Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

PO7.8 - Job Change and Termination

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective PO7.8 - Job Change and Termination is contained within Process Popup Manage IT Human Resources.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

 
This Topic Has:
2 Members
0 Online
698 Visits

 Recent Discussions

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Points: 3


Job Change and Termination

Take expedient actions regarding job changes, especially job terminations. Knowledge transfer should be arranged, responsibilities reassigned and access rights removed such that risks are minimised and continuity of the function is guaranteed.

View value and Risk Drivers  help

Hide value and Risk Drivers help


Value Drivers

  • Efficient and effective continuation of business-critical operations
  • Improved staff retention
  • A more secure information environment through timely and appropriate restriction of access
  Risk Drivers
  • Unauthorised access when employees are terminated
  • Lack of smooth continuation of business-critical operations

View Control Practices  help

Hide Control Practices  help

  1. Include the need for job change and termination procedures within human resource policies.
  2. Document and implement exit procedures for termination of employment that include reassignment of job duties so disruptions are minimised and job transfer procedures including necessary knowledge transfer, timely securing of logical and physical access, security of the organisation’s assets, and exit interviews.
  3. Design job change procedures to ensure efficient continuation with minimal disruption, providing guidance on the need for job mentoring, job handover steps and preparatory formal training.
  4. Include in job change procedures confirmation that logical and physical access privileges have been revised and aligned with the new job requirements.

 

Discussions: 0 total

Must be a Topic member to contribute

No Results Found

Documents & Publications: 7 total

Must be a Topic member to contribute
View All »
Books
Posted by ISACA 11 days ago
Books
Posted by ISACA 230 days ago
Books
Posted by ISACA 302 days ago
Books
Implement a systematic approach to security in mobile application development with help from this practical guide that also features case studies, code examples and best practices.
Posted by ISACA 351 days ago
Books
Posted by ISACA 720 days ago
Books
Posted by ISACA 720 days ago

Events & Online Learning: 7 total

7 May 2012
ISACA International Event
Orlando, Florida, USA
Get the knowledge you need to stay one step ahead of the competition and keep up with changing professional trends at ISACA’s North America CACS Conference.
12 Jun 2012
ISACA International Event
Dallas, Texas, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
7 Aug 2012
ISACA International Event
Chicago, Illinois, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
11 Sep 2012
ISACA International Event
San Francisco, California, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
2 Oct 2012
ISACA International Event
Orlando, Florida, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.
6 Nov 2012
ISACA International Event
New York, New York, USA
ISACA Training is a unique educational event designed to provide the tools you need to maintain, update and upgrade your skills, and to continue your professional development.

Journal Articles: 84 total

Volume 2, 2012
by Carl A. Foerster
This article discusses recently conducted research that examined the factors considered in the decision to apply access controls to segregate information within an organization.
Volume 1, 2012
by Michael Mendelsohn, CISSP, Antoine Philipovitch, William Welch, CISM, and Robert Zanella, CISA
One of today’s big security marketing pushes is enterprise single sign-on (ESSO).
Volume 1, 2012
by Tommie W. Singleton, Ph.D., CISA, CGEIT, CITP, CPA
This article offers some basic guidance to IT auditors in evaluating the access controls over relevant data files.
Volume 6, 2011
by Harmeet Kaur, CEH
As today’s business climate demands greater efficiency, security and regulatory compliance, the need for an effective IAM process has never been more pressing.
Volume 6, 2011
by Shiu-Kai Chin, Beth Older | Reviewed by Connie Spinelli, CISA, CFE, CIA, CMA, CPA
Access control, security and trust are among the greatest risks—compliance and otherwise—facing corporations today.
Volume 5, 2011
by Tommie W. Singleton, Ph.D., CISA, CGEIT, CITP, CPA
This article provides the IT auditor with concepts, techniques, processes and structures that can mitigate the change management risk associated with AppDev.

Wikis: 2 total

Blog Posts: 12 total

On the AS/400 (System i) it is possible to audit for default passwords using the ANZDFTPWD command. A default password is defined as a password which is the same as the user profile. The command behaves slightly differently depending on the value of the s...
Posted By : Ian Cooke | 0 comments
The main idea I am trying to advocate with these posts is a simple one.  Compare a database you are auditing against a database that you know already meets the standards required by the organisation you are auditing. This is achieved by creating “CSV ty...
Posted By : Ian Cooke | 1 comments
Before we get into auditing Oracle privileges a reminder of a few definitions might be helpful. A user privilege is the right to run a particular type of SQL statement, or the right to access an object belonging to another user, run a PL/SQL package, and...
Posted By : Ian Cooke | 1 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 0 comments
Hola, se les informa a todos los que llamaron y se registraron para los cursos de CISA 2.011, que los mismos comenzarán los siguientes días: 12SEP - 40 Hrs Grupo A  19SEP - 40 Hrs Grupo B 26Sep - 40 Hrs Grupo C Modalidad 16 Hrs intensivas y Presenciale...
Posted By : Alexander Osorio | 0 comments
17 Aug 2011
Posted By : masarker | 0 comments