Thursday, July 31, 2008

BE - 2008 Survey on the IT Business Balance - Deloitte

"Today, CEOs are still insufficiently aware of the added value of strategic cooperation with the IT department in optimally gearing the IT strategy to the business strategy and managing business risks, such as safety, fraud and privacy. This is one of the remarkable findings of Deloitte’s yearly IT Business Balance Survey." The survey is available at the following site. BE - 2008 Survey on the IT Business Balance - Deloitte

Tuesday, July 29, 2008

SEC: Ex-CFO Used Spreadsheets for Fraud - Accounting - CFO.com

Spreadsheets are used extensively in business - so extensively that they have become a normal part of many organizational information systems. However, control over spreadsheets is particularly problematic because they can be easily manipulated by a single user, and often there are no controls over what the user does to a spreadsheet. In a recent fraud case, the former CFO of a company used spreadsheets to hide his manipulations intended to support false balances he had created in the records. He used white fonts and hidden rows to conceal his entries. It reminds us of a need not only to tighten controls over spreadsheets, but more importantly to limit their use in an information system. If spreadsheets are being used too much, then it means there is a shortcoming in the formal IS software that needs to be addressed. SEC: Ex-CFO Used Spreadsheets for Fraud - Accounting - CFO.com

Monday, July 28, 2008

Saturday, July 26, 2008

Friday, July 25, 2008

AT&T : Enterprise Business : Article : Executive Summary : Quantum Cryptography

Quantum Cryptography is a new method of encryption key transmission that is beginning to be used in Virtual Private Networks (VPNs) This method is based on the concepts of Quantun Mechanics, under which keys are constructed using a protocol that allows key measurement to take place only once, making it supremely difficult to compromise the key. AT&T : Enterprise Business : Article : Executive Summary : Quantum Cryptography

Wednesday, July 23, 2008

Flunking the password test > Security Products, Practices and Infrastructure

In a recent poll, researchers found that one third of the administrators queried said they had used admin passwords to access information they otherwise wouldn't have had access to. It confirms the validity of the long standing procedures of IS Auditors to check on who holds admin passwords, whether the holders are appropriate and how the passwords are used. This is another example of how many of the threats come from within. Flunking the password test > Security Products, Practices and Infrastructure

Tuesday, July 22, 2008

PC World - Business Center: Protect Your Network From Rogue IT Employees

IT Auditors have long known that one of the greatest threats to a system comes from within - disgruntled, careless or misled employees who find a way to gain access to critical areas of the system and do damage. Something like this happened recently at the City of San Francisco, where an employee seized control of the administrative functions of the network. It's something that needs to be a significant focus of every security plan. PC World - Business Center: Protect Your Network From Rogue IT Employees