8.17: Difference between revisions

From Arizona Citizen Voice
No edit summary
 
(2 intermediate revisions by the same user not shown)
Line 3: Line 3:
'''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk'''
'''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk'''


'''Attribute''' '''8.17''' - Management considers information security risk factors, which may include the following:
'''Attribute''' '''8.17''' - Management considers information security risk factors, which may include the following:  


* the complexity of the entity's information technology;
* the complexity of the entity's information technology;
Line 15: Line 15:
'''>>>Navigational Buttons<<<'''
'''>>>Navigational Buttons<<<'''
* '''[[Index of Attributes]]'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - ?'''
* '''Previous Attribute - [[8.16]]'''
* '''Next Attribute - ?'''
* '''Next Attribute - [[8.18]]'''
__FORCETOC__
__FORCETOC__


=== '''No Examples''' ===
=== Jamie's Story ===
No examples are available to illustrate governance gaps for this attribute.
 
=== Election Anomalies ===
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
 
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Latest revision as of 09:13, 25 August 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.17 - Management considers information security risk factors, which may include the following:

  • the complexity of the entity's information technology;
  • new or emerging technologies;
  • information technology that may be outdated or incompatible with new technologies;
  • decentralized operating systems and communications networks;
  • external-party access to the entity's operating systems and communications networks;
  • information technology personnel not having the knowledge, skills, or abilities to maintain the entity's information technology and respond to related risks; and
  • personnel being unfamiliar with technology and related risks.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.