Physical and logical access controls - A pre-requsite for Internal Controls
bharathraob
3,788 views
22 slides
Feb 03, 2015
Slide 1 of 22
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
About This Presentation
Internal Controls truly forms an integral part for the efficient functioning in any business. The use of information technology to operate business is picking up rapid pace.
Physical and Logical Access Controls are the two areas to begin implementing internal controls. The objective of all IT rela...
Internal Controls truly forms an integral part for the efficient functioning in any business. The use of information technology to operate business is picking up rapid pace.
Physical and Logical Access Controls are the two areas to begin implementing internal controls. The objective of all IT related Internal controls is to protect confidentiality, integrity and availability of Data.
This presentation was jointly presented by Tarish Vasant ([email protected]) and myself (Bharath Rao, [email protected]) at the National Conclave held at Udupi on 6th January conducted by the Board of Studies of the Institute of Chartered Accountants of India and the Udupi Branch of SIRC of ICAI.
Size: 1.97 MB
Language: en
Added: Feb 03, 2015
Slides: 22 pages
Slide Content
Physical and Logical Access Controls A pre-requisite for internal controls?
Outline
What are Internal Controls?
Internal Controls The process designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of the entity’s objectives with regards to reliability of financial reporting, effectiveness and efficiency of operations, safeguarding of assets and compliance of applicable laws and regulations . The terms “control” refers to any aspect of one or more of the components of the internal controls.
Formula of Internal Control
IS Controls
Objective of IS Controls
Internal Controls
Some Terms
Physical Access Controls General Security
What are Physical Access Controls?
Illustrative Physical Access Control Objectives Enforcement of Policies and Procedures relating to management and security. Restriction of access to sensitive areas. Proper execution of procedures for Visitor Management Revocation of access privileges on termination of employment Constant monitoring of the premises Screening of baggage and frisking of employees and visitors
Logical Access Controls Application and General Security
What are Logical Access Controls They refer to controls that provide relevant authorization to appropriate personnel for the applications. This area of controls include – Granting Access Monitoring Access Revoking Access Preventing Conflict of Roles – Segregation of duties
Illustrative Control Objectives for Logical Access Controls (Security) Execution of security administration policies and procedures Avoidance of conflict of duties of personnel having security roles Approvals, Authorization and Documentation of access of new employees Revocation of access of terminated employees performed in a timely manner Periodical Review of user access roles and rights Enforcement of access password complexity parameters in all systems
What are Logical Access Controls?
What are Logical Access Control?
Regulations Under the Companies Act perspective
Regulations – Companies Act 2013 Section Reference Regulatory Requirement Section - 134 The directors would provide a responsibility statement have laid down internal financial controls to be followed by the company and are adequate and were operating effectively . Section - 143 The auditor’s report shall state that whether the company has adequate internal financial control system in place and the operating effectiveness of such controls.