11/18 Class IT Control Flashcards
IT controls
IT controls prevent problems,
IT GCC’s
information tech general computer controls
application controls
controls that the programmers must follow and document every part of the system and that will stop bad things from happening
Good general computer controls start
at the top,
good lines of authority will stop any fraud or error
segregation of duties -
segregation of duties IT
keeping the programmers separate from the live environment and the development sphere, this makes so that they can't change live data, four people that should be separated in IT developers users security people computer operators
Logical/access/authentication control
what you know - user name and password
who you are - fingerprint, retinal scanner
what you have - token based controls, magnetic cards etc
RSA Card
randomly makes a user name and constantly changes
authentication
anything related to ecommerce, you need to see what is working behind the browser, look at how the browser is working and how it is secured. public key and private key keeps people accountable
the administrators
you must monitor these people
project
if you are doing ecommerce you need to see what the controls are. we don’t care so much about what they do but how they do it and if they have good controls in place,
appendix must include references and screen shots of you testing the controls
Change management
programs are out there that have version control.
Backup/Recovery/Continuity
making so that we have our data backed up and getting data when you lose it
disaster recovery
how do we recover data? have data somewhere else that is easily setup to get going
business continuity
making so that my data pops up somewhere else in the event of a disaster
cold side - all we have is the data offsite
hot side - a site is already running with the other one to work when one fails(business continuity)
warm side - data offsite, arrangement with someone who has a lease on standby ready for a disaster
Network
firewall, IDS, etc.
completeness and accuracy,