SlideShare a Scribd company logo
1 of 12
Download to read offline
1
TODAY’S OBJECTIVES
• Review risks related to information technology
facilities, system access, data integrity, and system
maintenance.
• Describe techniques for the non-technical
professional to evaluate controls of information
technology and systems.
2
ABOUT VANDERBILT UNIVERSITY
MEDICAL CENTER
• $2.3 Billion Annual
Healthcare Operating
Expenses (excludes
academics and research)
• $471.6 Million Annual
Sponsored Research
Budget
• $843.6 Million Annual
Charity Care,
Community Benefits,
and other Unrecovered
Costs
3
4
INTEGRATED IT AUDITING
FOCUSED IT AUDITS
5
IT AUDIT PLANNING - REQUESTS
• HIPAA Security Risk
Assessment
• External auditor’s report
and management letter
• Consulting reports
• IT policies and
procedures
6
SYSTEM/APPLICATION LIST
• System or application name
• Vendor
• System purpose
• The business and IT owners
• Location(s) where the
system is physically housed
• Service Criticality (they
can’t all be Mission Critical)
C S M K T Z A L S M
I T E R F M V L N B
P P D O O E A E E I
E I I N S D I C M C
E R T O O A L I E E
L C E S R S I N I R
C S C L C S T M S N
A L H O I E Y O S E
R L T R M T S A P R
O A H O C S I C M E
ALLSCRIPTS
AVAILITY
CERNER
CISCO
EMC
EPIC
IBM
ITIL
KRONOS
MEDASSETS
MEDITECH
MICROSOFT
OMNICELL
ORACLE
SAP
SIEMENS
7
THE CLAW HAS SPOKEN
8
USER SECURITY & ADMINISTRATION
• Account administration
• User authentication and
passwords
• Session controls
Audit Objectives
9
ACCOUNT ADMINISTRATION
• Process to request and approve accounts
• How are accounts inactivated or deleted
• Documentation of requests
• Monitoring for non-use, change in employment
status, etc.
10
USER AUTHENTICATION & PASSWORDS
• Minimum password
length and
composition
• Periodic password
changes
• Multi-factor
authentication
• Lockouts and resets KillerInfographics.com
11
SESSION CONTROLS
• Session length
• Maximum inactivity
• Concurrent logins
12
CHANGE MANAGEMENT
• Documented processes
and policies (including
emergency changes)
• Segregated environment
and testing
• Production access
Audit Objectives
www.ibiblio.org/Dave/drfun.html
13
AN ICQ FOR EACH APPLICATION
• Are change requests
logged?
• Is version control
software used?
• What logical
environments exist?
• Are all changes required
to be tested?
• Who is responsible for
migrating changes?
• Are back-out procedures
required prior to
implementation?
• How are emergency
changes communicated
to business owners?
14
TESTING CHANGE
• Emergency Change
• Tech Approval
• Business Approval
• CAB Approval
• Programmed in Dev
• Tested Outside
Production
• Testing Completed
• User Testing Complete
• Programmer Deployed
Change
• Back-out Procedures
• Documentation Updated
• # of Resulting Issues
15
DATA CENTER PHYSICAL SECURITY
• Physical access for both
individuals and
equipment
• Power configurations
• Environmental controls
and monitoring
Audit Objectives
16
ACCESS CONTROLS
• Access logs - who,
when, and why
• Approvals and pre-
approvals
• Monitoring and
oversight
17
POWER
• Sources and
configurations
• Redundancy and
back-up
• Capacity Planning
• Joint Commission
18
ENVIRONMENT
• Cooling
• Humidity
• Fire suppression
• Water (and other wet
stuff)
• Raised floors
19
INTEGRATING IT INTO FINANCIAL
AND OPERATIONAL AUDITS
20
COMMON ISSUES: IT
• Storage of PHI on
unsecured media
• CD/DVD with Medical
Images
• Department File Servers,
Local PCs, Laptops, etc.
• Inadequate Password
Policy/Enforcement
• Unsecured/Sharing of
Clinic Workstations
• Disaster Recovery
• Documented Downtime
Procedures
• Oversight/Security of
Portable Devices (e.g.,
iPads)
21
ADDITIONAL READING
512 pages
1.8 pounds 696 pages
3.0 pounds
2,000 pages
7.6 pounds
22
QUESTIONS
Brad Adams, CPA
(615) 875-9554
brad.adams@vanderbilt.edu
23

More Related Content

What's hot

CIE AS Level Applied ICT Unit 4 - Systems Life Cycle
CIE AS Level Applied ICT Unit 4 - Systems Life CycleCIE AS Level Applied ICT Unit 4 - Systems Life Cycle
CIE AS Level Applied ICT Unit 4 - Systems Life CycleMr G
 
Electronic Document System for Pathology Laboratories
Electronic Document System for Pathology LaboratoriesElectronic Document System for Pathology Laboratories
Electronic Document System for Pathology LaboratoriesMahmood Aijazi, MD
 
Working with Argus Safety in a Global Community
Working with Argus Safety in a Global CommunityWorking with Argus Safety in a Global Community
Working with Argus Safety in a Global CommunityPerficient
 
Fundamental Aspects of Security Testing
Fundamental Aspects of Security TestingFundamental Aspects of Security Testing
Fundamental Aspects of Security Testingbquriousindia
 
General and Application Control - Security and Control Issues in Informatio...
General and Application Control - Security  and Control Issues in  Informatio...General and Application Control - Security  and Control Issues in  Informatio...
General and Application Control - Security and Control Issues in Informatio...Dr. Rosemarie Sibbaluca-Guirre
 
Emergency Access Management
Emergency Access ManagementEmergency Access Management
Emergency Access ManagementXpandion
 
Safety and Pharmacovigilance System: Oracle Argus Safety Suite
Safety and Pharmacovigilance System: Oracle Argus Safety SuiteSafety and Pharmacovigilance System: Oracle Argus Safety Suite
Safety and Pharmacovigilance System: Oracle Argus Safety SuitePerficient
 
Connect, Manage and Control millions of devices from the cloud with Azure IoT...
Connect, Manage and Control millions of devices from the cloud with Azure IoT...Connect, Manage and Control millions of devices from the cloud with Azure IoT...
Connect, Manage and Control millions of devices from the cloud with Azure IoT...Microsoft Tech Community
 
Elixir a5 flyermarch2011
Elixir a5 flyermarch2011Elixir a5 flyermarch2011
Elixir a5 flyermarch2011Welma Marais
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Schellman & Company
 
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...Perficient
 
SharePoint And 21 CFR Part 11 Share Fest
SharePoint And 21 CFR Part 11   Share FestSharePoint And 21 CFR Part 11   Share Fest
SharePoint And 21 CFR Part 11 Share Festpaulkfenton
 
21 cfr part 11 compliance
21 cfr part 11 compliance21 cfr part 11 compliance
21 cfr part 11 complianceKiran Kota
 
Electronic Document and Record Management (EDRMS)
Electronic Document and Record Management (EDRMS) Electronic Document and Record Management (EDRMS)
Electronic Document and Record Management (EDRMS) 6PM Solutions
 
Plant check Mobile Operator Rounds English
Plant check Mobile Operator Rounds EnglishPlant check Mobile Operator Rounds English
Plant check Mobile Operator Rounds EnglishYakup Bozkurt
 

What's hot (20)

CIE AS Level Applied ICT Unit 4 - Systems Life Cycle
CIE AS Level Applied ICT Unit 4 - Systems Life CycleCIE AS Level Applied ICT Unit 4 - Systems Life Cycle
CIE AS Level Applied ICT Unit 4 - Systems Life Cycle
 
Electronic Document System for Pathology Laboratories
Electronic Document System for Pathology LaboratoriesElectronic Document System for Pathology Laboratories
Electronic Document System for Pathology Laboratories
 
Working with Argus Safety in a Global Community
Working with Argus Safety in a Global CommunityWorking with Argus Safety in a Global Community
Working with Argus Safety in a Global Community
 
Fundamental Aspects of Security Testing
Fundamental Aspects of Security TestingFundamental Aspects of Security Testing
Fundamental Aspects of Security Testing
 
Introduction to Computer Programming
 Introduction to  Computer Programming  Introduction to  Computer Programming
Introduction to Computer Programming
 
General and Application Control - Security and Control Issues in Informatio...
General and Application Control - Security  and Control Issues in  Informatio...General and Application Control - Security  and Control Issues in  Informatio...
General and Application Control - Security and Control Issues in Informatio...
 
Emergency Access Management
Emergency Access ManagementEmergency Access Management
Emergency Access Management
 
Safety and Pharmacovigilance System: Oracle Argus Safety Suite
Safety and Pharmacovigilance System: Oracle Argus Safety SuiteSafety and Pharmacovigilance System: Oracle Argus Safety Suite
Safety and Pharmacovigilance System: Oracle Argus Safety Suite
 
Auditing information System
Auditing information SystemAuditing information System
Auditing information System
 
Procedural Controls
Procedural ControlsProcedural Controls
Procedural Controls
 
Occupational health v1.5
Occupational health v1.5Occupational health v1.5
Occupational health v1.5
 
System audit questionnaire
System audit questionnaireSystem audit questionnaire
System audit questionnaire
 
Connect, Manage and Control millions of devices from the cloud with Azure IoT...
Connect, Manage and Control millions of devices from the cloud with Azure IoT...Connect, Manage and Control millions of devices from the cloud with Azure IoT...
Connect, Manage and Control millions of devices from the cloud with Azure IoT...
 
Elixir a5 flyermarch2011
Elixir a5 flyermarch2011Elixir a5 flyermarch2011
Elixir a5 flyermarch2011
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1
 
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...
Integrating Oracle Argus Safety with other Clinical Systems Using Argus Inter...
 
SharePoint And 21 CFR Part 11 Share Fest
SharePoint And 21 CFR Part 11   Share FestSharePoint And 21 CFR Part 11   Share Fest
SharePoint And 21 CFR Part 11 Share Fest
 
21 cfr part 11 compliance
21 cfr part 11 compliance21 cfr part 11 compliance
21 cfr part 11 compliance
 
Electronic Document and Record Management (EDRMS)
Electronic Document and Record Management (EDRMS) Electronic Document and Record Management (EDRMS)
Electronic Document and Record Management (EDRMS)
 
Plant check Mobile Operator Rounds English
Plant check Mobile Operator Rounds EnglishPlant check Mobile Operator Rounds English
Plant check Mobile Operator Rounds English
 

Viewers also liked

Fundemental flaws in Waco
Fundemental flaws in WacoFundemental flaws in Waco
Fundemental flaws in WacoBenson Varghese
 
Soal dan pembahasan matematika ips un 2014
Soal dan pembahasan matematika ips un 2014Soal dan pembahasan matematika ips un 2014
Soal dan pembahasan matematika ips un 2014Muhammad Arif
 
Soal dan pembahasan mat ipa un 2014
Soal  dan pembahasan mat ipa un 2014Soal  dan pembahasan mat ipa un 2014
Soal dan pembahasan mat ipa un 2014Muhammad Arif
 
Complaint and Warrant - Waco Bikers
Complaint and Warrant - Waco BikersComplaint and Warrant - Waco Bikers
Complaint and Warrant - Waco BikersBenson Varghese
 
TNHFMA Newsletter - Successful Practices
TNHFMA Newsletter - Successful PracticesTNHFMA Newsletter - Successful Practices
TNHFMA Newsletter - Successful PracticesBrad Adams
 
The Art of Requesting Data from IT
The Art of Requesting Data from ITThe Art of Requesting Data from IT
The Art of Requesting Data from ITBrad Adams
 
Confessions of an Internal Auditor 2014 Florida HMFA Fall Institute
Confessions of an Internal Auditor 2014 Florida HMFA Fall InstituteConfessions of an Internal Auditor 2014 Florida HMFA Fall Institute
Confessions of an Internal Auditor 2014 Florida HMFA Fall InstituteBrad Adams
 
Database Essentials for Healthcare Finance Professionals
Database Essentials for Healthcare Finance ProfessionalsDatabase Essentials for Healthcare Finance Professionals
Database Essentials for Healthcare Finance ProfessionalsBrad Adams
 
Colorectal cancer
Colorectal cancerColorectal cancer
Colorectal cancerJenita John
 
Nutritional Problems in India
Nutritional Problems in IndiaNutritional Problems in India
Nutritional Problems in IndiaJenita John
 
Grand Jury Reform in Texas
Grand Jury Reform in TexasGrand Jury Reform in Texas
Grand Jury Reform in TexasBenson Varghese
 

Viewers also liked (17)

Fundemental flaws in Waco
Fundemental flaws in WacoFundemental flaws in Waco
Fundemental flaws in Waco
 
Soal dan pembahasan matematika ips un 2014
Soal dan pembahasan matematika ips un 2014Soal dan pembahasan matematika ips un 2014
Soal dan pembahasan matematika ips un 2014
 
Soal dan pembahasan mat ipa un 2014
Soal  dan pembahasan mat ipa un 2014Soal  dan pembahasan mat ipa un 2014
Soal dan pembahasan mat ipa un 2014
 
Complaint and Warrant - Waco Bikers
Complaint and Warrant - Waco BikersComplaint and Warrant - Waco Bikers
Complaint and Warrant - Waco Bikers
 
Zoos
ZoosZoos
Zoos
 
My myth
My myth My myth
My myth
 
Jeronimo
JeronimoJeronimo
Jeronimo
 
Healthy life
Healthy lifeHealthy life
Healthy life
 
TNHFMA Newsletter - Successful Practices
TNHFMA Newsletter - Successful PracticesTNHFMA Newsletter - Successful Practices
TNHFMA Newsletter - Successful Practices
 
The Art of Requesting Data from IT
The Art of Requesting Data from ITThe Art of Requesting Data from IT
The Art of Requesting Data from IT
 
Confessions of an Internal Auditor 2014 Florida HMFA Fall Institute
Confessions of an Internal Auditor 2014 Florida HMFA Fall InstituteConfessions of an Internal Auditor 2014 Florida HMFA Fall Institute
Confessions of an Internal Auditor 2014 Florida HMFA Fall Institute
 
Database Essentials for Healthcare Finance Professionals
Database Essentials for Healthcare Finance ProfessionalsDatabase Essentials for Healthcare Finance Professionals
Database Essentials for Healthcare Finance Professionals
 
Samburu tribe
Samburu tribeSamburu tribe
Samburu tribe
 
Echidna
EchidnaEchidna
Echidna
 
Colorectal cancer
Colorectal cancerColorectal cancer
Colorectal cancer
 
Nutritional Problems in India
Nutritional Problems in IndiaNutritional Problems in India
Nutritional Problems in India
 
Grand Jury Reform in Texas
Grand Jury Reform in TexasGrand Jury Reform in Texas
Grand Jury Reform in Texas
 

Similar to Confessions of an Internal Auditor: IT Edition

How important is IT auditing
How important is IT auditingHow important is IT auditing
How important is IT auditingLepide USA Inc
 
How to Restructure Active Directory with ZeroIMPACT
How to Restructure Active Directory with ZeroIMPACTHow to Restructure Active Directory with ZeroIMPACT
How to Restructure Active Directory with ZeroIMPACTQuest
 
ITIL Best Practice for Software Companies
ITIL Best Practice for Software CompaniesITIL Best Practice for Software Companies
ITIL Best Practice for Software CompaniesDaniel Brody
 
CISA_WK_4.pptx
CISA_WK_4.pptxCISA_WK_4.pptx
CISA_WK_4.pptxdotco
 
Aplication data security compliances
Aplication data security compliancesAplication data security compliances
Aplication data security compliancesAhmadi Madi
 
How to Restructure and Modernize Active Directory
How to Restructure and Modernize Active DirectoryHow to Restructure and Modernize Active Directory
How to Restructure and Modernize Active DirectoryQuest
 
Non functional requirements. do we really care…?
Non functional requirements. do we really care…?Non functional requirements. do we really care…?
Non functional requirements. do we really care…?OSSCube
 
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...HarshMangal20
 
10-3 Clinical Informatics System Selection & Implementation
10-3 Clinical Informatics System Selection & Implementation10-3 Clinical Informatics System Selection & Implementation
10-3 Clinical Informatics System Selection & ImplementationCorinn Pope
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory IntelligenceArmin Torres
 
Segregation of Duties and Sensitive Access as a Service
Segregation of Duties and Sensitive Access as a ServiceSegregation of Duties and Sensitive Access as a Service
Segregation of Duties and Sensitive Access as a ServiceSmart ERP Solutions, Inc.
 
An Introduction to Clinical Study Migrations
An Introduction to Clinical Study MigrationsAn Introduction to Clinical Study Migrations
An Introduction to Clinical Study MigrationsPerficient, Inc.
 
Structured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaStructured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaEnergySec
 
Cyber security series administrative control breaches
Cyber security series   administrative control breaches Cyber security series   administrative control breaches
Cyber security series administrative control breaches Jim Kaplan CIA CFE
 
Enterprise Risk Management Solutions
Enterprise Risk Management SolutionsEnterprise Risk Management Solutions
Enterprise Risk Management SolutionsLexComply
 

Similar to Confessions of an Internal Auditor: IT Edition (20)

How important is IT auditing
How important is IT auditingHow important is IT auditing
How important is IT auditing
 
How to Restructure Active Directory with ZeroIMPACT
How to Restructure Active Directory with ZeroIMPACTHow to Restructure Active Directory with ZeroIMPACT
How to Restructure Active Directory with ZeroIMPACT
 
audit_it_250759.pdf
audit_it_250759.pdfaudit_it_250759.pdf
audit_it_250759.pdf
 
ITIL Best Practice for Software Companies
ITIL Best Practice for Software CompaniesITIL Best Practice for Software Companies
ITIL Best Practice for Software Companies
 
CISA_WK_4.pptx
CISA_WK_4.pptxCISA_WK_4.pptx
CISA_WK_4.pptx
 
SmartERP PeopleSoft Security
SmartERP PeopleSoft  Security SmartERP PeopleSoft  Security
SmartERP PeopleSoft Security
 
Aplication data security compliances
Aplication data security compliancesAplication data security compliances
Aplication data security compliances
 
How to Restructure and Modernize Active Directory
How to Restructure and Modernize Active DirectoryHow to Restructure and Modernize Active Directory
How to Restructure and Modernize Active Directory
 
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
Overview of ISO 27001 [null Bangalore] [Dec 2013 meet]
 
Non functional requirements. do we really care…?
Non functional requirements. do we really care…?Non functional requirements. do we really care…?
Non functional requirements. do we really care…?
 
ISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An IntorductionISO / IEC 27001:2005 – An Intorduction
ISO / IEC 27001:2005 – An Intorduction
 
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...
SUMSEM-2021-22_ITE2015_TH_VL2021220701427_Reference_Material_I_20-07-2022_2.3...
 
Software Requirements engineering
Software Requirements engineeringSoftware Requirements engineering
Software Requirements engineering
 
10-3 Clinical Informatics System Selection & Implementation
10-3 Clinical Informatics System Selection & Implementation10-3 Clinical Informatics System Selection & Implementation
10-3 Clinical Informatics System Selection & Implementation
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory Intelligence
 
Segregation of Duties and Sensitive Access as a Service
Segregation of Duties and Sensitive Access as a ServiceSegregation of Duties and Sensitive Access as a Service
Segregation of Duties and Sensitive Access as a Service
 
An Introduction to Clinical Study Migrations
An Introduction to Clinical Study MigrationsAn Introduction to Clinical Study Migrations
An Introduction to Clinical Study Migrations
 
Structured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six SigmaStructured NERC CIP Process Improvement Using Six Sigma
Structured NERC CIP Process Improvement Using Six Sigma
 
Cyber security series administrative control breaches
Cyber security series   administrative control breaches Cyber security series   administrative control breaches
Cyber security series administrative control breaches
 
Enterprise Risk Management Solutions
Enterprise Risk Management SolutionsEnterprise Risk Management Solutions
Enterprise Risk Management Solutions
 

Recently uploaded

Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessSeta Wicaksana
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaoncallgirls2057
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africaictsugar
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxMarkAnthonyAurellano
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Timedelhimodelshub1
 

Recently uploaded (20)

Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful Business
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City GurgaonCall Us 📲8800102216📞 Call Girls In DLF City Gurgaon
Call Us 📲8800102216📞 Call Girls In DLF City Gurgaon
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africa
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Time
 

Confessions of an Internal Auditor: IT Edition

  • 1. 1 TODAY’S OBJECTIVES • Review risks related to information technology facilities, system access, data integrity, and system maintenance. • Describe techniques for the non-technical professional to evaluate controls of information technology and systems. 2
  • 2. ABOUT VANDERBILT UNIVERSITY MEDICAL CENTER • $2.3 Billion Annual Healthcare Operating Expenses (excludes academics and research) • $471.6 Million Annual Sponsored Research Budget • $843.6 Million Annual Charity Care, Community Benefits, and other Unrecovered Costs 3 4
  • 3. INTEGRATED IT AUDITING FOCUSED IT AUDITS 5 IT AUDIT PLANNING - REQUESTS • HIPAA Security Risk Assessment • External auditor’s report and management letter • Consulting reports • IT policies and procedures 6
  • 4. SYSTEM/APPLICATION LIST • System or application name • Vendor • System purpose • The business and IT owners • Location(s) where the system is physically housed • Service Criticality (they can’t all be Mission Critical) C S M K T Z A L S M I T E R F M V L N B P P D O O E A E E I E I I N S D I C M C E R T O O A L I E E L C E S R S I N I R C S C L C S T M S N A L H O I E Y O S E R L T R M T S A P R O A H O C S I C M E ALLSCRIPTS AVAILITY CERNER CISCO EMC EPIC IBM ITIL KRONOS MEDASSETS MEDITECH MICROSOFT OMNICELL ORACLE SAP SIEMENS 7 THE CLAW HAS SPOKEN 8
  • 5. USER SECURITY & ADMINISTRATION • Account administration • User authentication and passwords • Session controls Audit Objectives 9 ACCOUNT ADMINISTRATION • Process to request and approve accounts • How are accounts inactivated or deleted • Documentation of requests • Monitoring for non-use, change in employment status, etc. 10
  • 6. USER AUTHENTICATION & PASSWORDS • Minimum password length and composition • Periodic password changes • Multi-factor authentication • Lockouts and resets KillerInfographics.com 11 SESSION CONTROLS • Session length • Maximum inactivity • Concurrent logins 12
  • 7. CHANGE MANAGEMENT • Documented processes and policies (including emergency changes) • Segregated environment and testing • Production access Audit Objectives www.ibiblio.org/Dave/drfun.html 13 AN ICQ FOR EACH APPLICATION • Are change requests logged? • Is version control software used? • What logical environments exist? • Are all changes required to be tested? • Who is responsible for migrating changes? • Are back-out procedures required prior to implementation? • How are emergency changes communicated to business owners? 14
  • 8. TESTING CHANGE • Emergency Change • Tech Approval • Business Approval • CAB Approval • Programmed in Dev • Tested Outside Production • Testing Completed • User Testing Complete • Programmer Deployed Change • Back-out Procedures • Documentation Updated • # of Resulting Issues 15 DATA CENTER PHYSICAL SECURITY • Physical access for both individuals and equipment • Power configurations • Environmental controls and monitoring Audit Objectives 16
  • 9. ACCESS CONTROLS • Access logs - who, when, and why • Approvals and pre- approvals • Monitoring and oversight 17 POWER • Sources and configurations • Redundancy and back-up • Capacity Planning • Joint Commission 18
  • 10. ENVIRONMENT • Cooling • Humidity • Fire suppression • Water (and other wet stuff) • Raised floors 19 INTEGRATING IT INTO FINANCIAL AND OPERATIONAL AUDITS 20
  • 11. COMMON ISSUES: IT • Storage of PHI on unsecured media • CD/DVD with Medical Images • Department File Servers, Local PCs, Laptops, etc. • Inadequate Password Policy/Enforcement • Unsecured/Sharing of Clinic Workstations • Disaster Recovery • Documented Downtime Procedures • Oversight/Security of Portable Devices (e.g., iPads) 21 ADDITIONAL READING 512 pages 1.8 pounds 696 pages 3.0 pounds 2,000 pages 7.6 pounds 22
  • 12. QUESTIONS Brad Adams, CPA (615) 875-9554 brad.adams@vanderbilt.edu 23