A good governance policy goes a long way

Opinion
Aug 27, 20103 mins

* Recent data breaches demonstrate the need for companies to strengthen their policies and procedures

The recent newsletters about data governance (or lack of it) and data breaches brought in a bunch of e-mail from friends and other readers noting other problems that had cropped up around the world showing just how bad things are.

Maarten Stultjens, (he’s a director of BHOLD) in the Netherlands told me about a KLM airlines employee:

“The 44-year-old man worked at the airline’s customer service. He would have reported false complaints, which he filled in his personal bank account as a beneficiary. Then he authorized payments. The employee also reopened old cases against KLM and replaced the original account by his.

“In total, the man committed fraud for more than 145,000 euro.

“This employee held a toxic combination of authorizations which could have been detected with Access Governance & Access Auditing.

“The ‘Audit Firms Supervision Act’, reduced audit budgets and CobiT [The Control Objectives for Information and related Technology, a set of best practices (framework) for IT management] are driving a more professional audit approach — using dedicated tooling — then the laborious and [spreadsheet] based approaches used so far. Yet this development is going slow.

“Incidents like these call for a more thorough access audit. What is keeping you away demanding from your internal/external auditor a more thorough access audit as part of regular audit assignment — to detect and prevent this type of fraud?”

At almost the same time, Oracle’s Mark Dixon (formerly Sun’s Mark Dixon) sent me a link to this story about how “A three-person process for approving payments did not stop a lone insider from stealing $11 million by playing puppet master. The thief’s unauthorized access to the unused computer accounts of two other employees allowed her pull the strings and make it appear financial payments had the necessary three ‘independent approvals’.” It’s thought that the thief, a manager, kept open the user accounts of subordinates who had left the company then used their credentials for the second and third “approval.”

A good governance policy would have seen that the KLM employee was restricted by a “Separation of Duties” policy while the second problem should have been covered by a better deprovisioning policy — something I’ve been telling you all about since at least 2001.

Check your organization’s policies and procedures now, before the data breaches and embezzlements occur.