This site uses cookies to provide you with a more responsive and personalized service. By using this site you agree to our use of cookies. Please read our cookie notice for more information on the cookies we use and how to delete or block them.

Bookmark Email Print page

Case Study: Information Technology Function Assessment

Abstract

A leading Irish financial institution required an assessment of their Information Technology function and the identification of areas of potential improvement with the aim of implementing best practice.

Challenge

This project required Deloitte to evaluate the Information Technology function of a major Irish financial institution. We were required to assess the capabilities of the information technology department against best practice in the financial services industry.

Approach

The engagement focused on the examination of a number of areas, including:

  • Segregation of duties within the IT department
  • Network security
  • Regulatory requirements affecting the IT function
  • IT security policies
  • Hardware tracking and security
  • The IT procedures in operation

 

Solution

The IT department of this financial institution measured up well with the requirements for best practice in its industry however even in a well-run organisation there were vulnerabilities that needed to be addressed:

  • IT key man dependence
    • Organisational dependence on a single staff member to provide services to support critical information systems. This also highlighted weaknesses in the area of succession planning.
    • The organisation operated without a position that focused solely on information security. To ensure the information security requirements are kept up to date and centrally managed, an independent role should be created. Best practice requires this independent role as it facilitates wider communication and clarity of responsibility for policy.
  • Staff knowledge of procedures and operations has not been formally documented. These omissions can delay the implementation of system changes and the continuity planning of the organisation. 

 

Material on this website is © 2013 Deloitte Global Services Limited, or a member firm of Deloitte Touche Tohmatsu Limited, or one of their affiliates. See Legal for copyright and other legal information.

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a private company limited by guarantee, and its network of member firms, each of which is a legally separate and independent entity. Please see www.deloitte.com/ie/about for a detailed description of the legal structure of Deloitte Touche Tohmatsu Limited and its member firms.

Get connected
Share your comments
More on Deloitte
Learn about our site