IT systems that do not function properly constitute a risk to your business management. In view of a director’s responsibility for business management, management may decide to ask an independent expert for assessment and advice.
An IT audit gives you a grip on your IT processes and ensures you can be accountable. A rule-based IT audit complies with generally accepted standards and is mainly focused on risk analysis and risk management. However, changes within your organisation, internal discussions, departmental interests (politics!) and the interests of IT suppliers may cloud the picture, and a rule-based IT audit is not sufficient in such a case.
Therefore, Mazars has developed its own IT audit method which goes a step further, the context-based IT audit. In a context-based IT audit we consider your information systems in the context of your organisation and its environment. We consider the characteristics of products and markets, your future plans, your management model, the set-up of the organisation, the operating processes, and finally legislation and regulations. Your system will only furnish 'control' when your IT system is aligned to your organisation.
In practice, security measures are often left to the technicians, which means that management has little grip on it, yet management is and remains accountable.
During the Security Audit, we test the set-up, existence, and operation of the security measures against generally accepted standard and sector-specific regulations. But Mazars goes further, as we place your organisation in the context of its environment (product/ service/ market/ supplier/ client/ regulator/ etc.) and consider the complete picture for your organisation.
The people in your organisation are an important factor in our Security Audit. Who is responsible for what within your IT department, who has access to your system, how do users deal with back-up procedures and passwords, what is the influence of personnel turnover on the IT environment? We also look at the physical security of your office premises, and whether migration to a new Windows release takes account of 'security policies'.
For questions or observations please contact
Newsletter Management Consultants September 2010
13 September 2010
The Management Consultants newsletter is an information bulletin which is offered to all Mazars clients in the department Mazars Management Consultants. The bulletin appears 3-4 times per year.
Click here for a list of our job offers