Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO4.14 - Contracted Staff Policies and Procedures

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO4.14 - Contracted Staff Policies and Procedures is contained within Process Popup Define the IT Processes, Organisation and Relationships

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
2 Members
0 Online
2616 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!


Contracted Staff Policies and Procedures

Ensure that consultants and contract personnel who support the IT function know and comply with the organisation’s policies for the protection of the organisation’s information assets such that they meet agreed-upon contractual requirements.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Contracted staff supporting the needs of the business
  • Knowledge sharing and retention within the organisation
  • Protection of the information assets
  • Control over the contracted personnel’s activities
  Risk Drivers
  • Increased dependence on key (contracted) individuals
  • Gaps between expectations and the capability of contracted personnel
  • Work performed not aligned with business requirements
  • No knowledge capture or skills transfer from contracted personnel
  • Inefficient and ineffective use of contracted staff
  • Failure of contracted staff to adhere to organisational policies for the protection of information assets
  • Litigation costs from disagreements over expectations for responsibility and accountability

View Control Practices  help

Hide Control Practices  help

  1. Implement policies and procedures that describe when, how and what type of work can be performed or augmented by consultants and/or contractors, in accordance with the organisation’s enterprisewide IT procurement policy.
  2. Require contractors to comply with the organisation’s policies and procedures (e.g., requirements for security clearance, physical and logical access control requirements, client equipment and personnel, information confidentiality requirements, and nondisclosure agreements). At the commencement of the contract, the contractor formally agrees to be bound by the organisation’s IT policies. Contractors are advised that management reserves the right to monitor and inspect all usage of IT resources, including e-mail, voice communications, and all programs and data files.
  3. Provide contractors with a clear definition of their roles and responsibilities as part of their contracts. Contractors are explicitly required to document their work to agreed-upon standards and formats.
  4. Ensure that an individual with appropriate authority within the IT function has responsibility for reviewing the contractor’s work and approving payments.

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 83 total

Must be a Topic member to contribute
View All »
Downloads
Posted by ISACA 708 days ago
Downloads
Posted by ISACA 761 days ago
Downloads
Experienced business and IT professionals know that optimizing their use of big data as a resource will deliver real business value to the enterprise stakeholders.
Posted by ISACA 64 days ago
Downloads
Advanced persistent threat (APT) has been a term used frequently during security threat discussion; however, confusion exists as to what an APT is and how to manage the risk associated with it.
Posted by ISACA 89 days ago
Exam Preparation
Posted by ISACA 132 days ago

Events & Online Learning: 6 total

29 Oct 2012
ISACA International Event
New York, NY, USA
16 Sep 2013
ISACA International Event
London, England
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2013 in Berlin—the leading European conference for IT audit, assurance, security and risk professionals. Save over US $200 when you register by 22 July!
30 Sep 2013
ISACA International Event
Medellín, Colombia
La Conferencia Latinoamericana CACS/ISRM 2013 en Medellín, Colombia es la conferencia principal latinoamericana para los profesionales de auditoría, riesgo y seguridad de la información. Ahorre más de EE.UU. $ 100 si se inscribe antes del 7 de agosto!
14 Oct 2013
ISACA International Event
Boston, MA, USA
6 Nov 2013
ISACA International Event
Las Vegas, NV, USA
North America ISRM is a multidimensional event featuring security and risk content, and the security programs, tools and the resources you need to be responsive to industry changes.

Journal Articles: 176 total

Volume 2, 2013
by Rajesh Bhatia, CISA, CGEIT, PMP, MDP
This article discusses the benefits of using the framework of the five IT governance focus areas.
Volume 6, 2012
by Mukul Pareek, CISA, ACA, AICWA, PRM
In the world of market and credit risk, scenario analysis is used as a part of stress testing.
Volume 2, 2012
by Steven J. Ross, CISA, CISSP, MBCP
The Conference Board study addresses the resilience of companies “to bounce back from a disruption” caused by security events, which are defined rather loosely as environmental disasters, terrorism and cyberattacks.
Volume 5, 2011
by Steven De Haes, Ph.D., Dirk Gemke, John Thorp, CMC, ISP, and Wim Van Grembergen, Ph.D.
The goal of this article is to provide insight to practitioners regarding how to introduce better value management approaches.
Volume 2, 2011
by Steven J. Ross, CISA, CISSP, MBCP
How much more is a secure company worth than an insecure one?
Volume 2, 2011
by Gan Subramaniam, CISA, CISM, CCNA, CCSA, CIA, CISSP, ISO 27001 LA, SSCP
What should be our approach to determining and reaching agreement on the optimal percentage of business operations that must be or can be recovered in the event of a crisis?

Wikis: 2 total

Blog Posts: 63 total

Grupos de Estudio para Acreditaciones de JUNIO, SEPTIEMBRE Y DICIEMBRE 2013. Para los que esten interesados en la presentación del exámen de certificación CISA y CISM  o para cualquiera que desee comenzar a prepararse para estas o las próximas pruebas, pu...
Posted By : Alexander Osorio | 0 comments
DISCLAIMER :- Below information is just for knowledge sharing purpose and reference. Personally or on behalf of any organization; I do not recommend any specific / particular tool listed below. These are the ones which I have come across. there may be t...
Posted By : prathameshkarekar | 0 comments
Information security has been and remains a very specialized subject. Its early beginnings can be traced to the study of advanced mathematics and cryptography. even today the real theoretical advances happen in University Research Departments, Computer La...
Posted By : Dr Vishnu | 1 comments
5 Feb 2013
Physical Security Fire safety and equipment information: www.usfa.fema.gov/safety Halon alternatives: https://www.denix.osd.mil/denix/Public/News/DLA/Halon/hal1.html Biometric systems used by U.S. Homeland Security: http://tinyurl.com/564lzt Alarm a...
Posted By : Jermaine800 | 0 comments
(Cross posted in http://www.leetsecurity.com/en/2013/01/18/certification-or-rating)In some occasions, specially when the issue we want to analyze or study is complex or very new, it could be useful to use analogies. We say that because, to explain the use...
Posted By : Antonio Ramos | 0 comments
The technology is changing very fast and becoming more and more sophisticated everyday, which is helping billions of people in their everyday life. There are new innovations happening every day in the world of information technology, more and more softwar...
Posted By : Vikalp253 | 0 comments