10.07.2015 Views

Appendices - Department of Business - Northern Territory Government

Appendices - Department of Business - Northern Territory Government

Appendices - Department of Business - Northern Territory Government

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

appendicesAPPENDIX IIAudit Audit Outcome or Recommendation Summary ActionIT Controls Audit Year ending 30 June 2010Salary Processing Services (PIPS)Compliance 2010The reviewing and interpreting <strong>of</strong> security logsand events is not formalised and depends onindividual judgment.Security policies were not closely aligned withrecognised standards, policies do not appear to beconsistently reviewed or published on the intranetand compliance management plans do not measurecompliance with security policies and procedures.There is no centralised security managementframework or role within Data Centre Services.Controls over the review and follow up <strong>of</strong> PIPSexception reports are not always followed up.Controls over the commencement <strong>of</strong> new employeesand termination <strong>of</strong> employees could be enhanced.The implementation <strong>of</strong> a security event managementsystem and the most appropriate means to enhancenetwork security management will be investigated.ICT Security Policies and Standards were reviewedand a rolling upgrade and maintenance programwill commence. Security policies and standards willcontinue to be communicated to service providersand agencies and published on the intranet.A central security manager will be established t<strong>of</strong>ocus on security management activities.The control guide will be reviewed and amendedto manage the exception report process better,especially for nil reports.Compliance with procedures will be reiteratedto staff and a protocol to access records notheld by DBE will be developed in conjunctionwith the Auditor-General’s Office.<strong>Department</strong> <strong>of</strong> <strong>Business</strong> and Employment Annual Report 2009–10187

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!