Home About Gamma  Tour our Web Site  Events  White Papers  Services  Visitors' Book  How to contact us
         IMS  Internal Control  ISMS  Smart Cards  Common Criteria
                 

Internal control is the means by which you marshal your organisation's resources to achieve your business objectives.  Does your system of internal control help you to exploit your opportunities as well as manage your business risks?  Is it able to detect material errors in sufficient time for you do take appropriate action?  Can you quantify the effectiveness of your controls?  Do you just have enough controls - not too many and not too few? If the answer to any of these questions is "no", or you do not know then ...

Your response - choose from any of the Gamma Internal Control Services

The Gamma internal control services consists of a variety of complementary modules. You may not need them all - just choose the ones you need.

  • Structural assessment: We will assess the structure of your internal control system and recommend areas for improvement.  We will pay attention to the processes by which you establish, police and improve your system, particularly in the areas of developing risk treatment plans, opportunity exploitation plans and alternative ideas lists.  We have a structured methodology for carrying out this type of assessment, and our own system of internal control is based on this approach.
The architecture of the "management system" for establishing, policing and improving a system of internal control.  The architecture derives from advice given by the UK Audit Practices Board
  • Design and implementation: Following the structural assessment, we can assist you to implement our recommendations.  We can also assist you to design and implement a new internal control system from scratch.

  • Development of Risk Treatment Plans: We can assist you to develop your Risk Treatment Plans (RTPs).  We have a "one-stop" process for carrying out the risk assessment, risk treatment and selection of controls, and present our results in an easy to understand "tell it like a story approach".  Why not use this approach to determine what your corporate worldwide IT policies and strategies should be?

We have used this approach to determine Civil Service-wide polices for information security. 
  • Development of Opportunity Exploitation Plans: We can assist you to develop your Opportunity Exploitation Plans (OEPs).  As the OEPs have to consider the risks, this is another way to identify what dangers really matter to an organisation, and thus focus the internal controls towards meeting the business objectives.

  • Regulatory refreshment: We can assist you to keep pace with new regulations by creating new AILs, or translating established codes of practice and checklists to the AIL format.  We can then help you to complete the Statement of Applicability, justifying why particular controls are relevant to your organisation and which are not.  Adapting to new regulations will no longer mean a complete revamp of your existing procedures and each AIL is effectively a new "database" view on your existing internal controls.

The AIL concept and use of the statement of Applicability is explained in our paper on "Exploiting Integrated Management Systems"
  • Measuring the effectiveness of your internal controls:  We can assist you to measure the effectiveness of your internal controls using our established "time" theory.  We can help you to determine the cost effectiveness of your controls and recommend where improvements are desirable and how they can be achieved. We can also assist you to put the procedures into place for you to carry out these measurements and determinations on a regular basis in order to meet regulatory requirements such as Basel II.
A graph illustrating how to measure the effectiveness of controls (left), taken from our paper "Measuring the effectiveness of an internal control system" and a photograph of a white board showing its application to a bank in the context of Basel II for measuring the effectiveness of its Operational Risk Management Controls (June 2003)
A graph illustrating how to measure the effectiveness of controls (left), taken from our paper "Measuring the effectiveness of an internal control system" and a photograph of a white board showing its application to a bank in the context of Basel II for measuring the effectiveness of its Operational Risk Management Controls (June 2003)

Your next move

... simply contact David Brewer. Why not do it now!

             
             
             
 
Gamma is an ISO/IEC 27001:2005 and BS EN ISO 9001: 2000 registered company, certified for the provision of information security consultancy.  BSI certificate numbers IS 85916 and FS  30710.  Please send comments to webmaster@gammassl.co.uk or complete our Visitors'Book. Gamma Secure Systems, Diamond House, Frimley Road, Camberley, Surrey, GU15 2PS, UK Tel: +44 1276 702500 - Fax: +44 1276 692903Copyright © Gamma Secure Systems Limited 2006
 
 
Page last updated: 14 March, 2006