Regulatory Audit
Beechdale Community Housing Association Limited, received a request from their auditors for documentation spanning a wide range of issues, as part of a regulatory audit. Their Performance Development Manager, Denise Bamford, requested help from Quiss to provide documentation relating to many elements of their IT system and its associated processes and procedures. As their IT outsourcing provider, we were very happy to assist with this task as part of our WORKS outsourcing solution. It was apparent that a comprehensive report was needed covering many aspects of their IT provision.
Information requested by the auditor included reports on wide ranging issues such as:
- Servers, infrastructure, applications and hardware inventory
- Communications
- Internet service provision
- Internet usage monitoring
- Network traffic monitoring
- Error logs
- Local and remote user access permissions
- Firewall and anti-virus configuration
- Backup processes
- Security policy
- Security checking - Microsoft Baseline Security Analyzer (MBSA) was deployed. This is a tool designed that helps businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance. The report generated showed that the system passed all relevant tests and no further action was necessary.
- Change control procedures
- Training logs
In order to make the process as straightforward as possible for the auditor, Quiss created a master document with an innovative format with links to all documentation requested.
At a subsequent meeting at the Quiss office requested by the auditor, Quiss management were commended on the quality and scope of the information given.
Denise was delighted with the response and commented on how well Quiss responded throughout the audit whenever clarification of a particular point was needed, also stating that our effort had been of outstanding benefit.
As a result the auditor's report failed to identify a single issue with Quiss's provision of IT to the organisation - the system passed with flying colours.