Say it ain’t so

Frameworks don’t compete.  That can be accomplished by People.  Consider the evidence so far; audit bodies, corporations, and every member of the Big5 have been caught in the act of teamwork.  ISACA, IIA, AICPA represent a combined membership of one half million audit and technology professionals.  As found on their respective web sites, "ISACA is a leading information technology organization representing more than 47,000 individual members in more than 140 countries.  […]  ISACA has assumed a role as the harmonizing source for IT control practices and standards the world over[142]." AICPA reported the 2005 member total as 327,135 members, who passed the CPA exam and are certified to practice[143].  "IIA Membership reaches 110,000” is the noted headline of the IIA’s Home page[144].  These are not the full team required for national compliance.

Did you happen to notice where I left a half million auditors?

Total Accountants and Auditors in the United State are estimated to be around 1,007,760[145].  Each organization provides framework and guidance as required by the Unified Accountancy Act, as mandated by PCAOB, according to the U.S. laws for GAAP (Generally Acceptable Accounting Practice) and according to the state guidelines of the NASB[146]. Our charters serve the spirit of the law but each team applies different methods frameworks toward a fairly unified goals.  Whether if we walk, swim, bike or fly, we are over a million professionals who all know one thing about this country’s need for compliance; we need to get there and stay there.

Certainly all auditors involve themselves in maintaining Continued Professional Education requirements, and an enormous number work among the PwC, E&Y, D&T and KPMG (Big4), (surely Protiviti is overdue for making this a Big5).  Why are so many professionals creating faction organizations?  Why not join OASIS, IETF, IIA, and ISACA contributing to the greater good?  Why do so many IT consultants feel qualified to act as auditors, and why do auditors believe they have mastered the extent of needed learning to perform forensics?

Found them!

I knew they weren’t lost.  The circle of reference strikes again.  Audit is much more than IT.  Site details at  AICPA and NASB mention

  • AACSB International AACSB International—aacsb.edu.
  • Management accounting and the CMA designation is found at the IMA, Institute of Management Accountants imanet.org. Management accounting and the CMA designation is found at the IMA, Institute of Management Accountants www.imanet.org.
  • Accredited in Accountancy, Accredited Business Accountant, Accredited Tax Advisor, or Accredited Tax Preparer designations are supported by the Accreditation Council for Accountancy and Taxation, acatcredentials.org.
  • Government accounting is supported by the CGFM designation, earned with the help of Association of Government Accountants agacgfm.org.

I feel like such a Jackass: Donkey ‘Jackass’: “I thought they’d appreciate my creative talent. All the materials were so drab and a little color seemed like a great idea…” Sheep: “Let it go. No one really cares. Don’t forget, we’re not paid to sit around thinking all day.” Donkey: “I feel like such a fool. Do you think the sheep will have me back?” Sheep: “I have a career to protect. You know how it is…”

Did I mention all the new IT Audit and Control Organizations?

A problem not owned equals a problem not solved

We need to own a little bit of the solution or we lose interest in the problem.  This is misidentified as “NMO” or “not my idea.”  Even as a babies adopted a personal mission to take everything apart.  Our obsession evolved to putting pieces together followed by, reverse engineering.  (That’s why I parents have gone insane.)  Some of us matured to actual inventing, and even hacking for professional gain.  (Wolves invent, sharks hack, pigs use the hack created by a shark.)  We copy fashion, software, music and even personality.  The nature of copying is so pervasive, it is at least a significant reason for most areas of security and all of Title 17.

In fact, we assume we’re supposed to copy and in some cases this is a career strategy.  When asked to perform even a slightly creative task, we begin with a search for the right template.  In fact, very few people really want to hear our ideas.  Ask any boss and he’ll say, is there a template?  Great, let’s move one.

Where do the templates end and our unique configurations begin?  Living with blinders is a sure path to failure.  Propose anything dramatically different from the norm, and chances are, you become member to a class I’ve completely left off the list, the jackass.

Many business leaders will tell you that failure in one context drove success in another.  We have a proliferation of new organizations in IT Control and Information System Audit.  They can be characterized as toddlers, cute, creative, still in possession of baby superpowers.  Their interests are stirred by the exciting new problems in technology compliance standard.  Outsmarting our favorite cartoon villain holds fascination, joy and wonder, providing opportunity to flex our intellect, sense of justice and share in camaraderie.  You have to admit, for a while there SOX was holding almost as much country attention as the first round of Ben and Jen.

You want me to kill them now?  (But they're so cute!)

Are you sure about this?  I agree they will reproduce.  Yes, they may marry into family.  You’re right, they’ll publish more standards.  Correct, we will have to read them too.

Valid points and I see the wisdom in killing them while they’re weak, but I can’t support youth organization genocide.  It’s not even a religious hang-up.  I’m concerned these baby organizations may be needed in the compliance chain.

Basic principles in human dynamics limit team size as a factor in success.  Business and the army use a principle of five.  Schools try to do it with rules for number of students per class.  We need small groups to manage and learn.  Large mature groups tend to drown out creativity.  People lack a sense of place and purpose.  Newcomers to large established organizations see a list of problems that aren’t qualified to solve, leaving nothing to do but try to rub elbows with people who are “trusted to think.”

We need baby organizations.  In addition to pollinating the untapped dogs and sheep with inspiration, I’m pretty sure killing them isn’t legal.  (Check the ACLU site comments on “right to gather for any purpose, no matter how stupid or a waste of time”, First Amendment[147].)  New teams share uninformed optimism, a chemical we have not been able to bottle.  They believe they impact the world.  Sometimes, they do.

Consider the mission of ITPI, an organization focused on prescriptive, data-driven guidance for IT leaders.

Research – study top performers and identify the causal link between behavior and results.

Benchmarking – create tools that compare individual organizations to top performers.

Prescriptive Guidance – share content written to help IT organizations become top performers.

With this simple data-driven approach, the IT Process Institute aims to enhance the efficiency and effectiveness of our member organizations, and drive performance.  They are not Gartner, and they are not the OGC, but their leadership is comprised of Eagles, and their goals remind us there are stars.

 “Dreams are like stars...you may never touch them, but if you follow them they will lead you to your destiny.”
Informed Optimism

How did a handful of starving painters create all the works that are collectively known as Impressionism?  Why is it we tend to find that Nobel Prize winners are also best friend’s with a Golden Globe awarded play writes, parents to winners of the Tchaikovsky competition or just merely leaders of fortune five hundred corporations?  Don’t Tom Hanks, Paul Newman, Jane Fonda, Goldie Hawn and the Durnings understand what they’ve done to the bell curve on talent?  Will someone please tell these bumblebees that science has absolutely proven they can’t fly!

Last note on why we should let baby organizations live, and do everything in our power to help them along, is answered by simply reading the list of members who belong to ITPI.  We need this gene pool.

  • Kevin Behr – President and co-founder: CTO and Chief Operational Strategist for IP Services. Kevin co-founded the ITPI with Gene Kim. He is an active member of the Information Systems Audit and Control Association. Kevin is a frequently invited speaker called on to address a broad range of technology and management framework topics. Kevin is co-author of the Visible Ops Handbook.
  • Scott Alldridge – Vice President and founding officer: founding officer and board member of the ITPI. He provides key strategic and operational oversight, and provides key resources from IP Services to see the vision and mission of the ITPI is carried onward.
  • Ron Neumann – Vice President and founding officer: President of Neumann Management Group, Inc. Ron is a board member of the ITPI and participates in defining the vision and overall strategic direction of ITPI. He manages the organization’s finances, and develops strategic relationships and sponsorships.
  • Gene Kim – Director of Research and co-founder: CTO and co-founder of Tripwire. Gene Kim co-chaired the Best in Class Security and Operations Roundtable (BIC-SORT) with the Software Engineering Institute. He is co-author of the Visible Ops Handbook and is a primary researcher for the IT Controls Benchmarking Survey with Dr. Grant Castner.
  • Grant Castner – Director of Benchmarking: Professor in the Department of Decision Sciences, Lundquist College of Business, University of Oregon. His research interests include technology adoption and diffusion, accounting information systems, electronic commerce, and information-technology infrastructure best practices. Grant is the research lead for the IT Controls Benchmarking Survey. Grant has also developed the ITPI website, ecommerce systems, and content management system.
  • George Spafford Jr. – Director of Prescriptive Guidance: Managing Director of Spafford Global Consulting. He is a recognized expert in IT process and Audit. He is a prolific author contributing articles to a wide range of IT publications. He co-authored the Visible Ops Handbook.
  • Julia Allen: Senior member of the technical staff at the Software Engineering Institute (SEI), a unit of Carnegie Mellon University. Julia is engaged in developing and transitioning enterprise security frameworks and executive outreach programs in enterprise security and governance.
  • Kurt Milne – Managing Director IT Process Institute: He has over 15 years experience in various marketing management, alliance management, and engineering positions at leading technology companies. His main areas of expertise include IT service management and IT controls, inventory and supply chain management, and computer integrated manufacturing. He is responsible for overall ITPI operations including sponsorship and membership.

I don’t want a baby brother.  Tell the stork to bring ideas.

Consider just a sample of organization impacting at least some of the thoughts we actually we believe are our own.  Don’t get discouraged, even the mighty oak, was once a nut like …

Source Title:

Short Name

Web

American Chemistry Council

ACC

American Chemistry Council

American Civil Liberties Union (ACLU) Privacy Information

ACLU Privacy Information

American Civil Liberties Union: Privacy & Technology

American Institute of Certified Public Accountants

AICPA

American Institute of Certified Public Accountants

American National Standards Institute

ANSI

American National Standards Institute - ANSI

Basel Committee on Banking Supervision (BCBS)

BCBS

The Basel Committee on Banking Supervision

Business Software Alliance

BSA

Business Software Alliance - USA Home Page

Center for Internet Security (CIS), Benchmarks and Scoring Tools

CIS Benchmarks and Tools

Center for Internet Security

Center for Public Company Audit Firms

CPCAF

Center for Public Company Audit Firms

CERT Coordination Center

CERT/CC

CERT Coordination Center: Security Practices and Evaluations

Common Criteria Project

Common Criteria Project

Common Criteria Project

Chief Information Officers Council

CIO Council

Federal Chief Information Officers Council

Code of Federal Regulations Full listing at GPO

CFR Full Listing at GPO

Code of Federal Regulations: Main Page

Committee of Sponsoring Organizations of the Treadway Commission

COSO

Committee of Sponsoring Organizations

Corporate Information Security Working Group

CISWG

Corporate Information Security Working Group: Report of the Best Practices and Metrics Teams

Director of Central Intelligence Directives

DCID

DCID - Director of Central Intelligence Directives

Federal Emergency Management Agency Mitigation Division

FEMA Mitigation Division

FEMA: Mitigation Division

Financial Crimes Enforcement Network

FinCEN

Financial Crimes Enforcement Network (FinCEN)

Global Information Assurance Certification

GIAC

Global Information Assurance Certification

Government Accountability Office

GAO

Government Accountability Office

Information Systems Audit and Control Association

ISACA

Information Systems Audit and Control Association® (ISACA®)

Information Systems Security Association

ISSA

Information Systems Security Association

Information Technology Governance Institute

ITGI

Information Technology Governance Institute

Institute of Internal Auditors

IIA

The Institute of Internal Auditors (The IIA) - Progress Through Sharing

International Information Systems Security Certification Consortium, Inc

ISC2

(ISC)² - International Information Systems Security Certification Consortium, Inc

International Organization for Standardization

ISO

ISO - International Organization for Standardization - Homepage

National Archives and Records Administration

NARA

National Archive and Records Administration

National Association of State Boards of Accountancy NASBA

NASBA

National Association of State Boards of Accountancy

National Institute of Standards and Technology

NIST

National Institute of Standards and Technology

Organization for the Advancement of Structured Information Standards

OASIS

Organization for the Advancement of Structured Information Standards

Open Information Systems Security Group

OISSG

Open Information Systems Security Group - Home

Organization for Economic Co-operation and Development

OECD

Organization for Economic Co-operation and Development

Public Company Accounting Oversight Board

PCAOB

The Public Company Accounting Oversight Board

SANS Information and Computer Security Resources

SANS Resources

SANS Institute - Information and Computer Security Resources

Securities and Exchange Commission

SEC

U.S. Securities and Exchange Commission (Home Page)

SysAdmin Audit Network Security Institute (SANS)

SANS Institute

SysAdmin Audit Network Security Institute -About the SANS Institute

Thomas - Library of Congress On Line

Thomas

THOMAS - Library of Congress Online

United States Security Awareness Organization

USSAO

United States Security Awareness Organization

Competition is the spice of life

Consider why so many mission statements use words like “best”, “premier”, and “highest authority.”  ‘Amaarrikans’ are measured in increments of gold (medals).  We compete, because that is the only way to win.

That was a little harsh.  Let me take it back.  Searching the internet for “Edwards Deming, Cooperation and Competition” brings back a list including the U.S. Department of Defense.  In spite of reputation, The DoD has long promoted cooperation over competition, “Quality” over “Zero Defect,” citing Edwards Deming’s 14 points for management practice[148].  Here’s an example found buried in a memo on how to work with vendors:

“W. Edwards Deming recommended stable, ongoing relationships between vendors and customers as a key to long-term success.  Industry has applied this principle with great success.  On the other hand, the Government has traditionally taken the shorter view, e.g., one base year and four option years.  This mind-set can lead to rapid vendor turnover and encourages industry to maximize profit.  Long-term contracts provide the vendor with the steady income stream needed to make long-term investments in the tools, people, and facilities that the Government needs[149]."

The Wolf maintains a ruthless image which serves to protect the pack.  The leaders collaborate and optimize as a lifelong form of play.  They don’t care what it says in the history books.  Their children grow up on instinct.  Building the better mousetrap may make them wealthy or powerful, but good ideas just add to the world paradigm.

Evidence of Deming’s impact is honored in our Library of Congress.  We rate his ideas among our country’s greatest assets.  Stories of triumph through cooperation, by opposing forces represents a third of prime time television, even if the only reason to cooperate is to enforce the medal, but we are making our way towards living Deming's dream.

My only comment on our obsession with winning is I’m a Deming fan[150].

Get the data and proportionality[151]

Often associated to the Errol Morris film, The Fog of War[152], Robert McNamara’s revealing commentary regarding decision frameworks prolonging the Vietnam war, McNamara’s lesson includes messages regarding information and data.  Morris explains in an NPR interview that reading Paul Hendrickson's book, “The Living and the Dead: Robert McNamara and Five Lives of a Lost War,” set this film in motion.  As explained on the NPR website, "Robert McNamara was a believer in control accounting [...] a mathematical way to analyze and evaluate systems.  […] and was plucked from success at the Ford Motor Company to become President John F. Kennedy's Secretary of Defense.  His unique approach to management guided the United States involvement in Vietnam[153]."

Biographers and McNamara himself share a sense of irony in portraying the Fog of War lesson “Get the Data.”  Commentary regarding speech delivered by a class 39 graduate to his HBS alumni highlights his conviction that “Statistical data could instead be used proactively as a general management tool for analyzing an organization’s production and operations and measuring the efficacy of problem-solving initiatives.”  In spite of this, McNamara explained the conventional wisdom about the domino theory and the question of whether U.S. troops could ever in fact prevent the loss of South Vietnam“ was never debated at the government’s highest levels.”  In the case of Iraq, he says, “there are comparable issues that appear to have never been debated.  That includes ‘nation-building’ or what would happen after we passed through major military operations.”

Frameworks used for the analysis of risk, including financial, digital, criminal, military and social, and the ontology which may be common to those frameworks, is a topic deserving debate and global anticipation.  The implications derived from efforts to develop world standards to the design of detective, preventive and predictive controls are only now gaining popular interest in our national strategy, market demand and prioritized government funded research.

The greatest lessons, however, are the simple ones.  Realizing Robert McNamara’s professional history involved controls for both the World Bank and U.S. Department of Defense, I felt compelled to read the observations of an Eagle again.

  1. Empathize with your enemy.
  2. Rationality will not save us.
  3. There's something beyond one's self.
  4. Maximize efficiency.
  5. Proportionality should be a guideline in war.
  6. Get the data.
  7. Belief and seeing are both often wrong.
  8. Be prepared to reexamine your reasoning.
  9. In order to do good, you may have to engage in evil.
  10. Never say never.
  11. You can't change human nature[154].

Cartoon Plan:

Man in suit waiving arms saying: “You’ve got to give me something.  We go public with these results in less than an hour.  The President isn’t going to buy this.”

Man at computer with spreadsheets all around, looking into computer screen, perspiration bullets around his face: “The only event correlation consistent with the 23% drop in college admissions across every demographic group in the United States is that week Google was off line due to that massive cyber attack.  Fell right around that cram week when the kids write all those essays.”

Main Menu