ASSESSMENT REPORT Federal PKI Compliance Report September 6, 2013
|
|
|
- Camron Bradford
- 9 years ago
- Views:
Transcription
1 ASSESSMENT REPORT Federal PKI Compliance Report September 6, 2013
2 Date September 6, 2013 To Chief Information Officer From Inspector General Subject Assessment Report Federal PKI Compliance Report Report Number Enclosed please find the subject final report. The Office of the Inspector General administered a contract with Ernst & Young LLP (E&Y) to provide a compliance report of GPO s Public Key Infrastructure (PKI) for July 1, 2012 through June 30, E&Y conducted their work in accordance with attestation standards established by the American Institute of Certified Public Accountants. E&Y concluded that GPO s assertion is fairly stated in all material respects. E&Y also issued a Letter of Supplementary Information, concluding that the GPO Principal Certification Authority Certificate Practices Statement conformed in all material respects to the GPO Certificate Authority and Federal PKI common policies. E&Y is responsible for the attached report and the opinion expressed therein. We appreciate the courtesies extended to E&Y and to our audit staff. If you have any questions or comments about this report, please do not hesitate to contact Mr. Jeffrey C. Womack, Assistant Inspector General for Audits and Inspections at (202) or me at (202) Michael A. Raponi Inspector General Enclosure cc: Public Printer Deputy Public Printer General Counsel
3 U.S. Government Printing Office Report of Independent Accountants Federal PKI Compliance Report For the Period July 1, 2012 to June 30, 2013
4 Table of Contents Report of Independent Accountants... 1 Management Assertion... 2 Letter of Supplementary Information... 5 Summary of Matters Relating to Project Personnel
5 EY LLP 8484 Westpark Drive McLean, Virginia Tel: Fax: ey.com Report of Independent Accountants We have examined the assertion, dated August 16, 2013, by the management of the United States Government Printing Office ( GPO ), that GPO s Certification Authority (GPO-CA) complied with certain requirements of its Certificate Policy (CP), Version dated August 17, 2009 and its Certificate Practices Statement (CPS) Version dated February 21, 2013 for the period July 1, 2012 to June 30, 2013, as well as the requirements of the Federal PKI Authority and all current cross-certification Memorandum of Agreements (MOAs) executed by the GPO with other entities. Management of the GPO is responsible for its compliance with those requirements. Our responsibility is to express an opinion on management s assertion about the GPO s compliance based on our examination. Our examination was conducted in accordance with attestation standards established by the American Institute of Certified Public Accountants and accordingly, included examining, on a test basis, evidence about GPO-CA s compliance with those requirements and performing such other procedures as we considered necessary in the circumstances. We believe that our examination provides a reasonable basis for our opinion. Our examination does not provide a legal determination on GPO-CA s compliance with specific requirements. In our opinion, for the period from July 1, 2012 through June 30, 2013, GPO management s assertion, as set forth in the first paragraph, is fairly stated, in all material respects. This report is intended solely for the information and use of the GPO and the U.S. Federal PKI Policy Authority and is not intended to be and should not be used by anyone other than those specified parties. August 16, 2013 A member firm of EY Global Limited 1
6
7
8
9 EY LLP 8484 Westpark Drive McLean, Virginia Tel: Fax: ey.com August 16, 2013 Letter of Supplementary Information To the Inspector General of the United States Government Printing Office and the Management of the United States Government Printing Office Certification Authority (GPO CA): This letter provides supplementary information to the examination performed by Ernst & Young LLP of the assertion by the management of the GPO-CA regarding the certification authority services it provides at Management s assertions were based on the American Institute of Certified Public Accountants (AICPA)/Canadian Institute of Chartered Accountants WebTrust for Certification Authorities criteria. GPO-CA s management was responsible for its assertion. Our responsibility was to express an opinion on management s assertion based on our examination. Our examination was conducted in accordance with attestation standards established by the AICPA and, accordingly, included examining, on a test basis, evidence about GPO s compliance with those requirements and performing such other procedures as we considered necessary in the circumstances. We believe that our examination provides a reasonable basis for our opinion. Our examination does not provide a legal determination on GPO-CA s compliance with specified requirements. The period for this examination was from July 1, 2012 through June 30, Our examination was performed between February 14, 2013 and July 17, We examined the Certificate Policy (CP) for the GPO-CA version 1.3.1, dated August 17, 2009, and the Certification Practices Statement (CPS) for the GPO Principal Certification Authority (GPO-PCA) version 1.7.2, dated February 21, Multiple Root CAs were not in operation at GPO-CA. Our examination included, through our testing of management s assertion, the evaluation of GPO-CA s operations for conformance to the requirements of its CPS and the evaluation of GPO-CA s operations for conformance to the requirements of all current cross-certification Memorandum of Agreements (MOAs) executed by the GPO-CA with other entities. In our Report of Independent Accountants dated August 16, 2013, we reported that management s assertion was fairly stated in all material respects. A member firm of EY Global Limited 5
10 We have compared the CPS for the GPO-PCA version 1.7.2, dated February 21, 2013, for conformance to the CP for the GPO-CA version 1.3.1, dated August 17, We found, in all material respects, that the GPO-PCA CPS is in conformance with GPO-CA CP. We have compared the CPS for the GPO-PCA version 1.7.2, dated February 21, 2013 for conformance to the FPKI Common Policy. For this analysis we utilized the Framework Certification Practice Statement Evaluation Mapping Matrix, Version 2.8 (September 22, 2010). We found, in all material respects, that the GPO-PCA CPS is in conformance with the requirements of the FPKI Common Policy. We are independent of the GPO for the professional engagement period as required by the AICPA Professional Standards. A member firm of EY Global Limited 6
11 EY LLP 8484 Westpark Drive McLean, Virginia Tel: Fax: ey.com Summary of matters related to project personnel provided by Ernst & Young LLP August 16, 2013 To the Inspector General of the United States Government Printing Office and the Management of the United States Government Printing Office Certification Authority (GPO-CA): The GPO Office of Inspector General (OIG) has asked Ernst & Young LLP (EY or we) to provide certain information to assist in its efforts to provide the Federal Public Key Infrastructure Policy Authority (FPKIPA) with information about the individuals who performed work as part of the WebTrust for Certification Authority (WTCA) examination services; these services are performed in accordance with relevant American Institute of Certified Public Accountants (AICPA) standards. The FPKIPA sets policy governing operation of the U.S. Federal PKI Infrastructure, composed of: the Federal Bridge Certification Authority (FBCA); the Federal Common Policy Framework Certification Authority (CPFCA); the Citizen and Commerce Class Common Certification Authority (C4CA) and the E-Governance Certification Authority. EY makes no representation regarding the sufficiency of this information for the purposes for which this information was requested. That responsibility rests solely with the FPKIPA. Educational level and professional experience Client serving personnel (Professionals) EY has provided to the Agency have received a degree from an accredited college or university (or its equivalent if the individual was educated outside of the United States). Certain individuals may also have advanced degrees. The majority of Professionals provided to the Agency are part of EY s Advisory Services (AS) service line. Recruiting efforts for the AS practice focuses on candidates with information technology, accounting, finance and other business-related degrees. Hiring activities and types of Professionals hired into each EY service line, including Assurance and Tax, are generally the same as similar service lines and personnel of Deloitte, PwC and KPMG (who along with EY, are the Big Four). The experience levels of Professionals provided will vary based upon various factors including age and length of time the individual has worked since receiving their degree. The amount of professional experience of Professionals may not solely be related to a person s employment period with EY, as EY normally hires a combination of experienced Professionals and Professionals who recently graduated from a college or university. In most cases, the experience level within a rank classification of EY Professionals is generally the same as the other Big Four. A member firm of EY Global Limited 7
12 Methodologies, policies and procedures EY Professionals carrying out WTCA examinations are required to comply with policies and procedures within the EY Global Advisory Q&RM Guide ( the Guide ) and related methodologies. In those cases where we do not perform work directly under the supervision and responsibility of Agency personnel as part of an engagement to provide loan staff, and we provide management with our findings and recommendations in those areas where we observe internal controls that, in our view, could be improved, the Guide requires the work and any reports or deliverables to be in accordance with the Statement on Standards for Consulting Services (CS100) of the AICPA. The initial adoption of, and any subsequent changes in, policies and procedures have been reviewed and approved by EY s Professional Practice group. Professional certification and continuing education EY encourages its Professionals to obtain a professional certification. In certain service lines, obtaining a professional certification is a requirement for promotion. Individuals in AS are required to obtain a professional certification to be promoted to Manager. In the AS service line, the most common certifications are Certified Public Accountant (CPA) (or its equivalent in other countries), Certified Internal Auditor (CIA) as recognized by the Institute of Internal Auditors, Certified Information Systems Auditor (CISA) as recognized by ISACA, or Certified Management Accountant (CMA) as recognized by the Institute of Management Accountants. The continuing professional education requirements of the SEC (Securities and Exchange Commission) Practice Section of the AICPA Division for CPA firms are the foundation of EY s professional development policy. Participation in professional development programs is measured in units of continuing professional education (CPE) credit hours earned in our educational year. EY s educational year is July 1 through June 30. The EY policy for compliance is as follows: Commencing with the first full educational year of employment, each professional must obtain at least 20 CPE credit hours each year and at least 120 CPE credit hours during the most recent three-year period. Professionals who were not employed during the entire most recent educational year are not required to earn continuing professional education credits in that year. Professionals who were employed during the entire most recent educational year, but not during the entire most recent two educational years, are required to have participated in at least 20 hours of qualifying continuing professional education during the most recent educational year. Professionals who were employed during the entire most recent two educational years, but not during the entire most recent three educational years, are required to have participated in at least 20 hours of qualifying continuing professional education during each of the two most recent educational years. A member firm of EY Global Limited 8
13 Professionals who hold a professional designation or certification other than the CPA certification (e.g., CIA, attorney at law, CISA, CMA) may be subject to continuing education requirements as part of that designation or certification. Completion of courses to meet these requirements may be used to meet the firm s CPE requirements as long as the courses also meet the requirements of the AICPA s SEC Practice Section. Experience Auditing PKI Systems The EY executive team assigned to the GPO project has experience in performing audits and implementation of PKI systems and IT security. In addition, certain team members also have participated in a number of other commercial PKI and WebTrust for CA examinations both as a team member and as a quality reviewer. We have incorporated consultations with other EY personnel who represent the firm on the AICPA WebTrust Task Force. EY s client roster for PKI projects for governmental agencies other than the GPO includes other US federal agencies as well as foreign governmental monetary organizations. We are available if you need any additional information or would like to further discuss this memorandum. A member firm of EY Global Limited 9
14 Summary information for EY executives assigned to the engagement Name Rank Certifications Werner Lippuner Principal CA (Switzerland), CISA, CISM Years of experience In compliance with EY CPE policy (Yes/No) 24 Yes James Merrill Executive Director CPA, CISA 31 Yes Bruce Hamilton Senior Manager CISSP, CPA, CISA, CISM 32 Yes Staci Angel Senior Manager CISA 9 Yes 10
Independent Accountants Report
KPMG LLP 345 Park Avenue New York, NY 10154-0102 Independent Accountants Report To the Management of Unisys Corporation: We have examined the assertion by the management of Unisys Corporation (Unisys)
SECTION I INDEPENDENT SERVICE AUDITOR S REPORT
SOC2 Security Report on Controls Supporting DriveSavers Services Independent Service Auditor s Report on Design of Controls Placed in Operation and Tests of Operational Effectiveness Relevant to Security
Independent Accountants Report
KPMG LLP 1601 Market Street Philadelphia, PA 19103-2499 Independent Accountants Report To the Management of Unisys Corporation: We have examined the assertion by the management of Unisys Corporation (
PKI Audit Methodology
A white paper describing practical methods used to perform PKI compliance audits intended for maximum reliance and affordability Scott S. Perry CPA, CISA Solution Leader, IT Risk & Control Services Slalom
Review of U.S. Coast Guard's FY 2014 Drug Control Performance Summary Report
Review of U.S. Coast Guard's FY 2014 Drug Control Performance Summary Report January 26, 2015 OIG-15-27 HIGHLIGHTS Review of U.S. Coast Guard s FY 2014 Drug Control Performance Summary Report January 26,
AUDIT OF SBA S EMAIL SYSTEM AUDIT REPORT NUMBER 4-42 SEPTEMBER 10, 2004
AUDIT OF SBA S EMAIL SYSTEM AUDIT REPORT NUMBER 4-42 SEPTEMBER 10, 2004 This report may contain proprietary information subject to the provisions of 18 USC 1905 and must not be released to the public or
QUALITY CONTROL REVIEW REPORT
IG-02-007 QUALITY CONTROL REVIEW REPORT ERNST & YOUNG LLP AND DEFENSE CONTRACT AUDIT AGENCY AUDIT OF SOUTHWEST RESEARCH INSTITUTE, FISCAL YEAR ENDED SEPTEMBER 24, 1999 January 23, 2002 OFFICE OF INSPECTOR
Chapter 01 Accounting: The Language of Business
Chapter 01 Accounting: The Language of Business True / False Questions 1. The purpose of accounting is to provide financial information about an economic or social entity. 2. An accounting system is designed
RULES OF DEPARTMENT OF COMMERCE AND INSURANCE DIVISION OF REGULATORY BOARDS TENNESSEE STATE BOARD OF ACCOUNTANCY CHAPTER 0020-05 CONTINUING EDUCATION
RULES OF DEPARTMENT OF COMMERCE AND INSURANCE DIVISION OF REGULATORY BOARDS TENNESSEE STATE BOARD OF ACCOUNTANCY CHAPTER 0020-05 CONTINUING EDUCATION TABLE OF CONTENTS 0020-05-.01 Definitions 0020-05-.05
Agreed-Upon Procedures Engagements
Agreed-Upon Procedures Engagements 1323 AT Section 201 Agreed-Upon Procedures Engagements Source: SSAE No. 10; SSAE No. 11. Effective when the subject matter or assertion is as of or for a period ending
Copyright 2015, American Institute of Certified Public Accountants, Inc. All Rights Re... STATEMENT ON STANDARDS FOR CONSULTING SERVICES
Page 1 of 7 Consulting Services CS Section STATEMENT ON STANDARDS FOR CONSULTING SERVICES Statements on Standards for Consulting Services are issued by the AICPA Management Consulting Services Executive
How quality assurance reviews can strengthen the strategic value of internal auditing*
How quality assurance reviews can strengthen the strategic value of internal auditing* PwC Advisory Internal Audit Table of Contents Situation Pg. 02 In response to an increased focus on effective governance,
Cybersecurity and the AICPA Cybersecurity Attestation Project
Cybersecurity and the AICPA Cybersecurity Attestation Project Chris Halterman Executive Director EY Chair AICPA Trust Information Integrity Task Force 2 October 2015 Increasing awareness of cybersecurity
FS Regulatory Brief SEC Proposes Amendments to Broker- Dealer Financial Reporting Rule
SEC Proposes Amendments to Broker- Dealer Financial Reporting Rule Amendments call for brokerdealers assertion of compliance with the Financial Responsibility Rules, new reviews by independent auditors,
AUDIT REPORT. Federal Energy Regulatory Commission's Fiscal Year 2014 Financial Statement Audit
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections AUDIT REPORT Federal Energy Regulatory Commission's Fiscal Year 2014 Financial Statement Audit OAS-FS-15-05 December
Generally Accepted Privacy Principles. August 2009
Generally Accepted Privacy Principles August 2009 Acknowledgments The AICPA and Canadian Institute of Chartered Accountants (CICA) appreciate the contribution of the volunteers who devoted significant
Application Kit. A Guide to the AICPA Certified Information Technology Professional Credential
Application Kit A Guide to the AICPA Certified Information Technology Professional Credential Table of Contents What Is the CITP Credential?................................ 2 8 Great Reasons to Obtain
Experienced professionals may apply for the Certified Risk Management Professional (CRMP) certification under the grandfathering provision.
Application for CRMP Certification (part 1) GRCSI is now offering the Certified Risk Management Professional (CRMP) certification to support and recognize professionals who have skills and experience in
AUDIT REPORT REPORT NUMBER 14 08. Information Technology Professional Services Oracle Software March 25, 2014
AUDIT REPORT REPORT NUMBER 14 08 Information Technology Professional Services Oracle Software March 25, 2014 Date March 25, 2014 To Chief Information Officer Director, Acquisition Services From Inspector
CSA Position Paper on AICPA Service Organization Control Reports
CSA Position Paper on AICPA Service Organization Control Reports February 2013 2013, Cloud Security Alliance. All rights reserved. You may download, store, display on your computer, view, print, and link
ASSESSMENT REPORT 09 14 GPO WORKERS COMPENSATION PROGRAM. September 30, 2009
ASSESSMENT REPORT 09 14 GPO WORKERS COMPENSATION PROGRAM September 30, 2009 Date September 30, 2009 To Chief Management Officer Chief, Office of Workers Compensation From Assistant Inspector General for
Federal PKI (FPKI) Community Transition to SHA-256 Frequently Asked Questions (FAQ)
Federal PKI (FPKI) Community Transition to SHA-256 Frequently Asked Questions (FAQ) Version 1.0 January 18, 2011 Table of Contents 1. INTRODUCTION... 3 1.1 BACKGROUND... 3 1.2 OBJECTIVE AND AUDIENCE...
Goodbye, SAS 70! Hello, SSAE 16!
Goodbye, SAS 70! Hello, SSAE 16! A Session to Provide Insight on the New Standard and What Service Providers and End-Users Need to Know January 3, 2012 Agenda Introduction Background on what was SAS 70
Frequently asked questions: SOC 2 and 3
1. Is the licensing requirement for a SOC 2 or 3 different than for a SOC 1? SOC reports are attestation reports issued in accordance with AICPA standards. Therefore, licensing requirements are the same
Orange County Industrial Development Authority (a component unit of Orange County, Florida)
Orange County Industrial Development Authority Financial Statements Years Ended September 30, 2012 and 2011 Contents Management s Discussion and Analysis 3 Independent Auditors Report 4 Financial Statements
GAO. Government Auditing Standards: Implementation Tool
United States Government Accountability Office GAO By the Comptroller General of the United States December 2007 Government Auditing Standards: Implementation Tool Professional Requirements Tool for Use
WEBTRUST FOR CERTIFICATION AUTHORITIES SSL BASELINE REQUIREMENTS AUDIT CRITERIA V.1.1 [Amended 1 ] CA/BROWSER FORUM
WEBTRUST FOR CERTIFICATION AUTHORITIES SSL BASELINE REQUIREMENTS AUDIT CRITERIA V.1.1 [Amended 1 ] BASED ON: CA/BROWSER FORUM BASELINE REQUIREMENTS FOR THE ISSUANCE AND MANAGEMENT OF PUBLICLY-TRUSTED CERTIFICATES,
The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011
The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011 Table of Contents A Short History of SAS 70 Overview of SSAE 16 and ISAE 3402
Kevin Savoy, CPA, CISA, CISSP Director of Information Technology Audits Brian Daniels, CISA, GCFA Senior IT Auditor
IT Audit/Security Certifications Kevin Savoy, CPA, CISA, CISSP Director of Information Technology Audits Brian Daniels, CISA, GCFA Senior IT Auditor Certs Anyone? There are many certifications out there
X.509 Certification Practices Statement for the U.S. Government Printing Office Principal Certification Authority (GPO-PCA)
.509 Certification Practices Statement for the U.S. Government Printing Office Principal Certification Authority (GPO-PCA) June 11, 2007 FINAL Version 1.6.1 FOR OFFICIAL USE ONLY SIGNATURE PAGE U.S. Government
AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities Corporate Compliance and Internal Audit.
and Requirement: May be required if the organization must comply with Sarbanes-Oxley. Otherwise, is implemented as an organizational governance/business decision and best practice. Purpose: Provide independent
Federal Public Key Infrastructure (FPKI) Compliance Audit Requirements
Federal Public Key Infrastructure (FPKI) Compliance Audit Requirements July 10, 2015 Version REVISION HISTORY TABLE Date Version Description Author 10/15/09 0.0.1 First Released Version CPWG Audit WG 11/18/09
PROVING YOUR GRC KNOWLEDGE WITH CERTIFICATIONS
PROVING YOUR GRC KNOWLEDGE WITH CERTIFICATIONS PRESENTER: JASON MEFFORD, MEFFORD ASSOCIATES October 9, 2014 OCEG WEBINAR SERIES Housekeeping Download slides at http://www.oceg.org/event/ proving-your-grc-knowledge-with-certifications/
Part 2B of Form ADV SEC Firm Brochure Supplement
Part 2B of Form ADV SEC Firm Brochure Supplement (for Direct Clients) Professional Backgrounds of: Greg Miller, CPA (CEO, Principal) Darlene M. Murphy, CPA, CFP (President, Principal) Michael D. Miller
APPLICATION FOR EMPLOYMENT FOR PROFESSIONALS AND SUPPORT STAFF
State of New Jersey Department of Law and Public Safety Division of Criminal Justice APPLICATION FOR EMPLOYMENT FOR PROFESSIONALS AND SUPPORT STAFF The State of New Jersey is an Equal Opportunity Employer
IAASB Main Agenda (June 2010) Agenda Item. April 28, 2009
Agenda Item 8-B Statement of Position 09-1 April 28, 2009 Performing Agreed-Upon Procedures Engagements That Address the Completeness, Accuracy, or Consistency of XBRL-Tagged Data Issued Under the Authority
Orange County Industrial Development Authority (a component unit of Orange County, Florida)
Orange County Industrial Development Authority Financial Statements Years Ended September 30, 2011 and 2010 Contents Management s Discussion and Analysis 3 Independent Auditors Report 4 Financial Statements
STATE OF RHODE ISLAND AND PROVIDENCE PLANTATIONS. BOARD OF ACCOUNTANCY 1511 Pontiac Avenue, #68-1 Cranston, Rhode Island 02920
BOARD OF ACCOUNTANCY Cranston, Rhode Island 02920 APPLICATON FOR CPA CERTIFICATE WITHOUT WRITTEN EXAMINATION To the Rhode Island Board of Accountancy: I hereby make application to be examined by the Rhode
Report of Audit. FCA s Student Loan Repayment Program A-13-02 OFFICE OF INSPECTOR GENERAL. Auditor in Charge Tammy Rapp. Issued September 23, 2013
OFFICE OF INSPECTOR GENERAL Report of Audit FCA s Student Loan Repayment Program A-13-02 Auditor in Charge Tammy Rapp Issued September 23, 2013 FARM CREDIT ADMINISTRATION Farm Credit Administration Office
Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report
Service Organization Controls Managing Risks by Obtaining a Service Auditor s Report Contributing Authors Audrey Katcher, CPA/CITP, Partner at RubinBrown, LLP Janis Parthun, CPA/CITP, Sr. Technical Manager
Performance Measures for Internal Auditing
Performance Measures for Internal Auditing A simple question someone may ask is Why measure performance? An even simpler response would be that what gets measured gets done. McMaster University s discussion
CHANGYOU.COM LIMITED AUDIT COMMITTEE CHARTER
CHANGYOU.COM LIMITED AUDIT COMMITTEE CHARTER I. Composition of the Audit Committee: There will be a committee of the Board of Directors to be known as the Audit Committee. The Audit Committee will have
OBSERVATIONS FROM 2010 INSPECTIONS OF DOMESTIC ANNUALLY INSPECTED FIRMS REGARDING DEFICIENCIES IN AUDITS OF INTERNAL CONTROL OVER FINANCIAL REPORTING
1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org OBSERVATIONS FROM 2010 INSPECTIONS OF DOMESTIC ANNUALLY INSPECTED FIRMS REGARDING DEFICIENCIES
EXAMPLES OF AUDITOR'S REPORTS ON COMPLIANCE
EXAMPLES OF AUDITOR'S REPORTS ON COMPLIANCE LEGAL COMPLIANCE MANUAL EXAMPLES OF AUDITOR S REPORTS ON COMPLIANCE Page Minnesota Legal Compliance S Local Governmental Units (Other Than School Districts)
Committee on National Security Systems
Committee on National Security Systems CNSS POLICY No.25 March 2009 NATIONAL POLICY FOR PUBLIC KEY INFRASTRUCTURE IN NATIONAL SECURITY SYSTEMS. 1 CHAIR FOREWORD 1. (U) The CNSS Subcommittee chartered a
AUDIT REPORT 12-1 8. Audit of Controls over GPO s Fleet Credit Card Program. September 28, 2012
AUDIT REPORT 12-1 8 Audit of Controls over GPO s Fleet Credit Card Program September 28, 2012 Date September 28, 2012 To Director, Acquisition Services From Inspector General Subject Audit Report Audit
IRAP Policy and Procedures up to date as of 16 September 2014.
Australian Signals Directorate Cyber and Information Security Division Information Security Registered Assessors Program Policy and Procedures 09/2014 IRAP Policy and Procedures 09/2014 1 IRAP Policy and
WEBTRUST SM/TM FOR CERTIFICATION AUTHORITIES EXTENDED VALIDATION AUDIT CRITERIA Version 1.1 CA/BROWSER FORUM
WEBTRUST SM/TM FOR CERTIFICATION AUTHORITIES EXTENDED VALIDATION AUDIT CRITERIA Version 1.1 BASED ON: CA/BROWSER FORUM GUIDELINES FOR THE ISSUANCE AND MANAGEMENT OF EXTENDED VALIDATION CERTIFICATES Version
Life Care Center of Cleveland Cleveland, Tennessee
Life Care Center of Clevel Clevel, Tennessee Cost Reports for the Periods January 1, 2004, Through December 31, 2004, January 1, 2005, Through December 31, 2005, Resident Accounts for the Period January
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF ARMSTRONG FLOORING, INC. ADOPTED AS OF MARCH 30, 2016
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF ARMSTRONG FLOORING, INC. ADOPTED AS OF MARCH 30, 2016 I. PURPOSE OF THE COMMITTEE The purpose of the Audit Committee (the Committee ) of the
Management s Discussion and Analysis
Management s Discussion and Analysis 1473 AT Section 701 Management s Discussion and Analysis Source: SSAE No. 10. Effective when management s discussion and analysis is for a period ending on or after
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF EVERBANK FINANCIAL CORP
CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS OF EVERBANK FINANCIAL CORP 1 EverBank Financial Corp Charter of the Audit Committee I. PURPOSE OF THE COMMITTEE The purpose of the Audit Committee
THE UNIVERSITY OF TEXAS AT AUSTIN ACC 380K.12 Computer Audit & Systems Security (03100) Course Syllabus FALL 2015
THE UNIVERSITY OF TEXAS AT AUSTIN ACC 380K.12 (03100) Course Syllabus FALL 2015 Phone: Office: E-Mail: Bob George (Professor) Department of Accounting (512) 232-6788 GSB 5.124F (in McCombs) [email protected]
Compliance Audits 2463. Effective for compliance audits for fiscal periods ending on or after June 15, 2010. Earlier application is permitted.
Compliance Audits 2463 AU Section 801 Compliance Audits (Supersedes SAS No. 74.) Source: SAS No. 117. Effective for compliance audits for fiscal periods ending on or after June 15, 2010. Earlier application
Roles and Responsibilities Corporate Compliance and Internal Audit
Roles and Responsibilities and By Mark P. Ruppert, CPA, CIA, CISA, CHFP The focus group of Health Care Compliance Association (HCCA) and Association of Healthcare ors (AHIA) members continues to explore
DRAFT AUDITOR SERVICES CONTRACT AGREEMENT FOR AUDITOR SERVICES
ATTACHMENT 1 DRAFT AUDITOR SERVICES CONTRACT AGREEMENT FOR AUDITOR SERVICES THIS AGREEMENT, made and entered into on XXX XX, 2013, by and between the ORANGE COUNTY VECTOR CONTROL DISTRICT, (hereinafter
City of Miami, Florida Management Letter in Accordance With Chapter 10.550, Rules of the Florida Auditor General
Management Letter in Accordance With Chapter 10.550, Rules of the Florida Auditor General For the Year Ended September 30, 2014 Contents Management Letter in Accordance with Chapter 10.550 of the Rules
G11 EFFECT OF PERVASIVE IS CONTROLS
IS AUDITING GUIDELINE G11 EFFECT OF PERVASIVE IS CONTROLS The specialised nature of information systems (IS) auditing and the skills necessary to perform such audits require standards that apply specifically
SECURITY AND EXTERNAL SERVICE PROVIDERS
SECURITY AND EXTERNAL SERVICE PROVIDERS How to ensure regulatory compliance and manage risks with Service Organization Control (SOC) Reports Jorge Rey, CISA, CISM, CGEIT Director, Information Security
/-..~.~ JAN 4 2006. Mr. Dennis Conroy, SPHR
(. /-..~.~ OFFICE DEPARTMENT OF HEALTH & HUMAN SERVICES OFFICE OF INSPECTOR GENERAL OF AUDIT SERVICES 150 S. INDEPENDENCE MALL WEST SUITE 316 PHILADELPHIA, PENNSYLVANIA 19 I 06-3499 JAN 4 2006 Report Number:
Audit and Permitted Non-Audit Services Pre-Approval Policy (Pertaining to the Company s Independent Auditor)
Audit and Permitted Non-Audit Services Pre-Approval Policy (Pertaining to the Company s Independent Auditor) Statement of Principles Pursuant to the Sarbanes-Oxley Act of 2002 (the Act ) and in accordance
Amended and Restated. Charter of the Audit Committee. of the Board of Directors of. Tribune Publishing Company. (As Amended November 11, 2014)
Amended and Restated Charter of the Audit Committee of the Board of Directors of Tribune Publishing Company (As Amended November 11, 2014) This Charter sets forth, among other things, the purpose, membership
COLORADO CLAIMED UNALLOWABLE MEDICAID NURSING FACILITY SUPPLEMENTAL PAYMENTS
Department of Health and Human Services OFFICE OF INSPECTOR GENERAL COLORADO CLAIMED UNALLOWABLE MEDICAID NURSING FACILITY SUPPLEMENTAL PAYMENTS Inquiries about this report may be addressed to the Office
Service Organization Control (SOC) reports What are they?
Service Organization Control (SOC) reports What are they? Jeff Cook, CPA, CITP, CIPT, CISA June 2015 Introduction Service Organization Control (SOC) reports are on the rise in the IT assurance and compliance
Webtrends Inc. Service Organization Controls (SOC) 3 SM Report on the SaaS Solutions Services System Relevant to Security
Webtrends Inc. Service Organization Controls (SOC) 3 SM Report on the SaaS Solutions Services System Relevant to Security For the Period January 1, 2015 through June 30, 2015 SOC 3 SM SOC 3 is a service
How To Be A Successful Businessperson
FURGISON & CO., CPA, P.C. QUALITY CONTROL DOCUMENT Furgison & Co., CPA, P.C. s quality control policies and procedures for the six elements of quality control are presented below. All employees of the
RE: PCAOB Rulemaking Docket Matter No. 004 Statement Regarding the Establishment of Auditing and Other Professional Standards
May 12, 2003 Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, D.C. 20006-2803 RE: PCAOB Rulemaking Docket Matter No. 004 Statement Regarding the Establishment
SECURITIES AND EXCHANGE COMMISSION Washington, D.C. 20549 FORM 8-K
SECURITIES AND EXCHANGE COMMISSION Washington, D.C. 20549 FORM 8-K CURRENT REPORT PURSUANT TO SECTION 13 or 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 Date of Report: February 18, 2004 HUNTINGTON BANCSHARES
Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard
Information Systems Audit and Controls Association Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard February 4, 2014 Tom Haberman, Principal, Deloitte & Touche LLP Reema Singh,
STATE OF CONNECTICUT DEPARTMENT OF PUBLIC SAFETY DIVISION OF FIRE, EMERGENCY AND BUILDING SERVICES OFFICE OF STATE FIRE MARSHAL
STATE OF CONNECTICUT DEPARTMENT OF PUBLIC SAFETY DIVISION OF FIRE, EMERGENCY AND BUILDING SERVICES OFFICE OF STATE FIRE MARSHAL Policy Directive # 1 Date: July 1, 2001 Replaces: Directive # 1 dated 4/83,
FAIRCHILD SEMICONDUCTOR INTERNATIONAL, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS (As Amended through December 11, 2013)
FAIRCHILD SEMICONDUCTOR INTERNATIONAL, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS (As Amended through December 11, 2013) I. Audit Committee Purpose The audit committee is appointed by
Software Contract and Compliance Review
Audit Report Report Number IT-AR-15-009 September 18, 2015 Software Contract and Compliance Review The software contract did not comply with all applicable standards and management did not ensure the supplier
SAS No. 70, Service Organizations
SAS No. 70, Service Organizations A standard for reporting on a service organization s controls affecting user entities' financial statements. Only for use by service organization management, existing
