AICPA RSS
x
Username

Password

Information Security Management

Information Security Management 

Information Security is one of the major areas of concern for our government as it faces threats to the nation's critical infrastructure. For organizations, prevention of compromise to their information assets makes this issue a priority as focus and resources are placed on the formation of information security policy and the implementation of control measures to prevent access and/or manipulation of their systems and data.

With the ever-increasing demands and requirements to ensure your organization’s or clients' business data, information, and systems are secure, the AICPA’s Information Technology Center Web site provides the following content designed to help you in your own practice, as well as to serve as resources when advising or providing assurance to others.

Mastering the Payment Card Industry Standard
Becoming familiar with the Payment Card Industry Data Security Standard is a prerequisite to understanding the regulatory environment in which many businesses that accept credit and debit cards operate.

Test Your Information Security IQ
Information security is a dynamic field and, although accounting professionals have become much savvier on the subject, keeping track of the latest best practices can be a daunting task. How current are you? Take this quiz on information security basics to find out.

Discussion Paper: Identity Management and Access Control
With the near ubiquity of computerized accounting systems, identity and access management (IAM) has become a critical entity-level control functioning both at the system and application levels. This article introduces the related concepts of Identity Management and Access Control and discusses why they are so crucial for CPAs to understand.

Don't Let This Happen To You: Critical Information Security Audit Considerations
Review of specific policies and procedures related to the security portion of Information Technology internal audit.

Open Hide documents in this section

Page  1 2
Showing results 1 - 15 of 19
Order by:


Identity and Access Management - GTAG 9

Practice Aid : 
Published on March 15, 2012

Common Vulnerabilities and Exposures

Overview :  Common Vulnerabilities and Exposures (CVE's) is a list or dictionary of publicly known information security vulnerabilities and exposures international in scope and free for public use. CVE's common names facilitate the exchange of vulnerability information across security advisories, tools, databases, and services that did not exist prior to the creation
Published on January 28, 2011

PCI Data Security Standard Requirements and Security Assessment Procedures

Professional Standards :  The Payment Card Industry (PCI) Data Security Standard (DSS) provides a baseline of technical and operational requirements designed to protect cardholder data.
Published on December 14, 2010

Payment Card Industry (PCI) Data Security Standard - Requirements and Security Assessment Procedures

Article :  PCI DSS provides a baseline of technical and operational requirements designed to protect cardholder data. PCI DSS applies to all entities involved in payment card processing – including merchants, processors, acquirers, issuers, and service providers, as well as all other entities that store, process or transmit cardholder data. PCI DSS
Published on December 02, 2010

Information Security Management Content Suite

Report :  The following content is intended to introduce CPAs to the basic concepts and terminology surrounding IT security.
Published on September 25, 2010

ABCs of IT Security for CPAs

Overview :  An organization's security policy is a living document. It evolves over time to meet new challenges, as well as changing objectives and philosophies on a variety of security-related issues, from hardware configuration to human behavior. Security policy is a governance issue.
Published on September 25, 2010

Critical Security Audit Considerations

Article :  Don’t Let This Happen to You: Critical Information Security Audit Considerations.  This article will address specific policies, procedures, and methods related to the security portion of an information technology internal audit.  Security is arguably the most important element of an IT audit and requires that validity testing be interwoven through
Published on August 12, 2010

Information Security Management

Article :  Information Security is one of the major areas of concern for our government as it faces threats to the nation's critical infrastructure. For organizations, prevention of compromise to their information assets makes this issue a priority as focus and
Published on July 20, 2010

Identity Management AccessControl

Article :  Control of system and application levels.
Published on July 20, 2010

Imagine that the finance department internal audit passed with flying colors

Article :  Review of specific policies and procedures related to the security portion of Information Technology internal audit.
Published on July 07, 2010

Information Security Triangle Checklist

Checklist : 
Published on April 17, 2010

ABCs of IT Security for CPAs #7 A CPAs Introduction to Security Maintenance Considerations

Article : 
Published on February 04, 2010

ABCs of IT Security for CPAs #6 Introduction to Perimeter Security

Article : 
Published on February 04, 2010

ABCs of IT Security for CPAs #8 A CPAs Introduction to Peripheral Security Management

Article : 
Published on February 04, 2010

ABCs of IT Security #4 Introduction to Mobile & Remote Computing Security Considerations

Article :  A broad overview of the mobile security landscape provided at a time when mobile devices are growing and changing rapidly and creating new opportunities for potential attack and exploitation.
Published on February 04, 2010

Page  1 2
Showing results 1 – 15 of 19
Show Results per page

Related AICPA Products



Employee Benefit Plans: Audit and Accounting Guide

This guide is a handy tool for auditors that audit employee benefit plans or accountants that prepare the plan financial statements. It offers hands on advice in dealing with industry specific issues, such as statutory rules and regulations and the financial reporting requirement of ERISA and fair value disclosure requirements. Updated as of January 1, 2012.



Health Care Entities -- AICPA Audit and Accounting Guide

Understand the unique considerations of a healthcare organization with this authoritative accounting and auditing resource essential to financial managers and auditors operating in the healthcare industry today.

Copyright © 2006-2012 American Institute of CPAs.