8.17

From Corrective Action Plan AZ

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.17 - Management considers information security risk factors, which may include the following:

  • the complexity of the entity's information technology;
  • new or emerging technologies;
  • information technology that may be outdated or incompatible with new technologies;
  • decentralized operating systems and communications networks;
  • external-party access to the entity's operating systems and communications networks;
  • information technology personnel not having the knowledge, skills, or abilities to maintain the entity's information technology and respond to related risks; and
  • personnel being unfamiliar with technology and related risks.

>>>Navigational Buttons<<<


No Examples