1 / 2100%
This session we will address some findings in our recent audit.
Always starting off positively we have in most cases mitigated
majority of the previous year findings. However, this year there are
still some reoccurring issues along with one new unresolved. The
utilization of Shadow IT. To specify, active usage of unapproved and
unauthorized of cashless payments at several of our location and
office with in PB. Payment services at pb range from concierge desk
to contactless payment. It is important to remember that revenue of
all type improperly maintain or recorded possess financial, security risk
and could lead to tax evasion are actively taking measure to include a
cease, and this is desisted. We want to ensure that all financial
information reported is within our account information system and
abide by GAAS standards (astatebystate accounting guidre, 2021).
Issue with Shadow IT:
Compliance: the utilization of technology or application possess a
threat of many kinds to include compliance of standard use and
security and goes against our policies at PB as well.
Security - if the technology is not approved or not to standards our
location could be comprise. This would be very costly event to
mitigated. Going over budget in over time to find exactly how or what
was the breach and how to fix it. Also, or equipment are equipped
with everything that any anyone location should need.
Records of Sales- when using an authorized method at the point-of-
sale risk false reporting
Vulnerability – by use unapproved payment staff increase the risk
factor that already exist and create an unknow vulnerability (C-
CORPORATE COMPLIANCE INSIGHTS, 2019).
Ways to prevent noncompliance:
Third Party Compliance- Be able to verify that the vendor has been
approved and ensuring that the vendor are within standard of
requirements of policies and regulation for operation of PCI DSS
Ensuring End 2 -To- End Encryption with the POS is secured on every
level to safeguard financial transaction and records
Implement a financial information system- This allows for a company
to store, organize and analysis information as a stand-alone functional
application
Updates- allowing for regular updates of systems, patching, keeping in
the now to policy changes and updates avoids costly penalties.
The security risk of mobile devices such as mobile devices and
wearable devices that was not originally purposed for payment has to
meet PDIS standards with the exception of some devices stated in
category three scenario two. The location of which audits findings
are reflecting noncompliance will be penalized should the cease and
desist not immediately be effective and implemented throughout the
location.
Works Cited
astatebystate accounting guidre
. (2021, November 5). Retrieved from
AccountingEdu.org: https://www.accountingedu.org/public-
accounting-jobs-what-is-public-accounting-accountant-salaries-and-
degrees/
C-CORPORATE COMPLIANCE INSIGHTS
. (2019, September 9).
Retrieved from The Challenges of Managing PCI DSS Complianc:
https://www.corporatecomplianceinsights.com/challenges-pci-dss-
compliance/
Students also viewed