Principle 5: Security and Assurance
James J. DeLuccia IV · 2012
This principle “security and assurance” is identified from analysing the worldapos;s regulations. Control and safeguards are not the sole responsibility or duty of the technology security department. In fact, the current model has dispersed such controls across many different management divisions. The security and assurance of the organization is paramount for the proper processing and delivery of services. The use of information technology (IT) security raises the controls and effectiveness to a reasonable level of assurance. This chapter addresses risk intelligence, technology-secure platforms and networks, and validation and performance. Being cognizant of the risks an organization faces physically, logically, and naturally is key to properly structuring a control environment that is both responsive and effective. While every organization is exposed to risks from multiple sources, most organizations practice an informal method of responding to and addressing risks.