What Every IT Auditor Should Know About
INTRODUCTION
Lately
the world has been shocked by something called social media. This social media
comes with many benefits for businesses and organizations. The benefits
obtained include:
- Allows 24/7 communication between customers and customers and prospects
- Attract, or reach new customers
- Build new business opportunities
- Increase customer loyalty
- Diversification of marketing channels
- Recruit employees who understand IT
- Increase collaboration between employees
- Build personal, professional and organizational networks
Below
are examples of the benefits of using social media in real terms, including:
The
Ford Fiesta uses a social network system (SNS) in the US to attract customers
from its target market and build relationships with potential customers and
buyers. Ford achieved reservations for the conversion sales rate 10 times
higher than expected with SNS.
Examples
of social media used:
- More than 40 million impressions occur with Twitter, and 30 percent of them are people under 25 (ie, repeat buyers)
- Facebook is growing with an additional 100 million users every three months since reaching its first 100 million, and is approaching 1 billion users today.
- Twitter has around 140 million members and 340 million tweets sent per day.
- Use of YouTube in business as a social media and training facility. an example is Red Robin Restaurant, they offer training on the right temperature for food as an online video on YouTube, and that is the conventional comedy video found on YouTube that went viral.
- There are more than 150 million blogs available, and they have millions of followers and readers. LinkedIn has 135 million members worldwide and is generally used by professionals to build networks.
Social
media have many risks, including inefficiencies, wasted investment,
insufficient effectiveness, and loss of opportunities usually occur due to
damage to public image created by negative comments and posts in places of
social media.
FRAMEWORK FOR SOCIAL MEDIA AUDITS
There are actually two different areas of risk and concern regarding social media: public image and operational effectiveness. Public images are related to entities that try to manage and protect their public image. It is important that entities with social media risk are proactive in their search and management of false statements and negative posts on the web. As with other IT, entity management must pay attention to the operational effectiveness of using social media tools and, thus, need to include social media audits in their internal audit functions. This audit is no different from all other audits - starting with risk assessment, determining management objectives (which must be reconnected with the business model, entity goals and objectives), and auditing for effectiveness and efficiency in using certain IT.
There are actually two different areas of risk and concern regarding social media: public image and operational effectiveness. Public images are related to entities that try to manage and protect their public image. It is important that entities with social media risk are proactive in their search and management of false statements and negative posts on the web. As with other IT, entity management must pay attention to the operational effectiveness of using social media tools and, thus, need to include social media audits in their internal audit functions. This audit is no different from all other audits - starting with risk assessment, determining management objectives (which must be reconnected with the business model, entity goals and objectives), and auditing for effectiveness and efficiency in using certain IT.
THE RISK
Auditing process in social media is same as with others audit sectors, it is also have to decided the risk areas and the risk assesment. According to the framework above, we are focusing into two main factors there are public image and operational effectiveness. The relationship among these two factors are the effectiveness operational risk areas where is they occur will make result in damage to reputation/public image (figure 1). So, auditor must defining the several risks that will be identified whether they are include into public image or operational effectiveness or both of them.
Auditing process in social media is same as with others audit sectors, it is also have to decided the risk areas and the risk assesment. According to the framework above, we are focusing into two main factors there are public image and operational effectiveness. The relationship among these two factors are the effectiveness operational risk areas where is they occur will make result in damage to reputation/public image (figure 1). So, auditor must defining the several risks that will be identified whether they are include into public image or operational effectiveness or both of them.
In
the figure 2, these all the percentage of several possibility risk using the
social media. There are six risks that can conluded by researcher, the first
risk is users dont know that their personal information may take into somewhere
is dangerous. The second risk is some users that allowing other people to get
access from their login identity can be abusing their social media account and
the impact will accepted by the real owner of the account even though the
suspect is not the owner. The third risk is users often have been victims of
malware, then the fourth risk is there are many personal social networks that
still offered to users with free and this is can make the crime risk like
information selling unlegally. The fifth risk is social media social often to
be a place where is many offering a lot of kind contracts there and untrust sources
that often followed by many users. The sixth risk is there are many users have
been victims of identity theft for sexual interest illegally.
AUDITING
PROACTIVELY FOR IMAGE AND PUBLIC RELATIONS
To controlling the bad social media effect perhaps can influence the entity’s image, the company need people that expert in social media (internet) live. It can be daily duty for the controller of social media to monitoring the negative and the positive respons or comments by other users. The admin of a company’s social media have to has good attitude in order to answer these all comments wisely. The controlling process in social media is not without any cost because to paying a specialists who may need to spend all of their work hours on monitoring social media and an enterprise may even require more than one expert.
To controlling the bad social media effect perhaps can influence the entity’s image, the company need people that expert in social media (internet) live. It can be daily duty for the controller of social media to monitoring the negative and the positive respons or comments by other users. The admin of a company’s social media have to has good attitude in order to answer these all comments wisely. The controlling process in social media is not without any cost because to paying a specialists who may need to spend all of their work hours on monitoring social media and an enterprise may even require more than one expert.
AUDITING TRADITIONALLY FOR OPERATIONAL EFFECTIVENESS
Auditing social media for operational effectiveness is not much different from other IT audits of systems and technologies. The risk areas can be ranked using a combination of impact and probability. The IT auditor should include the aspect of risk velocity as well. Starting with the highest risk, the IT auditor should begin to audit and evaluate the controls. Moreover, the IT auditor should consider what organizational goals and objectives are tied to the use of SNS. Then, the IT auditor should audit the effectiveness of social media compared to a metric or benchmark of the goal, objective or business model. This audit would benefit from the use of the COBIT 4.1 Plan and Organize domain.
Auditing social media for operational effectiveness is not much different from other IT audits of systems and technologies. The risk areas can be ranked using a combination of impact and probability. The IT auditor should include the aspect of risk velocity as well. Starting with the highest risk, the IT auditor should begin to audit and evaluate the controls. Moreover, the IT auditor should consider what organizational goals and objectives are tied to the use of SNS. Then, the IT auditor should audit the effectiveness of social media compared to a metric or benchmark of the goal, objective or business model. This audit would benefit from the use of the COBIT 4.1 Plan and Organize domain.
CONCLUSION
The conclusion of the
discussion above is the proliferation of social media and the fact that the
main risk fields associated with it (whether the organization uses it or not)
creates the need for IT auditors to assist management in managing related risks
and ensure that social media is an effective tool. Effectiveness is related to
the goals, objectives, or strategy of the organization (if the entity is
actively involved with SNS).
This framework for social
media, shows that the audit of social media IT (being used by organizations) is
separate from the social media audit / monitoring used (SNS in general). The IT
audit (social media) itself is not much different from the approach used in
other IT audits, but the risk assessment component has several special
considerations (for example: Speed of risk, employee abuse). COBIT provides
an effective tool for conducting audits, as is the case with most IT audits,
will involve auditing operational effectiveness of controls and the strategic
effectiveness of the organization (managerial).
Social media must
remain monitored proactively and sustainably, to minimize the adverse effects
of SNS on the organization, especially from the wrong or negative posts that are
very detrimental. This audit / monitoring is increasingly important based on
how many organizations are being discussed in the SNS, and can ask for one or
more employees in full just to spend all of their working hours monitoring
various SNSs.
GROUP 1:
·
RISKI ENDAH S C1I016001
·
FIRDIAN LATHIFAH C1I016006
·
NURBAITI C1I016011
·
NABILLA TSALSA MIFTIANA C1I016018

Tidak ada komentar:
Posting Komentar