6 ms·
The only thing I wonder about here is how it's possible that the infosec/GRC team didn't notice this.
by 300 5y ago
The only thing I wonder about here is how it's possible that the infosec/GRC team didn't notice this.
- 2pEXgD0fZ5cF 5y agoI mean, what do you do if you notice this?
- Mauricebranagh 5y agoBack when I worked for BT an anonymous letter from "a friend" to the internal security team was one option.
- 300 5y agoBy following the basics of ISO27K1, for example: Good infosec teams keep inventory of all the software used in the org. If they see that the org already pays a vendor for software doing X, a question should be raised, why we need another one for doing the same thing. Also, each new vendor or software provider needs go get a "security clearance", after the infosec teams checks their state of security. These kinds of practices would probably discover the shady intents.
- Mauricebranagh 5y agoOr the Accounts / CFO /Audit departments. This sort of fraud is quite common in white collar crime
- jsmith99 5y agoAs a financial auditor I've no idea how we would pick this up. It wouldn't hit the books of the company at all. We would research board members and check their other directorships but that only covers executives and their formal relations. It would be more likely to be picked up by the auditors of the company offering the bribe (what's this payment for?).
- Mauricebranagh 5y agoI was thinking the internal controls that audited contracts, not external auditors.
- Aeolun 5y agoHow do you notice this? If the man is the ultimate arbiter of what does or does not get purchased, you don’t know why right?
- Mauricebranagh 5y agoA sensible company has internal audits and checks and balances.