Download presentation
Presentation is loading. Please wait.
Published byAndra Leonard Modified over 9 years ago
1
1 Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag Data security and positions with access to confidential information
2
2 Agenda About the audit Audit approach Audit findings E-Government algorithm: Report Cases Titel van de presentatie | Datum
3
3 About the audit Part of the 2011 audit into the state of central government accounts We performed audits at all the ministries and one departmental agency into information security ( IS): Quality of data protection policy; Protection of data systems. We examined positions with access to confidential information at all the ministries. ( PCI) Audit start: October 2011 Audit publication: May 2012 URL: http://www.courtofaudit.nl/english/Publications/Audits/Introdu ctions/2012/05/Data_security_and_positions_with_access_to_c onfidential_information http://www.courtofaudit.nl/english/Publications/Audits/Introdu ctions/2012/05/Data_security_and_positions_with_access_to_c onfidential_information
4
4 Audit approach IS & PCI - Questionnaire
5
5 Audit approach IS - Questionnaire
6
6 Audit findings IS – Analysing results
7
7 Audit findings IS - Quality of data protection policy Most ministries and departmental agencies score badly in the following two respects: It is not clear who is responsible for which data systems and data chains. No regular reviews of data protection policy have been planned or performed.
8
8 Audit findings IS - Protection of data systems Poor scores in the two following areas in particular: No clear picture of the security risks associated with data systems; The overall package of reliability requirements and security measures is not reviewed at regular intervals.
9
9
10
10 'IT audits' - Matthijs Kerkvliet, The Netherlands Court of Audit 10/27 Audit approach PCI – Matching positions with actual number of security clearances ## == √ ##
11
11 Audit findings PCI - results
12
12 E-Government algorithm – The form
13
13 E-Government algorithm – Case IS: Quality of data protection policy
14
14 E-Government algorithm – Case IS: Protection of data systems - Open for discussion -
15
15 E-Government algorithm – Case IS: Positions with access to confidential information - Open for discussion -
16
16 Algemene Rekenkamer | Postbus 20015 | 2500 EA Den Haag www.rekenkamer.nl @rekenkamer www.linkedin.com/company/ algemene-rekenkamer
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.