Procedure Step:Policies and Procedures
Audit Step:
Review policy and procedures manuals to determine if they are current and are reviewed periodically. Determine if personnel have access to copies of manuals. Obtain any available agency specific procedures that the agency has developed to meet State Standards for Information Security such as:
1. Environmental controls over the mainframe and/or servers;
2. what physical security requirements exist for the application and what restrictions are present for system access;
3. backup policies and procedures;
4. password policies and procedures; and,
5. how access to system documentation, data files, password files, programs, and the State IT agency are safeguarded.
Purpose:
To obtain relevant agency policies and procedures.

