SOX.2.3.4:: Difference between revisions

From HORSE - Holistic Operational Readiness Security Evaluation.
Jump to navigation Jump to search
No edit summary
No edit summary
Line 1: Line 1:
The BackupSystemAudit utility discovers and records system configuration information such as: 
* Disk partitioning information.
* Volume manager configuration.
* Filesystem configuration.
It records this information in a file that can later be cross-checked against the current configuration.  If BackupSystemAudit detects a change in the configuration, it can notify you. 
[[Media:BackupSystemAudit.txt]]
<blockquote style="background: #C8CDC7; padding: 1em; margin-left: 0.5em;">
<blockquote style="background: #C8CDC7; padding: 1em; margin-left: 0.5em;">
::'''1. Risk: Third party service providers may not meet business, compliance and regulatory needs of the business inducing risk.'''<br>
::'''1. Risk: Up-to-date backups of programs and data may not be available when needed.'''<br>
:::a. [[SOX.1.5:|'''SOX.1.5''']] A designated individual is responsible for regular monitoring and reporting on the achievement of the third-party service-level performance criteria.<br>
:::a. [[SOX.2.3.4:|'''SOX.2.3.4''']] Procedures exist and are followed to periodically test the effectiveness of the restoration process and the quality of media backup.<br>
</blockquote>
</blockquote>


Line 34: Line 24:
'''Control Stewards Process Narrative'''
'''Control Stewards Process Narrative'''
<blockquote style="background: white; border: 1px solid black; padding: 1em;">
<blockquote style="background: white; border: 1px solid black; padding: 1em;">
<p><font color=#008000>Provide control steward commentary indicating the formal methodology in place.</font></p>
<p><font color=#008000>The BackupSystemAudit utility discovers and records system configuration information such as: 
 
* Disk partitioning information.
* Volume manager configuration.
* Filesystem configuration.
 
It records this information in a file that can later be cross-checked against the current configuration.  If BackupSystemAudit detects a change in the configuration, it can notify you. 
 
[[Media:BackupSystemAudit.txt]]
 
</font></p>


<br>
<br>

Revision as of 14:01, 26 February 2007

1. Risk: Up-to-date backups of programs and data may not be available when needed.
a. SOX.2.3.4 Procedures exist and are followed to periodically test the effectiveness of the restoration process and the quality of media backup.

Testing Procedures

Determine if the management of third-party services has been assigned to appropriate individuals.

Testing Frequency

This should be an integral part of development in house. During the planning stages of development security, availability, and processing integrity must be considered.

Evidence Archive Location

Insert hyperlink or location of evidence archive.

Control Stewards Process Narrative

The BackupSystemAudit utility discovers and records system configuration information such as:

  • Disk partitioning information.
  • Volume manager configuration.
  • Filesystem configuration.

It records this information in a file that can later be cross-checked against the current configuration. If BackupSystemAudit detects a change in the configuration, it can notify you. Media:BackupSystemAudit.txt


Control Steward – Jane Manager

Process Illustration

Replace this test by inserting a process diagram, flowchart or other visual representation to illustrate the process narrative as necessary. Include a brief description of the process illustration.

Control Status and Auditors Commentary

The control is effective.


File:Greenlock.jpg

Status is acceptable.

Control Exception Commentary

Status is acceptable.

Remediation Plan

Remediation is not required at this time.