscribing to the PwC’s world class newsfeed is hardly a shabby approach to an audit career.  National Association of State Boards of Accountancy endorsed organizations assures timely access to uniform levels of training, materials and guidelines for our practice.

This writing only suggests that a diet consisting of “drinking from the fire hose” and every type of food they have in the company vending machine, will likely lead to poor thinking skills, obesity, and complete lack of resistance to minor changes in flu strain or weather.  Vary the daily circle of reference to reliable solid sources and defend against self induced white paper frenzy.  Protect whatever brain matter that may be left by careful selection of valid documents worthy of “Must Read™” rank.

Let ISACA handle it

Have I have skipped right over the “shared responsibility” clause?  Surfing for audit material has scary potential to drag us down dark alleys and rat holes.  Isn’t it safer to let ISACA and IIA handle the reading list?  Why not plug back in to three or four portals and stop the journey right here?

Because

The people, who maintain, manage use of and contribute to these critical resources, however, are not in the habit of playing it safe.  They demonstrate life long patterns of participation in the scope, applicability and intent behind international standards, treaties and laws.  Frameworks such as the widely implemented COBIT® are refined and optimized based in the solicited feedback of “rival” organizations.  Consider the intent of “COBIT® Mapping: Mapping ISO/IEC 17799: 2000 with COBIT," which painstakingly demonstrates a “global overview of […] important international standards and guidance for IT control and IT security in relationship to COBIT®: COSO, ITIL®, ISO/IEC 17799:2000, ISO/IEC 13335, ISO/IEC 15408, TickIT and NIST 800-14[138]."  ISACA clearly supports that we consider these standards in our manner of implementing IT governance. 

The influence of contributors to the Mapping Projects at ISACA and the GTAG at IIA are the same men and women who elevated a practice previously isolated to the department IT, into a major business and legal concern now known as Enterprise Governance.  I thought about the articles and papers that I typically read.  I examined a few references on papers people had been sending me to read.  Some had no references at all.  I compared one of the papers to a random (Carnegie Mellon Universities) CERT publications, IIA endorsed resource or and a product released under the guidance of ITGI.  The differences between articles and white papers, and then any item by the three organizations were impressive.  Look at the references listed on page two of “It Control Objectives for Sarbanes-Oxley: The Importance of It in the Design, Implementation and Sustainability of Internal Control over Disclosure and Financial Reporting[139]."

COBIT® 3rd Edition ©, IT Governance Institute, Rolling Meadows, Illinois, USA, July 2000

Committee of Sponsoring Organizations of the Treadway Commission (COSO), www.coso.org

Common Criteria and Methodology for Information Technology Security Evaluation, CSE (Canada), SCSSI (France), BSII (Germany), NLNCSA (Netherlands), CESG (United Kingdom), NIST (USA) and NSA (USA), 1999

Exposure Draft Enterprise Risk Management Framework, Committee of Sponsoring Organizations of the Treadway Commission (COSO), USA, July 2003

“Final Rule: Management’s Reports on Internal Control over Financial Reporting and Certification of Disclosure in Exchange Act Periodic Reports,” Release Nos.  33-8238; 34-47986; IC-26068; File Nos.  S7-40-02; S7-06-03, US Securities and Exchange Commission, USA, June 2003, <http://www.sec.gov/rules/final/33-8238.htm>

Internal Control—Integrated Framework, Committee of Sponsoring Organizations of the Treadway Commission (COSO), AICPA, New York, USA, 1992

ISO IEC 17799, Code of Practice for Information Security Management, International Organization for Standardization (ISO), Switzerland, 2000 […]

Here’s my visual take away and mental note regarding organizations, documents and writers deserving our professional attention and a rating as “critical” ten out of ten weights.

COBIT® (ISACA, ITGI) AND COSO (AICPA, IIA)

Common Criteria and Methodology for Information Technology Security Evaluation, CSE (Canada), SCSSI (France), BSII (Germany), NLNCSA (Netherlands), CESG (United Kingdom), NIST (USA) and NSA (USA)

Enterprise Risk Management Framework, (COSO)

Any Final Rule - US Securities and Exchange Commission

Any - ISO IEC 17799, Code of Practice for Information Security

ITIL® and OCG

CCTA

Public Company Accounting Oversight Board=Auditing Standards

Information Security Forum

Endorsed contributions: Deloitte & Touche, PricewaterhouseCoopers

Cartoon Plan

Friday Night Fight: Two men ring side seats, people standing and sitting, tossing tickets on ground looking angry or disappointed, ref with microphone in distance “… force cancellation of the long anticipated Mega Blockbuster Event “COSO vs.  COBIT®.”

Man one: “There goes another 80 bucks down the drain!”

Enough about them, let’s talk about us

Consider again, a “critical,” a ten out of ten weight, “IT Control Objectives for Sarbanes-Oxley: The Importance of It in the Design, Implementation and Sustainability of Internal Control over Disclosure and Financial Reporting”, Copyright© 2003 by the IT Governance Institute[140]."  Contribution in peer review and content include PricewaterhouseCoopers, Crowe Chizek, RBC Financial Group, Deloitte & Touche, Financial Executives Institute-Research Foundation (FERF)[141], Ernst & Young, Protiviti, META Group, Q Alliance, RBC Financial Group, demonstrating among business and regulators their highest rank and strongest talent.  The come from Banking, Audit, and Enterprise IT Consulting, in Industries ranging from Manufacturing to Insurance an Air Travel, (i.e., Electrolux, Great-West Life Assurance Company, Waviest Technologies, New Zealand Air).  Participation in this one project represents regulatory mandates as experienced in the USA, Canada, Singapore and Tokyo, Argentina, Australia, United Kingdom, Luxembourg, and Belgium.

What was the motivation that brought this group together?  Were they working as a team to be Olympic swimming gold medalists in the 1000 meter Reference List?  If so, I didn’t catch that on ESPN.  The product is in public domain and no particular individual is given exclusive rights except for guardianship on the copyright.  If IIA and ISACA aren’t going to fight, and PricewaterhouseCoopers is work along side Deloitte & Touche, Ernst and Young, Protiviti and KPMG, then… then…

Man two, “#&*=^%#! Promoter should have his license shoved down his throat.  What kind of moron puts a pair of pansies the ring.  Why don’t they have love-in now and sing Kum-ba-yah…”

Man one: “It’ ain’t worth it.  Let it go.  They’ll be other fights.”

Man two: Outside entering pub, “It’s just the principle of the thing…”

Main Menu