8.16: Difference between revisions

From Arizona Citizen Voice
No edit summary
No edit summary
Line 7: Line 7:
'''>>>Navigational Buttons<<<'''
'''>>>Navigational Buttons<<<'''
* '''[[Index of Attributes]]'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - ?'''
* '''Previous Attribute - '''
* '''Next Attribute - ?'''
* '''Next Attribute - ?'''
__FORCETOC__
__FORCETOC__


=== '''No Examples''' ===
=== '''No Examples''' ===

Revision as of 22:02, 21 August 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.16 - External risks may come from external parties that connect with or operate the entity's information technology or from unrelated attackers. External parties that connect with the entity's operating systems and databases in the normal course of operations may include end users, such as program beneficiaries; federal, state, and local government entities; and service organizations. External parties that operate the entity's information technology may include developers to which the entity outsources the design of information technology or service organizations or location-independent technology services that operate the systems on behalf of the entity. External information security risks may arise when an entity relies on these external parties' internal control systems as they perform business processes for the entity.

>>>Navigational Buttons<<<


No Examples