<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance, Risk, and Compliance &#187; Control System</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-governance/tag/control-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-governance</link>
	<description></description>
	<lastBuildDate>Mon, 17 Jun 2013 01:33:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Wikipedia: An assessment from a user’s perspective – Part VI</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-vi/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-vi/#comments</comments>
		<pubDate>Thu, 21 Feb 2013 04:11:43 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1853</guid>
		<description><![CDATA[Based on my careful analysis of the factors associated with information reliability, there is a medium-to-high inherent risk of a researcher conveying unreliable information through citing Wikipedia material due to inadequate identity management issues. Contextually, according to About.com, “In most cases, you should stay away from Internet information that doesn&#8217;t list an author&#8230; If the [...]]]></description>
				<content:encoded><![CDATA[<p>Based on my careful analysis of the factors associated with information reliability, there is a medium-to-high <a href="http://www.businessdictionary.com/definition/inherent-risk.html">inherent risk</a> of a researcher conveying unreliable information through citing Wikipedia material due to inadequate identity management issues. Contextually, according to About.com, “In most cases, you should stay away from Internet information that doesn&#8217;t list an author&#8230; If the author is named, you will want to find his/her web page to:<br />
• Verify educational credits<br />
• Discover if the writer is either published in a scholarly journal<br />
• Verify that the writer is employed by a research institution or university”</p>
<p><iframe width="420" height="315" src="http://www.youtube.com/embed/56jYpFkdqW8" frameborder="0" allowfullscreen></iframe></p>
<p>Sources:</p>
<p>Davis, Robert E. (2010). IT Auditing: An Adaptive System. Available from <a href="http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075">http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075</a></p>
<p>Davis, Robert E. (2008). IT Auditing: Assuring Information Assets Protection. Mission Viejo: Pleier. CD-ROM.</p>
<p>Fleming, Grace (2012), &#8220;Internet Research Tips: Finding Reliable Internet Sources,&#8221; About.com, &lt; <a href="http://homeworktips.about.com/od/researchandreference/a/internet.htm">http://homeworktips.about.com/od/researchandreference/a/internet.htm</a> &gt;, accessed September 17, 2012.</p>
<p>KnowThis.com, &#8220;Research Validity and Reliability,&#8221; &lt; <a href="http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/">http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/</a> &gt;, accessed September 17, 2012.</p>
<p>OneName Corporation. Requirements for a Global Identity Management Service. W3C Workshop on Web Services. Retrived from: <a href="http://www.w3.org/2001/03/WSWS-popa/paper57">http://www.w3.org/2001/03/WSWS-popa/paper57</a></p>
<p>TechTarget.com. <a href="http://searchunifiedcommunications.techtarget.com/definition/identity-management">http://searchunifiedcommunications.techtarget.com/definition/identity-ma&#8230;</a></p>
<p>U.S. GAO. (2002). Assessing the Reliability of Computer-Processed Data. Rev. ed. Washington, D.C.: Government Printing Office.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-vi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikipedia: An assessment from a user’s perspective – Part V</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-v/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-v/#comments</comments>
		<pubDate>Sun, 17 Feb 2013 00:02:15 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1850</guid>
		<description><![CDATA[To provide an appropriate answer to this foundational question regarding Wikipedia an assessor must take into consideration the primary traits of reliability. Therefore, as previously stated in Wikipedia: An assessment from a user&#8217;s perspective &#8211; part 1 as well as documented in IT Auditing: Assuring Information Assets Protection, minimally, information contained within technology can be [...]]]></description>
				<content:encoded><![CDATA[<p>To provide an appropriate answer to this foundational question regarding Wikipedia an assessor must take into consideration the primary traits of reliability. Therefore, as previously stated in Wikipedia: An assessment from a user&#8217;s perspective &#8211; part 1 as well as documented in <a href="http://www.amazon.com/Auditing-Assuring-Information-Protection-ebook/dp/B005CMHE4G/ref=la_B003LDE8V0_1_23?ie=UTF8&amp;qid=1347921249&amp;sr=1-23">IT Auditing: Assuring Information Assets Protection</a>, minimally, information contained within technology can be considered reliable when completeness, accuracy and <em>validity</em> attributes are independently verifiable as well as user neutral. In other words, <em>information reliability</em> requires representational faithfulness to ensure assertions and supporting purported events are in agreement.</p>
<p>Sources:</p>
<p>Davis, Robert E. (2010). IT Auditing: An Adaptive System. Available from <a href="http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075">http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075</a></p>
<p>Davis, Robert E. (2008). IT Auditing: Assuring Information Assets Protection. Mission Viejo: Pleier. CD-ROM.</p>
<p>Fleming, Grace (2012), &#8220;Internet Research Tips: Finding Reliable Internet Sources,&#8221; About.com, &lt; <a href="http://homeworktips.about.com/od/researchandreference/a/internet.htm">http://homeworktips.about.com/od/researchandreference/a/internet.htm</a> &gt;, accessed September 17, 2012.</p>
<p>KnowThis.com, &#8220;Research Validity and Reliability,&#8221; &lt; <a href="http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/">http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/</a> &gt;, accessed September 17, 2012.</p>
<p>OneName Corporation. Requirements for a Global Identity Management Service. W3C Workshop on Web Services. Retrived from: <a href="http://www.w3.org/2001/03/WSWS-popa/paper57">http://www.w3.org/2001/03/WSWS-popa/paper57</a></p>
<p>TechTarget.com. <a href="http://searchunifiedcommunications.techtarget.com/definition/identity-management">http://searchunifiedcommunications.techtarget.com/definition/identity-ma&#8230;</a></p>
<p>U.S. GAO. (2002). Assessing the Reliability of Computer-Processed Data. Rev. ed. Washington, D.C.: Government Printing Office.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikipedia: An assessment from a user’s perspective – Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iv/#comments</comments>
		<pubDate>Thu, 14 Feb 2013 13:45:50 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1846</guid>
		<description><![CDATA[Wikipedia is often been presented as a great research resource; however it is also a public forum, where any authorized user can make a declaration or an assertion. “If you find an article that provides relevant information for your research topic, you should take care to investigate the source to make sure it is valid [...]]]></description>
				<content:encoded><![CDATA[<p>Wikipedia is often been presented as a great research resource; however it is also a public forum, where any authorized user can make a declaration or an assertion. “If you find an article that provides relevant information for your research topic, you should take care to investigate the source to make sure it is valid and reliable. [Academically, this] is an essential step in maintaining sound <a href="http://homeworktips.about.com/od/paperassignments/a/Ethics-For-The-Beginning-Researcher.htm">research ethics</a>.” Thus, an important question concerning any published work classified as encyclopedic material is: How valid and reliable is documented information?</p>
<p>Sources:</p>
<p>Davis, Robert E. (2010). IT Auditing: An Adaptive System. Available from <a href="http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075">http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075</a></p>
<p>Davis, Robert E. (2008). IT Auditing: Assuring Information Assets Protection. Mission Viejo: Pleier. CD-ROM.</p>
<p>Fleming, Grace (2012), &#8220;Internet Research Tips: Finding Reliable Internet Sources,&#8221; About.com, &lt; <a href="http://homeworktips.about.com/od/researchandreference/a/internet.htm">http://homeworktips.about.com/od/researchandreference/a/internet.htm</a> &gt;, accessed September 17, 2012.</p>
<p>KnowThis.com, &#8220;Research Validity and Reliability,&#8221; &lt; <a href="http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/">http://www.knowthis.com/principles-of-marketing-tutorials/marketing-research/research-validity-and-reliability/</a> &gt;, accessed September 17, 2012.</p>
<p>OneName Corporation. Requirements for a Global Identity Management Service. W3C Workshop on Web Services. Retrived from: <a href="http://www.w3.org/2001/03/WSWS-popa/paper57">http://www.w3.org/2001/03/WSWS-popa/paper57</a></p>
<p>TechTarget.com. <a href="http://searchunifiedcommunications.techtarget.com/definition/identity-management">http://searchunifiedcommunications.techtarget.com/definition/identity-ma&#8230;</a></p>
<p>U.S. GAO. (2002). Assessing the Reliability of Computer-Processed Data. Rev. ed. Washington, D.C.: Government Printing Office.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikipedia: An assessment from a user’s perspective – Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iii/#comments</comments>
		<pubDate>Sat, 09 Feb 2013 17:48:10 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1840</guid>
		<description><![CDATA[As conveyed by TechTarget.com, “Identity management (ID management) is a broad administrative area that deals with identifying individuals in a system (such as a country, a network, or an enterprise) and controlling their access to resources within that system by associating user rights and restrictions with the established identity.” In this area, based on my [...]]]></description>
				<content:encoded><![CDATA[<p>As conveyed by TechTarget.com, “Identity management (ID management) is a broad administrative area that deals with identifying individuals in a system (such as a country, a network, or an enterprise) and controlling their access to resources within that system by associating user rights and restrictions with the established identity.” In this area, based on my experience, Wikipedia software does not provide adequate mechanisms for user accountability as presented in a position paper by OneName Corporation&#8217;s Requirements for a Global Identity Management Service. Specifically, it appears there is no password synchronization defining the one-to-many correspondence that may exist between a user and authorized accounts.</p>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/8iQLkt5CG8I" frameborder="0" allowfullscreen></iframe></p>
<p>Sources:</p>
<p>Davis, Robert E. (2010). IT Auditing: An Adaptive System. Available from <a href="http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075">http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075</a></p>
<p>Hanson, R. (2011, October 13). The Art of Dis-Connecting: Social Networking Risk Management. Presentation to the ISACA Perth Chapter. Converted PDF formatted material available at: <a href="http://www.isaca.org/chapters2/Perth/Documents/Social%20Networking%20Session%20-%20Rob%20Hanson.pdf">www.isaca.org/chapters2/Perth/Documents/Social%20Networking%20Session%20-%20Rob%20Hanson.pdf</a></p>
<p>Singleton, T. (2012). What Every IT Auditor Should Know About Auditing Social Media. ISACA Journal, 5. Retrived from: <a href="http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/What-Every-IT-Auditor-Should-Know-About-Auditing-Social-Media.aspx">http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/What-Every-IT-Auditor-Should-Know-About-Auditing-Social-Media.aspx</a></p>
<p>OneName Corporation. Requirements for a Global Identity Management Service. <a href="http://searchsoa.techtarget.com/definition/W3C">W3C</a> Workshop on Web Services. Retrived from: <a href="http://www.w3.org/2001/03/WSWS-popa/paper57">http://www.w3.org/2001/03/WSWS-popa/paper57</a></p>
<p>TechTarget.com. <a href="http://searchunifiedcommunications.techtarget.com/definition/identity-management">http://searchunifiedcommunications.techtarget.com/definition/identity-management</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikipedia: An assessment from a user’s perspective – Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-ii/#comments</comments>
		<pubDate>Thu, 07 Feb 2013 02:55:57 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1833</guid>
		<description><![CDATA[Following the framework outlined in IT Auditing: An Adaptive System, a critical aspect of an IT assessment is the identification of related risks. Though Wikipedia Project Administrators commonly disavow their Internet endeavors are based on a Social Networking System (SNS), their activities appear to fit within an academically accepted definition of Social Media. Thus, there [...]]]></description>
				<content:encoded><![CDATA[<p>Following the framework outlined in <em>IT Auditing: An Adaptive System</em>, a critical aspect of an IT assessment is the identification of related risks. Though Wikipedia Project Administrators commonly disavow their Internet endeavors are based on a Social Networking System (SNS), their activities appear to fit within an academically accepted definition of Social Media. Thus, there are application inherent risks. “These risk areas are similar to those brought about by other IT, such as inefficiency, wasted investment, insufficient effectiveness and lost opportunity. But, it also has some unique risk areas, including public image damage created by negative comments and postings in social media venues.” Consequently, my first identified weakness was recorded on August 21, 2012 concerning the integrity sub-domain of identity management.</p>
<p>Sources:</p>
<p>Davis, Robert E. (2010). IT Auditing: An Adaptive System. Available from <a href="http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075">http://www.lulu.com/product/ebook/it-auditing-an-adaptive-system/18809075</a></p>
<p>Hanson, R. (2011, October 13). The Art of Dis-Connecting: Social Networking Risk Management. Presentation to the ISACA Perth Chapter. Converted PDF formatted material available at: <a href="http://www.isaca.org/chapters2/Perth/Documents/Social%20Networking%20Session%20-%20Rob%20Hanson.pdf">www.isaca.org/chapters2/Perth/Documents/Social%20Networking%20Session%20-%20Rob%20Hanson.pdf</a></p>
<p>Singleton, T. (2012). What Every IT Auditor Should Know About Auditing Social Media. ISACA Journal, 5. Retrived from: <a href="http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/What-Every-IT-Auditor-Should-Know-About-Auditing-Social-Media.aspx">http://www.isaca.org/Journal/Past-Issues/2012/Volume-5/Pages/What-Every-IT-Auditor-Should-Know-About-Auditing-Social-Media.aspx</a></p>
<p>OneName Corporation. Requirements for a Global Identity Management Service. <a href="http://searchsoa.techtarget.com/definition/W3C">W3C</a> Workshop on Web Services. Retrived from: <a href="http://www.w3.org/2001/03/WSWS-popa/paper57">http://www.w3.org/2001/03/WSWS-popa/paper57</a></p>
<p>TechTarget.com. <a href="http://searchunifiedcommunications.techtarget.com/definition/identity-management">http://searchunifiedcommunications.techtarget.com/definition/identity-management</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikipedia: An assessment from a user&#8217;s perspective &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-i/#comments</comments>
		<pubDate>Fri, 01 Feb 2013 23:31:51 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Adaptive Systems]]></category>
		<category><![CDATA[Assurance Services]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Internal Control System]]></category>
		<category><![CDATA[Logical Security]]></category>
		<category><![CDATA[Non-profit]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Quality Assurance Program]]></category>
		<category><![CDATA[Trust Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1826</guid>
		<description><![CDATA[There has been a fair amount of discussion over the last few years regarding Wikipedia. As an educator as well as a professional writer my curiosity peaked on August 21, 2012. So in order to address my concerns objectively, I established a user account to investigate if Wikipedia meets generally accepted criteria for information as [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://itknowledgeexchange.techtarget.com/it-governance/files/2013/02/65b86922536fd0fa03a3e04b5695ad59.jpg"><img class="aligncenter size-full wp-image-1827" src="http://itknowledgeexchange.techtarget.com/it-governance/files/2013/02/65b86922536fd0fa03a3e04b5695ad59.jpg" alt="" width="430" height="323" /></a></p>
<p>There has been a fair amount of discussion over the last few years regarding <a href="http://www.techrepublic.com/blog/tech-news/university-professor-says-wikipedia-fosters-a-climate-of-blind-trust/2162?tag=content;blog-list-river">Wikipedia</a>. As an educator as well as a professional writer my curiosity peaked on August 21, 2012. So in order to address my concerns objectively, I established a user account to investigate if Wikipedia meets <a href="http://www.isaca.org/Knowledge-Center/cobit/Documents/COBIT4.pdf">generally accepted criteria for information</a> as produced through their open-source technology.</p>
<p>In conjunction, as a recognized leading compliance expert and specialist, I decided the best approach to this controversial issue would be to apply <a title="IT Auditing: An Adaptive System" href="http://www.lulu.com/us/en/shop/robert-e-davis-mba-cisa-cica/it-auditing-an-adaptive-system/paperback/product-20651731.html" target="_blank">The Davis Adaptive IT Auditing System</a>. Thus, the ambit of my assistive technology assessment is:</p>
<ul>
<li><strong>Confidentiality</strong> as epitomized by the preserving of authorized as well as unauthorized restrictions addressing information access and disclosure.</li>
<li><strong>Integrity</strong> as represented by protection against improper information modification or destruction.</li>
<li><strong>Availability</strong> reflecting ensuring timely and reliable information access and use.</li>
<li><strong>Effectiveness</strong> addressing the accomplishment of stated objectives.</li>
<li><strong>Efficiency</strong> dealing with the accomplishment of stated objectives economically.</li>
<li><strong>Compliance</strong> with stated policies and procedures.</li>
<li><strong>Reliability</strong> as the capability to maintain a specified acceptable level of performance under stated conditions. Minimally, information contained within technology can be considered reliable when completeness, accuracy and validity attributes are independently verifiable as well as user neutral.</li>
</ul>
<p>Sources:</p>
<p>Boritz, Efrin J. <em>IS Practitioners’ Views on Core Concepts of Information Integrity</em>. Rev. ed. Ontario: University of Waterloo, 2004.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/wikipedia-an-assessment-from-a-users-perspective-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Right-sizing IT Controls &#8211; Part VIII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-viii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-viii/#comments</comments>
		<pubDate>Tue, 03 May 2011 21:33:49 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Control Environment]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control Processes]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Internal Control Systems]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[IT Governanace]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Roles and Responsibilities]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=917</guid>
		<description><![CDATA[Deploying key IT governance practices enhance an entity’s ability to meet control objectives for cost, functionality, and quality.  Yet, regardless of the IT control techniques and automated tools available...]]></description>
				<content:encoded><![CDATA[<p>Deploying key <a href="http://www.amazon.com/Auditing-Robert-Davis-CISA-CICA/dp/1935133101">IT governance</a> practices enhance an entity’s ability to meet control objectives for cost, functionality, and quality.  Yet, regardless of the IT control techniques and automated tools available, the best possible means of regulating entity activity is, and always has been, selection of high-quality employees that value ethical conduct.  If entities are organizational formations providing good people a place to work, then the best path to right-sizing IT controls is supplying diligent subordinates with justified resources needed to achieve their specific IT control goals.</p>
<p>&#8220;<em>View Part I of the Right-sizing IT Controls series <a href="http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-viii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Right-sizing IT Controls &#8211; Part VII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-vii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-vii/#comments</comments>
		<pubDate>Fri, 29 Apr 2011 20:28:08 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Control Environment]]></category>
		<category><![CDATA[Control Evaluation]]></category>
		<category><![CDATA[Control Processes]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Internal Control Systems]]></category>
		<category><![CDATA[IT Controls]]></category>
		<category><![CDATA[IT Governanace]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Roles and Responsibilities]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=915</guid>
		<description><![CDATA[An entity’s controlling and monitoring activities should reflect management’s strategy for ensuring an adequate IT control system.]]></description>
				<content:encoded><![CDATA[<p>An entity’s controlling and monitoring activities should reflect management’s strategy for ensuring an adequate <strong>IT control system</strong>.  Consequently, IT policies, directives, standards, procedures, and rules should have a one-to-one or one-to-many correspondence with the assessed effectiveness and efficiency in addressing managements risk appetite.  Within this context, IT control policies and directives are commonly considered high-level governance documentation while standards, procedures, and rules are commonly considered detail-level governance documentation. Since IT managers plan, direct, and support technology deployments; an IT manager’s duties should include establishing departmental policies, procedures, and standards for ensuring the right-sizing of IT controls.  </p>
<p>&#8220;<em>View Part I of the Right-sizing IT Controls series <a href="http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/right-sizing-it-controls-part-vii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Compliance through Automation: Continuous Monitoring &#8211; Part VIII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-viii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-viii/#comments</comments>
		<pubDate>Mon, 18 Oct 2010 12:48:21 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Compliance Management]]></category>
		<category><![CDATA[Compliance Verification Systems]]></category>
		<category><![CDATA[Continuous Monitoring]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Data Provisioning]]></category>
		<category><![CDATA[Decision Techniques]]></category>
		<category><![CDATA[Enterprise Resource Planning]]></category>
		<category><![CDATA[ERP]]></category>
		<category><![CDATA[Exception Reporting Systems]]></category>
		<category><![CDATA[Expert Systems]]></category>
		<category><![CDATA[Inference Engine]]></category>
		<category><![CDATA[Knowledge Acquisition]]></category>
		<category><![CDATA[Knowledge Engineer]]></category>
		<category><![CDATA[Knowledge-base]]></category>
		<category><![CDATA[Management Information Systems]]></category>
		<category><![CDATA[MIS]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=758</guid>
		<description><![CDATA[Since management is responsible for the entity’s controls, they should have the means to determine, on an ongoing basis, whether selected controls are operating as designed.]]></description>
				<content:encoded><![CDATA[<p>Since management is responsible for the entity’s controls, they should have the means to determine, on an ongoing basis, whether selected controls are operating as designed.  Continuous monitoring typically addresses management’s responsibility to assess the adequacy and effectiveness of controls. It enhances <strong>managerial capabilities</strong> and <strong>entity-level controls</strong>, while striving to enable maintaining acceptable performance levels. Furthermore, with the ability to identify and correct control problems on a timely basis, automated continuous monitoring enriches an entity’s <a href="http://diy.craigspress.com/BookStore/BookStoreBookDetails.aspx?bookid=48453">compliance program</a>.  Nonetheless, the key to a successful deployment of automated continuous monitoring is process ownership by <a href="http://www.digitalgovernment.com/News/Executive-Insight--Meet-the-FISMA---Continuous-Monitoring-Program-Trainer--Jim-Litchko.shtml">personnel assigned responsibility</a> for responding to reported exception conditions.</p>
<p>&#8220;<em>View Part I of the Compliance through Automation: Continuous Monitoring series <a href="http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-viii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Compliance through Automation: Continuous Monitoring &#8211; Part VII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-vii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-vii/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 15:21:57 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Compliance Management]]></category>
		<category><![CDATA[Compliance Verification Systems]]></category>
		<category><![CDATA[Continuous Monitoring]]></category>
		<category><![CDATA[Control System]]></category>
		<category><![CDATA[Data Provisioning]]></category>
		<category><![CDATA[Decision Techniques]]></category>
		<category><![CDATA[Enterprise Resource Planning]]></category>
		<category><![CDATA[ERP]]></category>
		<category><![CDATA[Exception Reporting Systems]]></category>
		<category><![CDATA[Expert Systems]]></category>
		<category><![CDATA[Inference Engine]]></category>
		<category><![CDATA[Knowledge Acquisition]]></category>
		<category><![CDATA[Knowledge Engineer]]></category>
		<category><![CDATA[Knowledge-base]]></category>
		<category><![CDATA[Management Information Systems]]></category>
		<category><![CDATA[MIS]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=753</guid>
		<description><![CDATA[Typically, for IT, continuous monitoring involves ongoing automated testing of selected datum within a given process area against a suite of control protocols.]]></description>
				<content:encoded><![CDATA[<p>Continuous monitoring allows management to have greater insight into the entity’s current state of compliance. Typically, for IT, <a href="http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/Monitoring-Internal-Control-Systems-and-IT.aspx">continuous monitoring</a> involves ongoing automated testing of selected datum within a given process area against a suite of control protocols.  Management can utilize this information to set or reset process guidelines, rules and tests; through <strong>applied analytics</strong> identifying performance gaps or unusual events that may suggest control failures.  This type of continuous monitoring can exist in IT hardware, firmware or software enabled to observe and record automated activities.  Therefore, automated continuous monitoring provides a timely feedback mechanism for management to ensure that <a href="http://www.theiia.org/bookstore/product/it-auditing-service-delivery-and-support-1321.cfm">configuration items and controls</a> are operating as designed and datum are processed appropriately.  </p>
<p>&#8220;<em>View Part I of the Compliance through Automation: Continuous Monitoring series <a href="http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-i/">here</a>&#8220;</em></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/compliance-through-automation-continuous-monitoring-part-vii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
