Contingency Planning and Disaster Recovery Internal Control Questionnaire

Size: px
Start display at page:

Download "Contingency Planning and Disaster Recovery Internal Control Questionnaire"

Transcription

1 Contingency Planning and Disaster Recovery Internal Control Questionnaire [Institution s name] [Departments under review] [Heads of departments under review] A. POLICY AND SUPERVISION REVIEW 1. Was the policy reviewed for changes made since the last audit? 2. Did the board of directors minutes indicate that the changes were authorized? a. Were the changes implemented through appropriate adjustments to related internal controls? b. Were affected personnel notified of the changes in a timely manner? 3. Did the board of directors review and approve the contingency planning and disaster recovery policy? 4. Has the board of directors requested a completed disaster recovery plan and, thereafter, has the board reviewed and approved the plan? 5. After the internal audit was performed, were all deviations from prescribed controls noted and followed up with the appropriate management level? B. GENERAL GOALS 1. Are there planning procedures for the contingency planning and disaster recovery policy with senior management? a. Is there supporting memoranda and individual plans as evidence that senior management has complied with planning procedures? b. Have the CEO and also the contingency planning officer carried out their responsibilities with respect to: Assigning key personnel? Assigning authorization responsibilities? Prioritizing bank operations? 2. Do the board of directors minutes since the last audit indicate that the CEO has followed through with contingency planning and disaster recovery policy testing, evaluation, and reports? C. SPECIFIC GOALS 1. Are there specific plans for each department? 2. Do the specific plans for each department have the following items addressed in their plans: Disaster Recovery/Contingency Planning E2-1

2 a. Departmental management and other employees with various assigned responsibilities when an emergency is occurring? Do individuals within each department understand what their emergency responsibilities are and at what point during an emergency they are to assume them? b. Individuals designated to provide alternative and compatible equipment to replace destroyed equipment? c. Management guidelines on providing initial ongoing off-site backup, on a timely basis, of: Software? Data files? Documentation? Forms? Supplies? 3. Review testing memoranda and, if possible, observe the testing of backup systems and equipment by the disaster planning committee to answer the following: a. Has the committee performed periodic testing per its schedule? b. Was the testing performed by the committee to ascertain that prescribed procedures are being followed? 4. Is an annual report prepared by the disaster planning committee? 5. Does the annual report contain the following: a. Items tested and items scheduled to be tested in the same time period? 6. Do the board of directors minutes provide evidence that the board reviewed the annual report? 7. Does the board s meeting minutes indicate that the following were discussed: a. Variances in the schedule, if any? b. Problems that may have been discovered during the testing? c. Solutions to the problems? D. DESIGNATION OF AUTHORITY 1. Review the composition of the disaster planning committee and verify that officers representing each of the following functions are members of the committee: a. Commercial loans? b. Accounting? c. Human resources? d. Investment/trading? e. ALCO? f. Operations? E2-2 Disaster Recovery/Contingency Planning

3 g. Electronic data processing? 2. Review the contingency planning and disaster recovery policy with the officers sitting on the disaster planning committee and determine that they are aware of their responsibilities as members. Do committee members list the following responsibilities for the committee: a. Development and documentation of systems or plans to facilitate operations in the event of a disaster? b. Designation of personnel and their responsibilities during an emergency? Does the structure of this designation compare roughly as follows: A disaster recovery team composed of designated employees with specific assignments during a disaster? A disaster recovery administrator overseeing the disaster recovery team? An alternative disaster recovery administrator (called the disaster recovery coordinator) in case the disaster incapacitates the formerly mentioned disaster recovery administrator? c. Setting up alternative sites for operations if current sites are destroyed or substantially disabled in an emergency? d. Notification of personnel in the event of a disaster? E. DISASTER RECOVERY ADMINISTRATOR RESPONSIBILITIES 1. Does the contingency planning and disaster recovery policy require that the disaster recovery administrator perform a variety of duties? Does the disaster recovery administrator duties include, at a minimum, the following responsibilities: a. To notify personnel immediately in case of a disaster? b. To establish the command and control center in its designated site, or to select an alternative site for establishment of the control center? c. To implement the disaster recovery plan after determining the extent of the disaster? d. To establish communication with key personnel? e. To provide managerial support for key personnel during the recovery? f. To monitor progress during the course of the disaster? g. To document the actions taken and the progress made? Disaster Recovery/Contingency Planning E2-3

4 F. DISASTER RECOVERY COORDINATOR RESPONSIBILITIES 1. Does the contingency planning and disaster recovery policy require the disaster recovery coordinator to assist the disaster recovery administrator in performing his or her duties? Does the disaster recovery coordinator list, at a minimum, the following responsibilities: a. To assist the disaster recovery administrator? b. To notify the other disaster recovery team members that there is a disaster? c. To activate general notification procedures? d. To notify personnel of the site selected as the command and control center? e. To provide managerial support for key personnel during the recovery? Do key personnel perform the following tasks: Supervise the recovery activities? Document activities that the disaster recovery administrator has not handled directly? f. Keep team members informed of the progress of all recovery activities, since each area depends on the others? 2. Review and determine whether the disaster recovery coordinator confirms on a regular basis that backup systems remain in place and are adequate to meet the needs of the bank in the event of a disaster? G. DESIGNATED EMPLOYEE RESPONSIBILITIES IN DISASTER 1. Has the disaster recovery committee designated disaster recovery employees and their alternates in each division? Are these designations noted as follows: a. The annual report to the board of directors? b. The disaster recovery committee minutes? 2. Do the listings of designated employees and their alternates include home phone numbers? 3. In different data processing memoranda and/or committee minutes, has the disaster recovery committee provided for: a. Adequate training for designated employees? b. Periodic testing of designated employees performing disasterrelated responsibilities? c. Adequate support and guidance from committee members? 4. Through interviews of designated employees, determine whether they are aware of their duties and responsibilities? Are designated employees able to specifically detail: E2-4 Disaster Recovery/Contingency Planning

5 a. What their responsibilities are in a disaster including: Helping to coordinate the recovery process at a lower level than the disaster recovery coordinator? Helping to assess the nature and extent of the disaster? Activating recovery plans at an operations level? Informing bank managers of progress and problems encountered during the recovery process? Documenting steps taken and progress made during the recovery process? b. Whom they would report to in a disaster situation? c. What timing they would follow when initiating their responsibilities? d. What priority their responsibilities and division have in relation to other areas of the bank? H. PRIORITIZING OPERATIONS 1. Does the contingency planning and disaster recovery policy require the disaster planning committee to prioritize operations? Review the method used by the committee to assign priority status and consider the following: a. Are the assigned priorities reasonable, regarding the methodology used to prioritize? b. Is each department is aware of its status? c. Does each department understand the implications of its priority status? 2. Does a review of the board of directors minutes indicate evidence that the board reviewed and approved the priority listing? 3. Are the areas with the highest priority sufficiently prepared to begin operations as quickly as possible in the event of a disaster? I. BACKUP SYSTEMS 1. Through a review of the backup procedures with the officers and other appropriate employees within each division, is it evident that they are aware of their responsibilities, especially with respect to protection of data and software? 2. Are employees fully aware of the fact that the effectiveness of the backup program depends on the consistent and timely backup of data? 3. For each division affected, do the following operations occur as indicated: a. Customer data, including daily account balances and transactions, are backed up twice daily? Disaster Recovery/Contingency Planning E2-5

6 b. A review, on a sample basis, of the computer transaction log details evidence that the backup operation has consistently been performed on a regular basis? c. Customer data, including daily account balances and transactions, are backed up hourly on Fridays? d. System modifications and changes are copied immediately, electronically documented, and supplied immediately thereafter to an off-site storage facility? e. Have system modifications made since the last policy audit been copied and have copies of the modifications been stored in the off-site location? f. Were internal audit staff present when system modifications occurred and, therefore, have documentation that represent copies are held off-site? 3. Do personnel obtain proper authorization before releasing corporate or customer information? a. Is the information release procedures manual readily available to personnel? b. Do information release procedures, as followed by electronic data processing personnel and off-site storage personnel, ensure that information will not be released without proper authorization? J. OFF-SITE STORAGE 1. Per discussions with appropriate personnel regarding the procedures for establishing and maintaining off-site storage, are the following steps part of their duties: a. Making sure that backup systems and files are stored off-site? b. Ensuring that transfer of data occurs immediately after backup by armored car? c. Reviewing all forms quarterly? d. Destroying obsolete forms after new forms are available? 2. Is the application of the prior procedures regularly occurring during the transfer of files, per a sampling of divisions? 3. Are copies of the disaster recovery plan maintained in off-site storage? 4. Do both the bank president and the CEO each have the most recent copy of the disaster recovery plan? 5. Has the most recent copy of the disaster recovery plan been also placed in a safe deposit box at the bank? K. COMMUNICATION PROCEDURES AND CHANNELS 1. Do the responsibilities of the public relations manager during a disaster include the following: a. Make all outside announcements? E2-6 Disaster Recovery/Contingency Planning

7 b. Obtain management review and approval before making public announcements? c. Ensure that disaster damage assessment is published as soon as possible? 2. Has a disaster recovery team member been appointed to be responsible for activating communication procedures? 3. Does he/she have a clear understanding regarding timing and extent of those responsibilities? a. Does activation occur only after a physical inspection of the disaster site and an assessment of damages? b. Are there specific procedures utilized when the disaster occurs after hours? L. TESTING CONTINGENCY PLANS 1. Has the contingency plan been tested with as many steps as are practical? a. Has the internal audit staff been an active participant in the management and evaluation of the plan? 2. Were all key personnel involved in the test? 3. Were the following areas, at a minimum, tested: a. Data files? b. Equipment? c. Backup equipment? 4. Do testing memoranda provide details to indicate that: a. The test was evaluated? b. Any cited deficiencies were documented? c. Deficiencies were corrected? d. Deficiencies were retested? 5. Review the board of directors minutes and determine that when deficiencies were resolved, the board approved the final plan? 6. Once the final disaster recovery plan has been approved, has the disaster recovery committee been testing the plan on a semiannual basis? M. FINANCIAL CONDITION OF THE SERVICE PROVIDERS 1. Do the disaster recovery committee minutes indicate that the committee has reviewed all service providers on an annual basis? a. Does documentation indicate a review of service providers financial statements? b. Does the documentation indicate that a financial analysis was performed on those statements? c. Does the documentation of the service providers also include a review of copies of their backup plans? Disaster Recovery/Contingency Planning E2-7

8 d. Is there an analysis of the feasibility of the service providers backup plans? e. Are service providers backup plans fully integrated into the bank s disaster recovery plans? f. Have the service providers backup plans been tested with respect to backup of the bank s services? E2-8 Disaster Recovery/Contingency Planning

General IT Controls Audit Program

General IT Controls Audit Program Contributed February 5, 2002 by Paul P Shotter General IT Controls Audit Program Purpose / Scope Perform a General Controls review of Information Technology (IT). The reviews

More information

GREATER TEXAS FEDERAL CREDIT UNION RECORDS PRESERVATION PROGRAM

GREATER TEXAS FEDERAL CREDIT UNION RECORDS PRESERVATION PROGRAM Approved: September 17, 2002 Purpose of Program: GREATER TEXAS FEDERAL CREDIT UNION RECORDS PRESERVATION PROGRAM In accordance with the National Credit Union Administration ( NCUA ) Rules and Regulations

More information

DETAIL AUDIT PROGRAM Information Systems General Controls Review

DETAIL AUDIT PROGRAM Information Systems General Controls Review Contributed 4/23/99 by Steve_Parker/TBE/Teledyne@teledyne.com DETAIL AUDIT PROGRAM Information Systems General Controls Review 1.0 Introduction The objectives of this audit are to review policies, procedures,

More information

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS) Information Technology Disaster Recovery Policy Policy Statement This policy defines acceptable methods for disaster recovery planning, preparedness, management and mitigation of IT systems and services

More information

Federal Deposit Insurance Corporation Improvement Act 1

Federal Deposit Insurance Corporation Improvement Act 1 Federal Deposit Insurance Corporation Improvement Act 1 Appendix F SEC. 112. INDEPENDENT ANNUAL AUDITS OF INSURED DEPOSITORY INSTITUTIONS. (a) IN GENERAL. The Federal Deposit Insurance Act (12 U.S.C. 1811

More information

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard PUBLIC Version: 1.0 CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard (Approved by the Information Strategy and Governance Committee in December 2013; revision 1.1 approved by Chief

More information

Comparison of Joint Commission and Healthcare Facilities Accreditation Program (HFAP) Emergency-Related Standards for Hospitals.

Comparison of Joint Commission and Healthcare Facilities Accreditation Program (HFAP) Emergency-Related Standards for Hospitals. Comparison of Joint Commission and Healthcare Facilities Accreditation Program (HFAP) Emergency-Related Standards for Hospitals Planning Activities Emergency Plan Joint Commission The hospital must engage

More information

An organization properly establishes and operates its control over risks regarding the information system to fulfill the following objectives:

An organization properly establishes and operates its control over risks regarding the information system to fulfill the following objectives: p. 1 System Management Standards Proposed on October 8, 2004 Preface Today, the information system of an organization works as an important infrastructure of the organization to implement its management

More information

CANADIAN PAYMENTS ASSOCIATION LVTS RULE 11 CHANGE MANAGEMENT, TESTING AND CERTIFICATION

CANADIAN PAYMENTS ASSOCIATION LVTS RULE 11 CHANGE MANAGEMENT, TESTING AND CERTIFICATION CANADIAN PAYMENTS ASSOCIATION LVTS RULE 11 LVTS Rule 11, December 1998: as amended November 25, 2002, November 24, 2003, May 31, 2004, August 14, 2006, January 28, 2008, August 16, 2010, January 1, 2013

More information

The University of Texas at Tyler. Audit of Compliance with Texas Administrative Code 202

The University of Texas at Tyler. Audit of Compliance with Texas Administrative Code 202 Audit of Compliance with Texas Administrative Code 202 August 2015 OFFICE OF AUDIT AND CONSULTING SERVICES 3900 UNIVERSITY BOULEVARD TYLER, TEXAS 75799 BACKGROUND Texas Administrative Code (TAC) Title

More information

Company Quality Manual Document No. QM Rev 0. 0 John Rickey Initial Release. Controlled Copy Stamp. authorized signature

Company Quality Manual Document No. QM Rev 0. 0 John Rickey Initial Release. Controlled Copy Stamp. authorized signature Far West Technology, Inc. ISO 9001 Quality Manual Document No.: QM Revision: 0 Issue Date: 27 August 1997 Approval Signatures President/CEO Executive Vice President Vice President/CFO Change Record Rev

More information

SFC ELECTRONIC TRADING REGIME

SFC ELECTRONIC TRADING REGIME SFC ELECTRONIC TRADING REGIME CompliancePlus 2013 Year End Training 18 December 2013 Limited 801, Two Exchange Square, 8 Connaught Place, Central, Hong Kong Tel: (852) 3487 6903 www.complianceplus.hk Disclaimer

More information

Overview. Responsibility

Overview. Responsibility Overview Property management is an important function at the University. Prudent inventory practices help protect the University s multi-million dollar investment in equipment, provide documentation needed

More information

CORPORATE QUALITY MANUAL

CORPORATE QUALITY MANUAL Corporate Quality Manual Preface The following Corporate Quality Manual is written within the framework of ISO 9001:2008 Quality System by the employees of CyberOptics. CyberOptics recognizes the importance

More information

Overview of how to test a. Business Continuity Plan

Overview of how to test a. Business Continuity Plan Overview of how to test a Business Continuity Plan Prepared by: Thomas Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com BRP/DRP Test Plan Creation and Exercise Page: 1 Table of Contents BCP/DRP Test

More information

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS Appendix L DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS I. GETTING READY A. Obtain written commitment from top management of support for contingency planning objectives. B. Assemble

More information

Memorandum. ACTION: Report on Computer Security Controls of Financial Management System, FTA FE-2000-098. May 23, 2000.

Memorandum. ACTION: Report on Computer Security Controls of Financial Management System, FTA FE-2000-098. May 23, 2000. U.S. Department of Transportation Office of the Secretary of Transportation Office of Inspector General Memorandum ACTION: Report on Computer Security Controls of Financial Management System, FTA FE-2000-098

More information

Summary of CIP Version 5 Standards

Summary of CIP Version 5 Standards Summary of CIP Version 5 Standards In Version 5 of the Critical Infrastructure Protection ( CIP ) Reliability Standards ( CIP Version 5 Standards ), the existing versions of CIP-002 through CIP-009 have

More information

Land Agents Regulations 2010

Land Agents Regulations 2010 Version: 21.11.2015 South Australia Land Agents Regulations 2010 under the Land Agents Act 1994 Contents Part 1 Preliminary 1 Short title 3 Interpretation 4 Fees payment, waiver, reduction and refund Part

More information

Regulations of the Audit and Compliance Committee of Gamesa Corporación Tecnológica, S.A.

Regulations of the Audit and Compliance Committee of Gamesa Corporación Tecnológica, S.A. Regulations of the Audit and Compliance Committee of Gamesa Corporación Tecnológica, S.A. (Consolidated text approved by the Board of Directors on March 24, 2015) INDEX CHAPTER I. INTRODUCTION... 3 Article

More information

Product Name Manufacturer Manufacturer Part No Description Unit of Measure State Price

Product Name Manufacturer Manufacturer Part No Description Unit of Measure State Price Product Name Manufacturer Manufacturer Part No Description Unit of Measure State Price Consultant/Planner Distinctive Business Solutions DBS-CP-10 Project Manager Distinctive Business Solutions DBS-PM-10

More information

Appendix 4-2: Sample HIPAA Security Risk Assessment For a Small Physician Practice

Appendix 4-2: Sample HIPAA Security Risk Assessment For a Small Physician Practice Appendix 4-2: Administrative, Physical, and Technical Safeguards Breach Notification Rule How Use this Assessment The following sample risk assessment provides you with a series of sample questions help

More information

HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE

HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE How to Use this Assessment The following risk assessment provides you with a series of questions to help you prioritize the development and implementation

More information

Electronic Trading Information Template

Electronic Trading Information Template Electronic Trading Information Template Preface This Electronic Trading Information Template (the "Template") has been created through the collaborative efforts of the professional associations listed

More information

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1

AUDITING A BCP PLAN. Thomas Bronack Auditing a BCP Plan presentation Page: 1 AUDITING A BCP PLAN Thomas Bronack Auditing a BCP Plan presentation Page: 1 What are the Objectives of a Good BCP Plan Protect employees Restore critical business processes or functions to minimize the

More information

SAS 70 Exams Of EBT Controls And Processors

SAS 70 Exams Of EBT Controls And Processors Appendix VIII SAS 70 Examinations of EBT Service Organizations Background States must obtain an examination by an independent auditor of the State electronic benefits transfer (EBT) service providers (service

More information

DCU BULLETIN Division of Credit Unions Washington State Department of Financial Institutions Phone: (360) 902-8718 FAX: (360) 704-6991

DCU BULLETIN Division of Credit Unions Washington State Department of Financial Institutions Phone: (360) 902-8718 FAX: (360) 704-6991 DCU BULLETIN Division of Credit Unions Washington State Department of Financial Institutions Phone: (360) 902-8718 FAX: (360) 704-6991 August 30, 1999 No. B-99-12 Year 2000 Reporting by September 30, 1999;

More information

B U S I N E S S C O N T I N U I T Y P L A N

B U S I N E S S C O N T I N U I T Y P L A N B U S I N E S S C O N T I N U I T Y P L A N 1 Last Review / Update: December 9, 2015 Table of Contents Purpose...3 Background...3 Books and Records Back-up and Recovery...4 Mission Critical Systems...

More information

85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff

85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff 85-01-55 Overview of Business Continuity Planning Sally Meglathery Payoff Because a business continuity plan affects all functional units within the organization, each functional unit must participate

More information

ISO 9001: 2008 Construction Quality Management System Sample - Selected pages (not a complete plan)

ISO 9001: 2008 Construction Quality Management System Sample - Selected pages (not a complete plan) ISO 9001: 2008 Construction Quality Management System Sample - Selected pages (not a complete plan) Part 1: Project-Specific Quality Plan Part 2: Company Quality Manual Part 3: Submittal Forms Part 4:

More information

Disaster Recovery Planning Process

Disaster Recovery Planning Process Disaster Recovery Planning Process By Geoffrey H. Wold Part I of III This is the first of a three-part series that describes the planning process related to disaster recovery. Based on the various considerations

More information

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES New rule Current Rule Proposed Rule 4.6.21 Business Continuity Requirements The following requirements

More information

Assessing and Tax BS&A Application SLA April 2014. OAKLAND COUNTY MICHIGAN ASSESSING and TAX (BS&A) APPLICATION SERVICE LEVEL AGREEMENT (SLA)

Assessing and Tax BS&A Application SLA April 2014. OAKLAND COUNTY MICHIGAN ASSESSING and TAX (BS&A) APPLICATION SERVICE LEVEL AGREEMENT (SLA) OAKLAND COUNTY MICHIGAN ASSESSING and TAX (BS&A) APPLICATION SERVICE LEVEL AGREEMENT (SLA) 1.0 INTRODUCTION This Service Level Agreement (SLA) is an agreement between Oakland County Information Technology

More information

SECTION 15 INFORMATION TECHNOLOGY

SECTION 15 INFORMATION TECHNOLOGY SECTION 15 INFORMATION TECHNOLOGY 15.1 Purpose 15.2 Authorization 15.3 Internal Controls 15.4 Computer Resources 15.5 Network/Systems Access 15.6 Disaster Recovery Plan (DRP) 15.1 PURPOSE The Navajo County

More information

GUIDANCE NOTE ON OUTSOURCING

GUIDANCE NOTE ON OUTSOURCING GN 14 GUIDANCE NOTE ON OUTSOURCING Office of the Commissioner of Insurance Contents Page I. Introduction.. 1 II. Application...... 1 III. Interpretation.... 2 IV. Legal and Regulatory Obligations... 3

More information

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006

Department of Information Technology Data Center Disaster Recovery Audit Report Final Report. September 2006 Department of Information Technology Data Center Disaster Recovery Audit Report Final Report September 2006 promoting efficient & effective local government Executive Summary Our audit found that a comprehensive

More information

DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY

DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY This Plan we adopted by member, partner, etc.) on Our Program Coordinator (date). (Board of Directors, owner, We have appointed

More information

THE COMMONWEALTH OF MASSACHUSETTS. Division of Insurance. Arbella Indemnity Insurance Company, Inc.

THE COMMONWEALTH OF MASSACHUSETTS. Division of Insurance. Arbella Indemnity Insurance Company, Inc. THE COMMONWEALTH OF MASSACHUSETTS OFFICE OF CONSUMER AFFAIRS AND BUSINESS REGULATION Division of Insurance Report on the Comprehensive Market Conduct Examination of Arbella Indemnity Insurance Company,

More information

PAS 99: Integrated Management Systems Checklist IMPLEMENTATION CHECKLIST

PAS 99: Integrated Management Systems Checklist IMPLEMENTATION CHECKLIST PAS 99: Integrated Management Systems Checklist IMPLEMENTATION CHECKLIST INTRODUCTION This checklist is intended to be used by those organizations who are either looking at implementing an integrated management

More information

REQUEST FOR BOARD ACTION

REQUEST FOR BOARD ACTION REQUEST FOR BOARD ACTION HENDERSON COUNTY BOARD OF COMMISSIONERS MEETING DATE: 23 March 2005 SUBJECT: ATTACHMENT(S): HIPAA 1. Proposed Resolution adopting policies 2. Proposed policies SUMMARY OF REQUEST:

More information

SMKI Recovery Procedure

SMKI Recovery Procedure SMKI Recovery Procedure Consultation open: 1 July 2015 Consultation closes: 29 July 2015 DCC Public Page 1 of 55 Contents 1 Introduction... 3 1.1 Purpose & Interpretation...3 1.2 Scope...3 2 Overview of

More information

HIPAA Privacy & Security White Paper

HIPAA Privacy & Security White Paper HIPAA Privacy & Security White Paper Sabrina Patel, JD +1.718.683.6577 sabrina@captureproof.com Compliance TABLE OF CONTENTS Overview 2 Security Frameworks & Standards 3 Key Security & Privacy Elements

More information

University Executive Committee. IT Steering Group. IT Back-up and Recovery Policy (Data)

University Executive Committee. IT Steering Group. IT Back-up and Recovery Policy (Data) University Executive Committee IT Steering Group IT Back-up and Recovery Policy (Data) Background In March 2007 the Audit Committee received an IT Position Audit report from the Business Assurance Service

More information

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) 591-5553 Email: bronackt@dcag.com Fax: (718) 380-7322 Business Continuity and Disaster Recovery Job Descriptions Table of Contents Business Continuity Services Organization Chart... 2 Director Business Continuity Services Group... 3 Manager of Business Recovery

More information

PHASE 9: OPERATIONS AND MAINTENANCE PHASE

PHASE 9: OPERATIONS AND MAINTENANCE PHASE PHASE 9: OPERATIONS AND MAINTENANCE PHASE During the Operations and Maintenance Phase, the information system s availability and performance in executing the work for which it was designed is maintained.

More information

PDS (The Planetary Data System) Information Technology Security Plan for The Planetary Data System: [Node Name]

PDS (The Planetary Data System) Information Technology Security Plan for The Planetary Data System: [Node Name] PDS (The Planetary Data System) Information Technology Security Plan for The Planetary Data System: [Node Name] [Date] [Location] 1 Prepared by: [Author] [Title] Date Approved by: [Name] [Title] Date 2

More information

Disaster Recovery Policy

Disaster Recovery Policy Disaster Recovery Policy Organizational Functional Area: Policy for: Executive Division Bank Disaster Recovery Program Board Reviewed: September 14, 2011 Department/Individual Responsible for Maintaining/Updating

More information

Department of Public Utilities Customer Information System (BANNER)

Department of Public Utilities Customer Information System (BANNER) REPORT # 2010-06 AUDIT of the Customer Information System (BANNER) January 2010 TABLE OF CONTENTS Executive Summary..... i Comprehensive List of Recommendations. iii Introduction, Objective, Methodology

More information

Company Name Vendor Management Policy and Procedure. Table of Contents

Company Name Vendor Management Policy and Procedure. Table of Contents Policy and Procedure Table of Contents Table of Contents... i Introduction... 1 Risks of Using Vendors... 1 Vendor Due Diligence... 2 Monitoring... 2 Section 1 Personnel... 1 Section 2 - Outside Vendors

More information

Finansinspektionen s Regulatory Code

Finansinspektionen s Regulatory Code Finansinspektionen s Regulatory Code Publisher: Finansinspektionen, Sweden, www.fi.se ISSN 1102-7460 This translation is furnished for information purposes only and is not itself a legal document. Finansinspektionen's

More information

FORM 20A.9 SAMPLE AUDIT PROGRAM FOR TESTING IT CONTROLS. Date(s) Completed. Workpaper Reference

FORM 20A.9 SAMPLE AUDIT PROGRAM FOR TESTING IT CONTROLS. Date(s) Completed. Workpaper Reference FORM 20A.9 SAMPLE AUDIT PROGRAM FOR TESTING IT CONTROLS Workpaper Reference Date(s) Completed Organization and Staffing procedures used to define the organization of the IT Department. 2. Review the organization

More information

Ten Most Common Violations Found in DRE Audits

Ten Most Common Violations Found in DRE Audits Ten Most Common Violations Found in DRE Audits The real estate industry has moved into a new millennium. New things pop up every day changing the way we do business. Yet, certain things have not changed

More information

HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics

HIPAA Security. 2 Security Standards: Administrative Safeguards. Security Topics HIPAA Security SERIES Security Topics 1. Security 101 for Covered Entities 5. 2. Security Standards - Organizational, Security Policies Standards & Procedures, - Administrative and Documentation Safeguards

More information

PSU Hyland OnBase Document Imaging and Workflow Services Level Memorandum of Understanding

PSU Hyland OnBase Document Imaging and Workflow Services Level Memorandum of Understanding PSU Hyland OnBase Document Imaging and Workflow Services Level Memorandum of Understanding Table of Contents -I. Summary -II. Service Description-Scope of OnBase Document Imaging and Workflow Service Integration

More information

The Practice of Internal Controls. Cornell Municipal Clerks School July 16, 2014

The Practice of Internal Controls. Cornell Municipal Clerks School July 16, 2014 The Practice of Internal Controls Cornell Municipal Clerks School July 16, 2014 Page 1 July 18, 2014 Cash Receipts (Collection procedures) Centralize cash collections within a department or for the local

More information

39C-1 Records Management Program 39C-3

39C-1 Records Management Program 39C-3 39C-1 Records Management Program 39C-3 Sec. 39C-1. Sec. 39C-2. Sec. 39C-3. Sec. 39C-4. Sec. 39C-5. Sec. 39C-6. Sec. 39C-7. Sec. 39C-8. Sec. 39C-9. Sec. 39C-10. Sec. 39C-11. Sec. 39C-12. Sec. 39C-13. Sec.

More information

Information Technology Operational Audit DEPARTMENT OF STATE. Florida Voter Registration System (FVRS) Report No. 2016-002 July 2015

Information Technology Operational Audit DEPARTMENT OF STATE. Florida Voter Registration System (FVRS) Report No. 2016-002 July 2015 July 2015 Information Technology Operational Audit DEPARTMENT OF STATE Florida Voter Registration System (FVRS) Sherrill F. Norman, CPA Auditor General Secretary of State Section 20.10, Florida Statutes,

More information

GUIDANCE NOTE OUTSOURCING OF FUNCTIONS BY ENTITIES LICENSED UNDER THE PROTECTION OF INVESTORS (BAILIWICK OF GUERNSEY) LAW, 1987

GUIDANCE NOTE OUTSOURCING OF FUNCTIONS BY ENTITIES LICENSED UNDER THE PROTECTION OF INVESTORS (BAILIWICK OF GUERNSEY) LAW, 1987 GUIDANCE NOTE OUTSOURCING OF FUNCTIONS BY ENTITIES LICENSED UNDER THE PROTECTION OF INVESTORS (BAILIWICK OF GUERNSEY) LAW, 1987 CONTENTS Page 1. Introduction 3-4 2. The Commission s Policy 5 3. Outsourcing

More information

BNA FEDERAL CREDIT UNION DISASTER RECOVERY PLAN

BNA FEDERAL CREDIT UNION DISASTER RECOVERY PLAN BNA FEDERAL CREDIT UNION DISASTER RECOVERY PLAN INTRODUCTION The need for a contingency plan for business interruptions is vital to the operations of the BNA Federal Credit Union. Without such a plan,

More information

by: Scott Baranowski Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy

by: Scott Baranowski Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy Community Bank Auditors Group Best Practices in Auditing Record Retention, Safeguarding Paper Documents, GLBA and Privacy June 10, 2015 MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT

More information

Federal Home Loan Bank Membership Version 1.0 March 2013

Federal Home Loan Bank Membership Version 1.0 March 2013 Introduction The Federal Home Loan Banks (FHLBanks) are cooperative institutions owned by members. The Federal Home Loan Bank Act of 1932 (FHLBank Act) created the Federal Home Loan Bank System to support

More information

Ohio Supercomputer Center

Ohio Supercomputer Center Ohio Supercomputer Center IT Business Continuity Planning No: Effective: OSC-13 06/02/2009 Issued By: Kevin Wohlever Director of Supercomputer Operations Published By: Ohio Supercomputer Center Original

More information

GOVERNMENT NOTICE NO. 416 published on 28/12/2012 ARRANGEMENT OF SECTIONS THE BANK OF TANZANIA (CREDIT REFERENCE BUREAU) REGULATIONS, 2012

GOVERNMENT NOTICE NO. 416 published on 28/12/2012 ARRANGEMENT OF SECTIONS THE BANK OF TANZANIA (CREDIT REFERENCE BUREAU) REGULATIONS, 2012 GOVERNMENT NOTICE NO. 416 published on 28/12/2012 THE BANK OF TANZANIA (CREDIT REFERENCE BUREAU) REGULATIONS, 2012 ARRANGEMENT OF SECTIONS PART I PRELIMINARY PROVISIONS Section Title 1.Citation 2. Application

More information

Draft Copy. Change Management. Release Date: March 18, 2012. Prepared by: Thomas Bronack

Draft Copy. Change Management. Release Date: March 18, 2012. Prepared by: Thomas Bronack Draft Copy Change Management Release Date: March 18, 2012 Prepared by: Thomas Bronack Section Table of Contents 10. CHANGE MANAGEMENT... 5 10.1. INTRODUCTION TO CHANGE MANAGEMENT... 5 10.1.1. PURPOSE OF

More information

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033

CHAPTER 2016-138. Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 CHAPTER 2016-138 Committee Substitute for Committee Substitute for Committee Substitute for House Bill No. 1033 An act relating to information technology security; amending s. 20.61, F.S.; revising the

More information

NETWORK SERVICES WITH SOME CREDIT UNIONS PROCESSING 800,000 TRANSACTIONS ANNUALLY AND MOVING OVER 500 MILLION, SYSTEM UPTIME IS CRITICAL.

NETWORK SERVICES WITH SOME CREDIT UNIONS PROCESSING 800,000 TRANSACTIONS ANNUALLY AND MOVING OVER 500 MILLION, SYSTEM UPTIME IS CRITICAL. NETWORK SERVICES WITH SOME CREDIT UNIONS PROCESSING 800,000 TRANSACTIONS ANNUALLY AND MOVING OVER 500 MILLION, SYSTEM UPTIME IS CRITICAL. Your Credit Union information is irreplaceable. Data loss can result

More information

Installation and Operational Qualification Protocol (Reference: SOP )

Installation and Operational Qualification Protocol (Reference: SOP ) Project Name Equipment Process Line/Location Project Number Serial Number Model Number Protocol number WRITTEN BY: REVIEWED BY: Position APPROVAL TO EXECUTE: Position: PROTOCOL COMPLETION APPROVAL: Position:

More information

Exhibit to Data Center Services Service Component Provider Master Services Agreement

Exhibit to Data Center Services Service Component Provider Master Services Agreement Exhibit to Data Center Services Service Component Provider Master Services Agreement DIR Contract No. DIR-DCS-SCP-MSA-002 Between The State of Texas, acting by and through the Texas Department of Information

More information

Document subject to ISO 50001 Requirements

Document subject to ISO 50001 Requirements Document subject to 4.1 General requirements The organization shall: a) b) establish, document, implement, maintain and improve an EnMS in accordance with the requirements of this International Standard;

More information

STATE OF NEVADA Department of Administration Division of Human Resource Management CLASS SPECIFICATION TITLE GRADE EEO-4 CODE

STATE OF NEVADA Department of Administration Division of Human Resource Management CLASS SPECIFICATION TITLE GRADE EEO-4 CODE STATE OF NEVADA Department of Administration Division of Human Resource Management CLASS SPECIFICATION TITLE GRADE EEO-4 CODE ACCOUNTANT TECHNICIAN III 34 C 7.140 SERIES DISCUSSION Positions allocated

More information

Client Security Risk Assessment Questionnaire

Client Security Risk Assessment Questionnaire Select the appropriate answer from the drop down in the column, and provide a brief description in the section. 1 Do you have a member of your organization with dedicated information security duties? 2

More information

(iv) (Unchanged) July 27, 2015. To whom it may concern

(iv) (Unchanged) July 27, 2015. To whom it may concern Note: This English document has been translated from the Japanese original for reference purposes only. In the event of any discrepancy between this translation and the Japanese original, the Japanese

More information

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Table of Contents Introduction... 1 1. Administrative Safeguards...

More information

Consider the cash demands of a financial institution's customers; Anticipate funding needs in late 1999 and early 2000;

Consider the cash demands of a financial institution's customers; Anticipate funding needs in late 1999 and early 2000; AL 98-18 Subject: Year 2000 Q&A Guidance Date: December 10, 1998 TO: hief Executive Officers of National Banks, Federal Branches, Service Providers, Software Vendors, Department and Division Heads, and

More information

Evaluation Report. Weaknesses Identified During the FY 2013 Federal Information Security Management Act Review. April 30, 2014 Report Number 14-12

Evaluation Report. Weaknesses Identified During the FY 2013 Federal Information Security Management Act Review. April 30, 2014 Report Number 14-12 Evaluation Report Weaknesses Identified During the FY 2013 Federal Information Security Management Act Review April 30, 2014 Report Number 14-12 U.S. Small Business Administration Office of Inspector General

More information

Supervisory Policy Manual

Supervisory Policy Manual This module should be read in conjunction with the Introduction and with the Glossary, which contains an explanation of abbreviations and other terms used in this Manual. If reading on-line, click on blue

More information

Auditing in an Automated Environment: Appendix C: Computer Operations

Auditing in an Automated Environment: Appendix C: Computer Operations Agency Prepared By Initials Date Reviewed By Audit Program - Computer Operations W/P Ref Page 1 of 1 Procedures Initials Date Reference/Comments OBJECTIVE - To document the review of the computer operations

More information

Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report

Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report Health Insurance Portability and Accountability Act (HIPAA) Compliance Audit Final Report April 2009 promoting efficient & effective local government Background The Health Insurance Portability and Accountability

More information

Maintenance Connection Disaster Recovery Plan

Maintenance Connection Disaster Recovery Plan Maintenance Connection Disaster Recovery Plan Last Revised: January 2014 Maintenance Connection, Inc. 1477 Drew Ave. Suite 103 Davis, CA 95695 8885673434 1 Introduction Maintenance Connection s Disaster

More information

CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS

CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS 11-1 CHAPTER 11 COMPUTER SYSTEMS INFORMATION TECHNOLOGY SERVICES CONTROLS INTRODUCTION The State Board of Accounts, in accordance with State statutes and the Statements on Auditing Standards Numbers 78

More information

GOOD BANKING PRACTICE

GOOD BANKING PRACTICE THE FINNISH BANKERS ASSOCIATION GOOD BANKING PRACTICE Good banking practice has evolved from practical experience. It consists of general principles governing the relationship between a customer and a

More information

Disaster Preparedness & Response

Disaster Preparedness & Response 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 A B C E INTRODUCTION AND PURPOSE REVIEW ELEMENTS ABBREVIATIONS NCUA REFERENCES EXTERNAL REFERENCES Planning - Ensuring

More information

Fubon Financial Holding Co., Ltd. Corporate Governance Committee Organizational Rules

Fubon Financial Holding Co., Ltd. Corporate Governance Committee Organizational Rules Fubon Financial Holding Co., Ltd. Corporate Governance Committee Organizational Rules Adopted by the Board of Directors on August 14, 2002 1 st amendment by the Board of Directors on October 28, 2002 2

More information

How To Write A Health Care Security Rule For A University

How To Write A Health Care Security Rule For A University INTRODUCTION HIPAA Security Rule Safeguards Recommended Standards Developed by: USF HIPAA Security Team May 12, 2005 The Health Insurance Portability and Accountability Act (HIPAA) Security Rule, as a

More information

PART 10 COMPUTER SYSTEMS

PART 10 COMPUTER SYSTEMS PART 10 COMPUTER SYSTEMS 10-1 PART 10 COMPUTER SYSTEMS The following is a general outline of steps to follow when contemplating the purchase of data processing hardware and/or software. The State Board

More information

TITLE I SAFETY AND SOUNDNESS. Subtitle A Deposit Insurance Funds

TITLE I SAFETY AND SOUNDNESS. Subtitle A Deposit Insurance Funds Public Law 102-242 102d Congress An Act Dec. 19, 1991 [S. 543] Federal Deposit Insurance Corporation Improvement Act o f 1991. 12, USC 1811 note. To require the least-cost resolution o f insured depository

More information

Joseph Suchocki HIPAA Compliance 2015

Joseph Suchocki HIPAA Compliance 2015 Joseph Suchocki HIPAA Compliance 2015 Sponsored by Eagle Associates, Inc. Eagle Associates provides compliance services for over 1,200 practices nation wide. Services provided by Eagle Associates address

More information

HIPAA Information Security Overview

HIPAA Information Security Overview HIPAA Information Security Overview Security Overview HIPAA Security Regulations establish safeguards for protected health information (PHI) in electronic format. The security rules apply to PHI that is

More information

City of Raleigh Public Utilities Department. Wastewater EMS Manual

City of Raleigh Public Utilities Department. Wastewater EMS Manual City of Raleigh Public Utilities Department Wastewater EMS Manual TABLE OF CONTENTS PAGE 2 Wastewater EMS Manual Table of Contents Management Direction 1) EMS Manual 2) Management Policy Planning 3) Process

More information

Guidance Note on Credit and Credit Control for Credit Unions. October 2007. Office of the Registrar of Credit Unions

Guidance Note on Credit and Credit Control for Credit Unions. October 2007. Office of the Registrar of Credit Unions Guidance Note on Credit and Credit Control for Credit Unions October 2007 Office of the Registrar of Credit Unions Contents Page Introduction 2 1. The Board of Directors 3 2. Credit Policy 5 3. Credit

More information

NC SBI QUALITY ASSURANCE PROGRAM

NC SBI QUALITY ASSURANCE PROGRAM NC SBI QUALITY ASSURANCE PROGRAM for the SBI Reviewed by: Deputy Assistant Director Bill Weis Date: Approved by: Assistant Director Jerry Richardson Date: Originating Unit: SBI Effective Date: July 25,

More information

ACCIDENT PREVENTION PLAN. A Sample Plan for Counties

ACCIDENT PREVENTION PLAN. A Sample Plan for Counties ACCIDENT PREVENTION PLAN A Sample Plan for Counties TABLE OF CONTENTS MANAGEMENT COMPONENT... 1 Safety Policy Statement Safety Committee Members Authority and Accountability Statement RECORDKEEPING COMPONENT...

More information

BPA Policy 434-1 Cyber Security Program

BPA Policy 434-1 Cyber Security Program B O N N E V I L L E P O W E R A D M I N I S T R A T I O N BPA Policy Table of Contents.1 Purpose & Background...2.2 Policy Owner... 2.3 Applicability... 2.4 Terms & Definitions... 2.5 Policy... 5.6 Policy

More information

Implementing an Energy Management System Using ISO 50001

Implementing an Energy Management System Using ISO 50001 Implementing an Energy Management System Using ISO 50001 This article will address issues related to sustainability efforts, through energy management as it relates to ISO 50001, Energy Management System

More information

U. S. Department of Energy Consolidated Audit Program Checklist 5 Laboratory Information Management Systems Electronic Data Management

U. S. Department of Energy Consolidated Audit Program Checklist 5 Laboratory Information Management Systems Electronic Data Management U. S. Department of Energy Consolidated Audit Program Checklist 5 Laboratory Information Management Systems Electronic Data Management Revision 4.0 February 2014 Use of this DOECAP checklist is authorized

More information

Final Construction Quality Control Plan Non-Public Properties Newhall Street Neighborhood Site Hamden, Connecticut

Final Construction Quality Control Plan Non-Public Properties Newhall Street Neighborhood Site Hamden, Connecticut Final Construction Quality Control Plan Non-Public Properties Newhall Street Neighborhood Site Hamden, Connecticut Revision 0 Prepared for: Olin Corporation Cleveland, Tennessee Prepared by: Sevenson Environmental

More information

The first step in protecting Critical Cyber Assets is identifying them. CIP-002 focuses on this identification process.

The first step in protecting Critical Cyber Assets is identifying them. CIP-002 focuses on this identification process. CIPS Overview Introduction The reliability of the energy grid depends not only on physical assets, but cyber assets. The North American Electric Reliability Corporation (NERC) realized that, along with

More information

American International Group, Inc. DNS Practice Statement for the AIG Zone. Version 0.2

American International Group, Inc. DNS Practice Statement for the AIG Zone. Version 0.2 American International Group, Inc. DNS Practice Statement for the AIG Zone Version 0.2 1 Table of contents 1 INTRODUCTION... 6 1.1 Overview...6 1.2 Document Name and Identification...6 1.3 Community and

More information

543.7 What are the minimum internal control standards for bingo?

543.7 What are the minimum internal control standards for bingo? Bingo Purpose This section provides guidance on the development of internal controls, policies, and procedures for the operation of bingo. It has been compiled by tribal regulators, Class II gaming operators,

More information

Exhibit to Data Center Services Service Component Provider Master Services Agreement

Exhibit to Data Center Services Service Component Provider Master Services Agreement Exhibit to Data Center Services Service Component Provider Master Services Agreement DIR Contract No. DIR-DCS-SCP-MSA-002 Between The State of Texas, acting by and through the Texas Department of Information

More information