Verifying compliance with controls
Scenario: PS013 - Verifying system compliance with internal and external controls
Main Description

Context

Government regulations require company executives to certify the integrity of the systems generating financial reports. Part of maintaining integrity is controlling changes to critical infrastructure components that support financial reporting applications. Similarly, internal controls might require reporting against baseline server, desktop, or application configurations. Given the fast pace of change, its important to know what has changed and whether or not those changes were approved.

Description

Steps Process and Activity Roles Work products Tools Tools
Identify and document system or application baseline configurations.
Configuration Management
Configuration Management
Identify Configuration Items
Identify Configuration Items
Configuration Librarian
Configuration Librarian
Configuration Baseline Report
Configuration Baseline Report
Periodically scan application or CIs to verify configurations and detect violations.
Configuration Management
Configuration Management
Verify and Audit Configuration Items
Verify and Audit Configuration Items
Configuration Auditor
Configuration Auditor
Compliance Audit Reports
Compliance Audit Reports
For each CI in violation of the baseline a change request is created to document and initiate the correction of the CI.
Configuration Management
Configuration Management
Verify and Audit Configuration Items
Verify and Audit Configuration Items
Configuration Auditor
Configuration Auditor
Request for Change
Change Request
Review and schedule the required change.
Change Management
Change Management
Accept and Categorize Change
Accept and Categorize Change
Change Manager
Change Manager
Request for Change
Change Request
Process the change request and change the CI back to the desired state.
Change Management
Change Management
Prepare, Distribute, and Implement Change
Coordinate Change Implementation
Change Implementor
Request for Change
Change Request

Obtaining more information

To get more information, talk to a representative, purchase IBM® Service Management tools, or visit the IBM Service Management page.