11.02
Control Activities
Principle 11 - Design General Control Activities over Information Technology
Attribute 11.02 - Management designs general control activities over the entity's information technology to mitigate risks to information security. Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability. The reliability of information technology used within business processes, including automated controls, depends on the selection, development, and implementation of general control activities over information technology.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 11.01
- Next Attribute - 11.03
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues.
MC's voter registration database was not included in this Section 2 investigation of Drop Box issues. However, the consequences of a poorly maintained and corrupted database were identified by the AZ AG's inspector. See the heading Deviation: Fictious Addresses in MC Voter Registration Database from Maricopa Dropbox Collection (2020) webpage for an assessment of over 56,000 undeliverable early ballots. These early ballots under USPS control may be stolen and used for fraudulent purposes given that they are treated as first-class mail, not as valid ballots with potential to sway elections. The information within the MC Voter Registration database has been corrupted.
