CHAPTER 5
Group 3 A-336
0.5.01.
Introduction to IT
General Controls
- are the backbone of any organization’s information systems. They are designed to
ensure these systems’ reliability, security, and effectiveness.
ITGCs are the backbone of any organization’s information systems. They are designed to
ensure these systems’ reliability, security, and effectiveness.
Integral to an organization’s IS’s secure and efficient operation by encompassing
processes, practices and procedures that form a critical IT security and management
backbone.
They are crucial in establishing a safe IT environment by ensuring data confidentiality,
integrity, and availability. They include network security, access controls, and data integrity
mechanisms
They must evolve with changing technologies and business needs. They also play a critical
role in aligning IT with business objectives. They ensure that IT resources are used
efficiently and contribute to achieving organizational goals.
ITGCs is multifaceted, addressing various elements essential to an organization’s IT
framework.
They span the entire IT landscape of an organization. From governing user access to
managing network security, from ensuring data backup to overseeing software
development, ITGCs are all-encompassing.
Examples of Risks: (1) Threat of Cyber Attack (2) Internal Risks (3) Operational Risks (3)
Compliance Risks (4) Risks on technological changes and advancements
Type of IT General Control
1. IS Acquisition and Development ITGCs
2. IS Change Management Controls
3. User Access Administration ITGCs
4. IS Security Management Controls
5. Computer Operations Management ITGCs
6. Business Continuity and Disaster Recovery Preparedness Controls
7. Data Governance, Management, and Security ITGCs
8. IS Project Auditing Controls
0.5.02.
IS Acquisition and
Development
this is the most critical stages in the lifecycle of any organization’s IT
infrastructure.
the acquisition phase of IT systems involves evaluating, selecting, and purchasing
hardware, software, or services from external vendors.
the development phase focuses on creating or customizing software applications to
meet specific organizational needs through (1) in-house development, (2)IT outsourcing,
or a (3)combination of both.
A critical aspect of effective IS acquisition and development is Risk assessment.
A key element in this area is the evaluation of third-party vendor controls, as many
organizations rely on external vendors for their information system’s needs. They directly
affect the confidentiality, integrity, and availability of IS.
This area is not merely about choosing and building IT systems; it encapsulates a strategic
approach that aligns these systems with business goals, ensures their reliability, and
safeguards them against various risks.
Requirements Analysis and Definition Control
Vendor Assessment and Selection Control
Project Management Control
Testing and Quality Assurance Control
Security and Compliance Control
Change Management Control
User Training and Documentation Control
0.5.03.
IS CHANGE
MANAGEMENT
involves overseeing and facilitating software, hardware and IT process
modifications
Initiate Request: Submitted by users, IT, or stakeholders with scope
and purpose.
Evaluate: Assess impact, risk, and alignment; reviewed by Change
Advisory Board (CAB).
Plan: Define tasks, timelines, resources, and responsibilities.
Test: Perform unit, integration, and user acceptance testing (UAT).
Approve: CAB reviews test results and authorizes the change.
Implement: Deploy during scheduled time; use back-out plans if
needed.
Monitor & Review: Track post-change issues and conduct a post-
implementation review (PIR).
Prevent system downtime and security issues
Ensure changes are planned, tested, and approved
Assess risks before implementation
Maintain clear documentation and accountability
Support safe tech innovation and upgrades
Unauthorized Changes
Inadequate Testing
Poor Documentation
Lack of Communication
Regulatory Non-Compliance
Inadequate Training/Support
No Rollback Plan
Fragmented Processes
Resistance to Change
0.5.04.
USER ACCESS
ADMINSTRATION
a crucial component of IT General Controls managing and controlling access
to the organization’s IS
User Access Administration Process
Terminated User Access Management
Transferred User Access Management
Privileged User Access Management
Emergency Access Management
Role-Based Access Controls (RBAC)
Password Management
Segregation of Duties (SoD)
Monitoring of Current User Access
Unauthorized access & insider threats
Excessive or outdated privileges
Inadequate monitoring & weak
password policies
Failure to revoke access on time
Regulatory non-compliance
0.5.05.
IS Security Management
Typical network security practices include:
Firewalls - Employing firewalls to monitor and filter incoming and outgoing network traffic, allowing only authorized data to
pass through.
Intrusion Detection and Prevention Systems (IDPS) - Using IDPS to identify and block potential security threats or
suspicious activities on the network.
Virtual Private Networks (VPNs) - Implementing VPNs to encrypt data transmitted over public networks, ensuring secure
communication for remote workers.
Network Segmentation - Dividing the network into segments with different security levels, limiting lateral movement for
attackers.
Access Control Lists (ACLs) - Configuring ACLs to restrict network access based on user roles and privileges.
Regular Network Monitoring - Monitor network traffic for anomalies, unauthorized access attempts, orpotential security
breaches.
Typical data encryption practices include:
Encryption Algorithms - Using encryption algorithms like AES (Advanced Encryption Standard) to secure data at rest and
in transit.
Secure Sockets Layer (SSL) and Transport Layer Security (TLS) - Employing SSL/TLS protocols for securing data
transmission over the internet.
Full Disk Encryption - Encrypting all storage devices or drives to protect data in case of physical theft or loss.
End-to-end Encryption - Implementing end-to-end encryption in communication tools, ensuring that data remains
encrypted throughout its journey from sender to recipient
Key Management - Establishing robust critical management practices to securely store, distribute, and rotate encryption
keys
Typical periodic security audit and assessment practices include:
Vulnerability Scanning - Conducting automated scans to detect vulnerabilities in systems and applications.
Penetration Testing - Simulating real-world attacks to evaluate the effectiveness of security measures.
Security Risk Assessments - Identifying and assessing potential security risks and their impact on the
organization.
Compliance Audits - Ensuring security practices align with industry standards and regulatory requirements.
Security Incident Simulation - Running tabletop exercises or simulations to prepare the incident response team
for various cybersecurity scenarios
Typical incident response and management practices include:
Incident Detection - Utilizing security tools and monitoring to detect security incidents promptly.
Incident Classification - Categorizing incidents based on their severity and potential impact.
Incident Containment - Isolating affected systems to prevent further damage.
Root Cause Analysis - Investigating the cause of the incident to prevent future occurrences.
Communication Plans - Establishing communication protocols for notifying stakeholders, authorities, and
affected parties.
Documentation - Thoroughly documenting incident details, response actions, and lessons learned for future
reference.
Typical user security training and awareness practices include:
Security Training - Regular training sessions on phishing awareness, password hygiene, and safe browsing.
Phishing Simulations - Conducting simulated phishing attacks to test users’ ability to recognize and report
phishing attempts.
Security Policies - Communicating and enforcing security policies and guidelines throughout the organization.
Awareness Campaigns - Running awareness campaigns to keep security in mind for all employees.
Reporting Mechanisms - Offering clear and accessible channels for reporting security concerns or incidents.
In IS security management, organizations face several primary risks that can significantly impact their
operations and strategic objectives. Understanding these risks is vital for effective risk management and
protecting the organization’s networks, computer systems, and data from unauthorized access or attacks.
Cyber attacks
Security breaches
Data loss and corruption
Regulatory non-compliance
Inadequate incident response
Weak data encryption
Social engineering attacks
Insufficient security budget
In IS security management, a subset of IT General Controls (ITGC), several crucial controls ensure the security and
integrity of an organization’s information systems. These controls are vital in aligning existing IS with business
objectives, managing risks, and ensuring successful outcomes.
Network Security Control
Data Encryption Control
Regular Security Audits and Assessment Control
Incident Response and Monitoring Control
User Security Training and Awareness Control
0.5.06.
Computer
Operations
Management
Focuses on ensuring the daily smooth functioning of an organization’s IT
systems—spanning servers, networks, data storage, processing, and
aligning technical operations with strategic goals.
The primary goals are to prevent downtime, protect data integrity, and
safeguard the organization's IT assets
Core Components of Operations
Management
System Performance Monitoring
Data Backup & Recovery
Hardware Maintenance
Software Patch Management
Incident & Problem Management
Environmental Control
Capacity Planning & Scalability
Inadequate System Performance Monitoring
Insufficient Data Backup and Recovery Procedures
Neglected Hardware Maintenance
Poorly Managed Software Updates and Patching
Inefficient Incident and Problem Management
Weak Environmental Controls
Inadequate Data Center Capacity Planning
Inadequate Disaster Recovery Preparedness
Ineffective Scalability Strategies
IT General Controls (ITGC)
Objectives & Activities
Performance Monitoring Control
Backup & Recovery Control
Hardware Maintenance Control
Patch Management Contro
Incident & Problem Management Control
Environmental Control
Capacity & Scalability Control
Audit Program
Reviewing daily system logs and monthly
maintenance reports.
Inspecting backup logs and recovery test reports.
Checking hardware maintenance logs.
Verifying patch and update records.
Assessing incident management documentation
0.5.07.
Business Continuity
Management and
Disaster Recovery
Preparedness
A crucial area of IT General Controls (ITGC) is the plans and
actions a company takes to make sure it can keep running and
quickly recover in the event of a disaster or major disruption.
Its main goal is to protect the organization's capacity to
continue operating both during and after unforeseen events,
like natural catastrophes, cyberattacks, or system malfunctions.
• Workforce continuity plans to ensure critical employees can perform
their roles.
• Alternate work location strategies for employees if the primary site is
unavailable.
• Communication plans for employees, customers, suppliers, and other
stakeholders.
• Protocols for accessing critical resources and supplies during a crisis.
The primary component of an effective BCP
and DRP framework is the Business Impact
Analysis (BIA).
BIA typically starts with forming a competent team of representatives
from various departments and organizational functions.
Assess the potential impacts of disruptive events (financial loss,
reputation damage, legal obligations, and regulatory compliance)
Evaluates dependencies between processes, systems, and personnel to
understand their relationship
After completing the BIA, the organization develops its Disaster
Recovery Plan (DRP)
It involves dedicated IT and business continuity teams. These teams work
together to outline the steps and procedures required to recover IT systems
and data following a disaster. The DRP includes details such as:
Clear recovery procedures for each critical system and application.
Roles and responsibilities of team members during recovery efforts.
Contact information for key personnel and vendors.
Hardware and software requirements for recovery.
Detailed recovery timelines and escalation procedures.
Tabletop exercises: Participants discuss hypothetical scenarios and evaluate
their responses.
Simulations: Realistic disaster scenarios are enacted to test the plans and
team reactions.
Full-scale drills: Comprehensive tests involving recovery efforts and team
coordination.
Relevant Risks
Organizations can experience a number of major risks when it
comes to disaster recovery planning and business continuity
management, which can have a big influence on their operations
and strategic goals. Effective risk management and maintaining
the operational continuity and resilience of the company relies
understanding of these risks.
RELEVANT RISKS IN BUSINESS CONTINUITY MANAGEMENT
AND DISASTER RISK PLANNING
[Link] BIA and Risk Assessment
Regular update for the DRP and BCP or leave critical
components out of these plans to ensure adequate response
strategies during a disaster.
2. Outdated or Incomplete DRP and BCP
Regular update for the DRP and BCP or leave critical
components out of these plans to ensure adequate response
strategies during a disaster.
3. Lack of Testing and Drills
Not doing regular testing and drills to leave recovery teams and
employees unfamiliar with procedures and unprepared for
real-world disaster scenarios
4. Insufficient Employee Training
Employees are not adequately trained in disaster response and
business continuity, they may not know how to react, leading to
disorganized and ineffective responses. Employee safety,
operational efficiency, and the ability to recover from a disaster
are compromised.
5. Data Backup Failures
Inadequate data backup and replication processes may result in
data loss or prolonged downtime during recovery efforts.
6. Ineffective Emergency Communication
Emergency communication plans and systems are unreliable or
improperly maintained, critical information may not reach the
right individuals during a disaster.
7. Third-Party Dependencies
Reliance on third-party vendors for critical services or
resources may expose the organization to risks if these vendors
experience disasters or disruptions.
8. Resource Constraints
Inadequate budget allocation and resource availability for
disaster recovery and business continuity efforts may limit the
organization’s ability to implement robust preparedness
measures.
9. Compliance and Regulatory Risks
Failing to comply with industry-specific regulations or legal
requirements related to disaster recovery and business
continuity can result in legal penalties and reputational damage.
Non-compliance may lead to fines, legal actions, and loss of
customer trust
Relevant IT General Controls Objectives and Activities
Several essential controls, which are a subset of IT General Controls (ITGC), guarantee
the efficient business continuity of information systems. These controls are essential
for minimizing risks, guaranteeing successful outcomes, and coordinating current IS
with business objectives.
Objective: Business Impact Analysis Control
To conduct a comprehensive Business Impact Analysis (BIA) to identify critical business
processes, assess potential impacts of disruptions, and establish recovery priorities.
Activities:
Maintain comprehensive records of the BIA process
Protect the confidentiality and integrity of BIA data
Implement access controls to restrict access to BIA information
Objective: Disaster Recovery Plan Development Control
To ensure the development and maintenance of a detailed Disaster Recovery Plan (DRP) that
outlines recovery procedures, responsibilities, and resource requirements for IT systems and
data
Activities:
Maintain version control of the Disaster Recovery Plan (DRP)
Implement a change management process for DRP updates
Encrypt sensitive data within the DRP
Objective: Business Continuity Plan Development Control
To establish and maintain a comprehensive Business Continuity Plan (BCP)
that addresses overall business operations, including workforce continuity, alternate
work locations, and communication plans
Activities:
Create detailed process maps as part of the Business Continuity Plan (BCP)
Establish a schedule for regularly reviewing and updating the BCP
Implement access controls and multi-factor authentication for the BCP
Objective: Testing and Drills Control
To regularly conduct testing and drills to evaluate the effectiveness of the DRP and BCP,
identify weaknesses, and refine recovery procedures.
Activities:
Plan and schedule regular testing and drills
Document the results of each test or drill
Provide training to participants involved in testing and drills t
Objective: Training and Awareness Control
To provide ongoing training and awareness programs to educate employees about their
roles and responsibilities during disasters and increase overall preparedness
Activities:
Develop and maintain training material
Conduct periodic awareness campaigns
Encourage employees to participate in testing and drills
Objective: Data Backup and Replication Control
To implement robust data backup and replication controls that align with recovery
objectives and ensure the availability and integrity of critical data. It establishes automated
and secure data backup and replication processes that align with the established RTOs and
RPOs
Activities:
Establish a regular backup schedule
Encrypt data during transit and storage
•mplement monitoring and alerting systems
Objective: Emergency Communication Control
To establish effective emergency communication plans that define how information is
disseminated to employees, stakeholders, and the public during disasters
Activities:
Establish and maintain multiple communication channels
Maintain up-to-date contact lists for employees, stakeholders, and key personnel
Implement emergency notification systems that allow mass communication to employees
and stakeholders
0.5.08.
Data Governance,
Management, and
Security
It refers to the policies, procedures, and standards that
ensure an organization’s effective management and
use of data.
1. Data Governance, Management
& Security
Ensures responsible, secure handling of data across its lifecycle.
Aligns data practices with business goals and legal compliance
(e.g., GDPR, HIPAA).
Poor management leads to inefficiencies, legal risks, and loss of
trust.
2. Data Classification
Categorizes data by sensitivity (e.g., Public,
Confidential).
Guides security, access, and retention policies.
Supports regulatory compliance.
3. Access Controls & Encryption
Role-Based Access Control (RBAC) limits access by job role.
Authentication methods: passwords, biometrics, MFA.
Encryption protects data at rest, in transit, and during
processing.
Regular audits ensure security effectiveness.
4. Encryption Key Management
Keys must be securely generated, stored, and rotated.
Covers all data states: rest, transit, processing.
Ensures only authorized users can decrypt sensitive data.
5. Data Retention & Disposal
Defines how long data is kept and how it's securely deleted.
Disposal methods: shredding, secure erasure.
Reduces storage costs and legal risks.
6. Data Quality Management
Ensures data is accurate, complete, and timely.
Techniques: validation, cleansing, profiling.
Improves decision-making and operational efficiency.
7. Data Privacy & Compliance
Aligns data handling with laws (GDPR, CCPA, HIPAA).
Includes consent management, data mapping, and user rights.
Requires DPIAs and a Data Privacy Officer (DPO).
8. Incident Response & Breach Management
Detects, contains, and mitigates data breaches.
Uses monitoring tools and severity classification.
Involves reporting, forensics, and stakeholder notification.
Post-incident reviews drive continuous improvement.
11.. Inadequate Data Classification
2..
2 Unauthorized Access
3..
3 Data Encryption Failures
4..
4 Data Retention Non-Compliance
5..
5 Data Quality Degradation
6..
6 Non-Compliance with Data Privacy Regulations
77.. Ineffective Incident Response
8..
8 Insider Threats
9..
9 Data Disposal Failures
11.. Robust Security: Implement strong technical safeguards.
2..
2 Regulatory Compliance: Follow relevant laws and standards.
3..
3 Data Quality: Ensure accuracy and reliability of data.
4..
4 Access Controls: Restrict data access to authorized users.
5..
5 Backup & Recovery: Plan for data loss and system recovery.
6..
6 Unified Management: Coordinate controls across platforms.
77.. Governance Policies: Define clear rules for data handling.
8..
8 Insider Threat Monitoring: Detect and prevent internal risks.
9..
9 Tech Adaptation: Stay updated with evolving technologies.
CONTROL PURPOSE
Data Classification Categorize data by sensitivity and value to apply proper protection measures.
Access Control Management Restrict data access to authorized users based on roles and responsibilities.
Data Encryption Encrypt data at rest, in transit, and during processing to ensure confidentiality
Data Retention & Disposal Define retention periods and secure disposal to reduce risk and ensure compliance.
Data Quality Management Maintain data accuracy, consistency, and completeness for reliable decision-making.
Data Privacy & Compliance Ensure adherence to privacy laws (e.g., GDPR, CCPA) and protect user rights.
Incident Response & Data Detect, respond to, and mitigate data breaches to minimize impact and improve
Breach Management security.
0.5.09.
IS project auditing
Project Planning and Approval - project is created (scope, objectives, and deliverables), a feasibility study
is conducted and reviewed by stakeholders.
Execution - project is planned in detail with tasks, timelines, and resource allocation defined. IS project
auditing is conducted for project progress and manage changes.
Closeout - project is formally completed, requires final review to ensure deliverables are complete and all
objectives are met.
1.1. PROJECT PLANNING AND APPROVAL CONTROL - Ensures projects are well-defined and aligned with
organizational goals. Activities include conducting feasibility studies and defining a project charter with
clear scope.
2.. BUDGET AND COST MANAGEMENT CONTROL - Focuses on tracking and managing project costs to
2
prevent overruns. Activities include preparing detailed budgets, monitoring expenditures, and
implementing change requests for budget modifications.
3.. SCHEDULE AND TIMELINE CONTROL - Ensures projects are completed within predefined schedules.
3
Activities include using tools like Gantt charts to track progress and holding regular status meetings.
4.. QUALITY ASSURANCE CONTROL - Aims to ensure project deliverables meet established quality
4
standards. Activities include comprehensive testing, code reviews, and quality control checklists.
11.. PROJECT PLANNING AND APPROVAL CONTROL - Ensures projects are well-defined and aligned with organizational goals. Activities include conducting feasibility studies and defining a project charter with clear scope.
2.. BUDGET AND COST MANAGEMENT CONTROL - Focuses on tracking and managing project costs to prevent overruns. Activities include preparing detailed budgets, monitoring expenditures, and implementing change requests for budget modifications.
2
3.. PROJECT SCHEDULE AND TIMELINE CONTROL - Ensures projects are completed within predefined schedules. Activities include using tools like Gantt charts to track progress and holding regular status meetings.
3
4.. QUALITY ASSURANCE CONTROL - Aims to ensure project deliverables meet established quality standards. Activities include comprehensive testing, code reviews, and quality control checklists.
4
5. RISK MANAGEMENT CONTROL - Establishes a systematic process to identify, assess, and mitigate project
5.
risks. This includes risk identification, developing mitigation strategies, and creating contingency plans.
6.. COMPLIANCE AND REGULATORY CONTROL - Ensures projects adhere to relevant laws and regulations,
6
such as HIPAA or GDPR. Activities include conducting regulatory assessments and preparing for external
audits.
77.. CHANGE MANAGEMENT CONTROL - Provides a structured process to manage and document changes to
the project's scope, schedule, or resources. Activities include assessing the impact of changes and a
formal review process for change requests.
Risk Description Example
Uncontrolled expansion of project scope beyond its initial Adding new features to an application during development
Scope Creep Risk definition. without adjusting timelines.
Exceeding the allocated project budget due to unforeseen
Budget Overrun Risk expenses.
Unexpected hardware procurement costs.
A team member with specialized skills leaves, causing
Resource Constraints Risk Insufficient resources like skilled personnel or equipment.
project delays.
Schedule Delays Risk Tasks taking longer than expected due to unforeseen issues. An unexpected software bug discovered during testing.
A rushed software release with numerous user-reported
Quality Assurance Failures Risk Inadequate quality validation leading to defects or errors.
bugs.
A healthcare project failing to meet HIPAA compliance
Compliance Violations Risk Non-compliance with legal or industry standards.
requirements.
A change request is not properly documented or
Change Management Challenges Risk Ineffective management of project changes.
communicated to all stakeholders.
A project manager fails to update team members on key
Communication Breakdown Risk Poor communication between project stakeholders.
decisions.
Technology risks like data breaches or security
Technology Risk vulnerabilities.
A data breach occurs due to inadequate security measures.
Detailed Description of the Risk and its Impact Relevant IT General Control Activity Detailed Test of Controls Audit Procedure
Comprehensive project planning is conducted for each IT
Review 2 recent project plans. Use inspection techniques to
project, including scope definition, resource allocation, and
verify that the plans include detailed project activities, well-
Inadequate project planning can lead to delays, cost milestone establishment. This includes defining project
defined timelines, and risk assessments. Assess whether the
overruns, and failure to meet objectives. objectives, determining resource requirements, setting
project objectives and goals are clear, realistic, and check
realistic timelines, and identifying potential risks. The project
for regular updates and amendments.
plan is reviewed and updated monthly.
Conduct regular project risk assessments and implement Examine two quarterly project risk assessment reports. Use
risk mitigation strategies. This involves identifying potential analysis techniques to evaluate the effectiveness of the risk
Overlooking project risks can result in unaddressed issues
risks, evaluating their impact, and developing mitigation identification and mitigation strategies. Confirm that risks
and project failures.
strategies. Risk assessments are performed at the initiation are appropriately classified, their impact is assessed, and
of the project and reviewed quarterly. effective mitigation strategies are implemented.
Ensure compliance with relevant laws and regulations Inspect documentation from 1 recent compliance audit. Use
Non-compliance with legal and regulatory requirements in throughout the project lifecycle. This involves periodic confirmation techniques to verify that the project adheres
project execution risks legal penalties and project compliance reviews and semi-annual audits. Responsibilities to applicable legal and regulatory requirements. Check for
invalidation. involve ensuring compliance with legal requirements and evidence of regular compliance reviews and obtain a
industry standards. reference to relevant laws and regulations.
Review 2 recent monthly financial reports for IT projects. Use
Rigorous budget management and monitoring are
analysis techniques to assess adherence to the budget and
Poor budget management in IT projects leads to financial conducted for each IT project, including tracking and
investigate any significant variances. Determine if the
shortfalls and potential project cancellations. controlling expenditures against the budget. This process is
expenditures are within budget limits and understand the
carried out monthly.
reasons for any deviations.
Detailed Description of the Risk and its Impact Relevant IT General Control Activity Detailed Test of Controls Audit Procedure
Maintain regular communication with stakeholders and Examine records from 2 recent stakeholder communication
Imperfect communication and stakeholder engagement can ensure their engagement throughout the project. This sessions. Use observation and inquiry techniques to assess
result in poorly aligned project objectives and stakeholder includes periodic status reports and stakeholder meetings the effectiveness of meetings. Interview staff members and
dissatisfaction. conducted monthly. Responsibilities involve disseminating leaders to verify that stakeholders are regularly informed
project progress and addressing stakeholder concerns. and that their feedback is considered in project decisions.
Review documentation from 2 recent quality reviews. Use
Implement thorough quality assurance processes, including inspection techniques to verify that quality assurance
Inadequate quality assurance practices can compromise the
regular quality checks and tests of project deliverables. procedures are being used and effectively implemented.
quality of the project deliverables.
Quality reviews are conducted at key project milestones. Assess whether the quality checks are comprehensive and
whether their findings are addressed promptly.
Inspect documentation for five recent significant project
Maintain detailed documentation of all project changes and changes. Use inspection techniques to confirm that all
Document project changes and decisions to avoid confusion critical decisions, including the rationale and approvals for changes and decisions are appropriately documented,
and lack of accountability. each change. This documentation is updated with every including rationale and authorization. Check for
significant change. comprehensive documentation that traces changes and
decisions made during the project.
0.5.10.
cloud computing and
mobile computing
Access Control and User Authentication
This involves using mechanisms and protocols to verify user identity and restrict access to resources. A
common method is Role-based Access Control (RBAC), where users are assigned roles with specific
permissions. Audit trails record who accessed what and when.
Cloud Data Backup and Recovery
Auditors assess backup and recovery procedures to ensure business continuity. They evaluate the frequency
and methods of data backups, which can be incremental or full.
Cloud Security Monitoring
involves the continuous surveillance of cloud infrastructure to detect and respond to security incidents.
Security Information and Event Management (SIEM) systems are central to this process. They collect and
correlate data to generate alerts for suspicious activity.
focuses on the management of mobile devices, applications, and the data used within an organization. It brings
significant benefits like flexibility and productivity, but also introduces several important security concerns.
Mobile Device Management
essential for securing mobile devices used within an organization. MDM systems manage and enforce security
policies on devices by handling device functions. They also manage mobile applications by allowing IT
administrators to distribute, update, and blacklist or allow list apps.
Mobile Application Security Testing
auditing mobile app security is a process that uses different methods to find and fix vulnerabilities. Penetration
testing simulates attacks to find weak spots. Static analysis examines the app's source code without running it,
while dynamic analysis tests the app while it's running to uncover hidden flaws. Together, these methods
ensure the application is secure.
Risk Objective Key Terms
Unauthorized person gaining access to sensitive data due to An attacker uses a weak password to gain access to a cloud
Unauthorized Access to Cloud Resources weak authentication or access controls. server and steal customer data.
Malicious actors intercept unencrypted data as it's being
Interception and compromise of data while it's being
Data Breaches During Data Transfer transmitted.
sent from a mobile app to a cloud server, leading to data
theft.
An outdated mobile device becomes vulnerable to a
Weak security practices on mobile devices leading to
Inadequate Mobile Device Security malware attacks or unauthorized access.
malware attack, allowing unauthorized access to corporate
data.
When a cloud provider fails to maintain robust security, A cloud service provider neglects a critical security patch,
Insufficient Cloud Service Provider Security creating vulnerabilities. which cybercriminals exploit to access customer data.
A mobile banking app has a coding vulnerability that allows
Apps with vulnerabilities that attackers can exploit for data
Insecure Mobile Applications breaches or privacy compromise.
attackers to access user accounts and conduct fraudulent
transactions.
Inadequate backup and recovery procedures leading to An organization loses critical customer data due to
Data Loss in Cloud Backups irreversible data loss. misconfigured cloud backups, causing operational issues.
Delayed detection of security incidents due to lack of A security breach goes unnoticed for weeks, allowing
Inadequate Security Monitoring continuous monitoring. attackers to access sensitive data.
Failing to adhere to data protection regulations, resulting in A healthcare organization stores patient data without proper
Regulatory Non-Compliance penalties and reputational damage. encryption, violating regulations like HIPAA.
An employee's stolen smartphone, containing sensitive
Mobile Device Theft or Loss Physical loss of devices containing sensitive corporate data.
company data, falls into the wrong hands.
Activities Objectives Example
Multi-Factor Authentication (MFA), strict access control
Access Control and User Authentication Ensure only authorized users and devices access resources.
policies, user roles, permissions.
TLS/SSL (for data in transit), Encryption Algorithms (for data
Data Encryption in Transit and at Rest Encrypt sensitive data during transmission and storage.
at rest).
MDM Solutions, configuring passcodes, encryption, remote
Mobile Device Management and Security Secure and manage mobile devices within the organization.
wipe capabilities, app management.
Cloud Service Providers, security standards, Service Level
Cloud Service Provider Assessment Evaluate cloud providers' security and compliance.
Agreements, data governance, disaster recovery.
Penetration Testing, code review, Static Analysis, Dynamic
Mobile Application Security Testing Identify and mitigate mobile application vulnerabilities.
Analysis
Cloud Data Backup and Recovery Establish reliable backup and recovery to ensure business Backup frequency, Recovery Point Objectives , Recovery
Procedures continuity. Time Objectives, data restoration procedures.
Security Information and Event Management (SIEM) systems,
Cloud and Mobile Security Monitoring Continuously monitor environments for security incidents. network traffic analysis, cloud-native security tools,
continuous surveillance.
THANK YOU