Performance Audit of the San Diego Convention Center s HR Systems AUGUST 2014
|
|
|
- Blake Bryant
- 10 years ago
- Views:
Transcription
1 Performance Audit of the San Diego Convention Center s HR Systems HUMAN RESOURCES SOFTWARE AS A SERVICE SYSTEM RISKS ARE APPROPRIATELY MITIGATED AUGUST 2014 Audit Report Office of the City Auditor City of San Diego
2 This Page Intentionally Left Blank
3 Table of Contents Introduction 1 Background 2 Audit Results 4 THE CONVENTION CENTER HAS MITIGATED RISKS INHERENT TO OUTSOURCING HR SYSTEM SOFTWARE 4 Appendix A: Objectives, Scope, and Methodology 6
4 This Page Intentionally Left Blank
5 August 14, 2014 Carol Wallace, President and Chief Executive Officer San Diego Convention Center Transmitted herewith is an audit report on the San Diego Convention Center s Human Resources Systems. We have completed this report as requested by the Convention Center. This report is presented in accordance with City Charter Section Management s response to the report is presented on page 8. We would like to thank the Convention Center s staff for their assistance and cooperation during this audit. All of their valuable time and efforts spent providing us information is greatly appreciated. The audit staff members responsible for this audit report are Stephen Gomez, Danielle Knighten, and Kyle Elser. Respectfully submitted, Eduardo Luna City Auditor cc: City of San Diego Audit Committee Members OFFICE OF THE CITY AUDITOR 1010 SECOND AVENUE, SUITE 555, WEST TOWER SAN DIEGO, CA PHONE (619) FAX (619) TO REPORT FRAUD, WASTE, OR ABUSE, CALL OUR FRAUD HOTLINE (866)
6 This Page Intentionally Left Blank
7 Introduction Performance Audit of the San Diego Convention Center s HR Systems SDCC Current and Previous IT Performance Audits The San Diego City Auditor s Office (OCA) previously conducted two performance audits of risk areas within the San Diego Convention Center s (SDCC) information systems at the request of the Convention Center. The audit of the SDCC s HR Systems is the third of four IT risk areas identified in a previous risk assessment of the organization information systems environment as shown below: 1. IT infrastructure operations and security; 2. Financial systems IT controls; 3. Human Resources contracted system services; and 4. Management of IT system implementations; specifically, the implementation of the customer relationship management system. The Office of the City Auditor has completed the first three audits at the request of the San Diego Convention Center. OCA Page 1
8 Background Performance Audit of the San Diego Convention Center s HR Systems The San Diego Convention Center s Role in San Diego SDCC s Economic Impact to the San Diego Region The San Diego Convention Center (SDCC) facilitates business, educational, social, cultural, and entertainment activities through several types of events, including convention and trade shows, consumer shows, conferences, community functions, meetings, seminars and performing arts. SDCC is a nonprofit public benefit corporation founded in 1984 by the City of San Diego, and operates under an independent Board of Directors appointed by the San Diego City Council. According to their 2013 annual report, the Convention Center generated $1.3 billion in economic impact to the San Diego region resulting from 148 events held in the building and the more than 760,000 attendees associated with those events. In addition to the significant economic benefits, an estimated 12,500 local jobs are supported by events held at the center. The SDCC projects their total operating revenues to be approximately 33 million dollars for Fiscal Year Due to the nature of their business, they schedule events far in advance, with several repeat annual events such as Comic-Con. In addition, the SDCC collects full payment prior to each event. The advance planning and collection of fees allows for a detailed revenue projection. The Convention Center hosts most of their IT services to maintain services such as financials, sales, and event calendar in-house; however, they have outsourced their Human Resources (HR) systems through Ultimate Software. OCA Page 2
9 Performance Audit of the San Diego Convention Center s HR Systems Ultimate Software Group Inc. Ultimate Software has a proven product and longevity in the market. The vendor has been in the Human Resources IT services market and publicly traded on the Nasdaq stock exchange since the 1990 s. Ultimate has employees in 150 countries with approximately 2,700 customers, including Adobe Systems Incorporated, Bloomin Brands, Culligan International, Major League Baseball, Pep Boys, Texas Rangers Baseball, and Texas Roadhouse. According to their shareholder letter in their financial statements, they have had continuous growth year after year further demonstrating their financial health. Outsourced HR System Service Offering through SaaS Model The Convention Center has utilized UltiPro by Ultimate Software as their primary HR system since The system is provided using the Software-as-a-Service (SaaS) model, where the vendor maintains all the Information Technology (IT) Aspects of the system and the Convention Center accesses it through a web portal to maintain all the day to day HR operations. The roles and responsibilities of this model as well as recourse in the case of failure are governed by a contract between the parties, with an initial three year term and extended through four addendums through June OCA Page 3
10 Audit Results Performance Audit of the San Diego Convention Center s HR Systems THE CONVENTION CENTER HAS MITIGATED RISKS INHERENT TO OUTSOURCING HR SYSTEM SOFTWARE The risks associated with utilizing the Software-as-a-Service (SaaS) model of outsourcing have been mitigated through contractual safeguards, contractual segregation of duties, external audits, and secondary controls. Contract Risks & Mitigations Common risks associated with outsourcing IT services to third party hosting include: Failure to deliver contractual services (inadequate contract definitions, poor business practices, insolvency); Poor IT security resulting in theft of data/data breach; Disclosure of sensitive data; and Loss of data resulting from inadequate data recovery ability. The Convention Center mitigates several of these risks through appropriate contract definition, such as roles & responsibilities definitions, recovery requirements, and warranty and indemnification clauses. We reviewed Ultimate Software s most recent Service Organization Controls (SOC1 1 ) Type 2 report, which provides an overall assessment of their financial and product control environment to provide third party assurance over the reliability of Ultimate Software s service offering. KPMG conducts control testing and issues Ultimate Software s SOC report every six months. 1 As defined by the AICPA, an SOC1 Type 2 reports on the fairness of the presentation of management s description of the service organizations system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period. OCA Page 4
11 Performance Audit of the San Diego Convention Center s HR Systems Customer Responsibilities Ultimate Software is responsible for all aspects of the HR system, except those defined as the responsibility of the Convention Center. The Convention Center is responsible for maintaining their User IDs and Passwords, maintaining the customer side environment, and notifying Ultimate Software of events that permit changes to contractual terms. Maintaining the customer side environment includes providing UltiPro webside administration. This web-side administration contains access to define approval requirements for adjusting employee compensation and managing some Convention Center-specific process flows. The Convention Center staff still need to submit most significant changes to Ultimate Software through a ticketing system; however, a Convention Center privileged user can modify the process flow controls around the payroll approvals using the available administration access. This risk is mitigated through restricting the number of users with this access, and financial controls outside of the system requiring significant collusion to bypass payroll controls and remain undetected. Additionally, Ultimate Software maintains back-ups of customer data for 12 weeks in addition to other SaaS standard controls meant to safeguard customer data. OCA Page 5
12 Performance Audit of the San Diego Convention Center s HR Systems Appendix A: Objectives, Scope, and Methodology Objectives In accordance with the City Auditor s FY 2015 Work Plan and at the request of the San Diego Convention Center (SDCC), we conducted an IT audit of the Human Resources (HR) Systems to assess the controls over the HR systems contract and customer responsibilities. Specifically, our objective was to review the appropriateness of the controls and performance measures defined in the contract and review the strength of the controls as well as the vendor s compliance with the defined controls. Scope & Methodology In order to ensure we reviewed all relevant systems corresponding to the HR processes, we performed a risk assessment of SDCC s HR systems environment, including a review of SDCC s HR business processes. Through this assessment we confirmed that the Convention Center utilizes UltiPro by Ultimate Software in a Software-as-a- Service (SaaS) for their HR processes. We then reviewed the Ultimate Software Contract, dated September 2007 through the fourth addendum active until June 2015, to ensure it appropriately addressed responsibilities, Convention Center risks, and mitigations. In addition, we reviewed system data as well as the results of a Service Organization Controls review to evaluate Ultimate s compliance with the defined controls. We then reviewed remaining risks resulting from customer responsibilities to ensure the Convention Center has adequately mitigated remaining significant contractual risks. System configuration and user access data was obtained and reviewed during the May through July 2014 audit period. OCA Page 6
13 Performance Audit of the San Diego Convention Center s HR Systems We conducted this performance audit in accordance with generally accepted government auditing standards. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide a reasonable basis for our findings and conclusions based on our audit objectives. We believe that the evidence obtained provides a reasonable basis for our findings and conclusions based on our audit objectives. OCA Page 7
14 San Diego Convention Center Corporation WWW. VISITSANOIEGO.COM 111 WEST HARBOR DRIVE, SAN DIEGO, CA PHONE FAX August 8, 2014 Mr. Eduardo Luna City Auditor Office of the City Auditor Dear Mr. Luna: The San Diego Convention Center Corporation's management would like to thank the City Auditors for their through audit of our Human resources IT System, and to convey our agreement with the audit
Performance Audit of the San Diego Convention Center s Information Technology Infrastructure JULY 2012
Performance Audit of the San Diego Convention Center s Information Technology Infrastructure JULY 2012 Audit Report Office of the City Auditor City of San Diego This Page Intentionally Left Blank July
CASH COUNT AND BANK RECONCILIATION AUDIT
City of San Diego AUDIT REPORT CASH COUNT AND BANK RECONCILIATION AUDIT KROLL REMEDIATION OF THE CITY S BANK RECONCILIATION PROCESS April 28, 2008 Internal Audit Eduardo Luna, CIA, CGFM, Internal Auditor
Cloud Computing Contract Clauses
Cloud Computing Contract Clauses Management Advisory Report Report Number SM-MA-14-005-DR April 30, 2014 Highlights The 13 cloud computing contracts did not address information accessibility and data security
SRA International Managed Information Systems Internal Audit Report
SRA International Managed Information Systems Internal Audit Report Report #2014-03 June 18, 2014 Table of Contents Executive Summary... 3 Background Information... 4 Background... 4 Audit Objectives...
STATE OF NORTH CAROLINA
STATE OF NORTH CAROLINA PERFORMANCE AUDIT OFFICE OF INFORMATION TECHNOLOGY SERVICES STATE TERM CONTRACT FOR MICROCOMPUTERS AND PERIPHERALS JULY 2013 OFFICE OF THE STATE AUDITOR BETH A. WOOD, CPA STATE
EVALUATION REPORT. Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review. March 13, 2015 REPORT NUMBER 15-07
EVALUATION REPORT Weaknesses Identified During the FY 2014 Federal Information Security Management Act Review March 13, 2015 REPORT NUMBER 15-07 EXECUTIVE SUMMARY Weaknesses Identified During the FY 2014
Information Security Program
Stephen F. Austin State University Information Security Program Revised: September 2014 2014 Table of Contents Overview... 1 Introduction... 1 Purpose... 1 Authority... 2 Scope... 2 Information Security
Submitted by: Christopher Mead, Director, Department of Information Technology
Office of the City Manager INFORMATION CALENDAR March 21, 2006 To: From: Honorable Mayor and Members of the City Council Phil Kamlarz, City Manager Submitted by: Christopher Mead, Director, Department
Client Security Risk Assessment Questionnaire
Select the appropriate answer from the drop down in the column, and provide a brief description in the section. 1 Do you have a member of your organization with dedicated information security duties? 2
STATE OF NORTH CAROLINA
STATE OF NORTH CAROLINA PERFORMANCE AUDIT STATE HEALTH PLAN RISK ASSESSMENT SEPTEMBER 2011 OFFICE OF THE STATE AUDITOR BETH A. WOOD, CPA STATE AUDITOR PERFORMANCE AUDIT STATE HEALTH PLAN RISK ASSESSMENT
Workers Compensation Commission
Audit Report Workers Compensation Commission March 2009 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY This report and any related follow-up correspondence are
AUSTIN INDEPENDENT SCHOOL DISTRICT INTERNAL AUDIT DEPARTMENT TRANSPORTATION AUDIT PROGRAM
GENERAL: The Technology department is responsible for the managing of electronic devices and software for the District, as well as the Help Desk for resolution of employee-created help tickets. The subgroups
OFFICE OF THE CITY CONTROLLER
OFFICE OF THE CITY CONTROLLER PUBLIC WORKS AND ENGINEERING DEPARTMENT CELL PHONE CHARGE REIMBURSEMENTS AUDIT Annise D. Parker, City Controller Steve Schoonover, City Auditor Report No. 05-34 April 3, 2006
Interim Audit Report. Borough of Broxbourne Audit 2010/11
Interim Audit Report Borough of Broxbourne Audit 2010/11 The Audit Commission is an independent watchdog, driving economy, efficiency and effectiveness in local public services to deliver better outcomes
Audit Report. Effectiveness of IT Controls at the Global Fund Follow-up report. GF-OIG-15-20b 26 November 2015 Geneva, Switzerland
Audit Report Effectiveness of IT Controls at the Global Fund Follow-up report GF-OIG-15-20b Geneva, Switzerland Table of Contents I. Background and scope... 3 II. Executive Summary... 4 III. Status of
Practical and ethical considerations on the use of cloud computing in accounting
Practical and ethical considerations on the use of cloud computing in accounting ABSTRACT Katherine Kinkela Iona College Cloud Computing promises cost cutting efficiencies to businesses and specifically
SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch
SSAE 16 for Transportation & Logistics Companies Chris Kradjan Kim Koch 1 The material appearing in this presentation is for informational purposes only and should not be construed as advice of any kind,
State and District Monitoring of School Improvement Grant Contractors in California FINAL AUDIT REPORT
State and District Monitoring of School Improvement Grant Contractors in California FINAL AUDIT REPORT ED-OIG/A09O0009 March 2016 Our mission is to promote the efficiency, effectiveness, and integrity
Data Privacy, Security, and Risk Management in the Cloud
Data Privacy, Security, and Risk Management in the Cloud Diana S. Hare, Associate General Counsel and Chief Privacy Counsel, Drexel University David W. Opderbeck, Counsel, Gibbons P.C. Robin Rosenberg,
March 17, 2015 OIG-15-43
Information Technology Management Letter for the U.S. Citizenship and Immigration Services Component of the FY 2014 Department of Homeland Security Financial Statement Audit March 17, 2015 OIG-15-43 HIGHLIGHTS
Austin Fire Department Worker Safety Audit
City of Austin AUDIT REPORT A Report to the Austin City Council Mayor Lee Leffingwell Mayor Pro Tem Sheryl Cole Austin Fire Department Worker Safety Audit Council Members Chris Riley Mike Martinez Kathie
OFFICE OF THE STATE AUDITOR TWO COMMODORE PLAZA 206 EAST NINTH STREET, SUITE 1900 LAWRENCE F. ALWIN, CPA
OFFICE OF THE STATE AUDITOR TWO COMMODORE PLAZA 206 EAST NINTH STREET, SUITE 1900 LAWRENCE F. ALWIN, CPA AUSTIN, TEXAS 78701 State Auditor July 22, 1998 RE: A Review of General Automation Controls at Selected
U.S. Department of Energy Office of Inspector General Office of Audits & Inspections. Evaluation Report
U.S. Department of Energy Office of Inspector General Office of Audits & Inspections Evaluation Report The Department's Unclassified Cyber Security Program - 2012 DOE/IG-0877 November 2012 MEMORANDUM FOR
PRIVACY POLICIES AND FORMS FOR BUSINESS ASSOCIATES
PRIVACY POLICIES AND FORMS FOR BUSINESS ASSOCIATES TABLE OF CONTENTS A. Overview of HIPAA Compliance Program B. General Policies 1. Glossary of Defined Terms Used in HIPAA Policies and Procedures 2. Privacy
Information for Management of a Service Organization
Information for Management of a Service Organization Copyright 2011 American Institute of Certified Public Accountants, Inc. New York, NY 10036-8775 All rights reserved. For information about the procedure
System and Network Security Policy Internet User Guidelines and Policy. North Coast Council. 5700 West Canal Road Valley View, Ohio 44125
North Coast Council 5700 West Canal Road Valley View, Ohio 44125 Telephone: 216-520-6900 Fax: 216-520-6969 1885 Lake Avenue Elyria, Ohio 44035 Telephone: 440-324-3185 Fax: 440-324-7355 URL: www.nccohio.org
PeopleSoft IT General Controls
PeopleSoft IT General Controls Performance Audit December 2009 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of
Risk Management of Outsourced Technology Services. November 28, 2000
Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the
Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations. kpmg.com
Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations kpmg.com b Section or Brochure name Effectively using SOC 1, SOC 2, and SOC 3 reports for increased
ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL
ACCOUNTING AND FINANCIAL REPORTING REGULATION MANUAL STATE BOARD OF ACCOUNTS 302 West Washington Street Room E418 Indianapolis, Indiana 46204-2769 Issued January 2011 Revised April 2012 TABLE OF CONTENTS
System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012
System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012 Moss Adams LLP 9665 Granite Ridge Drive, Suite 600 San Diego, CA 92123
GARMIN LTD. CORPORATE GOVERNANCE GUIDELINES
GARMIN LTD. CORPORATE GOVERNANCE GUIDELINES The Board of Directors (the "Board") of Garmin Ltd. (the "Company") has adopted these Corporate Governance Guidelines ("Guidelines"), in order to assist the
Office of the City Auditor. Audit Report. AUDIT OF ACCOUNTS PAYABLE APPLICATION CONTROLS (Report No. A10-003) October 2, 2009.
CITY OF DALLAS Dallas City Council Office of the City Auditor Audit Report Mayor Tom Leppert Mayor Pro Tem Dwaine Caraway Deputy Mayor Pro Tem Pauline Medrano Council Members Jerry R. Allen Tennell Atkins
Innovation and Technology Department
PERFORMANCE AUDIT Innovation and Technology Department IT Inventory Asset Management January 11, 2016 Office of the City Manager Internal Audit Division Cheryl Johannes, Internal Audit Manager PERFORMANCE
Payroll Process Final Audit Report Report Nr. 13/12 August 30, 2012
Payroll Process Final Audit Report Report Nr. 13/12 August 30, 2012 Distribution: To: President & CEO Senior Vice President & Chief Financial Officer Senior Vice President, Human Resources & Communications
HIPAA/HITECH Compliance Using VMware vcloud Air
Last Updated: September 23, 2014 White paper Introduction This paper is intended for security, privacy, and compliance officers whose organizations must comply with the Privacy and Security Rules of the
INFORMATION TECHNOLOGY RISK MANAGEMENT PLAN
10/25/2012 TECHNOLOGY SERVICES INFORMATION TECHNOLOGY RISK MANAGEMENT PLAN Procedure Name: LIT Risk Management Information Technology Plan ver 2.31.docx Risk Management Plan Issue Date: TBD Procedure Owner:
GUIDANCE FOR MANAGING THIRD-PARTY RISK
GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,
Vendor Management Best Practices
23 rd Annual and One Day Seminar Vendor Management Best Practices Catherine Bruder CPA, CITP, CISA, CISM, CTGA Michigan Texas Florida Insight. Oversight. Foresight. SM Doeren Mayhew Bruder 1 $100 billion
Office of Inspector General
Audit Report OIG-07-043 GENERAL MANAGEMENT: Departmental Offices Did Not Have An Effective Workers Compensation Program July 13, 2007 Office of Inspector General Department of the Treasury Contents Audit
City of Berkeley. Prepared by:
City of Berkeley Berkeley Public Library Purchasing and Accounts Payable Audit Prepared by: Ann-Marie Hogan, City Auditor, CIA, CGAP Teresa Berkeley-Simmons, Audit Manager, CIA, CGAP Frank Marietti, Senior
Date: October 1, 2015. Audit, Finance and Enterprise Committee. Jennifer Ruttman, City Auditor. Audit of Workers Compensation Program
Date: October 1, 2015 To: From: Subject: cc: Audit, Finance and Enterprise Committee Jennifer Ruttman, City Auditor Mayor and Council John Pombier, Assistant City Manager Gary Manning, Human Resources
HIPAA in the Cloud. How to Effectively Collaborate with Cloud Providers
How to Effectively Collaborate with Cloud Providers Speaker Bio Chad Kissinger Chad Kissinger Founder OnRamp Chad Kissinger is the Founder of OnRamp, an industry leading high security and hybrid hosting
Policy-Standard heading. Fraud and Corruption Policy
Policy-Standard heading Fraud and Corruption Policy September 2013 Table of contents Introduction 3 Purpose 3 Scope 3 Related Policies and Processes 3 Definition of Fraud and Corruption 4 Policy 4 Code
Comptroller of Maryland Information Technology Division Annapolis Data Center Operations
Audit Report Comptroller of Maryland Information Technology Division Annapolis Data Center Operations March 2015 OFFICE OF LEGISLATIVE AUDITS DEPARTMENT OF LEGISLATIVE SERVICES MARYLAND GENERAL ASSEMBLY
Estate Agents Authority
INFORMATION SECURITY AND PRIVACY PROTECTION POLICY AND GUIDELINES FOR ESTATE AGENTS Estate Agents Authority The contents of this document remain the property of, and may not be reproduced in whole or in
Credit Union Liability with Third-Party Processors
World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with
Software-as-a-Service (SaaS) Solutions from CA Technologies Frequently asked questions
FAQ Edition / April 30, 2014 Software-as-a-Service (SaaS) Solutions from CA Technologies Frequently asked questions FAQ Edition April 2014 Informational Guidelines Table of Contents EXECUTIVE SUMMARY...
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Audit Report The Department's Configuration Management of Non-Financial Systems OAS-M-12-02 February 2012 Department
CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS
11-1 CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS INTRODUCTION The State Board of Accounts, in accordance with State statutes and the Statements on Auditing Standards Numbers 78
OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Lynne Prizzia, CISA, CRISC Senior Auditor:
Avoiding Theft in Your Nonprofit Ohio Attorney General Mike DeWine
Avoiding Theft in Your Nonprofit Ohio Attorney General Mike DeWine 1 Dear Nonprofit Leader, The single greatest asset of a nonprofit is arguably its reputation. When theft or misappropriation of assets
MICHIGAN AUDIT REPORT OFFICE OF THE AUDITOR GENERAL THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL
MICHIGAN OFFICE OF THE AUDITOR GENERAL AUDIT REPORT THOMAS H. MCTAVISH, C.P.A. AUDITOR GENERAL ...The auditor general shall conduct post audits of financial transactions and accounts of the state and of
BARRIO COMPREHENSIVE FAMILY HEALTH CARE CENTER, INC., DID NOT ALWAYS FOLLOW FEDERAL REGULATIONS
Department of Health and Human Services OFFICE OF INSPECTOR GENERAL BARRIO COMPREHENSIVE FAMILY HEALTH CARE CENTER, INC., DID NOT ALWAYS FOLLOW FEDERAL REGULATIONS Inquiries about this report may be addressed
Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015
Risky Business Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015 What We ll Cover About Me Background The threat Risks to your organization What your organization can/should
Cybersecurity: Protecting Your Business. March 11, 2015
Cybersecurity: Protecting Your Business March 11, 2015 Grant Thornton. All LLP. rights All reserved. rights reserved. Agenda Introductions Presenters Cybersecurity Cybersecurity Trends Cybersecurity Attacks
OPERATIONAL AUDIT OKLAHOMA BOARD OF LICENSED ALCOHOL AND DRUG COUNSELORS FOR THE PERIOD JULY 1, 2006 THROUGH JUNE 30, 2008
OKLAHOMA BOARD OF LICENSED ALCOHOL AND DRUG COUNSELORS FOR THE PERIOD JULY 1, 2006 THROUGH JUNE 30, 2008 OPERATIONAL AUDIT Oklahoma State Auditor & Inspector Audit Report of the Oklahoma Board of Licensed
Can You be HIPAA/HITECH Compliant in the Cloud?
Can You be HIPAA/HITECH Compliant in the Cloud? Background For the first 10 years of its existence, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) was a toothless tiger. Although
Using COBiT For Sarbanes Oxley. Japan November 18 th 2006 Gary A Bannister
Using COBiT For Sarbanes Oxley Japan November 18 th 2006 Gary A Bannister Who Am I? Who am I & What I Do? I am an accountant with 28 years experience working in various International Control & IT roles.
Department of Homeland Security
for the Immigration and Customs Enforcement Component of the FY 2013 Department of Homeland Security s Financial Statement Audit OIG-14-85 April 2014 OFFICE OF INSPECTOR GENERAL Department of Homeland
STATEMENT OF JOHN E. MCCOY II DEPUTY ASSISTANT INSPECTOR GENERAL FOR AUDITS U.S. DEPARTMENT OF HOMELAND SECURITY BEFORE THE
STATEMENT OF JOHN E. MCCOY II DEPUTY ASSISTANT INSPECTOR GENERAL FOR AUDITS U.S. DEPARTMENT OF HOMELAND SECURITY BEFORE THE COMMITTEE ON OVERSIGHT AND GOVERNMENT REFORM SUBCOMMITTEE ON GOVERNMENT ORGANIZATION,
Cloud Technology Platform Enables Leading HR and Payroll Services Provider To Meet Solution Objectives
Greytip Online Cloud based HR & Payroll software Cloud Technology Platform Enables Leading 16 Snapshot Client Profile A global HR & Payroll outsourcing company. The company is in the business of delivering
