0% found this document useful (0 votes)
105 views1 page

IT Risk Register Overview

The risk register summarizes risks in the company's information technology systems. It identifies three main risks: lack of access control for visitors, lack of employee training on strong password maintenance, and lack of formal change management procedures. For each risk, it describes the potential impacts and notes there are currently no controls in place to mitigate the risks. It recommends the company develop policies and controls to require visitor access cards, provide password training to employees, and establish a formal change management process.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
105 views1 page

IT Risk Register Overview

The risk register summarizes risks in the company's information technology systems. It identifies three main risks: lack of access control for visitors, lack of employee training on strong password maintenance, and lack of formal change management procedures. For each risk, it describes the potential impacts and notes there are currently no controls in place to mitigate the risks. It recommends the company develop policies and controls to require visitor access cards, provide password training to employees, and establish a formal change management process.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INFORMATION TECHNOLOGY RISK REGISTER

EVENT OWNER MOHD. MOQTADAR JALEEL


AUDITOR INTERNAL AUDIT TEAM
AREA INFORMATION TECHNOLOGY

Inherent Residual
Area Risk Description Potential Impact Risk Category Any other observation, if any Current Controls, Risk Risk Recommendation
if any Respon
se

Likelihood

Likelihood
Risk Score

Risk Score
Impact

Impact
Access System Lack of access cards for visitors 1) Unwanted visitors for reason of unregulated Operational It has been observed that currently, there is no policy or controls in place for Almost certain High There are no set controls for the Almost certain High The Company should be having the same parameters with
access Financial granting access to building or factory premises for the visitors. same. respect to entry and exit of employees across all
2) Possible theft of assets locations.
3) Lack of building safety and possible criminal The Company does have access grant mechanism through face recognition installed Besides this, company should also have the access card
activity at the entry gates, especially at Ras Al Khaimah plant. For plant at Bahra & Asfan mechanism for visitors as they face recognition cannnot
in Saudi Arabia and also the AIC Metals, the entry gates are not secured by either be done as they are not on company's payroll.
face recognition or access cards.

Password Lack of trainings on the use of strong passwords 1) Possible security breach Strategic It has been observed that currently, the company is not stressing the importance of Almost certain High There are no set controls for the Almost certain High The Company should be providing trainings to the
Maintainence 2) Confidential companys' data loss Operational having strong passwords use which is evident from the fact that there are no same. employees on the use strong passwords to help users
3) Easy to guess passwords leading to leakage of Financial trainings on the same as well. protect against misuse by others.
personal information Apart from the trainings, there should be automated
reminders sent all across the organisation to every
employee mail id to change the password mandatorily
every fortnight or month.

Program Changes Lack of changes management proceduers in place 1) Lack of approvals for changing the processes Operational It has been obsered that currently, there is no formal process to handle change Likely Moderate There are no set controls for the Likely Moderate The Company should develop a policy with respect to
and Development 2) No risk assessment before going for a change management. All changes made to the system whether for servers, databases, same. change management process having following objectives:
3) No available protocols for emergency changes batch jobs, infrastructure are not tracked and documented as well. 1) Changing standards and procedures
2) Impact assessment, prioritization and authorization
3) Emergency changes
4) Change status tracking and reporting
5) Change closure and documentation
Along with policy development, the company has should
also develop metrics for controlling the change process
like:
1) Number of disruptions or data errors caused by
inaccurate specifications or incomplete impact
assessment
2) Amount of application of infrastructure rework caused
by inadequate change specifications
3) Percent of changes that follow formal change control
processes

Disaster Recovery No disaster recovery documented plan in place 1) Possiblililty of applications not getting online Strategic It has been observed that there is no documented plan for disaster receovery. Almost certain High The company does take back up of Almost certain High We recommend having a disaster recovery plan
Plan 2) Losing customers Operational data on Acronis Backup Software as implemented as soon as possible.
3) No priority set for applications well the physical copy. The The company does take backups but backup is intended
important data is also uploaded on as a long-term, low-cost solution for storing data,
to the cloud on regular basis. applications, configurations, etc. Disaster recovery is
designed to get the most critical portions of your IT
infrastructure back online as fast as possible. Disaster
recovery and data backups go hand in hand to support
business [Link] recovery (DR), on the other
hand, encompasses the full strategy for responding to a
disaster event and putting the backups into action. DR is
the umbrella under which backups reside.

EVENT OWNER
MOHD. MOQTADAR JALEEL
AUDITOR
INTERNAL AUDIT TEAM
AREA
INFORMATION TECHNOLOGY 
Area
Risk Description
Potential Im

You might also like