ISACA® Western New York Chapter - July 2009 Newsletter



Monthly Newsletter

July 2009 

Vol.1 Issue 4

CHAPTER NEWS

ISACA-WNY Goes Out to the Ball Game

Tim Meyers Recieves Web Site 2.0:Reboot Award at June's Rochester Red Wings Game

From Left to Right: Peter Spier (Chapter President), Tim Meyers, and Evan Routenberg (Chapter Vice President)

ISACA Western New York Chapter members enjoyed a 6-1 win by the home team over the Columbus Clippers this past June 26th.  Rochester Red Wings starter, Brian Duensing gave up six hits over eight innings before being called up to serve out of the bullpen for the Minnesota Twins.  Members additionally enjoyed both a performance by the Rochester Philharmonic Orchestra and stadium fireworks.

 

In This Issue:

Chapter News
Member Spotlight
President's Message
Upcoming Events
Journal Guest Editorial
Technology News
Featured Download
Trivia

MEMBER SPOTLIGHT

Dominick Desiderio, Jr.

Dominick Desiderio, Jr., is a Senior ITAuditor for Erie Insurance. Desiderio has over 28 years of EDP, IT Audit, and Information Security industry experience and holds his CISA certification. A long time member, he served as chapter President in 1988 and provided CISA Coordinator and Board of Directors leadership for several years after that.

He most identifies ISACA with quality training opportunities, program offerings, and strong leadership.  "The website and newsletters are top notch," says Desiderio.

PRESIDENT'S MESSAGE

I would like to thank you for being a member of our chapter. I am looking forward to attending the Canaudit Seminaro this coming Thursday, July 16th and am proud that our chapter is able to offer this event. 

I also hope that you and yours are enjoying a safe and fun summer.


Peter Spier

Chapter President

UPCOMING EVENTS

Seminar: Auditing IT - Identifying Exposures in Your Environment
We are accepting registrations for this coming July 16th 8-CPE Seminar as provided by Canaudit.  Don't miss this excellent training opportunity. Register Now!

IT GRC Framework with Bruce Jones
IT GRC has emerged as a unifying theme aligning IT governance, risk and compliance with the priorities of the business.   GRC is about collaboration and communication - it is getting many silos of risk, compliance, and governance to work together and share information and processes.  Join us at Mario's Italian Steakhouse for this breakfast presentation on August 20th from 7:30-10:00am Register Now!  

JOURNAL GUEST EDITORIAL

Managing IT Governance Through Market Turbulence

By Edge Zarrella, CISA, CA
Volume 4, 2009
 

We are well aware of the global financial crisis at present—given the exhaustive media coverage, it has been pretty hard to miss. It is interesting to note the impacts of this on the IT governance industry, as over the years technology has been an increasingly important business enabler. Therefore, the effects of this global financial crisis on business have also significantly impacted the IT stakeholders involved with the business.

As businesses prepare for the impact of the global credit market meltdown, IT professionals anticipate:
  • Intense pressure to cut technology costs
  • Mandates to improve operational performance
  • A need for technology to realign to meet new business needs
  • A focus on cash management and a priority around liquidity

A rapid, decisive response is the key to success here. Proactive business leaders will use a variety of tools to turn this market turbulence to their organisation’s advantage, creating a sustainable platform to emerge from this financial crisis as marketplace winners for the next growth cycle.

Pressure to Cut Technology Costs

In my travels, I am seeing many businesses cutting costs aggressively. These cuts are across the board in all areas of the businesses, as the businesses are hurting and are finding any way they can to focus on core activities.

Immediate activities encompass reducing power costs, rationalising unnecessary technology, right-sizing software licence fees and terminating non-essential projects.

It is interesting to note that even at a time when there is significant pressure to ‘cut technology costs’, some organisations are initiating major projects with significant budgets around consolidation activities and compliance projects.The purpose of these projects is to spend short term, in order to produce long-term savings.

Businesses are considering the cost of maintenance around having multiple unique software instances installed across a variety of different hardware platforms, as well as the cost of accounting consolidation and maintenance when running multiple general ledgers. Consolidation projects around multiple software instances and different hardware platforms can produce significant savings from an operational and maintenance perspective, both from a pure technology perspective as well as from a business process and activity perspective.

The cost of compliance is ever increasing, and organisations are looking to address this by implementing automated controls. As a result, I have seen many businesses reducing their compliance costs through implementing governance, risk and compliance tools. Again, these are projects that require significant upfront investment to ensure that they are implemented properly from a business process and controls perspective. However, the long-term savings can often justify the significant project costs.

Mandate to Improve Operational Performance

It is critical to note that while businesses focus on cutting technology costs, they will not tolerate a resultant drop in operational performance. In fact, they expect operational performance to improve, applying the ‘do more, with less’ approach.

This translates to a ‘business as usual’ expectation on the operational performance of technology to support the business. Key in this space, from a technology perspective, will be protection of information assets.

At this time of market turbulence, it is important to protect corporate information and knowledge assets. The speed and dramatic impact of the current crisis suggests that rapid technology action in key areas may help to reduce the impact of the crisis on information security, integrity and consistency. Key threats include internal security and data protection, loss of know-how, increased errors, and external security threats.

Realignment of Technology

In this time, it is important for technology to keep an open dialogue with the business leaders. As the business is adapting to changes required as a result of the financial crisis, the technology group needs to be an active voice in supporting the change required as well as facilitating the required change from a technology perspective.

Active participation in this process can demonstrate proactive leadership with positive results for morale, productivity and employee retention. Key steps that can be taken include having a plan ready in advance, building agreement with the business and communicating proactively.

Focus on Cash Management and Liquidity

A key issue resulting from the current global financial crisis is the significant lack of available credit. As a result, it is important for businesses to be able to free up available cash and manage their liquidity to ensure the viability of their business.

IT can play a significant part in this process by looking at key costs that can be cut as well as reviewing the project portfolio for non-core projects that can either be deferred or terminated. Technology’s support for the process of optimising accounts receivable, accounts payable and inventory levels will also support this process. A careful examination of the timing of cash payments for vendor services is a key source of liquidity for organisations that are cash-strapped.

What Does This Mean for IT Governance Professionals?

At times of significant business change, it is important for IT governance professionals and IT auditors to be aware of how business is changing as a result of all this activity around the financial crisis, how these changes affect the risks in a business and where new controls are required. Accordingly, IT governance professionals and IT auditors must be flexible in how they assess risks and ensure that they are appropriately covered by the necessary controls.

Information, People and Change

At this time of market turbulence, the most sought-after asset by business leaders is timely, effective information that can help them with the decision-making process. Technology plays a key role in the process of producing this information.

There has been a lot of press around the ‘war for talent’. At this time of significant change, the market for technology talent is likely to be fluid. By paying close attention to the cost and value of key skills, a proactive IT organization can reposition itself to cherry-pick top talent, renegotiating vendor contracts based on reduced cost assumptions and maintaining internal IT productivity, focus and morale.

There is also the opportunity for new technology to mitigate risk and/or create value, which is a powerful tool to help unleash new strategies or uses for information that were not possible in the past.

Conclusion

I am a strong believer that now is a time for focus on key priorities. Having recently moved to Asia, it is interesting to note that the Chinese characters used to describe ‘crisis’ are comprised of two other characters ‘risk’ and ‘opportunity’. Proactive business leaders will take the opportunities during this time of crisis to position themselves to be marketplace winners in the next growth cycle.

Edge Zarrella, CISA , CA
is the global partner in charge of IT advisory at KPMG. Zarrella has spent his 20-year career in business and IT advisory. His specialisations include IT strategy and governance, sourcing and projects. Zarrella has been an advisor in numerous areas including due diligence in corporate acquisitions, offshoring and outsourcing, and IT strategy.

 

 

 

TRIVIA

More Than a Few

Given a choice of attribute, variable, stratified mean per unit, or difference estimation sampling methods; which would be most useful when testing for compliance?


Submit your response through our Contact form. The first received, correct answer wins a $5 Amazon Gift Certificate and special mention in our next issue!

 

TECHNOLOGY NEWS

 

New 'cyber attacks' hit S Korea

By John Sudworth

South Korea is experiencing a third wave of suspected cyber-attacks - co-ordinated attempts to paralyse a number of major websites.
Source:BBC NEWS


 

One of the country's biggest banks, a leading national newspaper and the South Korean spy agency appear to have been targeted.

Some reports suggest the attacks might be the work of North Korea.

South Korea and the US reported similar attacks earlier in the week, with the White House and the Pentagon targeted.

The South Korean government, and the country's internet service providers, are still trying to fight off what appears to be a deliberate attempt to shut down major websites that began earlier this week.

In what is known as a "denial of service" attack, thousands of virus-infected computers are hijacked and simultaneously directed to a particular site, overwhelming it with the sheer volume of traffic.

Cyber defence

A third wave of attacks is now reported to be underway, slowing down or paralysing the internet operations of large organisations including a bank, a national newspaper and the South Korean spy agency.

The agency is reportedly the source of the speculation that the operation may have been instigated by North Korea or its sympathisers.

The United States is the only other country to have been affected by the cyber attacks, where the White House, the Pentagon and the State Department are all said to have been targeted.

While undoubtedly causing inconvenience for the organisations, and their customers, the attacks affect only their public websites, and present no other security threat.

Despite the speculation, no evidence has been produced to prove a link with North Korea.

But some reports suggest it has a long-established military unit, employing up to 1,000 skilled computer hackers.

In response to the ongoing disruption, South Korea has announced that it will speed up plans for a cyber warfare unit to counter such threats.

FEATURED DOWNLOAD

CobiT and Application Controls: A Manager's Guide


The dependence of enterprises on automated processing of information is indisputable. Virtually every aspect of day-today business activity is dependent on timely, accurate and reliable information—information that is generated, processed, accumulated, stored and reported by automated information systems. Customers, suppliers, employees, line management,
middle management, the C-suite, board of directors, shareholders and all other stakeholders make decisions based on the information they receive—information whose integrity and reliability depend almost exclusively on the application systems and
surrounding control processes that are used to process the information. These decisions can be only as good as the quality of the information upon which they are based. Bad information will almost invariably result in bad decisions—garbage in, garbage
out. The examples of bad information leading to fateful decisions are numerous and no enterprise is immune. There are many examples within anyone’s personal experiences.

Copyright © 2009 ISACA® Western New York Chapter. All rights reserved.
If you wish to cancel your subscription to this newsletter click here