ADVANCED ICT Consultants & Auditors LLP provide a variety of advisory services to assist internal audit departments with their policy and procedure review needs.
A policy that governs information technology systems is necessary to minimize risks and maintain organizational control of information.
Regulatory agencies require incident response protocols that are actionable.
In many cases, these agencies hold organizations accountable for data breaches, often requiring detailed information on remediation steps and preventative measures.
Therefore, it is crucial to create a framework that will ensure an organization can withstand the complexity and sophistication of repeat attacks and the regulatory requirements associated with a cyberattack.
Ultimately a review of policies and procedures is to: Ensure that they are implemented as they were intended. Assess how often they are used and to gather responses on how accessible/practical they are. To determine if changed circumstances render them less relevant.
IT Risk Assessments
Our team of professional consults often engage in such assessment with the assumption that; The purpose of a comprehensive review is to take an in depth look at existing administrative policies to:
- Determine if a policy is still needed or if it should be combined with another administrative policy.
- Determine whether the purpose and goal of the policy is still being met
- Determine if changes are required to improve the effectiveness or clarity of the policy and procedures, and
- To ensure that appropriate education, monitoring and ongoing review of the policy is occurring.
Depending on the nature and scope of the IT Consulting Engagement, services may include the following:
- IT Policy and Procedure Review
This analysis will review policies and procedures relating to incident detection and response, incident investigation and forensics, mobile devices, device commissioning and decommissioning, data classification, vendor contracting, vulnerability identification and mitigation, help desk ticketing and patching.
- IT Policy Drafting
Our team of experienced consultants can help create IT policies to ensure they comply with the governing authorities and adhere to industry best practices.
- IT General Controls Review
IT general control reviews are designed to assess an organization’s policies, processes, procedures, structure, software and hardware in order to identify risk and potential areas of exposure.
Our team of professionals will interview with key staff, review the existing organizational documentation and perform a technical review of the existing organizational software and hardware.