|
The IT Examination Working Group monitors state usage of automated examination tools (ACL), technology changes, and emerging issues, in order to reevaluate examination processes and keep states abreast of the latest tools, techniques, and training.
Update as of May 19, 2009:
The IT Examination Working Group adopted a revised version
of the General Information Technology Review (formerly titled
Examination of Computer-Based Operations) located in Section
3, Part 3 of the Financial Condition Examiner’s Handbook
on April 16, 2009. The guidance outlines the procedures to be followed
when conducting an IT review under the Risk-Focused Examination approach.
In
addition, the IT Examination Working Group adopted a revised version
of Exhibit C – Evaluation of Controls in Information Technology (formerly Exhibit
C – Evaluation of Controls in Information Systems (IS)) located within
Section 2 of the Financial Condition Examiner’s Handbook on May 7, 2009. The
guidance is to be used as a tool when conducting the new IT review procedures
(adopted above). The guidance also follows the Risk-Focused
Examination approach, in addition to utilizing the widely-accepted
COBiT framework.
The new guidance described above can be accessed through the Financial Condition
Examiner’s Handbook Updates
page at the following link:
http://www.naic.org/secure/feh_updates/index.htm .
Note
the website is password protected. The user ID and password
is located in the front of the 2009 Financial Condition Examiner’s
Handbook. Updates are located within the "Risk- Focused Surveillance Approach Updates" link.
2009 Charges
- Monitor state usage of automated examination tools (ACL and TeamMate), technology changes, and emerging issues in order to re-evaluate examination processes and keep states abreast of the latest tools, techniques and training.
- Enhance current training opportunities for auditing tools and techniques: IT Examination, Introductory ACL, Advanced ACL, TeamMate and offering on-site training programs that are available to states upon request.
- Continually review and consider revising the “Examination of Computer-Based Operations” and “Exhibit C – Evaluation of Controls in Information Systems” sections of the NAIC Financial Condition Examiners Handbook.
- Develop and maintain tools that will be part of a more complete information technology (IT) examination process.
|