Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO4.14 - Contracted Staff Policies and Procedures

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO4.14 - Contracted Staff Policies and Procedures is contained within Process Popup Define the IT Processes, Organisation and Relationships

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

This Topic Has:
3 Members
0 Online
4386 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer

Contracted Staff Policies and Procedures

Ensure that consultants and contract personnel who support the IT function know and comply with the organisation’s policies for the protection of the organisation’s information assets such that they meet agreed-upon contractual requirements.

View value and Risk Drivers  help

Hide value and Risk Drivers help

Value Drivers

  • Contracted staff supporting the needs of the business
  • Knowledge sharing and retention within the organisation
  • Protection of the information assets
  • Control over the contracted personnel’s activities
  Risk Drivers
  • Increased dependence on key (contracted) individuals
  • Gaps between expectations and the capability of contracted personnel
  • Work performed not aligned with business requirements
  • No knowledge capture or skills transfer from contracted personnel
  • Inefficient and ineffective use of contracted staff
  • Failure of contracted staff to adhere to organisational policies for the protection of information assets
  • Litigation costs from disagreements over expectations for responsibility and accountability

View Control Practices  help

Hide Control Practices  help

  1. Implement policies and procedures that describe when, how and what type of work can be performed or augmented by consultants and/or contractors, in accordance with the organisation’s enterprisewide IT procurement policy.
  2. Require contractors to comply with the organisation’s policies and procedures (e.g., requirements for security clearance, physical and logical access control requirements, client equipment and personnel, information confidentiality requirements, and nondisclosure agreements). At the commencement of the contract, the contractor formally agrees to be bound by the organisation’s IT policies. Contractors are advised that management reserves the right to monitor and inspect all usage of IT resources, including e-mail, voice communications, and all programs and data files.
  3. Provide contractors with a clear definition of their roles and responsibilities as part of their contracts. Contractors are explicitly required to document their work to agreed-upon standards and formats.
  4. Ensure that an individual with appropriate authority within the IT function has responsibility for reviewing the contractor’s work and approving payments.

Discussions: 1 total

Must be a Topic member to contribute
Hello All, I am a member of
Giovanni998 | 2/17/2015 6:46:00 PM | COMMENTS(0)

Documents & Publications: 59 total

Must be a Topic member to contribute
View All »
Posted by FarmService 1379 days ago
Posted by FarmService 2464 days ago
Posted by ISACA 797 days ago
Posted by ISACA 939 days ago

Events & Online Learning: 9 total

16 Mar 2015
ISACA International Event
Orlando, FL, USA
15 Jun 2015
ISACA International Event
Ciudad de México, Mexico
1 Aug 2016
ISACA International Event
Chicago, IL, USA

Journal Articles: 60 total

Volume 3, 2107
by Jayakumar Sundaram, CISA, ISO 27001 LA
The SoA is a continuously updated and controlled document that provides an overview of information security implementation.
Volume 6, 2017
by Pedro Alexandre de Freitas Pereira, CCNA
The security of technology has become an increasing global concern. For some professionals such as network managers or security managers, this subject is intrinsically linked to their daily work.
Volume 4, 2017
The root causes of privacy incidents include the outsourcing of data, malicious insiders, system glitches, cyberattacks, and the failure to shred or dispose of privacy data properly.
Volume 4, 2017
by Mathew Nicho, Ph.D., CEH, CIS, ITIL Foundation, RWSP, SAP, Shafaq Khan, Ph.D., CIS, PMBOK, PMP, SAP, and Ram Mohan, CRISC, CISM, CGEIT, ISO 27001, ITIL Foundation
A key issue often cited by information systems (IS) executives in the last three decades is aligning IT with business, which assists in realizing value from IT investments.
Volume 4, 2017
by Steven De Haes, Ph.D., Anant Joshi, Ph.D., Tim Huygh and Salvi Jansen
IT governance, also referred to as governance of enterprise IT (GEIT) or corporate governance of IT, is a subset of corporate governance that is concerned with enterprise IT assets.
Volume 4, 2017
by Mathew Nicho, Ph.D., CEH, CIS, ITIL Foundation, RWSP, SAP, Shafaq Khan, Ph.D., CIS, PMBOK, PMP, SAP and Ram Mohan, CRISC, CISM, CGEIT, ISO 27001
The Emirates National Oil Company embarked on an initiative to realize value out of IT assets through Information Technology Infrastructure Library (ITIL) process implementation.

Wikis: 2 total

Blog Posts: 65 total

Have you experienced ransomware attack so far and, if yes, what did you do to resolve? I set up Twitter poll here: It lasts for seven days. Thank you for taking part in the poll.
Posted By : Dragan Pleskonjic | 0 comments
Globally, many organizations are spending millions of dollars protecting their businesses and its enabling infrastructure, but are they really secure? We shall discuss answer to this question in a little while. We need to understand core basics before we ...
Posted By : SudireddyRamreddy | 2 comments
Mi primer acercamiento real al Framework (o Marco de Referencia) de ISACA COBIT 5, fue a mediados del año pasado (2016) cuando decidí tomar un curso de examinación para la certificación de COBIT® 5 Foundation (Fundamentos de COBIT 5). La jerga técnica me ...
Posted By : MNUNEZA | 0 comments
There is need to for ISACA through our local; chapter to allow fees to be paid in installments or split invoices given the fact that in our country - one has to find currency first and then deposit into a VISA card account. Thus i can raise my exam and ma...
Posted By : Hamadzashe | 0 comments
Hello fellow members COBIT 5 is an excellent guide to developing ICT Governance Frameworks. Many organisations have well documented Frameworks but find it challenging when it comes to implementation. The objective of this post is to start a debate o...
Posted By : Thansen Singh | 1 comments
Information Security and Privacy is hot issue at present time. Number of security breaches is rapidly increasing.  In case of late detection, costs of breaches are skyrocketing. In the same time Artificial Intelligence (AI), Machine Learning (ML) are fast...
Posted By : Dragan Pleskonjic | 0 comments