13.07.2015 Views

the Connector - The Institute of Internal Auditors

the Connector - The Institute of Internal Auditors

the Connector - The Institute of Internal Auditors

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>the</strong> <strong>Connector</strong>Vancouver Island Chapter Newsletter“Your Space” Corner (cont’d)Application <strong>of</strong> <strong>the</strong> RM Policy to <strong>the</strong> Third Party ServiceOrganization: This area may be ano<strong>the</strong>r area to include inyour engagement.Individual Staff’s Understanding <strong>of</strong> RM: <strong>The</strong> collectiveeffectiveness <strong>of</strong> a RM program begins with that <strong>of</strong>individual staff and follows with refreshing/ updatingtraining. <strong>The</strong> training can be programmed at <strong>the</strong> corporateand department levels or both.Scope <strong>of</strong> Electronic Records: What we included were <strong>the</strong>email system, network drives, SharePoint, portablecommunication devices, and portable electronic storagemedia.Location <strong>of</strong> records: A record can be stored in multiplelocations and multiple forms. An <strong>of</strong>ficial record’s locationand form can be a point for <strong>the</strong> review.Information Security Classification: This area could be part<strong>of</strong> <strong>the</strong> project or it can be a separate project itself.Better Practices VS Best Practices: Depending on yourorganizational priority, recommendations may aim toachieve better practices as opposed to best practices dueto business needs and resource requirements.Useful Document References‣ National Standard <strong>of</strong> Canada: Electronic Records AsDocumentary Evidence (CAN/CGSB‐72.34‐2005)‣National Standard <strong>of</strong> Canada: Micr<strong>of</strong>ilm and ElectronicImages as Documentary Evidence (CAN/CGSB‐72.11‐93)‣International Standard: Information andDocumentation – Records Management (ISO15489)Securing Personal Information: A Self‐Assessment Toolfor Organizationshttp://www.priv.gc.ca/resource/tool‐outil/securitysecurite/english/AssessRisks.asp?x=1Note: <strong>The</strong>re are overlapping contents between <strong>the</strong> ISOdocument and <strong>the</strong> Canadian Standard documents as <strong>the</strong>latter ones specially address electronic recordsmanagement. <strong>The</strong> ISO document provides <strong>the</strong> principles<strong>of</strong> RM regardless <strong>of</strong> <strong>the</strong> form <strong>of</strong> records.I hope you find <strong>the</strong> points noted useful. If you have a RMreview on <strong>the</strong> radar and would like discuss about it inmore details, feel free to contact me. You can alsocomment this article through this email:teeravit.ch@gmail.comcom►Attention all members ◄Doyouhaveanythingyouwouldliketoshare with your local IIA members? Hereis your space!To contribute to our chapter’s newsletter(plus you also earn CPE hours), pleasecontact me here. You will also receive afree lunch training event.4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!