“Of the top 25 industrial corporations in the United States in 1900, only two remained on that list at the start of the 1960s. And of the top 25 companies on the Fortune 500 in 1961, only six remain there today. Some of the leaders of those companies that vanished were dealt a hand of bad luck. Others made poor choices. But the demise of most came about because they were unable simultaneously to manage their business of the day and to build their business of tomorrow. As you read this, IBM begins its 101st year. Today we take a moment to step back and view the longer arc of history. We’d like to share some of what we have learned—sometimes in humbling ways—on our journey so far.” Read the full essay on the IBM 100 website. Explore an evolving collection of stories about the 100 IBM innovations that helped shape the last century. Celebrate IBM’s 100-year history with commemorative memorabilia designed exclusively for IBMers, families and friends.
Friday, June 24, 2011
Wednesday, June 22, 2011
20 Questions Directors Should Ask about Information Technology Security
“The CICA’s Information Technology Advisory Committee developed this booklet to guide Boards of Directors in evaluating information technology (IT) security issues. It should also be of use to other bodies responsible for governance — in particular audit committees and strategic bodies such as IT steering committees, risk management committees, and CEO/CFO controls certification committees. Directors are expected to satisfy themselves that risks potentially jeopardizing the integrity of information, the availability of information and operational systems, the confidentiality of sensitive data, and compliance with regulatory bodies, are identified and reduced or eliminated. This booklet provides questions for Boards to ask senior management as well as the context needed to ask the questions and assess responses. In this document, IT Security (Security) is defined as the protection of data captured, processed, transmitted, reported and stored electronically. IT Security also covers the protection of related components such as application systems, system software, networks and hardware, as well as the supporting people, policies, procedures, processes and organization.” (Read the CICA publication 20 Questions Directors Should Ask about Information Technology Security.)
Labels:
CICA,
IT,
risk and uncertainty,
risk management,
security
Friday, June 17, 2011
Green Gauge
The idea that business organizations have a responsibility to account for their impact on the environment once seemed radical, even eccentric. Now, it is accepted as a mainstream concept – but to put it into practice, corporate reporting will have to evolve dramatically. It’s a challenge to which the accountancy profession must step up, if it is to retain its relevance in the 21st century. As a start, the Sustainability Advisory Group of the Institute of Chartered Accountants of Scotland (ICAS) has launched a dedicated section on the institute’s website providing links to a number of useful resources and a template Corporate Social Responsibility Report. (Read the article “Green Gauge” in the May 2011 issue of CA Magazine (Scotland) online.)
Wednesday, June 15, 2011
Data-Centric Security - A CICA White Paper
In most organizations, data that was once static and stored in one place now moves freely from platform to platform throughout the organization and beyond. Because data is now often generated and modified by users and is resident in different forms and versions in different places simultaneously, maintaining a secure environment is a growing challenge. A White Paper issued by the Canadian Institute of Chartered Accountants (CICA) suggests that a data-centric policy should be the focus for management, auditors and others involved in securing data in this new mobile environment. The term “security” is taken in its broadest sense to include confidentiality, integrity (accuracy, completeness and validity) and availability. (Read the CICA publications on Data-Centric Security and
Labels:
CICA,
collaboration,
data integrity,
data theft,
IT,
reputation risk,
risk management,
security
Monday, June 13, 2011
A Framework for Board Oversight of Enterprise Risk
The Risk Oversight and Governance Board of the Canadian Institute of Chartered Accountants (CICA) has developed "A Framework for Board Oversight of Enterprise Risk" to provide a practical approach to risk oversight, including a methodology and tools designed specifically for boards of directors. The framework includes a nine-part process to assist boards in better identifying and addressing critical risk as well as understanding the inter-connectivity of risks.
Subscribe to:
Posts (Atom)
