前沿观点 | Facebook数据又泄露: 这几方面, 内审怎可忽视!
- 2019-05-24 06:55:00
- 理查德·钱伯斯 转贴
- 4207
原标题:内部审计人员从Facebook数据泄露中应吸取的教训
曾几何时,作为社交媒体的宠儿,Facebook在用户和投资者眼中几乎永不犯错。然而,继去年的数据丑闻后,最近遭遇了又一次挫折。一家网络安全公司的研究人员发现,在亚马逊(Amazon.com)运行的云计算服务器上,Facebook的用户信息很容易获取。
大约一年前,Facebook因剑桥分析公司(Cambridge Analytica)数据泄露丑闻而受到热议,当时一名应用程序开发商与一家政治咨询公司共享了数百万Facebook用户的数据。尽管Facebook首席执行官马克•扎克伯格(Mark Zuckerberg)保证公司将采取更多措施保护用户数据,但今天涉及亚马逊(Amazon)云数据的失误仍被曝光。
从内部审计的角度来看,Facebook的困境提供了一个清晰而令人信服的教训:数据曾经被看作一种可以加杠杆的资产,如今也必须被视为一种潜在的负债或风险。越来越多的人要求加强对数据的保护,或者更准确地说,要求保护个人可识别的信息,因为这些信息成为市场营销人员、零售商、政治活动人士以及其他想要影响公众想法和行为的人的宝贵财富。
越来越多的政府正在考虑立法,要求数据收集者保护数据及其隐私。IBM商业价值研究所(IBM Institute of Business Value)最近的一项调查清楚地表明,公众也有这种要求。
IBM上述调查的四分之三的对象表示,他们不相信公司能够保护他们的数据。此外,87%的人认为政府应该对管理个人数据的公司进行监管,40%的人认为如果高级管理人员不能保护他们的数据,就应该被罚款或监禁(见“消费者的数据焦虑”)。
简而言之,数据呈现出两面性。数据挖掘和数据分析是战略业务决策的基本步骤。它帮助企业和组织建立基于历史信息的模型来预测未来的行为。但糟糕地管理数据和错误地理解数据,将会导致风险。当未能保护数据而损害组织的声誉时,这种风险变得更加明显和复杂。事实上,在回应IIA 2019年内部审计脉冲调查的首席审计执行官中,70%将数据泄露造成的声誉损害列为他们对网络安全的最大担忧。
组织是如何收集、管理、保护、使用和共享数据的呢?他们是如何处理过去和当前的数据使用和存储实践的呢?对这些问题,内部审计人员必须培养并保持敏锐的理解。可以肯定的是,列出一个内部审计能够为数据提供确认服务领域的清单是很重要的。
遵循情况
从欧洲的《全球数据保护条例》(Global Data Protection Regulation),到将于明年生效的《加州消费者隐私法》(California Consumer Privacy Act),新的数据保护法规正迅速形成一个复杂的合规风险网络。内部审计必须跟上这些规定,以及任何潜在的新规定,并就组织必须采取的步骤提供洞察力和远见。
运营和流程
处理如何收集、管理和保护数据的策略和流程提供了许多确认业务的机会。与数据保护相关的一个关键领域是如何在内部和外部共享数据。对于许多组织来说,旨在保护数据的政策和流程是次要的,而那些旨在将数据货币化的政策和流程则会增加数据泄露的风险。
战略
董事会和高管层根据包括数据分析在内的许多因素做出战略决策。内部审计必须对数据的准确性和分析过程本身提供确认。
文化
这是数据风险中更具挑战性且最不明显的方面之一。内部审计必须了解组织对数据的处理方法和决策如何影响日常运营。更重要的是,内部审计人员需要理解组织为适应不断变化的数据需求所拥有的能力。文化通常被定义为“在这里我们如何做事”。如果“我们如何做事”忽视了保护数据的需要,那么我们就面临着一个文化问题。
分析机构Gartner在2018年的一项调查发现,87%以上的组织被归类为商业智能和分析成熟度较低的组织。这不仅给那些想要增加数据资产价值并利用新兴分析技术的公司制造了障碍,还表明它们对数据使用的法律和伦理含义知之甚少。
显然,内部审计可以提供很多与数据相关的信息。CAEs应向董事会和行政管理部门坦率地说明在这里列出的每一个领域中确认业务的价值,并准备在机会出现时提供这种保证。
我一如既往地期待着您的真知灼见。
【原文】
FacebookData Exposure Offers Critical Lesson for Internal Auditors
Richard Chambers April08, 2019
Facebook, once the social media darling that could do nowrong in the eyes of users and investors, was hit with another setbackrecently. Researchers at a cybersecurity firm discovered Facebook userinformation readily available on cloud computing servers runby Amazon.com.
The revelation comes about a year after Facebook waspilloried for the Cambridge Analytica scandal, where an app developer shareddata on millions of Facebook users with a political consulting firm. Despiteassurances from Facebook CEO Mark Zuckerberg that the company would do more toprotect user data, lapses such as the one involving Amazon continue to come tolight.
From an internal audit perspective, Facebook's woes offer aclear and compelling lesson: Data, once viewed solely as an asset to beleveraged, now must be viewed as a potential liability or risk, as well. Demandis growing for greater protection of data, or more precisely, protecting thepersonally identifiable information that makes such information a treasuretrove for marketers, retailers, political campaigns, and others who want toinfluence what the public thinks and does.
More governments are considering legislation requiring dataaggregators to protect data and ensure privacy. A recent survey from the IBMInstitute of Business Value makes it clear that the public also is demandingaccountability.
Three quarters of respondents to the IBM survey said theydon't trust companies with their data. Additionally, 87 percent saidgovernments should regulate companies that manage personal data, and 40 percentsaid C-level executives should be fined or imprisoned for failing to doso (see "The Consumer's Data Anxiety" ).
In short, data has taken on a Dr. Jekyll and Mr. Hydepersona. Mining and analyzing data is a fundamental step in strategic businessdecisions. It helps businesses and organizations build models based onhistorical information to predict future behavior. But poor data management anda failure to understand what it tells us is a risk. That risk becomes moredistinct and complex when failing to protect data damages the organization'sreputation. Indeed, 70 percent of chief audit executives responding to TheIIA's 2019 Pulse of Internal Audit survey listed reputational damage from a data breach astheir biggest cybersecurity concern.
Internal auditors must cultivate and maintain a keenunderstanding of how their organizations collect, manage, protect, use, andshare data. They also must have a handle on past and current practices on datausage and storage. To be sure, the list of areas where internal audit canprovide assurance on data is significant.
Compliance . New data-protection regulations — from the Global DataProtection Regulation in Europe to the new California Consumer Privacy Act setto go into effect next year — are quickly creating a complex web of compliancerisks related to data protection. Internal audit must stay abreast of theseregulations, as well as any potential new regulations, and provide insight andforesight on steps that organizations must take to comply.
Operational. Policies and processes addressing how data is collected,managed, and protected offer many opportunities to provide assurance. One keyarea relating to data protection is how it is shared internally and externally.For many organizations, policies and processes designed to protect data aresecondary to those designed to monetize it, which heightens the risk of databreaches.
Strategic. Boards and C-suites make strategic business decisions basedon many factors, including data analytics. Internal audit must provideassurance on the accuracy of the data and on the analysis process itself.
Culture. This is one of more the challenging and least obvious aspectsof data risk. Internal audit must understand how an organization's approach toand decisions made about data influence day-to-day operations. What's more,auditors need to grasp the organization's capacity to adapt to changing dataneeds. Culture is often defined as "how we do things around here." If"how we do things" disregards the need to protect data, then we havea cultural problem, too.
A 2018 Gartner survey found more than 87 percent oforganizations are classified as having low business intelligence and analyticsmaturity. This not only creates obstacles for organizations that want toincrease the value of their data assets and exploit emerging analyticstechnologies, it also suggests there is little understanding of the legal andethical implications of data usage.
Clearly, there is much internal audit can offer relating todata. CAEs should speak candidly to boards and executive management on thevalue of assurance in each of the areas outlined here and be prepared toprovide that assurance when the opportunity arises.
As always, I look forward to your comments.
- 2025年培训课程计划:审计/内控/合规(全年计划·收藏)
- “经济责任审计实务与案例” (线上+线下) 培训通知
- 穿透式监管视角下的企业内控升级与风险管控实践-研修班培训通知
- AI驱动“审计人员四能四会胜任力提升与思维决策”(线上+线下)培训通知
- AI驱动采购全流程风险管理、审计实务课程-培训通知
- 拥抱AI:DeepSeek赋能工程建设项目审计实务-培训通知
- 拥抱AI:DeepSeek赋能内审智能化转型与实践课程
- DeepSeek驱动下的内部审计创新与 价值重构(线上/线下)实务培训通知
- 公开课 / 内训课 / 网课-审计·内控·财税:实务课程计划清单
- 行政事业单位严肃财经纪律暨内部控制业务能力提升-培训通知
- 行政事业单位财经纪律教育与财会审计管理提质增效-培训班
- 高风险业务经营价值挖掘与风控实务(线上+线下)培训通知
- 【热门】新时期内审精英实务综合课
- 【最新】中/高级审计师 / CIA 考试培训课程
- 拥抱AI:DeepSeek赋能智能财务创新与实践课程
- 128554 【2025高级审计师/初级中级考试 // 正高/高审评审培训课程】
- 92665 【CIA 国际注册内部审计师】培训课程全集
- 84538 【课件】内部审计实务+案例·精讲
- 79691 【课件】注册制IPO审计全流程实务详解
- 79663 【课件】审计方案+报告+证据+审计能力建设+经济责任审计培训课程
- 79608 【EPC工程总承包项目管理与审计实务】培训课程
- 79255 【课件】国有企业审计与内部控制
- 79089 【经济责任审计·准则解读】课程
- 78991 【绩效审计与内部控制审计】培训课程
- 78794 【建设工程全过程审计】培训课件
- 77369 【建设项目竣工决算审计】培训课程
- 77218 【工程项目招投标风险管理与审计】培训课程
- 80948 《内部审计工作法》
- 80083 《企业内部审计全流程指南》
- 79959 《数字化审计实务指南》高效审计工具书
- 79502 《内控总监工作笔记》 企业内部控制工作法及案例解析
- 79487 《金融机构审计实务指南》
- 79131 《内部审计工作指南》+《增值型内部审计》+《内部审计情景案例》《内部审计思维与沟通》《合规型内部审计》
- 78980 《行政单位经济责任审计实务指南》
- 78863 《企业内部控制流程手册》- 第3版
- 78767 《内审人员进阶之道 内部审计操作实务与案例解析》
- 78751 《业内部控制架构设计实操手册》
- 78634 《财务审计实务指南》
- 78456 《房地产企业审计从入门到精通》模块分解+操作流程+案例解析
- 78124 《企业内控精细化管理全案》第三版
- 78044 《企业内部控制基本规范操作指南 图解版》
- 78029 《舞弊审计实务指南》
- 77492 《企业内部控制全流程实操指南》