Microcomputer Security Internal Control Questionnaire
Last Modified Thursday, 05-Sep-1996 12:12:44 PDT
ACKNOWLEDGMENTS: Internal Audit Departments and individuals that contributed to this internal control questionnaire are listed at the bottom of this page. Contributions and comments would be greatly appreciated!
OBJECTIVE: To determine that there is accountability for computer system used and to ensure integrity of microcomputer-based programs and data.
- Is the computer equipment physically secured by being located in a secured area (no public access) or by the use of locking devices?
- Has the department analyzed and classified its data and files in terms of sensitivity or criticality?
- Does the department use access control software to establish access controls over its critical data and programs? If yes, what kind of software?
- Has the department established a formal procedure for adding individuals to the list of those authorized to access the system, changing their access capabilities, and deleting them from the list? Is this procedure followed on a consistent basis?
- Are user IDís and PASSWORDS required to access the system?
- Do the access controls only allow authorized persons access to the system?
- Do the access controls restrict access to only those resources needed to perform the job and provide varying access levels (i.e., on a need-to-know basis)?
- Are passwords uniquely assigned (not shared or no group passwords) to each authorized user?
- Are passwords kept confidential?
- Are passwords constructed in such a way that they are difficult to decipher or guess?
- Does the system require passwords to be at least 4 alpha/numeric characters in length?
- Does the system mask passwords from appearing/displaying on the screen or appearing when entered?
- Does the system force passwords to change on a regular basis (e.g., every 30 days or at least quarterly)?
- Does the system permit certain passwords to be re-used by the same individuals?
- Are passwords quickly and easily changed by the password owner or designated management personnel?
- Does the system allow the use of blanks for passwords?
- Does the system allow the use of the same password consecutively?
- Are passwords stored in an encrypted file?
- Does the access control software disable or disconnect terminals after a predetermined number of invalid/unsuccessful access attempts (e.g., 3 times) to the system?
- Does the access control software disable or disconnect terminals after a predetermined period of inactivity (e.g., 5 or 15 minutes)?
- Does the system maintain a log of system activities including unsuccessful access attempts to provide an audit trail of activity? If yes, is the log reviewed periodically? Are exception items investigated? Who perform these duties?
- Does the department use any programs to analyze system log and report on specifically defined security items? If yes, what programs and who control these programs?
- Are changes to the system log (if permitted) routinely documented and reviewed by an independent individual for propriety? Is the system log protected from accidental or intentional destruction?
- Has the department purchased any hardware/software in the past twelve months? If yes, what and when? Was the request approved by user management?
- Does the department have the original diskettes and documentation of each software package that is executed/installed on each computer?
- Does the department utilize any non-standard (e.g., in-house developed) software packages?
- Is access to powerful utilities or service aids that can alter data files and programs (i.e., allow programs or users to circumvent standard software protection) restricted (i.e., used only for authorized purposes)?
- Are all files, programs, and documentation need to operate the critical end user computing systems backed-up and maintained off-site? What is the location of the remote off-site facility? Is the facility properly secured?
- Does the department have an emergency preparedness/disaster recovery plan?
- How will the department perform critical functions if there a system failure?
- Has the departmental disaster recovery plan been put into writing, staff trained, and the plan tested? If yes, when?
- Is the disaster recovery plan updated after each periodic test of the plan?
- University of California, Santa Barbara (Internal Audit)
- University of California, Santa Cruz (Internal Audit)
[ Home Page ]
[ What's New? ]
[ Auditing ]
[ Security ]
[ Technologies ]
[ Control ]
For comments or problems, please e-mail
Slemo Warigon firstname.lastname@example.org
or call (805) 893-3817.
Copyright © 1996 The WariNet Haven