Measurement items for SysTrust
| The main principles | Selected items measures | References |
|---|---|---|
| Availability | Polices for minimizing risk system downtime; Data backup, and restoration Incremental backup and differential backup Disaster plan recovery Business continuity planning | AICPA, (2013; 2017); Greenberg, et al. (2012) Saito, (2001) Bedard, et al. (2005). |
| Security | IT security policy and producers Security awareness, and communication Logical access; Physical access Security monitoring User authentication; Incident management Systems development, and maintenance Personnel security; Configuration management; Change management Monitoring, and compliance | AICPA (2013; pp. 2-17); Abu‐Musa, (2010); Saito, (2001). |
| Confidentiality | Confidentiality policy; confidentiality of inputs; confidentiality of data processing confidentiality of outputs Information disclosures (including third parties) Confidentiality of information in systems development | AICPA, (2013), Saito, (2001); Boritz, (2005). |
| Integrity processing | System processing integrity policies Completeness, accuracy, timeliness, and authorization of inputs, system processing, and outputs. Information tracing from source to disposition | AICPA, (2013, 2017); Greenberg, et al. (2012), Saito, (2001); Bedard, et al. (2005). |
| Privacy | It defines documents, communicates, and assigns accountability for its privacy policies and procedures It provides notice about its privacy policies and procedures It describes the choices available to the individual and obtains implicit or explicit consent with respect to the collection, use, and disclosure of personal information It collects personal information only for the purposes identified in the notice. It limits the use of personal information to the purposes identified in the notice It provides individuals with access to their personal information for review and update It discloses personal information to third parties only for the purposes identified in the notice and with the implicit or explicit consent of the individual It maintains accurate, complete, and relevant personal information for the purposes identified in the notice | AICPA, (2013, 2017); Greenberg et al. (2012), Boritz, (2005). |
| The main principles | Selected items measures | References |
|---|---|---|
| Availability | Polices for minimizing risk system downtime; | |
| Security | IT security policy and producers | |
| Confidentiality | Confidentiality policy; confidentiality of inputs; confidentiality of data processing | |
| Integrity processing | System processing integrity policies | |
| Privacy | It defines documents, communicates, and assigns accountability for its privacy policies and procedures |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.