<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-562158015259901802</id><updated>2011-11-27T17:01:35.705-08:00</updated><title type='text'>IT Audit and information security</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>23</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-3840946190980942152</id><published>2008-09-02T07:33:00.001-07:00</published><updated>2008-09-02T07:34:43.178-07:00</updated><title type='text'>Bitkom: number of phishing victims increased by 25 percent</title><summary type='text'>Annual accounts 2007: 4100 cases with 19 million euro loss recordedIn the year 2007 are far more Internet users victims of fraudsters become Password: The number of phishing cases of online banking by 25 percent. This is apparent from an extrapolation of the high-tech association Bitkom, which is the current data Landeskriminalämter based.Nationwide lifted criminals, according to Bitkom in more </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/3840946190980942152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=3840946190980942152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3840946190980942152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3840946190980942152'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/09/bitkom-number-of-phishing-victims.html' title='Bitkom: number of phishing victims increased by 25 percent'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-7421779432263675747</id><published>2008-08-31T03:51:00.000-07:00</published><updated>2008-08-31T03:59:37.098-07:00</updated><title type='text'>Password protection of the iPhones can be easily bypassed</title><summary type='text'>Obtain unauthorized access to e-mails, contacts, SMS and the Safari browser.A user of the MacRumors forum has found an easy way to password protect an iPhone with the installed firmware version 2.0.2 to circumvent. As Gizmodo reports must be only the emergency button and then the Home button is pressed. This will open without entering a password the Favorites menu, which also full unauthorised </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/7421779432263675747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=7421779432263675747' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/7421779432263675747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/7421779432263675747'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/08/password-protection-of-iphones-can-be.html' title='Password protection of the iPhones can be easily bypassed'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-225974174869821366</id><published>2008-08-30T14:09:00.000-07:00</published><updated>2008-08-30T14:28:04.563-07:00</updated><title type='text'>Automated roles and rights assignment: A secure identity and access management creates customer confidence</title><summary type='text'>   Link of the day - Claim your Black MacBook Air with participation.Do you want to receive a Black MacBook Air? New data-reporting breakdown in German offices: According to the newspaper "taz" have at least eight companies with millions of illegal records from  registers traded. One of these companies have a database with 72 million records. This paper describes how data leaks occur and what </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/225974174869821366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=225974174869821366' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/225974174869821366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/225974174869821366'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/08/automated-roles-and-rights-assignment.html' title='Automated roles and rights assignment: A secure identity and access management creates customer confidence'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_UaNRfCmr3pk/SLm7XCsiviI/AAAAAAAAAAc/FGIvKZ1T3es/s72-c/black-macbook-air-1.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-7608192098830690740</id><published>2008-03-18T20:44:00.000-07:00</published><updated>2008-03-18T20:47:43.811-07:00</updated><title type='text'>GRC new buzzword it IT Governance area</title><summary type='text'>Today, organizations of all shapes and sizes face stringent industry regulations and standards that often threaten hefty fines or even punishment for decision-makers in the case of non-compliance. In addition, to Sarbanes-Oxley (SOX), CIOs and CSOs must understand and achieve compliance with the Health Insurance Portability and Accountability Act (HIPAA) for health-related industries; the Payment</summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/7608192098830690740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=7608192098830690740' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/7608192098830690740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/7608192098830690740'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/03/grc-new-buzzword-it-it-governance-area.html' title='GRC new buzzword it IT Governance area'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-1125147302116541358</id><published>2008-03-18T20:20:00.000-07:00</published><updated>2008-03-18T20:27:12.591-07:00</updated><title type='text'>SOA - mitigate compliance and security risks</title><summary type='text'>SOA: A Brief Technological OverviewService-Oriented Architecture is an approach to enterprise architecture that is based on the idea of software applications sharing functions with one another as “services.” In contrast to conventional architectures, where each application stands alone within its own “silo” and performs its function strictly by using its own code base, an SOA opens up </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/1125147302116541358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=1125147302116541358' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1125147302116541358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1125147302116541358'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/03/soa-mitigate-compliance-and-security.html' title='SOA - mitigate compliance and security risks'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-4236458133675076738</id><published>2008-01-31T02:32:00.000-08:00</published><updated>2008-01-31T02:36:00.979-08:00</updated><title type='text'>IT Risk Managemet Report, Volume 2</title><summary type='text'>Urban Risk Legends RevealedIT Risk — encompassing Security, Availability, Performance, and Compliance elements — is a critical issue for executives and boards of directors. In this second volume of the IT Risk Management Report, Symantec extends its analysis of IT professionals’ insights into the nature of IT Risk and the most effective ways to manage it, with added focus on Availability and </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/4236458133675076738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=4236458133675076738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4236458133675076738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4236458133675076738'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/01/it-risk-managemet-report-volume-2.html' title='IT Risk Managemet Report, Volume 2'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-5051271919918785848</id><published>2008-01-28T00:19:00.000-08:00</published><updated>2008-01-28T00:25:54.406-08:00</updated><title type='text'>Audit Office Threatens To Sack IT Auditor - Whistleblower</title><summary type='text'>A “WHISTLEBLOWER” has been threatened with dismissal by the Wales Audit Office after raising concerns with the Western Mail.Andrew Hurley, a £54,000-a-year IT specialist employed by the WAO, said he had been sent on gardening leave the day before he was due to start an investigation into concerns the NHS body Health Solutions Wales may have been breaching protocols relating to patient </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/5051271919918785848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=5051271919918785848' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5051271919918785848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5051271919918785848'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2008/01/audit-office-threatens-to-sack-it.html' title='Audit Office Threatens To Sack IT Auditor - Whistleblower'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-561350710980592136</id><published>2007-12-12T19:42:00.000-08:00</published><updated>2007-12-12T19:59:40.171-08:00</updated><title type='text'>MIS Training Institute Announces Keynote Speaker for InfoSec World 2008</title><summary type='text'>MIS Training Institute today announced InfoSec World Conference &amp; Expo 2008 featuring Oliver North as this year’s keynote speaker. Conference organizers are also introducing a new conference line up for the leading IT security event taking place March 10-12, 2008 in Orlando, Florida. Oliver North, combat-decorated marine, best-selling author, and former U.S. counter-terrorism coordinator will </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/561350710980592136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=561350710980592136' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/561350710980592136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/561350710980592136'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/12/mis-training-institute-announces.html' title='MIS Training Institute Announces Keynote Speaker for InfoSec World 2008'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-4450185547330494779</id><published>2007-12-11T20:02:00.000-08:00</published><updated>2007-12-11T20:25:10.258-08:00</updated><title type='text'>IT governance 'key part of corporate management'</title><summary type='text'>DUBAI — A non-profit professional initiative under Dubai government's Financial Audit Department has argued for IT governance becoming an integral part of corporate management. "It is obvious that good governance in any organisation depends mainly on good IT governance," said Yasser Abdullah Amiri, the department's director-general and chairman of Information Technology Governance Assurance Forum</summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/4450185547330494779/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=4450185547330494779' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4450185547330494779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4450185547330494779'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/12/it-governance-key-part-of-corporate.html' title='IT governance &apos;key part of corporate management&apos;'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-5253868827667843751</id><published>2007-11-28T02:21:00.000-08:00</published><updated>2007-11-28T02:28:02.338-08:00</updated><title type='text'>Employees Don’t Understand the Real Value of Data</title><summary type='text'>If someone asked you to deliver a briefcase with $10 million in it, would you box it up, stick stamps on it and put it in the out-going mail? Of course not. Yet that’s the way many workers treat sensitive data in their organizations.The enormous data snafu the British government announced last week is the latest example. Government workers lost two computer disks containing the names, addresses, </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/5253868827667843751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=5253868827667843751' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5253868827667843751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5253868827667843751'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/employees-dont-understand-real-value-of.html' title='Employees Don’t Understand the Real Value of Data'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-5050345230997262421</id><published>2007-11-25T22:53:00.000-08:00</published><updated>2007-11-25T22:59:30.589-08:00</updated><title type='text'>10 Ways To Avoid Corporate Fraud</title><summary type='text'>Here are some tips provided by Ray Dunkle, an Akron certified public accountant with Brockman, Coats, Gedelian &amp; Co. and a certified fraud examiner.1. SET THE PROPER TONE AT THE TOPBe ethical and show that you're monitoring and paying attention.''If you're running your business unethically, don't be surprised if someone returns the favor at some point,'' Dunkle said.2. AWARENESS TRAININGBring </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/5050345230997262421/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=5050345230997262421' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5050345230997262421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5050345230997262421'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/10-ways-to-avoid-corporate-fraud.html' title='10 Ways To Avoid Corporate Fraud'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-499414334840187320</id><published>2007-11-23T21:20:00.000-08:00</published><updated>2007-11-23T21:23:51.531-08:00</updated><title type='text'>New Minimum Standard  for Software Development Security Announced</title><summary type='text'>BETHESDA, Md., Nov. 20 /PRNewswire/ -- The SANS Institute announcesthat at 3:00 PM EST today, Tuesday, November 20, the Secure ProgrammingCouncil will release its first proposed standard for software developers todemonstrate they have the skills and knowledge to write secure software.    This standard, combined with a standardized test of the skills coveredin the standard, will enable employers </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/499414334840187320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=499414334840187320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/499414334840187320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/499414334840187320'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/new-minimum-standard-for-software.html' title='New Minimum Standard  for Software Development Security Announced'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-9086951970219553248</id><published>2007-11-23T02:46:00.000-08:00</published><updated>2007-11-23T03:08:12.555-08:00</updated><title type='text'>Boeing. Deficiencies In Computer Controls Were Found During SOX Compliance Review.</title><summary type='text'>The Boeing Co. has told the Seattle P-I, in response to questions, that it is making progress on its Sarbanes-Oxley compliance testing in its information technology department, despite auditor turnover.While the Chicago-based company won't disclose its full compliance status until it files its annual financial report, "We can say that for 2007, SOX testing is progressing well and we're making </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/9086951970219553248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=9086951970219553248' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/9086951970219553248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/9086951970219553248'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/boeing-deficiencies-in-computer.html' title='Boeing. Deficiencies In Computer Controls Were Found During SOX Compliance Review.'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-8467040683442683987</id><published>2007-11-19T09:02:00.000-08:00</published><updated>2007-11-19T09:03:54.483-08:00</updated><title type='text'>35% Of Employees Violated Information Security Policy Deliberately</title><summary type='text'>ROLLING MEADOWS, Ill.--(BUSINESS WIRE)--A national survey of U.S. white-collar workers commissioned by the nonprofit, independent organization ISACA (formerly the Information Systems Audit and Control Association) has found that more than one-third (35%) of employees have violated their company’s information technology (IT) policies at least once and that nearly one-sixth (15%) of employees have </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/8467040683442683987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=8467040683442683987' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/8467040683442683987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/8467040683442683987'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/35-of-employees-violated-information_19.html' title='35% Of Employees Violated Information Security Policy Deliberately'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-4254544440839684131</id><published>2007-11-17T04:07:00.000-08:00</published><updated>2007-11-17T04:16:49.903-08:00</updated><title type='text'>CISA Salary Increase</title><summary type='text'>Want more money for your information security skills? Try getting a professional certification. For all the continuing debate about the real value of IT certification programs, the premiums that companies are willing to pay for certified information security professionals is actually trending upwards.A report released last week by New Canaan, Conn.-based Foote Partners LLC shows that formally </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/4254544440839684131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=4254544440839684131' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4254544440839684131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4254544440839684131'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/cisa-salary-increase.html' title='CISA Salary Increase'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-5372749603124351490</id><published>2007-11-07T21:45:00.000-08:00</published><updated>2007-11-07T21:57:45.698-08:00</updated><title type='text'>Information Security in the 1984 - Glance from The Past</title><summary type='text'> The video is the issue of "Computer Chronicles" program dedicated to information security. It's about the emergence of information security problems in the distant 80's.</summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/5372749603124351490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=5372749603124351490' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5372749603124351490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/5372749603124351490'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/information-security-in-1984-glance.html' title='Information Security in the 1984 - Glance from The Past'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-8511582399736833938</id><published>2007-11-07T21:34:00.000-08:00</published><updated>2007-11-08T00:04:04.351-08:00</updated><title type='text'>Social engineering in action - Office security</title><summary type='text'>The video shows us simple rules, which should be kept to prevent unauthorized access to assets of the company including confidential information.</summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/8511582399736833938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=8511582399736833938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/8511582399736833938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/8511582399736833938'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/11/social-engineering-in-action-office.html' title='Social engineering in action - Office security'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-3076311604372039696</id><published>2007-10-29T21:23:00.000-07:00</published><updated>2007-10-31T20:33:48.376-07:00</updated><title type='text'>CISA Exam Scaled Score System</title><summary type='text'>There was a question about CISA scaled score system. Here is an excerpt from ISACA's explanations: "...Beginning with the June 2007 exam administration, exam scores are being reported on a scale from 200-800. This is a change from the 1-100 point scale that was used previously. Regardless of the scoring scale, the overall exam pass/fail results are the same. In other words, no more, or fewer </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/3076311604372039696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=3076311604372039696' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3076311604372039696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3076311604372039696'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/10/cisa-exam-scaled-score-system.html' title='CISA Exam Scaled Score System'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-1813007459031421725</id><published>2007-10-11T21:16:00.000-07:00</published><updated>2007-10-29T21:54:57.079-07:00</updated><title type='text'>CISA Exam Preparation</title><summary type='text'>Well this year deadline has passed. Those who were in time for registration should begin the preparation. Others who decided not to attend this year exam have chance to do preparation without rush.Let me share some experience in my approach to CISA exam preparation.First of all you need to read latest CISA Review Manual.In second place you need the questionary. I browsed ISACA bookstore and found</summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/1813007459031421725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=1813007459031421725' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1813007459031421725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1813007459031421725'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/10/cisa-exam-preparation.html' title='CISA Exam Preparation'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-3719942383811831524</id><published>2007-09-10T23:09:00.000-07:00</published><updated>2007-10-29T21:52:29.554-07:00</updated><title type='text'>Why to CISA?</title><summary type='text'>Yesturday i received a letter from ISACA. They reminded me that I passed CISA (Certified Information System Auditor) exam in 2005. And the deadline for certification is in December 2010. Why didn't I complete certification process? Well the answer is - I don't need the certificate right now. It is enough for the employeer to know that I have passed the CISA exam.So why do we need this </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/3719942383811831524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=3719942383811831524' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3719942383811831524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/3719942383811831524'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/09/cisa-exam.html' title='Why to CISA?'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-4383540734813112866</id><published>2007-09-02T21:33:00.000-07:00</published><updated>2007-09-05T06:23:10.442-07:00</updated><title type='text'>Basic IT KPI development tutorial</title><summary type='text'>This time I want to share my experience of Key Performance Indicator (KPI) development in IT area. For instance we have a procedure saying all user accounts in domain must be disabled after employee's dismissal. Employee should sign-off depature clearance by system administrator, who will lock or delete user accounts of such an employee. Our task is to implement KPI that will show us how well </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/4383540734813112866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=4383540734813112866' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4383540734813112866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/4383540734813112866'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/09/basic-kpi-development-tutorial.html' title='Basic IT KPI development tutorial'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-2959185680601627474</id><published>2007-08-20T03:35:00.000-07:00</published><updated>2007-08-26T22:25:10.905-07:00</updated><title type='text'>Internal Control, Internal Audit and IT Audit</title><summary type='text'>So, let's start with basics.What is the difference between Internal control and Internal audit and how to extend it to aspects of information technology?We could say that internal control is the process intended to improve the quality of buisness processes of organization. And main tasks of internal audit are to assure the quality of internal controls are and give recommendations on how to </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/2959185680601627474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=2959185680601627474' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/2959185680601627474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/2959185680601627474'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/08/internal-control-internal-audit-and-it.html' title='Internal Control, Internal Audit and IT Audit'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-562158015259901802.post-1403365970034748212</id><published>2007-08-16T10:07:00.000-07:00</published><updated>2007-08-17T00:04:52.744-07:00</updated><title type='text'>IT Audit, Information Security and Internal Control, why do we need to bother?</title><summary type='text'>Why do we need to audit and control all these boring things? Do the people really need somebody, who will crack a whip, indeed?Unfotunately our practice and experience shows that it is our case. It is like Murphy's low: If something could be done wrong, it will be done wrong.The answer, why it is happen, if the answer exists at all, lies in areas of philosophy and psychology. But it easy to see, </summary><link rel='replies' type='application/atom+xml' href='http://iaudit.blogspot.com/feeds/1403365970034748212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=562158015259901802&amp;postID=1403365970034748212' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1403365970034748212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/562158015259901802/posts/default/1403365970034748212'/><link rel='alternate' type='text/html' href='http://iaudit.blogspot.com/2007/08/it-audit-and-internal-control.html' title='IT Audit, Information Security and Internal Control, why do we need to bother?'/><author><name>TJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry></feed>
