Main public logs

From Corrective Action Plan AZ

Combined display of all available logs of Corrective Action Plan AZ. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).

Logs
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)
  • 12:16, 16 August 2026 Neil thibodaux talk contribs created page 16.04 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.04''' - Management monitors the internal control system through ongoing monitoring and separate evaluations. Ongoing monitoring is built into the entity's operations, performed continually, and responsive to change. Separate evaluations are performed periodically and may provide feedback on the effectiveness of ongoing monitoring. Many of the methods and tools described below may be use...") Tag: Visual edit
  • 12:14, 16 August 2026 Neil thibodaux talk contribs created page 16.03 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.03''' - Once established, management can use the baseline as criteria in evaluating the internal control system and make changes to reduce the difference between the criteria and condition. Management reduces this difference in one of two ways. Management either changes the design of the internal control system to better address the objectives and risks of the entity or improves the ope...") Tag: Visual edit
  • 12:14, 16 August 2026 Neil thibodaux talk contribs created page 16.02 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.02''' - Monitoring activities evaluate whether each of the five components of internal control, including controls to effect the principles within each component, is present and functioning or if change is needed. Management establishes a baseline to monitor the internal control system. The baseline is the current state of the internal control system compared against management's design...") Tag: Visual edit
  • 12:13, 16 August 2026 Neil thibodaux talk contribs created page 16.01 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.01''' - Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. <u>Attribute Categories</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Establishment of a Baseline * Internal Control System Monitoring * Evaluation of Results") Tag: Visual edit
  • 12:03, 16 August 2026 Neil thibodaux talk contribs created page 15.09 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.09''' - Government entities not only report to the head of the government, legislators, and regulators but to the public as well. In the federal government, entities not only report to the President and Congress but also to the public. Entities consider appropriate methods for communicating with such a broad audience.") Tag: Visual edit
  • 12:00, 16 August 2026 Neil thibodaux talk contribs created page 15.08 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.08''' - Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity's methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout and outside of the entity on a timely basis.") Tag: Visual edit
  • 11:59, 16 August 2026 Neil thibodaux talk contribs created page 15.07 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.07''' - Management selects appropriate methods for communicating externally. Management considers a variety of factors in selecting an appropriate method of communication. Some factors to consider follow: * '''Audience''' - The intended recipients of the communication. * '''Nature of information''' - The purpose and type of information being communicated. * '''Availability'...") Tag: Visual edit
  • 11:58, 16 August 2026 Neil thibodaux talk contribs created page 15.06 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.06''' - External parties use separate reporting lines when external reporting lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs external parties of these separate reporting lines, how they operate, how they are...") Tag: Visual edit
  • 11:57, 16 August 2026 Neil thibodaux talk contribs created page 15.05 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.05''' - The oversight body obtains information through reporting lines from external parties. Information communicated to the oversight body includes significant matters relating to risks, changes, and issues that impact the entity's internal control system. This communication is necessary for the effective oversight of internal control.") Tag: Visual edit
  • 11:55, 16 August 2026 Neil thibodaux talk contribs created page 15.04 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.04''' - Management obtains information through reporting lines from external parties. Information communicated to management includes significant matters relating to risks, changes, or issues that impact the entity's internal control system. Communication may also include information for the entity to achieve program-related objectives. These communications are necessary for...") Tag: Visual edit
  • 11:54, 16 August 2026 Neil thibodaux talk contribs created page 15.03 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.03''' - Management communicates relevant and quality information externally through reporting lines so that appropriate external parties can help the entity achieve its objectives, address related risks, and support its internal control system. Information communicated by management includes significant matters relating to the entity's events and activities that impact its i...") Tag: Visual edit
  • 11:51, 16 August 2026 Neil thibodaux talk contribs created page 15.02 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.02''' - Management communicates with, and obtains relevant and quality information from, appropriate external parties using established reporting lines. Open two-way external reporting lines allow for this communication. External parties may include service organizations, suppliers, contractors, regulators, regulated entities, external auditors, federal entities, state and l...") Tag: Visual edit
  • 11:41, 16 August 2026 Neil thibodaux talk contribs created page 14.08 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.08''' - Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity's methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.") Tag: Visual edit
  • 11:40, 16 August 2026 Neil thibodaux talk contribs created page 14.07 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.07''' - Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication. Some factors to consider follow: * '''Audience''' - The intended recipients of the communication. * '''Nature of information''' - The purpose and type of information being communicated. * '''Availability'...") Tag: Visual edit
  • 11:38, 16 August 2026 Neil thibodaux talk contribs created page 14.06 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.06''' - Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how...") Tag: Visual edit
  • 11:37, 16 August 2026 Neil thibodaux talk contribs created page 14.05 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.05''' - The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel. Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the ef...") Tag: Visual edit
  • 11:37, 16 August 2026 Neil thibodaux talk contribs created page 14.04 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.04''' - Management obtains relevant and quality information about the entity's business processes that flows up the reporting lines from personnel to help management achieve the entity's objectives. Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.") Tag: Visual edit
  • 11:36, 16 August 2026 Neil thibodaux talk contribs created page 14.03 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.03''' - Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning o...") Tag: Visual edit
  • 11:34, 16 August 2026 Neil thibodaux talk contribs created page 14.02 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.02''' - Management communicates relevant and quality information throughout the entity using established reporting lines. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.") Tag: Visual edit
  • 11:33, 16 August 2026 Neil thibodaux talk contribs created page 14.01 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.01''' - Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system. <u>Attribute Categories</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Communication...") Tag: Visual edit
  • 11:26, 16 August 2026 Neil thibodaux talk contribs created page 13.07 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.07''' - Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management...") Tag: Visual edit
  • 11:25, 16 August 2026 Neil thibodaux talk contribs created page 13.06 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.06''' - Management develops the entity's information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.") Tag: Visual edit
  • 11:24, 16 August 2026 Neil thibodaux talk contribs created page 13.05 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.05''' - Management processes relevant data obtained or generated from reliable sources into quality information through the entity's information system. The entity's information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity's business processes.") Tag: Visual edit
  • 11:22, 16 August 2026 Neil thibodaux talk contribs created page 13.04 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.04''' - Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and fait...") Tag: Visual edit
  • 11:20, 16 August 2026 Neil thibodaux talk contribs created page 13.03 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.03''' - Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity's controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management cha...") Tag: Visual edit
  • 11:19, 16 August 2026 Neil thibodaux talk contribs created page 13.02 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.02''' - Management designs a process that uses the entity's objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropr...") Tag: Visual edit
  • 11:17, 16 August 2026 Neil thibodaux talk contribs created page 13.01 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.01''' - Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identification of Information Requirements * Relevant Data from Reliable Sources * Data Proces...") Tag: Visual edit
  • 11:12, 16 August 2026 Neil thibodaux talk contribs created page 12.05 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.05''' - Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity's objectives or mitigating related risks. If there is a significant change in an entity's process, management reviews this process in a timely manner after the change to determine that the control activit...") Tag: Visual edit
  • 11:10, 16 August 2026 Neil thibodaux talk contribs created page 12.04 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.04''' - Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Manage...") Tag: Visual edit
  • 11:09, 16 August 2026 Neil thibodaux talk contribs created page 12.03 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.03''' - Management documents in policies and procedures for each unit within the entity's organizational structure its responsibility for a business process's objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the...") Tag: Visual edit
  • 11:07, 16 August 2026 Neil thibodaux talk contribs created page 12.02 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.02''' - Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity's objectives to acceptable levels ['''documentation requirement''']. Note: The GAO emphasized "'''documentation requirements."'''") Tag: Visual edit
  • 11:04, 16 August 2026 Neil thibodaux talk contribs created page 12.01 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.01''' - Management should implement control activities through policies and procedures. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Documentation of Control Activities Through Policies and Procedures * Periodic Review of Control Activities") Tag: Visual edit
  • 01:50, 16 August 2026 Neil thibodaux talk contribs created page 11.17 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.17''' - Contingency planning protects critical and sensitive data against loss and allows for critical operations to continue without disruption or be promptly resumed when unexpected events occur. Maintaining technology through contingency planning often includes backup and recovery procedures, as well as continuity of operations plans, depending...") Tag: Visual edit
  • 01:49, 16 August 2026 Neil thibodaux talk contribs created page 11.16 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.16''' - Segregation of duties control activities help prevent fraud, waste, and abuse from being executed using information technology in the internal control system and mitigate the risk of management override of automated processes. Management considers the need to separate responsibilities for control activities related to the entity's informat...") Tag: Visual edit
  • 01:48, 16 August 2026 Neil thibodaux talk contribs created page 11.15 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.15''' - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management proces...") Tag: Visual edit
  • 01:46, 16 August 2026 Neil thibodaux talk contribs created page 11.14 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.14''' - Control activities for maintaining information technology include identifying vulnerabilities to patch and other functional updates to be made. Management continuously monitors the entity's information technology to establish a baseline for evaluating performance, detecting underlying deficiencies before they negatively impact users, colle...") Tag: Visual edit
  • 01:45, 16 August 2026 Neil thibodaux talk contribs created page 11.13 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.13''' - Control activities for developing information technology, commonly referred to as systems development controls, prevent the use of unauthorized or untested systems. Management may internally develop information technology, acquire it from suppliers, or outsource its development to service organizations. Management incorporates methodologie...") Tag: Visual edit
  • 01:44, 16 August 2026 Neil thibodaux talk contribs created page 11.12 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.12''' - Configuration management control activities involve the identification and management of operating and security features for information technology (i.e., infrastructure, platforms, and software) throughout the technology development process. Management may use a technology development methodology to provide a structure for a new informati...") Tag: Visual edit
  • 01:44, 16 August 2026 Neil thibodaux talk contribs created page 11.11 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.11''' - Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access c...") Tag: Visual edit
  • 01:42, 16 August 2026 Neil thibodaux talk contribs created page 11.10 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.10''' - Security management is the ongoing process for mitigating information security risks as part of the entity's overall internal control system (sometimes referred to as a security management program). This ongoing process covers all components of internal control related to information security risks.") Tag: Visual edit
  • 01:41, 16 August 2026 Neil thibodaux talk contribs created page 11.09 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.09''' - General control activities may be applied at the entity, system, and business process levels. General control activities include the following: * '''Security management''' - A separate process, addressing all components of internal control, for responding to risks related to information security. * '''Logical and physical access''' - Cont...") Tag: Visual edit
  • 01:40, 16 August 2026 Neil thibodaux talk contribs created page 11.08 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.08''' - The nature, timing, and precision of general control activities will depend on various factors, such as the complexity of the technology, sensitivity of information, use of service organizations, use of shared service or data centers, and risk of the underlying business process being supported.") Tag: Visual edit
  • 01:39, 16 August 2026 Neil thibodaux talk contribs created page 11.07 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.07''' - Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. They support the proper operation of the entity's information technol...") Tag: Visual edit
  • 01:37, 16 August 2026 Neil thibodaux talk contribs created page 11.06 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.06''' - Management designs the information technology infrastructure to support the entity's business processes. Information technology requires a physical infrastructure in which to operate, including communication networks for linking information technologies, computing resources for software and platforms to operate, and electricity to power th...") Tag: Visual edit
  • 01:36, 16 August 2026 Neil thibodaux talk contribs created page 11.05 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.05''' - nformation technology consists of the infrastructure, platforms, and software used to automate processes. Infrastructure comprises the physical information technology resources necessary to run software, including the hardware and devices used for information processing, data storage, and network communication. Infrastructure also includes...") Tag: Visual edit
  • 01:35, 16 August 2026 Neil thibodaux talk contribs created page 11.04 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.04''' - Management designs the entity's use of information technology in the information system by considering the defined information requirements for each of the entity's business processes. Information technology incorporated into business processes enables information related to those processes to become available to the entity on a timelier b...") Tag: Visual edit
  • 01:34, 16 August 2026 Neil thibodaux talk contribs created page 11.03 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.03''' - Management designs information technology to support the entity's information system and business processes. The entity's information system includes both manual and automated processes. Automated processes are wholly or partially performed using information technology.") Tag: Visual edit
  • 01:33, 16 August 2026 Neil thibodaux talk contribs created page 11.02 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.02''' - Management designs general control activities over the entity's information technology to mitigate risks to information security. Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and avai...") Tag: Visual edit
  • 01:32, 16 August 2026 Neil thibodaux talk contribs created page 11.01 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.''' - Management should design general control activities over information technology to mitigate risks to achieving the entity's objectives to acceptable levels. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Response to Risks * Design of the Entity's Info...") Tag: Visual edit
  • 01:19, 16 August 2026 Neil thibodaux talk contribs created page 10.23 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.23''' -If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.") Tag: Visual edit
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)