-
3
pages
-
English
-
Documents
Description
ƒƒƒƒINFORMATION TECHNOLOGY MANAGEMENT IN ENFORCEMENT EXECUTIVE SUMMARY We found that the Division of Enforcement’s (Enforcement or the Division) information technology (IT) management was generally adequate. However, the Division needs to issue additional guidance to ensure a sound IT program. During our review, the Division and the Office of Administrative Services (OAS) developed procedures for preventing and resolving physical security incidents at the Division’s forensics lab. To enhance the Division’s IT management, we are recommending that it prepare an IT plan and document its procedures for IT management, major initiatives (such as the document imaging project), and security management. OBJECTIVES, SCOPE, AND METHODOLOGY Our audit objective was to evaluate the Division of Enforcement’s IT management to determine if it was adequate and in compliance with applicable guidelines. During the review, we analyzed relevant IT documentation, interviewed Division, OAS and Office of Information Technology (OIT) staff, and observed the Division’s IT operations. The specific areas of review were: General IT management; IT security management; Staff IT training; and IT policies, standards and guidelines. We used selected best practices and standard IT controls (Control Objectives for Information and related Technology or COBIT) to perform this review. We conducted this performance audit from September 2005 to August 2006 in ...
-
Publié par
-
Langue
English