ISO27001 Segregation of Duties Audit Procedures

ISO27001 Segregation of Duties Audit Procedures Free Download
Objectives
- The organization establishes appropriate divisions of responsibility and separates duties as needed to eliminate conflicts of interest in the responsibilities and duties of individuals; and

- The information system enforces separation of duties through assigned access authorizations

Procedures
- Examine list of divisions of responsibility and separation of duties, or other relevant documents; reviewing for the intended divisions of responsibility and separation of duties determined by the organization as being needed to eliminate conflicts of interest in the responsibilities and duties of individuals.

- Examine an agreed-upon representative sample of relevant job descriptions; studying for evidence that documented job descriptions accurately reflect the intended separation of duties and responsibilities

- Interview an agreed-upon specific sample of organization personnel responsible for defining appropriate divisions of responsibility and separation of duties; conducting focused discussions for evidence that the divisions of responsibility and separation of duties

- Examine the security plan, information system design documentation, or other relevant documents; reviewing for the automated mechanisms and their configuration settings to be employed by the information system to enforce separation of duties through assigned access authorizations.

AttachmentSize
iso27001-segregation-of-duties-audit-procedures.jpg27.67 KB
iso27001-segregation-of-duties-audit-procedures.xls14 KB
iso27001-segregation-of-duties-audit-procedures.pdf10.69 KB

Trackback URL for this post:

http://www.securitycompliances.com/trackback/26

User login

Who's online

There are currently 0 users and 1 guest online.

Who's new

  • arrercuby
  • brijtiwari28
  • Fantasko
  • pyosaterryysx
  • ugg54685