You are on page 1of 1

PwC 2021 Internal Control Audit Findings

2.0 IT General Control


2.1 Password control for Boss I-Net (payroll application) & Windows 10 Pro operating system not configured adequately

No PwC Recommendation Harimic's present configuration Action required to meet recommendations Action Deadline
a) Maximum password age - 90 days or lower
b) Account lockout treshold - 3 invalid logon attempts

Password history memory - limited to last 3 passwords


c)
and prohibit users from changing into old password

User account lockout duration after failed logon set to


d)
30 minutes or higher
e) Minimum password length set to at least 8 characters
Password must have combination of characters
other than alphabets (e.g. symbol, upper case, lower
f) case, numbers etc)

Action required includes updating/documenting it in IT procedure

2.2 Password configurations and security parameters should be established


As above

2.3 Improvement to IT policies and procedures and communicating them to relevant personnel periodically when updates are needed

No PwC Recommendation Harimic's present practice Action required to meet recommendations Action Deadline
a) User account creation, modification, deletion
b) Password policy As in 2.1
c) Privilege access management procedure
d) Periodic review of user access rights

Action required includes updating/documenting it in IT procedure

2.4 No PwC Recommendation Harimic's present situation Action required to meet recommendations Action Deadline
Data restoration practice be established to ensure
a) recoverability/restoration of payroll data

You might also like