Table II.

Measurement items for SysTrust

The main principlesSelected items measuresReferences
AvailabilityPolices for minimizing risk system downtime;
Data backup, and restoration
Incremental backup and differential backup
Disaster plan recovery
Business continuity planning
AICPA, (2013; 2017); Greenberg, et al. (2012) Saito, (2001) Bedard, et al. (2005).
SecurityIT security policy and producers
Security awareness, and communication
Logical access; Physical access
Security monitoring
User authentication;
Incident management
Systems development, and maintenance
Personnel security; Configuration management; Change management
Monitoring, and compliance
AICPA (2013; pp. 2-17); Abu‐Musa, (2010); Saito, (2001).
ConfidentialityConfidentiality policy; confidentiality of inputs; confidentiality of data processing
confidentiality of outputs
Information disclosures (including third parties)
Confidentiality of information in systems development
AICPA, (2013), Saito, (2001); Boritz, (2005).
Integrity processingSystem processing integrity policies
Completeness, accuracy, timeliness, and authorization of inputs,
system processing, and outputs.
Information tracing from source to disposition
AICPA, (2013, 2017);
Greenberg, et al. (2012), Saito, (2001); Bedard, et al. (2005).
PrivacyIt defines documents, communicates, and assigns accountability for its privacy policies and procedures
It provides notice about its privacy policies and procedures
It describes the choices available to the individual and obtains implicit or explicit consent with respect to the collection, use, and disclosure of personal information
It collects personal information only for the purposes identified in the notice.
It limits the use of personal information to the purposes identified in the notice
It provides individuals with access to their personal information for review and update
It discloses personal information to third parties only for the purposes identified in the notice and with the implicit or explicit consent of the individual
It maintains accurate, complete, and relevant personal information for the purposes identified in the notice
AICPA, (2013, 2017); Greenberg et al. (2012), Boritz, (2005).

or Create an Account

Close subscription notice
Close access options