PCI Compliance From an Internal Audit point of view

Size: px
Start display at page:

Download "PCI Compliance From an Internal Audit point of view"

Transcription

1 PCI Compliance From an Internal Audit point of view University of Oklahoma Board of Regents, Internal Audit May 24, 2016 Tim Marley CPA CIA CISA CFE GSNA CISSP CIPP CISM PCI ISA PCIP IT Audit Director

2 The 3 Lines of Defense IIA Position Paper: The Three Lines of Defense In Effective Risk Management and Control, January 2013 EY Insights on Governance, Risk and Compliance Maximizing Value From Your Lines of Defense, December 2013 Chartered Institute of Internal Audit Governance of Risk: Three Lines of Defense, December 2015 Journal of Accountancy, Using Three Lines of Defense to Manage Internal Controls, July 2015

3 IIA Position Paper: The Three Lines of Defense In Effective Risk Management And Control, January 2013

4 The 3 Lines of Defense Model 1. Own and manage risk and control. 2. Monitor risk and control in support of management. 3. Provide independent assurance about effectiveness of risk management and control to the board and senior management. Operating Management Rick, Control, and Compliance functions put in place by management Internal Audit

5 Internal Audit in Higher Education Different reporting structures Different resources People Skills Experience Tools Systems vs. Non-systems

6 Identifying your IA function OU Charter example Mission Definition of Internal Auditing Authority and Organization Independence and Objectivity Responsibilities Quality Assurance and Improvement Program Fraud

7 Institute of Internal Auditors Mission of Internal Audit To enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight International Professional Practices Framework (IPPF)

8 Mission The mission of University of Oklahoma Internal Audit is to assist management and staff of the universities under the governance of the University of Oklahoma Board of Regents in the effective discharge of its responsibilities by providing them and the Board with independent and objective analysis, appraisals, recommendations, and pertinent comments with reference to: the adequacy and effectiveness of the internal control structure, the safeguarding of assets, compliance with applicable laws, regulations and university policies, and the achievement of management s objectives.

9 Authority and Organization

10 ACUA A professional organization comprised of audit professionals from all over the globe. We strive to continually improve the internal operations and processes of the individual institutions we serve, through continued professional development and the dissemination of individual internal audit experiences in an open forum with friends and colleagues.

11 IA Roles in PCI Compliance 1. Assurance 2. Consultation 3. Validation

12 Developing the plan Mandatory audits Requested audits Risk-based assessment Change in management Potential for fraud (cash) Historical audit results Time elapsed since last audit Budget (hours), etc.

13 Nearly 1,500 audit committee members Top challenges Audit committee s increasing workload Corporate performance Effectiveness of CFO and finance organization Quality of information received about the company s key risks kpmg.com/globalaci.com

14 kpmg.com/globalaci.com

15 IT Audit Universe Enterprise IT Departmental IT ERP/Campus/University

16 Enterprise IT IT functions that service external departments Central or core IT Application responsibilities Network responsibilities Server responsibilities Datacenters Service Provider

17 Departmental IT Typically services a single department Not necessarily traditional roles or employees Facilities less sophisticated? under-resourced? less structured? Shadow IT

18 Approach 1. Determine level of validation 2. Determine scope 3. Large audits Identify responsible parties Assess efficiencies Assess effectiveness Report

19 Audit scope by merchant or by campus/university? Factors Who owns the compliance responsibility? How many owners do you have? How many merchants do you have? How complex is your environment? How mature is your compliance effort?

20 By campus/university Operational/Performance Audit Program - compliance owner CFO, CIO, Bursar, treasurer, cashier, registrar, IT, etc. Appropriate signature on the validation submission to the processor/acquiring bank Policy and procedures Efficiencies Effectiveness* *Compliance Audit Program merchants and compliance owner Split into logical populations, SAQ A, B, C, etc. for sampling purposes Perform a risk analysis/assessment similar to the annual audit plan? Achieve economies of scale

21 Operational/Performance David (CMMI) Scope Adequacy Policy Content Policy Coverage Entities Quality Program Integration Accountability and Ethics Program Oversight Direction Enablement Evaluation Reporting

22 Operational/Performance Andy (GRA) Program Governance Employee Training and Awareness Policies and Procedures Compliance with University Policies and Procedures IT Compliance with University Policies and Procedures Bursar Program Attributes

23 Merchant Sampling Statistical or Judgmental? Define your population By SAQ type? By Transaction count? Geographical? Reporting structure?

24 Verify Merchant audit process the scope for the cardholder data environment. the correctness of the validation form/media, etc. (i.e. did they use the proper SAQ if applicable) the accuracy and completeness of the merchant s submission. compliance with applicable organizational policies.

25 Control Sampling Not for validation purposes Risk-based assessment Depends on the SAQ Depends on the complexity of the CDE Depends on the confidence in the overall effort

26 Organizational Policy By campus standards Assign responsibilities Business Units Bursar Human Resources IT Support IT Security/Compliance CSIRT PCI DSS Cloud Computing Guidelines

27 Organizational Policy

28 See: Third-Party Security Assurance, Appendix B Organizational Policy

29 QUESTIONS Tim Marley CPA, CIA, CISA, CFE, GSNA, CISSP, CIPP, CISM, PCI ISA, PCIP IT Audit Director, University of Oklahoma desk

9/11/2015. Auditing PCI Compliance. Introductions. Introductions

9/11/2015. Auditing PCI Compliance. Introductions. Introductions Auditing PCI Compliance Tim Marley CPA, CIA, CISA, GSNA, CISSP, CIPP, CISM, PCI ISA, PCIP IT Audit Director, University of Oklahoma September 30, 2015 Introductions Introductions Me Harold s MIS, October

More information

The Institute of Internal Auditors 247 Maitland Avenue Altamonte Springs, FL 32701-4201 USA

The Institute of Internal Auditors 247 Maitland Avenue Altamonte Springs, FL 32701-4201 USA INTERNATIONAL Professional Practices Framework (IPPF) Disclosure Copyright 2009 by The Institute of Internal Auditors Research Foundation (IIARF), 247 Maitland Avenue, Altamonte Springs, Florida 32701-4201.

More information

Report of Internal Audit Results 2006

Report of Internal Audit Results 2006 F-10 Report of Internal Audit Results 2006 Finance, Audit and Facilities Committee Board of Regents Department of Audits University of Washington March 2007 Table of Contents Executive Summary.....................................................

More information

Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014

Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014 Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014 Summary of Request: The purpose, authority, and responsibility of the internal

More information

BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL

BOARD OF EDUCATION OF BALTIMORE COUNTY OFFICE OF INTERNAL AUDIT - OPERATIONS MANUAL INTERNAL AUDIT OPERATIONS MANUAL BOARD OF EDUCATION OF BALTIMORE COUNTY INTERNAL AUDIT OPERATIONS MANUAL BACKGROUND The Office of Internal Audit Operations Manual was developed to be used as a guide and resource for the Office of Internal

More information

2012 Audit Plan. Finance, Audit and Facilities Committee Board of Regents. November 2011 ATTACHMENT

2012 Audit Plan. Finance, Audit and Facilities Committee Board of Regents. November 2011 ATTACHMENT 2012 Audit Plan Finance, Audit and Facilities Committee Board of Regents November 2011 ATTACHMENT Table of Contents Executive Summary...1 2012 Audit Plan...2 Analysis of Coverage of University Auditable

More information

Internal Audit and Advisory Services DRAFT

Internal Audit and Advisory Services DRAFT Internal Audit and Advisory Services DRAFT PAGE(S) Message from the Internal Audit and Advisory Services...1-2 Internal Audit and Advisory Services Plan...3-5 Objectives...6-7 Risk Assessment Process...8

More information

PCI Compliance 2012 - The Road Ahead. October 2012 Hari Shah & Parthiv Sheth

PCI Compliance 2012 - The Road Ahead. October 2012 Hari Shah & Parthiv Sheth PCI Compliance 2012 - The Road Ahead October 2012 Hari Shah & Parthiv Sheth What s the latest? Point-to-Point Encryption (P2PE) Program Guide Updated Solution Requirements and Testing Procedures for hardware-based

More information

Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997

Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997 Table of Contents Comptroller of Public Accounts Effectiveness of Internal Engagement May 1997 Overall Conclusion...1 The Internal Audit Department Is Currently Effective in All Eight Criteria, But Could

More information

Larry Laine, Deputy Land Commissioner and Chief Clerk. Annual Report on the Internal Audit Quality Assurance and Improvement Program

Larry Laine, Deputy Land Commissioner and Chief Clerk. Annual Report on the Internal Audit Quality Assurance and Improvement Program DATE: TO: FROM: SUBJECT: Larry Laine, Deputy Land Commissioner and Chief Clerk Tracey Hall, Deputy Commissioner of Internal Audit Annual Report on the Internal Audit The following report is presented in

More information

INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE

INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE INTERNAL AUDIT CHARTER AND TERMS OF REFERENCE CHARTERED INSTITUTE OF INTERNAL AUDIT DEFINITION OF INTERNAL AUDIT Internal auditing is an independent, objective assurance and consulting activity designed

More information

Emerging Strategies for Performance Auditing

Emerging Strategies for Performance Auditing IIA R E S E A R C H R E P O R T Emerging Strategies for Performance Auditing Insights from City Auditors in Major Cities in the U.S. and Canada Ronald C. Foster, CIA, CRMA, CISA, CPA, CMA, PMP, CFE Thomas

More information

PCI Compliance and the Cloud: What You Can and What You Can t Outsource Presented By:

PCI Compliance and the Cloud: What You Can and What You Can t Outsource Presented By: PCI Compliance and the Cloud: What You Can and What You Can t Outsource Presented By: Peter Spier Managing Director PCI and Risk Assurance Fortrex Technologies Agenda Instructor Biography Background On

More information

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization

Internal Audit Quality Assessment. Presented To: World Intellectual Property Organization Internal Audit Quality Assessment Presented To: World Intellectual Property Organization April 2014 Table of Contents List of Acronyms 3 Page Executive Summary Opinion as to Conformance to the Standards,

More information

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance Project No. AU13-012 September 16, 2013 Kevin W. Barthold, CPA, CIA,

More information

October 10, 2013. Report on Web Applications #13-205

October 10, 2013. Report on Web Applications #13-205 Office o f Auditi n g & Advisory Services The University of Texas Health Scie n ce Ce nter a t Ho us to n October 10, 2013 Report on Web Applications #13-205 We have completed our audit of web application

More information

Section 1: Assessment Information

Section 1: Assessment Information Section 1: Assessment Information Instructions for Submission This document must be completed as a declaration of the results of the service provider s self-assessment with the Payment Card Industry Data

More information

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Public Affairs & Security Studies Report No.

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Public Affairs & Security Studies Report No. THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES Report No. 15-06 OFFICE OF INTERNAL AUDITS THE UNIVERSITY OF TEXAS - PAN AMERICAN 1201 West University Drive Edinburg, Texas

More information

Department of Environmental Health & Safety

Department of Environmental Health & Safety THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES Report No. 14-05 OFFICE OF INTERNAL AUDITS THE UNIVERSITY OF TEXAS - PAN AMERICAN 1201 West University Drive Edinburg, Texas

More information

Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors

Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors Importance of Effective Internal Controls and COSO COSO

More information

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc.

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc. PCI Compliance at The University of South Carolina Failure is not an option Rick Lambert PMP University of South Carolina ricklambert@sc.edu Payment Card Industry Data Security Standard (PCI DSS) Who Must

More information

Internal Audit Charters

Internal Audit Charters Internal Audit Charters Part of a series of notes to help Centers review their own internal management processes from the point of view of managing risks and promoting good governance and value for money,

More information

Information Security Governance:

Information Security Governance: Information Security Governance: Designing and Implementing Security Effectively 2 nd Athens International Forum on Security 15 16 Jan 2009 Anestis Demopoulos, CISA, CISSP, CIA President of ISACA Athens

More information

Office of Audits and Analysis

Office of Audits and Analysis Office of Audits and Analysis Fiscal Year 2016 Audit Plans Carole M. Fox, CPA System Director, Office of Audits and Analysis TABLE OF CONTENTS INTRODUCTION AND PURPOSE.........1 SYSTEM ADMINISTRATION AUDIT

More information

University System of Maryland University of Baltimore

University System of Maryland University of Baltimore Audit Report University System of Maryland University of Baltimore October 2014 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up

More information

Comprehensive Risk Assessment and Developing the Audit Plan

Comprehensive Risk Assessment and Developing the Audit Plan Comprehensive Risk Assessment and Developing the Audit Plan Laure Boyd, CIA, CGAP Internal Audit Manager Leon County Clerk of the Circuit Court and Comptroller Our Time Today Background Risk Assessment

More information

Internal Audit Activity Update

Internal Audit Activity Update Internal Audit Activity Update April 17, 2013 Agenda Internal Audit (IA) purpose, authority and responsibility State Internal Audit Advisory Board (SIAAB) Fiscal Control and Internal Auditing Act ( FCIAA)

More information

AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities Corporate Compliance and Internal Audit.

AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities Corporate Compliance and Internal Audit. and Requirement: May be required if the organization must comply with Sarbanes-Oxley. Otherwise, is implemented as an organizational governance/business decision and best practice. Purpose: Provide independent

More information

IS Audit and Assurance Guideline 2402 Follow-up Activities

IS Audit and Assurance Guideline 2402 Follow-up Activities IS Audit and Assurance Guideline 2402 Activities The specialised nature of information systems (IS) audit and assurance and the skills necessary to perform such engagements require standards that apply

More information

CITY OF VAUGHAN EXTRACT FROM COUNCIL MEETING MINUTES OF MARCH 24, 2015

CITY OF VAUGHAN EXTRACT FROM COUNCIL MEETING MINUTES OF MARCH 24, 2015 CITY OF VAUGHAN EXTRACT FROM COUNCIL MEETING MINUTES OF MARCH 24, 2015 Item 2, Report No. 7, of the Finance, Administration and Audit Committee, which was adopted, as amended, by the Council of the City

More information

Effective Internal Audit in the Financial Services Sector

Effective Internal Audit in the Financial Services Sector Effective Internal Audit in the Financial Services Sector Recommendations from the Committee on Internal Audit Guidance for Financial Services: How They Relate to the Global Institute of Internal Auditors

More information

The State of Security and Compliance for E- Commerce and Retail

The State of Security and Compliance for E- Commerce and Retail The State of Security and Compliance for E- Commerce and Retail Current state of security PCI regulations and compliance Does the data you hold require PCI compliance Security and safeguarding against

More information

Domain 1 The Process of Auditing Information Systems

Domain 1 The Process of Auditing Information Systems Certified Information Systems Auditor (CISA ) Certification Course Description Our 5-day ISACA Certified Information Systems Auditor (CISA) training course equips information professionals with the knowledge

More information

What a Processor Needs from a University to Validate Compliance

What a Processor Needs from a University to Validate Compliance What a Processor Needs from a University to Validate Compliance Lisa T. Conroy Merchant Compliance Manager Vantiv May 24, 2016 Disclosures The information included in this presentation is for information

More information

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101 DIVISION: Finance & Administration TITLE: Policy & Procedures for Credit Card Merchants DATE: October 24, 2011 Authorized by: K. Ann Mead, VP for Finance & Administration

More information

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY PURPOSE The Payment Card Industry Data Security Standard was established by the credit card industry in response to an increase in identify theft

More information

CORPORATE AUDITOR SERIES

CORPORATE AUDITOR SERIES CORPORATE AUDITOR SERIES INCLUSIONS This is a four level series that applies to positions that provide professional audit services from within Internal Audit and Consulting Services or the Office of the

More information

Practice guide. quality assurance and IMProVeMeNt PrograM

Practice guide. quality assurance and IMProVeMeNt PrograM Practice guide quality assurance and IMProVeMeNt PrograM MarCh 2012 Table of Contents Executive Summary... 1 Introduction... 2 What is Quality?... 2 Quality in Internal Audit... 2 Conformance or Compliance?...

More information

Merchant Card Processing Request Form

Merchant Card Processing Request Form Merchant Card Processing Request Form This form must be filled out and approved before accepting credit card payments at any new location or via any website. of Application: Type of Request: e-commerce

More information

Establishing a Quality Assurance and Improvement Program

Establishing a Quality Assurance and Improvement Program Chapter 2 Establishing a Quality Assurance and Improvement Program O v e rv i e w IIA Practice Guide, Quality Assurance and Improvement Program, states that Quality should be built in to, and not on to,

More information

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Rehabilitation Report No. 14-15

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Rehabilitation Report No. 14-15 THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES Report No. 14-15 OFFICE OF INTERNAL AUDITS THE UNIVERSITY OF TEXAS - PAN AMERICAN 1201 West University Drive Edinburg, Texas

More information

Business/Fiscal Pay Program Minimum Qualifications

Business/Fiscal Pay Program Minimum Qualifications Accountant 1 experience. Degree must be in Accounting or related field with related accounting experience. An Accountant 1 will be eligible for promotion to Accountant 2 after eighteen (18) months provided

More information

Information Security Management System for Microsoft s Cloud Infrastructure

Information Security Management System for Microsoft s Cloud Infrastructure Information Security Management System for Microsoft s Cloud Infrastructure Online Services Security and Compliance Executive summary Contents Executive summary 1 Information Security Management System

More information

Internal Audit Manual

Internal Audit Manual Internal Audit Manual Version 1.0 AUDIT AND EVALUATION SECTOR AUDIT AND ASSURANCE SERVICES BRANCH INDIAN AND NORTHERN AFFAIRS CANADA April 25, 2008 #933907 Acknowledgements The Institute of Internal Auditors

More information

Audit Schedule July 1, 2016 through June 30, 2017

Audit Schedule July 1, 2016 through June 30, 2017 Audit Schedule July 1, 2016 through June 30, 2017 Office of the City Auditor 2401 Courthouse Drive, Room 344 Virginia Beach, Virginia 23456 757.385.5870 Promoting Accountability and Integrity in City Operations

More information

Brown Smith Wallace, LLC

Brown Smith Wallace, LLC Brown Smith Wallace, LLC Successful Software Selection Whitepaper Series How to Adhere to Payment Card Industry Data Security Standards By Ron Schmittling, CPA/CITP, QSA, CISA, CIA To learn more about

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Standards for the Professional Practice of Internal Auditing

Standards for the Professional Practice of Internal Auditing Standards for the Professional Practice of Internal Auditing THE INSTITUTE OF INTERNAL AUDITORS 247 Maitland Avenue Altamonte Springs, Florida 32701-4201 Copyright c 2001 by The Institute of Internal Auditors,

More information

Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE

Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE Practice Guide COORDINATING RISK MANAGEMENT AND ASSURANCE March 2012 Table of Contents Executive Summary... 1 Introduction... 1 Risk Management and Assurance (Assurance Services)... 1 Assurance Framework...

More information

HOW SECURE IS YOUR PAYMENT CARD DATA?

HOW SECURE IS YOUR PAYMENT CARD DATA? HOW SECURE IS YOUR PAYMENT CARD DATA? October 27, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director PCI Practice Leader Kevin Villanueva,, CISSP,

More information

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant Seccuris is Canada s premier Information Assurance integrator. We enable organizations to achieve business goals through effective management of information risk. We are agile, innovative, flexible, and

More information

REPORT NO. 2011-063 DECEMBER 2010 MIAMI DADE COLLEGE. Operational Audit

REPORT NO. 2011-063 DECEMBER 2010 MIAMI DADE COLLEGE. Operational Audit REPORT NO. 2011-063 DECEMBER 2010 MIAMI DADE COLLEGE Operational Audit BOARD OF TRUSTEES AND PRESIDENT Members of the Board of Trustees and President who served during the 2009-10 fiscal year are listed

More information

PCI DSS 3.0 Changes & Challenges P R E S I D E N T/ C O - F O U N D E R F R S EC U R E

PCI DSS 3.0 Changes & Challenges P R E S I D E N T/ C O - F O U N D E R F R S EC U R E PCI DSS 3.0 Changes & Challenges EVAN FRANCEN, CISSP CISM P R E S I D E N T/ C O - F O U N D E R F R S EC U R E PCI DSS 3.0 Changes & Challenges Topics FRSecure, the company Introduction to PCI-DSS Recent

More information

PCI Policy Compliance Using Information Security Policies Made Easy. PCI Policy Compliance Information Shield Page 1

PCI Policy Compliance Using Information Security Policies Made Easy. PCI Policy Compliance Information Shield Page 1 PCI Policy Compliance Using Information Security Policies Made Easy PCI Policy Compliance Information Shield Page 1 PCI Policy Compliance Using Information Security Policies Made Easy By David J Lineman

More information

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Criminal Justice Report No. 15-13

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Department of Criminal Justice Report No. 15-13 THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES Report No. 15-13 OFFICE OF INTERNAL AUDITS THE UNIVERSITY OF TEXAS - PAN AMERICAN 1201 West University Drive Edinburg, Texas

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

Please feel free to call on our organizations if we can be of assistance in any way on further deliberations, task forces or committees.

Please feel free to call on our organizations if we can be of assistance in any way on further deliberations, task forces or committees. 17 May 2012 International Internal Audit Standards Board Via e-mail: Lily.Bi@theiia.org Re: Definition of Internal Auditing Ms. Lily Bi, CIA, CISA, CGEIT Director, Standards and Guidance The Institute

More information

OAS 2015 Final Progress Report and 2016 Annual Audit Plan

OAS 2015 Final Progress Report and 2016 Annual Audit Plan OAS 2015 Final Progress Report and 2016 Annual Audit Plan TAB C BACKGROUND As outlined in the charter of the Oregon State University (OSU) Board of Trustees Executive & Audit Committee (Committee), the

More information

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer?

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? # SAIC CoM 2014 RG R79343 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? 2. Approximately how many credit card transactions do you process per year? 300,000;

More information

The following are responsible for the accuracy of the information contained in this document:

The following are responsible for the accuracy of the information contained in this document: AskUGA 1 of 5 Credit/Debit Cards Responsible administrator: Senior Vice President for Finance and Administration Related Procedure: The Credit/Debit Card Processing Procedures Responsible department: Bursar's

More information

Office of Internal Audit. Activity Report. For the period from March 16, 2014 to August 8, 2014. Internal Audit Team

Office of Internal Audit. Activity Report. For the period from March 16, 2014 to August 8, 2014. Internal Audit Team Activity Report For the period from March 16, 2014 to August 8, 2014 Internal Audit Team Stefanie Powell, CPA, CISA Interim Director Kelly Mintern, CPA, CIA Auditor Cynthia Nickerson, CPA Auditor Karen

More information

Texas Workforce Commission

Texas Workforce Commission Fiscal Year 2016 Audit Plan Approved by Commission September 28, 2015 Fiscal Year 2016 Audit Plan 1 Table of Contents Overview... 3 The Role of Internal Audit... 3 Professional and Statutory Requirements...

More information

policy D Reaffirmation of existing policy

policy D Reaffirmation of existing policy Name of Policy: Credit Cards Policy Number: 3364-40-24 Approving Officer: President.TOLE'DO l t.?-2 Responsible Agent: Treasurer Scope: All credit card Merchants at The University rg] New policy proposal

More information

University of Oregon Policy Statement Development Form

University of Oregon Policy Statement Development Form University of Oregon Policy Statement Development Form Policy Title: Electronic Commerce Policy submitted by: Name: Mark McCulloch Phone: 541 346 6249 Email: mmccullo@uoregon.edu Organization: Business

More information

PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants. UT System Administration Information Security Office

PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants. UT System Administration Information Security Office PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants UT System Administration Information Security Office Agenda Overview of PCI DSS Compliance versus Non-Compliance PCI

More information

Italy. EY s Global Information Security Survey 2013

Italy. EY s Global Information Security Survey 2013 Italy EY s Global Information Security Survey 2013 EY s Global Information Security Survey 2013 This year s survey our 16th edition captures the responses of 1,909 C-suite and senior level IT and information

More information

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Revised: October 2012 i Table of contents Attribute Standards... 3 1000 Purpose, Authority, and Responsibility...

More information

Title 4 - Codification of Board Policy Statements. Chapter 9 NEVADA SYSTEM OF HIGHER EDUCATION INTERNAL AUDIT, FINANCE AND ADMINISTRATION POLICIES

Title 4 - Codification of Board Policy Statements. Chapter 9 NEVADA SYSTEM OF HIGHER EDUCATION INTERNAL AUDIT, FINANCE AND ADMINISTRATION POLICIES Title 4 - Codification of Board Policy Statements Chapter 9 NEVADA SYSTEM OF HIGHER EDUCATION INTERNAL AUDIT, FINANCE AND ADMINISTRATION POLICIES A. Internal Audit Department Charter... 2 Section 1. Nature...

More information

IS Audit and Assurance Guideline 2202 Risk Assessment in Planning

IS Audit and Assurance Guideline 2202 Risk Assessment in Planning IS Audit and Assurance Guideline 2202 Risk Assessment in Planning The specialised nature of information systems (IS) audit and assurance and the skills necessary to perform such engagements require standards

More information

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards

Administrative Guidelines on the Internal Control Framework and Internal Audit Standards Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page

More information

J u n e 2 0 1 0. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a. I n t e r n a l A u d i t, N R C. Audit of Risk Management.

J u n e 2 0 1 0. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a. I n t e r n a l A u d i t, N R C. Audit of Risk Management. N a t i o n a l R e s e a r c h C o u n c i l C a n a d a Audit of Risk Management I n t e r n a l A u d i t, N R C J u n e 2 0 1 0 June 2010 i 1.0 Executive Summary and Conclusion Background This audit

More information

CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS I. PURPOSE The audit committee (the Audit Committee ) is a committee of the board of directors (the Board of Directors ) of Talon Metals Corp. (the

More information

PCI Compliance for Cloud Applications

PCI Compliance for Cloud Applications What Is It? The Payment Card Industry Data Security Standard (PCIDSS), in particular v3.0, aims to reduce credit card fraud by minimizing the risks associated with the transmission, processing, and storage

More information

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE

LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE Committee of Sponsoring Organizations of the Treadway Commission Governance and Internal Control LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE By The Institute of Internal Auditors Douglas J. Anderson

More information

IIA Position Paper: THE THREE LINES OF DEFENSE IN EFFECTIVE RISK MANAGEMENT AND CONTROL

IIA Position Paper: THE THREE LINES OF DEFENSE IN EFFECTIVE RISK MANAGEMENT AND CONTROL IIA Position Paper: THE THREE LINES OF DEFENSE IN EFFECTIVE RISK MANAGEMENT AND CONTROL JANUARY 2013 TABLE OF CONTENTS Introduction... 1 Before the Three Lines: Risk Management Oversight and Strategy-Setting...

More information

Internal Audit Practice Guide

Internal Audit Practice Guide Internal Audit Practice Guide Continuous Auditing Office of the Comptroller General, Internal Audit Sector May 2010 Table of Contents Purpose...1 Background...1 Definitions...2 Continuous Auditing Professional

More information

The Framework for Quality Assurance

The Framework for Quality Assurance Chapter 1 The Framework for Quality Assurance O v e rv i e w One of internal audit s major assets is its credibility with stakeholders. To provide credible assistance and constructive challenge to management,

More information

Executive Summary: Internal Audit Report # 11-07 IT Governance April 13, 2011

Executive Summary: Internal Audit Report # 11-07 IT Governance April 13, 2011 Executive Summary: Internal Audit Report # 11-07 IT Governance Organization Impact Audit Objective & Scope Professional auditing standards require internal auditors to periodically review and assess the

More information

University of Oregon Information Technology Risk Assessment. December 2, 2015

University of Oregon Information Technology Risk Assessment. December 2, 2015 December 2, 2015 Table of Contents EXECUTIVE SUMMARY... 3 BACKGROUND... 3 APPROACH... 4 IT UNITS... 5 NOTED STRENGTHS... 5 THEMES... 6 IT RISKS... 11 IT RISKS DESCRIPTIONS... 12 APPENDIX A: BAKER TILLY

More information

UCSD Credit Card Processing Policy & Procedure

UCSD Credit Card Processing Policy & Procedure UCSD Credit Card Processing Policy & Procedure The Payment Process UCSD accepts Visa, MasterCard, American Express and Discover credit cards. We perform credit transactions only, no debit sales with cash

More information

AMTRUST FINANCIAL SERVICES, INC. AUDIT COMMITTEE CHARTER

AMTRUST FINANCIAL SERVICES, INC. AUDIT COMMITTEE CHARTER Audit Committee Charter AMTRUST FINANCIAL SERVICES, INC. AUDIT COMMITTEE CHARTER Audit Committee Purpose The Audit Committee ( Committee ) is appointed by the Board of Directors of AmTrust Financial Services,

More information

A Risk-Based Audit Strategy November 2006 Internal Audit Department

A Risk-Based Audit Strategy November 2006 Internal Audit Department Mental Health Mental Retardation Authority of Harris County ENTERPRISE RISK MANAGEMENT A Framework For Assessing, Evaluating And Measuring Our Agency s Risk A Risk-Based Audit Strategy November 2006 Internal

More information

PAYMENT CARD PROCESSING

PAYMENT CARD PROCESSING CSU The California State University Office of Audit and Advisory Services PAYMENT CARD PROCESSING California State University, Bakersfield Audit Report 15-42 October 13, 2015 EXECUTIVE SUMMARY OBJECTIVE

More information

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879 Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 2 of 116 PageID: 4880 Payment Card Industry (PCI)

More information

Internal Auditing: Assurance, Insight, and Objectivity

Internal Auditing: Assurance, Insight, and Objectivity Internal Auditing: Assurance, Insight, and Objectivity WHAT IS INTERNAL AUDITING? INTERNAL AUDITING business people all around the world are familiar with the term. But do they understand the value it

More information

How quality assurance reviews can strengthen the strategic value of internal auditing*

How quality assurance reviews can strengthen the strategic value of internal auditing* How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,

More information

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS)

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING (STANDARDS) Introduction to the International Standards Internal auditing is conducted in diverse legal and cultural environments;

More information

Compliance and Industry Regulations

Compliance and Industry Regulations Compliance and Industry Regulations Table of Contents Introduction...1 Executive Summary...1 General Federal Regulations and Oversight Agencies...1 Agency or Industry Specific Regulations...2 Hierarchy

More information

SAS No. 70, Service Organizations

SAS No. 70, Service Organizations SAS No. 70, Service Organizations A standard for reporting on a service organization s controls affecting user entities' financial statements. Only for use by service organization management, existing

More information

How To Understand The Role Of An Internal Audit

How To Understand The Role Of An Internal Audit Top Ten Issues facing Internal Auditing in the Future The IIA Dallas Chapter April 6, 2006 Presented by: David A. Richards, CIA, CPA President The Institute of Internal Auditors drichards@theiia.org 1

More information

G13 USE OF RISK ASSESSMENT IN AUDIT PLANNING

G13 USE OF RISK ASSESSMENT IN AUDIT PLANNING IS AUDITING GUIDELINE G13 USE OF RISK ASSESSMENT IN AUDIT PLANNING The specialised nature of information systems (IS) auditing and the skills necessary to perform such audits require standards that apply

More information

MISSION STATEMENT OBJECTIVES IN ACCOMPLISHING OUR MISSION

MISSION STATEMENT OBJECTIVES IN ACCOMPLISHING OUR MISSION MISSION STATEMENT Internal Audit exists to support administration and the Board of Directors in the effective discharge of their responsibilities. Using our knowledge and professional judgment, we will

More information

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS)

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS) CSU, Chico Credit Card Handling Security Standard Effective Date: July 28, 2015 1.0 INTRODUCTION This standard provides guidance to ensure that credit card acceptance and ecommerce processes comply with

More information

PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS

PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS CIVICA Conference 22 January 2015 WELCOME AND AGENDA Change is here! PCI-DSS 3.0 is mandatory starting January 1, 2015 Goals of the session

More information

Adding Value to the UK Community

Adding Value to the UK Community 2011 ANNUAL REPORT Adding Value to the UK Community Table of Contents Director s Message 1 In-House Quality Initiatives 2-3 Governance 4 Metric Scorecard 5-7 UKIA Staff 8-9 Internal Audit assists the University

More information

University System of Maryland University of Maryland University College

University System of Maryland University of Maryland University College Audit Report University System of Maryland University of Maryland University College June 2015 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY For further information

More information

Microsoft Confidential

Microsoft Confidential Brock Phillips, CPA, CFE, CCEP Forensic Accounting Sr. Manager Financial Integrity Unit Microsoft Audit Group Lou DeCola, CPA, CIA, CFE Forensic Accounting Sr. Manager Financial Integrity Unit Microsoft

More information

TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER

TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER Page 1 of 7 A. GENERAL 1. PURPOSE The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Teck Resources Limited ( the Corporation ) is to provide an open avenue of

More information

INTERNAL CONTROL POLICIES

INTERNAL CONTROL POLICIES INTERNAL CONTROL POLICIES 2701 Internal Control Policy 2701.1 Addendum Internal Control Standard #1 Payments Cycle 2701.2 Addendum Internal Control Standard #2 Conversion Cycle 2701.3 Addendum Internal

More information

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Office of Alumni Relations Report No. 15-10

THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES. Office of Alumni Relations Report No. 15-10 THE UNIVERSITY OF TEXAS-PAN AMERICAN OFFICE OF AUDITS & CONSULTING SERVICES Report No. 15-10 OFFICE OF INTERNAL AUDITS THE UNIVERSITY OF TEXAS - PAN AMERICAN 1201 West University Drive Edinburg, Texas

More information