Wednesday, March 13, 2013

Social Media for Small Businesses

Posted by EYHokie


Monday night we discussed auditing Social Media.  Our discussion (really my short lecture) focused on anything from twitter, facebook, LinkedIn to Google Docs.  My suggested approach focused more on a corporations and less on small businesses. For this post, lets focus on the small business.

Understanding the Organization:
The first place to start should always be to understand the business and the business processes. 
·         What exactly does the company do? 
·         What is the culture like? 
·         What are the short and long-term goals? 
·         What is the company structure? 
·         What social media formats are being used?
·         How do they align with the company goals/direction?

Understand the Business Unit
Now that you have an overall understanding of the organization, its important to understand the business units. Here we are taking one step closer to the business processes.
·         What is the breakdown of the organization (structurally) by department?
·         What are the department’s goals?
·         How do they align with the companies short and long-term goals?
·         What does the business unit do?  How do they fit into the organization?

Understand the Business Processes
This can be a difficult piece to understand.  Above we explored the organization and then dove into a specific business unit.  We know what the groups do at a high level but what does the day to day look like?  This will take some skill.  We want to get enough detail that we can identify what can go wrong with the business processes.  At the same time, we don’t want to get stuck in the details.  The conversation should be an open-ended conversation.  Repeating your understanding or drawing pictures is a great was to feel comfortable that you can speak to the department at a later date.

Porter’s Five Forces[1]
Why analyze the industry?  To fully complete any audit, I think it is important to step away from the details and take a look at the overall industry.  We can then move into the company and then down to the business processes.   There are many sites online that can help with this step.

SWOT/TOWS Matrix
Now to understand the internal company, a SWOT analysis should be completed.  This will further give guidance on the risks the company faces.  This will also help determine how the use of social media aligns with the strengths and opportunities in the organization.  Some of the notable business risks may include:
·         Disclosure of corporate assets/sensitive information
·         Violation of law/regulation
·         Loss of customer confidence
·         Loss of reputation
·         Dissemination of fake/fraudulent information

Let’s stop here.  We’ve spent a good bit of time understanding the industry, the company and the business processes.  This is a discussion on social media.  Why all the extra work?  From this point forward, we can either assume you knew all of this information or you were new to the company and needed to get a strong foundation.  By now, we’ve identified the major risks to the organization and should have determined how the use of social media fits into the organization.  If the company cannot get past this point, there is no real value in moving forward.  The company can have all the controls in the world but if it doesn’t align with the external and internal strengths, then why are they even using these tools?

Governance[2]
Surprisingly enough, the Citizenship and Immigration Canada provides an interesting audit of IT Governance.  Ok, surprisingly may be a push.  The following are some topics to consider:
·         Policies and procedures
o   Legal counsel review of all policies
o   Personal use (social media) at work
o   Personal use (social media) outside of work.  Why care?  The image portrayed outside of the work environment can have an impact on the greater image of the company.
o   Who can use the tools for business purposes
·         Strategy
o   Risk Management
§  Approval of social media projects
§  Inventory of all media outlets
o   Ongoing assessments
·         People (Office Manager)
o   HR Function
§  HR review of all policies
§  Defined violation policies (up to and including termination)
o   Training and Awareness
§  Associate/contractor/customer awareness of responsibility related to social media
·         Update training/people on a regular basis.
o   Staffing
§  Evaluate staffing levels related to support
·         Internal support (IT)
·         Customer facing (marketing)
§  Background checks
§  Employment criteria
·         Processes
o   Social media align with business/department processes
o   Brand protection
§  Protect from negative publicity
§  Response channel for negative events (hacking facebook, credit cards, internal data storage)
§  Consistency in branding
o   Monitoring of adverse posts/publicity
§  When identifies, how is this addressed? 
§  Is there a plan in place to handle such situations?
o   Access to social media data
§  Location of data (appropriateness)
§  Data encryption
§  Data classification (define the critical data)
o   Access management
§  Authorization and authentication
§  Contractor access

Technology
At this point, we should be feeling good about the company.  Now lets take the next step into the actual technology.
·         Social media technology infrastructure
o   Anti-virus software management
§  Current licenses
§  Up to date virus definitions
§  Continually monitoring for latest viruses patches
§  Update/deploy virus definitions
·         Incident response
o   Handling outages when they arise
o   Timely response to customer/associate issues
·         Content filtering
o   Are there limitations to content
§  Content the associates can view at work
§  Restricted access to content (internal and customer)
o   Web browser settings
§  Cookie retention
§  Server certifications
§  HTTPS/SSL
§  Popups
§  Java scripts
·         Monitor social media and effect on technology
o   Monitor key matrices
§  Align with business goals
§  Customer “hits”
§  Bandwidth
o   Processes for monitoring (Incident response)
o   Involvement of key stakeholders
§  Owner/President
§  Head of IT
§  Legal Council (legal retainer)
§  Office Manager

As you can see there is a lot to take into consideration.  I would suggest, if there is going to be a big investment in social media, a full FTE be brought on-staff to manage content.  Think of this as your marketing.  Do you have a full time marketer?  If so, social media is a clear interaction with your customer, good or bad.  Proper attention needs to be made.

While modified, the core structure of the last half of this post was supported by ISACA’s Social Media information.  Strategy, People, Processes and Technology

Tuesday, March 5, 2013

Segregation of Duties for Small Businesses

Posted by EYHokie


Small businesses, by the nature of their size, often do not have the ability/resources to fully segregate their back-office operations.  For some companies, the visionary is driving the direction of the company and controls are not at the forefront.  The objective is to grow, grow, grow.  With success, the company continues to focus on the strategy, marketing and operations.  What about the back-office? 

Upon a quick search, I found a great SOD matrix developed by University System of Georgia.  Their definition of SOD is as follows:
“The concept of Segregation of Duties is to separate the major responsibilities of authorizing transactions, custody of assets, recording of transactions and reconciliation/verification of transactions for each business process.”[1]

A document I found from the Technology Evaluation Centers Inc. has a great matrix to use[2].  Due to the size of a small business the matrix is a bit excessive and impossible to fully implement.  Remember, we are talking about that visionary that isn’t worried about the accounting and supporting technology.  What are some of the key functions the firm should care about?  How do they handle them?  I’m going to do a bit of research and find out what some companies do.  Nothing big or formal.




[1] www.busfin.uga.edu/controller/Segregation_of_duties_matrix.xls
[2] http://blog.technologyevaluation.com/files/2008/09/sox-sod.xls

Wednesday, February 27, 2013

Craft Beer

Posted by EYHokie


An article on CNN Money about craft beer got me wondering, what’s the risk for craft breweries?

Protection of storage
As the beer is being made, the vats of beer must be secured. Contaminates introduced into the product can and likely will have a big impact on taste and longevity.

Length of storage
How long can beer sit in storage?  That I am not sure of.  Regardless, inventory must be tracked and the storage date should always be known. LIFO? FIFO?

Transportation of goods
In the beginning, control of goods is very important. The company cannot lose product when their volume is low.  Do you keep shipment in-house? Do you work with a distributer that will carry your inventory? I would image as you grow you will have to work with a distributer.

Lack of back-office expertise
The brew master is likely a dreamer. As I’ve seen on shark tank several times, the investors are willing to invest in the product with the caveat that an MBA be hired to direct the company. I know, an MBA Is not required but you atleast know they have the training.

Inadequate software (GL package)
Similar to above, how much was invested in their GL package? Tracking the finances does little to get the product on the street, as a brewer may think. Their goal is to make a good product and get it in restaurants and grocery stores. Spend on back-office software may not appear important.  If not spend, adequate software.

In the 10 minutes I have, I’ve created the short list above. 

Tuesday, February 26, 2013

System Accounts

Posted by EYHokie


What do I find to be one of the biggest misses in companies today? 

The biggest issue is controlling system accounts.  How can a company control an account that is not tied back to an individual user?  Likely, for ease of management, passwords are the same across all system accounts with the same naming convention.   For example, Windows has a built-in administrator account called “BUILTIN\Administrator.”  Depending on the size of the company, it may be easiest for the IT department to use the same password on all servers for this account.  They’ve changed it from the default, so they feel good about the control.  Well as MicroSoft points out, once a hacker gets control of the password they now have control of every Windows server.  My point though is not a discussion about hacking.  Rather my point is around controlling the activity run under these types of accounts.

The easiest way I can see to control the account is to control the password.  Give one person, typically in a leadership role, ownership of the password.  They are responsible for logging into the system and changing the password.  Therefore, the manager knows exactly who has used the account.  However, the concern remains is that the manager knows who used the account but not what they did with the account.  In a mid-size company, this may not be feasible.  The password may need to be distributed to associates from time to time.  It is the responsibility of the manager to change the password periodically.  How often is up for debate.  If one associate is on-call for a week, the manager changes the account at the beginning of the next week.  Again, this only controls the who not the what.  I am sure there are logging tools available on the market for tracking the activity.  If the tool and password control were put together there would be a reasonable assessment of the who and the what.

How does audit fit into the picture? In a mid-sized company with limited resources, we are going to have to rely on the password controls. The company likely does not have the resources, financial or FTEs, to log and review all activity.  Faith in associates becomes critical.  The system can provide some comfort if the last password change date is available.  Entity level control may provide additional comfort.  Are the IT associates properly trained? Is there a password policy that requires system account passwords to be changed periodically? Are there background checks performed for new hires? While at the entity level, they do start to describe the culture of the company.


Monday, February 25, 2013

Employee Access - Facebook

Posted by EYHokie

I did a quick search for security breach and up came an article about Apple getting hacked.  In reading through the article, I came across a link to a Facebook post.  It looks like there has been a string of high profile companies that have gotten hacked recently.

The article talks about how Facebook employee's went to a website with malware.  That got me thinking!  How do you control employees from an audit standpoint?

As an industry there has been a push to move towards a risk-based approach.  What does that mean?  For me, I believe there are several ways to look at this.  My initial reaction is to approach the issue from a financial standpoint.  For some companies there may be areas of the business that are just as important (i.e. customer information, credit card information, health care information, proprietary data, etc.).  To focus solely on the financials (GL package and those systems feeding it) may not be enough. I hope you have already scoped out the areas of focus.

Lets stick with financials first since Facebook has already have issues (on wall street) with that.  Though I will say, they have a pretty sweet gig with paying no taxes. I believe a malware virus can hit Facebook and, without knowing their accounting structure, should have little financial reporting impact.

Sure.  As IT Auditors we want to dive into all the IT controls that need to be in place in the application and the database.  However, lets take into consideration the bigger picture.  Whats the potential risk? Ultimately it is the risk that the 10K filing is inaccurate.  Is that possible from a malware virus?  I suppose anything is possible, but not likely.  Why?  The accounting department must have strong manual controls in place.  We are not in a state where the accounting department cannot step completely away from manual controls.  There should still be monthly account reconciliations at a minimum.

Do I think Facebook faced a big risk? Absolutely.  Did they face a financial risk, probably not. Should they work to control (either systematically or via policies/training) the websites their employees visit? Absoluately.




http://www.fastcompany.com/3005987/fast-feed/facebook-says-it-was-target-sophisticated-attack
http://www.wsav.com/story/21140135/facebook-stock-slides-after-analysts-downgrades
http://www.forbes.com/sites/robertwood/2013/02/19/tax-increases-why-facebooks-billion-dollar-income-isnt-taxed-at-all-by-irs/

Mid-term Exam

Posted by EYHokie

Tonight is the Spring 2013 class' mid-term exam.  I am very excited for the students.  I know this is a hard exam but it should really show them what they have learned.  My exam is very open ended so they have a lot of room to share with me what their thoughts are.  I want to know they have learned something.

Good luck!