Where a business process is executed by an information system, the actual rules of that process are its configuration. An internal document expresses the intention of the organisation; the system carries out the settings.
The divergence between intention and configuration is, as a rule, examined by no one. The process owner does not consult the configuration, as this falls outside their remit, while the person maintaining the configuration is not accountable for the substance of the process and is under no obligation to reconcile the settings with the internal documents of the organisation. Responsibility for that reconciliation is ordinarily assigned to no department at all.
This gives rise to a question that organisations rarely put to themselves: by whom, and when, was it verified that the system does precisely what the policy, the regulation or the contract provides for. That question is answered by an independent examination, the conclusions of which are supported by documented evidence and set out in a form suitable for submission to a regulator, a shareholder, a counterparty or a court.
To obtain a preliminary estimate of scope, timing and fees, please complete the questionnaire. A response is provided within several business days.
Adjacent services and their subject matter
The question above borders on several types of professional service, each with its own subject matter and its own purpose.
|
Audit of financial statements
|
Development and implementation
|
Information security services
|
|
The subject matter is the fair presentation of the financial statements. Information systems are considered only to the extent that they affect reported figures; application rules that do not bear on the financial statements fall outside the scope. |
The subject matter is the creation of a solution and its transition into operation. Confirmation that a result meets the requirements of the client, given by the party that performed the work, lacks the attribute of independence, which limits its evidential weight. |
The subject matter is the resilience of a system against external and internal interference. Whether a protected system executes the application rule established by the organisation remains outside the scope of such work. |
The practice occupies the space between these areas and substitutes for none of them.
Services in Turkmenistan
The examination is performed against criteria set by the client. These are ordinarily the requirements of an international group parent, the terms of an agreement with a lender or investor, the requirements of an international development institution financing a project, or the internal documents of the organisation itself. Any applicable local requirements are settled as at the date work begins.
Requests come predominantly from the divisions of international companies operating in the republic and from organisations taking part in externally financed projects.
Engagements are performed by specialists of the practice attending on site. Reports are prepared in Russian or English; where prepared for a group parent or a financing institution, English is ordinarily required.
Methodological basis
Engagements are performed under the methodology of the practice. Its structure draws on generally recognised models for the governance of information technology and information security, while the areas included and the depth of procedures are determined for each organisation individually: by reference to the question posed, the characteristics of the sector, the size and structure of the information landscape, and the actual condition of the processes.
Full conformity with any international model is neither a condition of the engagement nor a criterion of assessment. Such models serve as a source of structure and of control formulations; the areas applied are those bearing on the subject matter, in a measure proportionate to the size of the organisation. An organisation whose processes are at an early stage of maturity is offered the same course of work as one with a developed governance system: what differs is the depth of the procedures and the substance of the recommendations, not the feasibility of the engagement itself.
The practice maintains its own methodological base: a hierarchy of information technology management processes, registers of regulatory requirements, and a catalogue of controls and test procedures. A work programme for a subject matter not previously encountered is assembled from that base within a matter of days. This makes it possible to accept engagements for which no established sector methodology exists — from anti-fraud systems to video surveillance — without relaxing the standard of evidence.
Matters on which clients approach the practice
|
Question 1 Does the organisation meet the requirements applicable to it
|
Question 2 Does the system do what it is stated to do
|
|
The engagement is performed where the outcome is to be submitted to a regulator, a parent organisation, a group auditor, a lender or an international development institution. The outcome is a report containing an independent assurance conclusion. |
An examination of a single system or a single business rule: whether the system executes what internal documents prescribe, and what becomes of the transaction thereafter. Organisations approach the practice where a reasonable doubt has arisen but a full audit is not required or would be premature. |
|
Question 3 What happened, and who is answerable
|
Question 4 What did it cost, and was it warranted
|
|
A dispute over the outcome of development or implementation, the investigation of an incident, or questions arising in the course of an investigation or judicial proceedings. The form of the outcome follows from its addressee, and the service is accordingly divided by legal setting. |
Determination of the cost of creating a software product, assessment of whether information technology meets the needs of the organisation, and calculation of total cost of ownership. |
How the work is structured
The sequence is the same across all of the above services and differs only in the extent of the scope, the depth of the procedures and the form of the final document.
|
1
|
Preliminary survey and definition of scope
On the basis of the completed questionnaire and an introductory discussion, the objects to be brought within the engagement are established. Depending on the subject matter, the scope may include governance documentation, application systems and their interfaces, server and network infrastructure, virtualisation and backup facilities, communication channels and remote access, premises where information is processed and stored, engaged service providers and contractors, and the personnel involved in the processes under examination. The preliminary effort in person-days, the composition of the team, the need for site attendance and the timetable are then determined. The estimate is provided within several business days. |
|
2
|
Agreement of criteria
Before work begins, it is established against what the examination is to be performed. Criteria may comprise regulatory requirements, internal documents of the organisation, requirements of a parent company or group, terms of contracts with counterparties, provisions of selected areas of international governance models, or the terms of a technical specification. The criteria are recorded in the engagement contract and are not thereafter varied unilaterally. Absent agreed criteria no conclusion can be expressed, as there is nothing against which to measure. Agreement of the criteria also determines the extent of the work: the controls to be examined follow from the criteria selected. |
|
3
|
Request for documents and information
A structured schedule of requested materials is issued. It ordinarily comprises:
The schedule is adapted to the subject matter and to the size of the organisation; materials outside the agreed scope are not requested. |
|
4
|
Fieldwork
The principal stage, during which evidence is obtained. The following groups of procedures are applied:
Each control is considered in two respects: design — whether it is capable in principle of achieving its stated objective; and operating effectiveness — whether it was in fact performed, at the established frequency, throughout the period under examination. The involvement of the organisation’s staff is required for interviews and demonstrations. Those ordinarily engaged include the head of the information technology function, system and database administrators, network administrators, the officer responsible for information security, representatives of the human resources function and the owners of the processes under examination. |
|
5
|
Evaluation of findings
Each finding is related to a specific criterion and supported by evidence enabling the observation to be reproduced. A risk assessment is then performed: scenarios of realisation are described, and the likelihood and possible consequences for personnel, systems, premises, infrastructure and the obligations of the organisation are determined. Findings are ranked by significance, which establishes the order in which they are best addressed. |
|
6
|
Discussion of preliminary results
Findings are discussed with the responsible members of staff before being included in the report. This precludes conclusions founded on an incomplete understanding of the circumstances and affords the organisation the opportunity to submit further evidence or explanations, which are taken into account in the final version. |
|
7
|
Report and accompanying documents
A signed report is delivered, setting out the scope and the procedures applied, the findings with supporting evidence and risk assessment, and a register of recommendations with an indication of priority; where required, a management letter and materials for submission to the governing bodies are also provided. By arrangement, the results are presented to the board of directors, the audit committee or another body. |
Systems need not be taken out of service for the engagement to proceed. Any action capable of affecting availability is agreed separately and performed at an agreed time.
Independence and absence of conflicts of interest
The practice does not resell software, equipment or licences, does not act as a partner of solution vendors and receives no remuneration from them, whether by way of commission, bonus or partner discount. The financial outcome of an engagement does not depend on what the organisation may subsequently procure.
Recommendations are expressed in terms of functional requirements and controls rather than of particular products or vendors. Where remediation calls for the acquisition of a tool, the recommendation states the properties that tool should possess; the choice of vendor rests with the organisation and is made without the involvement of the practice.
Engagements to implement the solutions examined, and any participation in remediation in the capacity of implementer, are not accepted: independence is incompatible with subsequently examining one’s own work.
The extent of an engagement follows from the question posed and the criteria agreed, not from any interest in continuing the relationship. Reports contain no offers of further services, and findings are not used as an occasion for making them.
Scheduling
Fieldwork is planned well in advance. It is performed by named specialists rather than by interchangeable staff, and the date of attendance is therefore agreed beforehand.
The usual lead time between signature of the engagement contract and the commencement of fieldwork is four to eight weeks. During financial year-end closing and ahead of scheduled regulatory inspections the workload of the practice increases and that period may extend.
Where the engagement is tied to an external deadline — a regulatory direction, a reporting date, the date of a transaction — please indicate this at first contact. Feasibility is either confirmed or, where the deadline cannot be met to the requisite standard, discussed with the client before the contract is signed: the scope may be revised, the work phased, or an alternative timetable agreed.
What determines the extent of the work
The extent of an engagement is determined individually and expressed in person-days, with fees following from it. No single price is set for a service of this kind, since two outwardly similar requests may differ severalfold in effort depending on the scope and the degree of assurance required.
The following factors are taken into account in determining effort:
- the subject matter and purpose of the engagement, and the degree of assurance required: a review engagement or an engagement expressing an independent conclusion
- the criteria agreed for the engagement and the controls that follow from them
- the number of information systems within scope, their interdependencies and the extent of customisation
- the number of legal entities, separate divisions and sites
- the number of staff involved in the processes under examination and the number of roles to be interviewed
- sector characteristics and the presence of external requirements against which the examination is performed
- the length of the period over which the operating effectiveness of controls is tested
- the need for site attendance, its duration and the number of locations visited
- the language of the report and any requirement to translate working materials
The final extent is determined following the preliminary survey and recorded in the engagement contract before work begins. Any change of scope during performance is documented by an addendum.
Scope of the practice
Conclusions as to the culpability of individuals are not expressed: circumstances are established and documented, while their legal characterisation is a matter for the competent authorities. The function of a certified valuer is not assumed in cases where legislation requires a valuation report; where necessary, such a document is prepared jointly with the valuation practice.
The boundary of the practice runs along the layer rather than the sector. Application systems and management processes are within scope: recording, registration, movement, access, reporting and decision-making. Industrial automation and equipment firmware are not: such matters are resolved by calibration, manufacturer certification, metrological control and specialist examination.
| ✓ | A healthcare information system in respect of patient records, prescriptions and pharmaceutical stock |
| ✕ | Diagnostic equipment and its embedded software |
| ✓ | The warehouse system of a manufacturing enterprise |
| ✕ | The production line and industrial control systems |
| ✓ | An access control system in respect of rights, logs and the issue procedure |
| ✕ | The actuating mechanisms of an access control system |
Qualifications
The specialists of the practice hold degrees in information technology from leading universities of the Kyrgyz Republic, the Russian Federation and other countries of the Commonwealth, and undertake regular professional training and continuing education, including specialist courses in information systems auditing, information risk management and information protection.
|
Professional training
|
Professional bodies
|
|
The University of Texas (USA). The Federal Emergency Management and Critical Infrastructure Protection Institute of the United States Department of Homeland Security. The Academy of Ethical Hacking (USA). |
The Institute of Internal Auditors. The Chamber of Forensic Experts, in the field of computer forensic examination. |
The practice includes specialists qualified as ISO/IEC 27001 Lead Auditor for information security management systems, Certified Information Systems Auditor (CISA), non-state forensic expert in the examination of computer media and equipment, and specialist in information security risk management and the protection of critical information infrastructure.
Frequently asked questions
How are fees determined
Fees follow from the extent of the engagement, which is expressed in person-days and determined following the preliminary survey. An estimate is provided within several business days of receipt of the completed questionnaire and covers scope, timetable and fees.
How long does an engagement take
This follows from the extent of the work. The examination of a single information system ordinarily takes two to four weeks; a comprehensive audit of an organisation, six to twelve weeks. The scheduling lead time is additional to these periods.
What is required of the organisation
The appointment of a coordinator, provision of the requested documents and extracts, access to premises and systems within the agreed scope, and the release of staff for interviews and demonstrations. The total time required of an individual member of staff is ordinarily between a few hours and two days.
Do systems need to be taken out of service
No. Any action capable of affecting availability is agreed separately and performed at an agreed time.
What if the documentation of the organisation is incomplete
The state of documentation is one of the matters examined rather than a precondition of the engagement. Missing or outdated documents are recorded as findings and addressed by recommendations; this does not affect the feasibility of the work.
When can work commence
The usual lead time for fieldwork is four to eight weeks following signature of the engagement contract. Where the work is tied to an external deadline, please indicate this at first contact.
Will the outcome be accepted by the regulator
The report is prepared in a form answering the requirements against which the examination was performed. Those requirements are agreed before work begins and recorded in the engagement contract.
Does the report include recommendations
Recommendations, with an indication of priority, are provided for each finding. They are expressed in terms of requirements and controls rather than of particular products or vendors.
Who has access to the results
The report is delivered to the client. Confidentiality and the terms on which it may be disclosed to third parties are governed by the engagement contract.