C.R. McGuffin Consulting Services

 

Home
News
Seminars
Schedule
CISA Prep Course
Assignments
Books

 

Representative Assignments


Our firm has provided valuable information system control and consulting services to many valued clients throughout the world.  Representative assignments are described in the following sections:


Direct Client Services

Investigated and provided guidance regarding information systems controls and security, and general information systems management. Managed and participated in teams with client operational staff. Presented and reported findings and recommendations to client senior management. Representative activities include:

Information Resource Security

  • Currently in the process of piloting a public-key infrastructure (PKI), including the implementation of a X.509 Certificate Authority and LDAP-compliant Directory Services (based on "Entrust"). The PKI supports encryption applications that include electronic-mail, Virtual Private Networks, secure remote access to the corporate network via the Internet, and secure sessions (world-wide web, telnet, file transfer protocol, and specialized client / server applications) within the corporate network.
     
  • Reviewed and evaluated computer security mechanisms available and implemented as part of advanced client-server network architectures. Computers used included multiple UNIX/Oracle database severs connected to clients via TCP/IP and X.25 networks. Recommended improvements to better protect key customer records and system functions within a high-profile financial services environment.
     
  • Designed a security architecture for a province-wide, multiple-protocol communications network, connecting government ministries using different computing platforms, local area networks, and other data sources such as voice and video. Architecture defined specific security mechanisms required in each network component to protect critical information resources.
     
  • Designed a security architecture for a widely distributed financial application. Addressed security objectives, requirements, and techniques across multiple operating systems (MVS and VMS), network protocols (SNA, DECnet), and public and private data networks. Architecture served as security evaluation criteria for all subsequent system development.
     
  • Developed and implemented strategies and guidelines for business contingency and disaster recovery planning. Decreased risk of loss of critical processing capabilities.
     
  • Developed and implemented corporate security policy in conjunction with client security staff. Increased employee awareness and understanding of security implications in the business.
     
  • Planned and executed specific procedures to address the resignation or termination of key client security personnel. Protected information resources from possible repercussions.

Information Resource Integrity

  • Designed, evaluated, and tested controls within wide scope of sophisticated financial application systems. Applied skills to address control requirements of non-traditional and highly-complex information systems, such as those using "Electronic Data Interchange". Through automation of control mechanisms, enhanced reliability of information, and reduced need for labour-intensive manual control procedures.
     
  • Developed and executed creative automated techniques for system testing and data analysis. Increased efficiency and effectiveness of testing efforts.

Information Resource Management

  • Performed a comprehensive management review of the information services area. Inventoried resources in use, assessed efficiency and effectiveness of deployment, and identified particular risk areas. Provided detailed recommendations on alternatives to achieve cost-savings and improvements in information quality and timeliness.
     
  • Assumed senior management role for information services area. Examined existing resource usage, recommended and implemented cost-saving alternatives. Improved efficiency and effectiveness of system development methodology. Achieved significant cost reductions, while improving quality of services provided.

Audit Support Services

Assisted audit staff to deal with audit requirements within a variety of complex information systems environments. Identified controls within client financial application systems, and designed appropriate approach which reduced auditors’ level of risk. Designed computerized techniques for audit analysis, and to replace labour-intensive audit procedures.


Additional Related Experience


Send mail to administrator@crmcg.com with questions or comments about this web site.
Copyright © 2003 C.R. McGuffin Consulting Services
Last modified: 28-Mar-2004