Acronym Glossary and Definitions

Acronyms

Definition

Approver

An individual who reviews the change to ensure the integrity and reliability of the document and grants approval for the document to be posted.

Document Owner

Manager designated as having ownership of all documents associated with the production system and, thereby, having the authority to change it.

Dual control

Two people are required for an important activity to be accomplished.

Employee

Person, including contractors and temporary staff, who have been granted access to ARL resources.

Owner

Manager of a department or business unit responsible for production processes, systems, applications, platforms or users. In accordance with Information Security policies, and standards, owners determine the level of sensitivity and confidentiality of their information. As such, they determine changes, access, and dissemination of their information.

Activity

An element of work performed during the course of a project. An activity normally has an expected duration

CISA

Certified Information Systems Auditor

CobiT

The COBIT (Control Objectives for Information and Related Technology) framework was released in 1996 and updated in 1998 and 2000 by the Information Systems Audit and Control Foundation (ISACF) in response to the need for a reference framework for security and control in information technology. In 2000, the IT Governance Institute and ISACA developed the Management Guidelines for COBIT. These guidelines respond to a need by Management for control and measurability of IT, for the purpose of ensuring that IT activities achieve business objectives.

Control

The policies, procedures, practices and organizational structures designed to provide reasonable assurance that business objectives will be achieved and that undesired events will be prevented or detected and corrected

Document or Source Document

A sample document that adheres to the criteria necessary for completion of a process and includes the essential contents defined in the template.

Function

A group of related actions contributing to a larger action. Security Policy, Access Control, and Perimeter Security represent security functions.

IT Control Objective

A statement of the desired result or purpose to be achieved by implementing control procedures in a particular IT activity

ITIL

Information Technology Infrastructure Library

Process

A series of tasks that transform inputs into desired outputs. The term procedure is sometimes used interchangeably with the process in this methodology. Administer Accounts, Perform Risk Assessment, Audit Perimeter Security, Install Hardware are example

Process Management Architecture

A high-level description of the system that provides a fully integrated Knowledge Base [of process information]. The Knowledge Base, in turn, provides control of process change and access to all processes and procedures.

Task

A task is a specific action performed as part of a process. Disable accounts, Interview Network Manager, and run Crack on the Unix machine are examples of security tasks.

Template

A skeleton document, spreadsheet, or graphic presentation that represents the essential requirements for deliverable content.

default/img/items.gif); background-position: 0% 100%;">Comprehensive Glossary of all Corporate Terms

glossaries

EnterpriseGRC Solutions, Inc., Inc. FCM™ Actual Glossary has over 5000 terms.

Related Documents

The COBIT (Control Objectives for Information and Related Technology) framework was released in 1996 and updated in 1998 and 2000 by the Information Systems Audit and Control Foundation (ISACF) in response to the need for a reference framework for security and control in information technology. In 2000, the IT Governance Institute and ISACF developed the Management Guidelines for COBIT. These guidelines respond to a need by Management for control and measurability of IT, for ensuring that IT activities achieve business objectives. http://www.isaca.org/cobithorizon.htm

The IT Infrastructure Library, ITIL (®), is a series of documents that are used to aid the implementation of a framework for IT Service Management (ITSM). This framework defines how Service Management is applied within specific organizations. Being a framework, it is completely customizable for application within any type of business or organization that has a reliance on IT infrastructure.
http://www.itil-itsm-world.com/

Project Management Skill and Knowledge Requirements in an Information Technology Environment (ISACA)

A Guide to the Project Management Body of Knowledge (PMBOK® Guide)-2000 Edition, Project Management Institute, Project Management Institute, Inc., Newtown Square, PA, USA, 2000

Six Sigma Project Management: A Pocket Guide, by Jeffrey N., Ph.D. Lowenthal, (American Society for Quality; Spiral edition, August 1, 2001)

Risks and Associated Controls (SAMPLE)

Significance

Likelihood * Impact

Risk Items

Control

How implemented and actual review schedule

2 * 5

[RiskWatch id here]

Authorization:
In addition to the limit access to documentation from within the corporate network, persons are further restricted from reading and modifying documents through the use of security properties on process asset folders. Approval to post or modify a process is in accordance with management's general policies and procedures. Access to assets is further restricted through the use of hyperlinks in place of attachments, enforcing limits for viewing documents based on the person's profile within the organization.

PAL infrastructure is carefully managed by process engineering, with administrative controls as provided within Windows 2000 server and as enforced by the data owners.

1 * 5

[RiskWatch id here]

Configuration/Account Mapping Controls: System configuration controls restrict non-authorized users from deleting and modifying files. Process approval is required in order to post new or modified process.

Security is managed by Network or Data Center Operations and is enforced by Process Engineering and the Data Owner.

2 * 5

[RiskWatch id here]

Interface/Conversion Controls: Data Integrity - (data is not changed or manipulated) and security (no one can access it). Interfaces/conversion includes controls in these areas. Data management (date/time stamps, file names) Processing (no missing, duplicate, or redundant data and to ensure completeness and accuracy.) Validation/reconciliation (on-line edits, batch totals) Over the detection and correction of exceptions and errors.

When data cannot be altered without explicit audit trail and approval, it is managed in VSS. When code or documentation appears changed, VSS allows for review of edits and roll back. Data integrity in code is assured via promotion to the production process, where the code is tested in the Quality environment and then approved for movement.
The PAL is backed up nightly and content change is evident via time stamp.

3 * 5

[RiskWatch id here]

Key Performance Indicators KPI's: Periodic review by Process Engineering enforces the goal of having processes documented for all management functional areas. Where information indicates a need for process optimization, process engineering notes this requirement and reviews the timely completion of required process change. Process engineering also catalogs reviews and guides process development and collection.

There is Risk that Management may fail to assure that procedures are finished in a timely manner or that existing processes are not routinely reviewed to insure their validity or usability.

The PAL XLS and inventories within Facilitated Compliance Management database allow the Process Engineering team visibility on the key performance of process items as required for SAS 70 audit and as agreed upon by department owners.

1 * 1

[RiskWatch id here]

Segregation of Duties (SOD):
The separation of duties and responsibilities of a business process to prevent individuals from being in a position to both perpetrate and conceal an error or irregularity.

Reconciliation of existing rights within the PAL to rights as designed and approved by department owners demonstrates that persons who should not have access to documentation types are segregated. Roles in the approval process deny persons authority to review and approve their own work.

2 * 5

[RiskWatch id here]

Risk of accidental or intentional distribution of classified private and or sensitive information: 

Documentation practice

  • Hyperlink vs. Attachment
  • manager enforcement of storing
  • data in proper file location
  • department role-based limit to user access
  • enforcing control-related Data Owners
  • document property capture of key control data
  • document classification,

-are all control activities that make the likelihood of this risk negligible. Each business or management functional owner has access to modify contents inside their own area but cannot modify files outside their Process domain. The remaining risk is file shares that still require review for misplaced content.

Process "Piece of Cake!"

howdoIdocument

Now can you ask and answer the question: "What Type of Document Should I Write?"

IT Process Asset Library - Recommendations for information organization and visibility over document assets

Main Menu