公認内部監査人(CIA)tunetterのブログです。 内部監査の試行錯誤を記録していきます。

にほんブログ村 経営ブログ 経営学へ
いま何位?

2010年2月27日土曜日

iPhoneをお財布ケータイにする

現在のところiPhoneには、日本のケータイで常識のICカード機能がありません。これを解決するためiPhoneにはICカードを入れられるケースがいくつか販売されています。
私が使っているもののひとつがサンワサプライのシリコンケースです。

このケースはiPhoneとICカードを一体で包み込むシリコンケースです。カードの分だけ少し厚みが増しますが、割とスマートに一体化することができます。そして、この手のケースを使うようになってからICカードもiPhoneも忘れることがなくなりました。
難点はICカードへのチャージですが、クレジットカードとの組み合わせでオートチャージを設定すればほぼカードを取り出す必要がなくなります。
お財布ケータイ機能がないからiPhoneの購入を躊躇している方におススメです。

2010年2月26日金曜日

Consistency With Applicable Laws and Regulations, Defined Commitments, Service-Level Agreements, and Other Contracts

今回も引き続き勝手訳を続けます。

Consistency With Applicable Laws and Regulations, Defined Commitments, Service-Level Agreements, and Other Contracts法令と規則、確約、サービスレベルに関する合意、その他 契約との一貫性

.08 Several of the principles and criteria refer to “consistency with applicable laws and regulations, defined commitments, service-level agreements, and other contracts.” Under normal circumstances, it would be beyond the scope of the engagement for the practitioner to undertake identification of all relevant “applicable laws and regulations, defined commitments, service-level agreements, and other contracts.”
Furthermore, Trust Services engagements do not require the practitioner to provide assurance of an entity’s compliance with applicable laws and regulations, defined commitments, service-level agreements, and other contracts, but rather of the effectiveness of the entity’s controls over monitoring compliance with them. Reference should be made to other professional standards related to providing assurance over compliance with laws, regulations, and agreements.


.08 いくつかの原則と基準は「適用される法律や規則、確約、サービスレベルに関する合意、その他契約との一貫性」について言及している
通常の環境下では全ての「適用される法律や規則、確約、サービスレベルに関する合意、その他契 約との一貫性」に関する識別を請け負う実務家にとって契約の目的外であるかも知れない。
さらに信用提供契約は実務家に、対象に適用される法律や規 則、確約、サービスレベルに関する合意、その他契約の遵守に関する信用提供を要求しない。し かし、むしろ求められるのは、対象について法令順守のモニタリングによる統制の有効性の保証である。証明書は、法令や規則そして合意の順守の保証供給に関連した他の専門家の標準に対して作られるべきである。

今 回もわかりにくい英語でしたがポイントは、
  • コンプライアンスは信用提供の目的外である。
  • 信用提供ではコン プライアンスの統制の有効性保証する。
  • コンプライアンスの保証は他の標準によってなされるべきである。
といったこ とだ思います。

2010年2月25日木曜日

Principles, Criteria, and Illustrative Controls

今回も引き続き勝手訳です。

Principles, Criteria, and Illustrative Controls(原則、基準そして実例となる統制)
  • .06 The following material sets out broad statements of principles and identifies specific criteria that should be achieved to meet each principle. Trust Services principles are broad statements of objectives. Criteria are benchmarks used to measure and present the subject matter and against which the practitioner evaluates the subject matter. Suitable criteria are objective, measurable, complete, and relevant—they will yield information useful to intended users. It is the view of the Assurance Services Executive Committee that the Trust Services principles and supporting criteria meet the characteristics for suitable criteria. Trust Services principles are used to describe the overall objective; however, the practitioner’s opinion makes reference only to criteria.
  • .06 以下の材料は原則について多くの声明を出し、それぞれの原則に見合うために達成すべき特定の基準を明らかにする。信用提供の原則は目的に関する多くの声明 である。基準は従うべきこと測定し示すこと、そして、実務家が従うべきことであると評価したことへの反論に使われるベンチマークである。適切な基準は、客観的で測定可能で、完全で、そして、妥当である。-それらは意図した利用者への情報を有用にする。信用提供の原則とそれらをサポートする基準を適切な基準の特徴に合致させる保証 提供執行委員会(Assurance Services Executive Committee)の視点である。信用提供の原則は全体の目的を述べてきたものである。しかしながら、実務家は基準だけを参照することを主張している。
  • .07 In the Trust Services Principles and Criteria, the criteria are supported by a list of illustrative controls. These illustrations are not intended to be all-inclusive and are presented as examples only. Actual controls in place at an entity may not be included in the list, and some of the listed controls may not be applicable to all systems and client circumstances. The practitioner should identify and assess the relevant controls the client has in place to satisfy the criteria. The choice and number of those controls would be based on the entity's management style, philosophy, size, and industry. In order to receive an unqualified opinion on a Trust Services engagement, all criteria must be met unless the criterion is clearly not applicable. In the context of the Trust Services Principles and Criteria, the term policies is used to refer to written statements that communicate management's intent, objectives, requirements, responsibilities, and/or standards for a particular subject. Such communications may be explicitly designated as policies, whereas others (such as communications with users not otherwise documented as policies, or written procedures) may be implicit. Policies may take many forms but should be in writing.
  • .07 信用提供の原則と基準の中では、基準は実例となる統制のリストによりサポートされている。これらの実例はすべてを包括することを意図するものでなく、また例示するのみでもない。現実に正しく行われている実際の統制はリストに含まれていないかもしれないし、いくつかの列挙された統制はすべてのシステムや顧客 環境に適用できないかもしれない。実務家は顧客が正しく基準を満足する妥当な統制を明らかにし、評価するべきである。選択とそれらの統制の数は実体のマネ ジメントスタイルや哲学、規模、そして産業に基づく。信用提供契約において無限定適正意見を受け取るためには、明確に適用外であるもの以外の全基準に合致 しなければならない。信用提供の原則と基準(the Trust Services Principles and Criteria)の文脈では、方針という用語は経営者の意思や目的や要求や責任そして/または特定の問題のための標準を伝達する文書化された声明で あるとされる。そのような伝達は明確に方針とされるが、他のもの(方針のように別途文書化されないユーザーとのコミュニケーションのような)は暗 示とされる。方針は形式は様々であるが文書化されていなければならない。
大変英語らしい言い回しが続きますが、ポイントは、
  • 原則を達成するために基準が存在する。
  • 信用提供の原則は目的について述べており、基準だけを参照 してはいけない。
  • 基準には実例となる統制がある。
  • 方針は文書化されなければならない。
といったところでしょうか。

Trust Services

今回はTrust Servicesです。引き続き、勝手訳を続けます。がんばって訳しますが、間違いがある可能性は否定できません。。。

Trust Services(信用提供)

  • .03 Trust Services (including WebTrust® and SysTrust®) are defined as a set of professional assurance and advisory services based on a common framework (that is, a core set of principles and criteria) to address the risks and opportunities of IT. Trust Services principles and criteria are issued by the Assurance Services Executive Committee.
  • .03 信用提供(WebTrustとSysTrustを含む)はITのリスクと機会について述べられた共通の枠組み(原則と基準を中核とした)に基づく専門家の保証と助言提供が一体となったものであると定義される。

Assurance Services(保証提供)

  • .04 Assurance services are those that result in the expression of an opinion by the reporting practitioner; for example, the opinion as to whether a defined system meets the principles and criteria for systems reliability. Assurance services are developed within the framework of Chapter 1, “Attest Engagements,” of Statement on Standards for Attestation Engagements (SSAE) No. 10, Attestation Standards: Revision and Recodification (AICPA, Professional Standards, vol. 1, AT sec. 101), as amended. Only certified public accountants (CPAs) may provide the assurance services of Trust Services that result in the expression of a Trust Services, WebTrust, or SysTrust opinion.
  • .04 保証提供は実務家の報告による意見の表明の結果である。例えば、当該システムがシステムの信頼性の原則と基準に合致するか否かという意見である。保証提供 は第1章すなわち立証契約の標準の声明(SSAE)No.10の"立証契約”と立証標準:改正版である「改訂と再編」(AICPA、専門家の標準 vol.1、AT sec. 101)の枠組みの中で開発される。公認会計士だけがWebTrustまたはSysTrustの表明結果である信用提供の保証提供を供給することが許され る。

Advisory Services(助言提供)

  • .05 In the context of Trust Services, advisory services include strategic, diagnostic, implementation and sustaining/managing services using Trust Services principles and criteria. Practitioners providing such services follow Statement on Standards for Consulting Services (AICPA, Professional Standards, vol. 2, CS sec. 100). There is no expression of an opinion by the practitioner under these engagements.
  • .05 信用提供としての助言提供には、戦略、診断、実装そして信用提 供の原則および基準を使用した、維持・管理サービスが含まれる。これらのサービスを供給する実務家はコンサルティングサービスの標準の声明 (AICPA, 専門家の標準, vol. 2, CS sec. 100)に従う。これらの契約下では実務家の意見は表明されない。

と ても直訳っぽくなりましたが、つまり、
  • Trust ServicesにはWebTrustとSysTrustが含まれる。
  • Trust Servicesには保証提供と助言提供がある。
  • 保証提供では実務家の意見が表明される。
  • 公認会計士だけ が保証提供を行うことができる。
  • 助言提供では実務家は意見を表明しない。
といったことが書かれていると思われます。

2010年2月23日火曜日

目次

前回ご紹介したSysTrust(含、WebTrust)のガイドラインとして、
Trust Services Principles, Criteria and Illustrations for Security, Availability,
Processing Integrity, Confidentiality, and Privacy (Including WebTrust® and
SysTrust®)

が あります。当ブログではしばらくこの長い題名のガイドラインの内容を確認していきたいと思います。初回はまず、Table of Contents(目次)です。

INTRODUCTION(序論)

  • TRUST SERVICES(信用提供)
  • PRINCIPLES, CRITERIA, AND ILLUSTRATIVE CONTROLS(原則および基準と統制の実例)
  • CONSISTENCY WITH APPLICABLE LAWS AND REGULATIONS, DEFINED COMMITMENTS, SERVICE-LEVEL AGREEMENTS, AND OTHER CONTRACTS(適用法令・規則、定義された責任、サービスレベルに関する合意、そしてその他契約との一貫性)
  • FOUNDATION FOR TRUST SERVICES—TRUST SERVICES PRINCIPLES AND CRITERIA.(信用提供の基礎-信用提供の原則と基準)
  • TRUST SERVICES—OFFERINGS OF SYSTRUST AND WEBTRUST(信用提供 -SysTrustとWebTrustの提供)

PRINCIPLES AND CRITERIA.(原則と基準)

  • SECURITY PRINCIPLE AND CRITERIA(セキュリティーの原則と基準)
  • AVAILABILITY PRINCIPLE AND CRITERIA(可用性の原則と基準)
  • PROCESSING INTEGRITY PRINCIPLE AND CRITERIA(処理過程の完全性の原則と基準)
  • CONFIDENTIALITY PRINCIPLE AND CRITERIA(機密性の原則と基準)
  • PRIVACY PRINCIPLES AND CRITERIA(個人情報の原則と基準)

APPENDIX A: ILLUSTRATIVE DISCLOSURES FOR E-COMMERCE SYSTEMS(付録A:Eコマースシステムの開示例)
APPENDIX B: EXAMPLE SYSTEM DESCRIPTION FOR NON–E-COMMERCE SYSTEMS .(付録B:Eコマースではないシステムのシステ ム説明の例)
APPENDIX C: PRACTITIONER GUIDANCE ON SCOPING AND REPORTING ISSUES(付録C:範囲の絞込みと報告事項の実務家用ガイダンス)
APPENDIX D: GENERALLY ACCEPTED PRIVACY PRINCIPLES – A GLOBAL PRIVACY FRAMEWORK(付録D:一般に公正妥当と認められた個人情報原則-グローバルな個人情報の枠組み)

分量としては、「導入」が3ページ、「原則と基準」が47ページ、付録A~Dが102ページあります。まずは、最初の50ページを意訳していきたいと思いま す。

2010年2月21日日曜日

大山鳴動して虫(?)一匹

自転車のタイヤの空気がすぐに抜けるようになりました。
これはパンクに違いないと思い、タイヤをリムから外し、チューブを点検したけど空気もれを確認できません。
もしやと思い、空気バルブを確認したところ、プランジャーの虫ゴムが破れていました。
そうです、空気漏れの原因はパンクではなく、虫ゴムの劣化だったのです。
結局、虫ゴムを交換し、無事空気漏れはなくなりました。
タイヤを外すのはかなり大変なので、まずは虫ゴムの確認を先にするべきだったと思います。
ネットで調べたところ、このようなページを見つけました。このマニュアルでも、最初に確認すべきは虫ゴムとなっています。

内部監査もパンク修理も思い込みは危険です。

2010年2月20日土曜日

鷹の爪.jp

木曜日の夜に秘密結社鷹の爪THE MOVIE3 ~http://鷹の爪.jpは永遠に~ を観に行きました。
一部でコアなファンがいる深夜番組のフラッシュアニメ「鷹の爪」の劇場版第3弾です。
映画のタイトルに日本語ドメイン名が使われていたり、本格的なCGが“部分的に”使われていたり、あからさまにスポンサーの宣伝が行われていたり、島根県と石川県が出てきたりと、大変楽しい内容です。
首都圏での上映はそろそろ終了し始めていますが、こういう遊び心いっぱいの映画はあまりないので、まだ間に合う方は是非ご覧になることをおススメします。