auditoria de sistemas de informaÇÃo: (proposta de critÉrio para avaliar a eficÁcia)

Upload: diego-bianchetti

Post on 11-Feb-2018

218 views

Category:

Documents


0 download

TRANSCRIPT

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    1/62

    ^@GQCTNU EN@TRI ^@GQNRUGTRGICDMG@GUTRCI EIM FCBGLGTCI NM C@LGUN DN UGUTNMCU

    C^DGTIRGC DN UGUTNMCU DN G@AIRMCI8&ZRIZIUTC DN ERGTRGI ZCRC CQCLGCR C NAGEEGC'

    Cl~`i8 Dgnki Bgc`efnttgIrgn`tcdir8 Ec`dgdi Ai`unec dc Uglqc

    Mi`ikrcagc czrnun`tcdc ci E~rui dnCdmg gutrci eim Fcbglgtci nmC`lgun dn Ugutnmcu di En`tri^`gqnrugtrgi - ^@GQCTNU

    Lchncdi, `iqnmbri dn 2::;

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    2/62

    CKRCDNEGMN@TIU

    Ciumn~uzcgu,Hi`nunMcrgcC`gtc,znliczigi,nutr~t~rc,ecrg`fin

    dndgeciUnmnlnu`cdcunrgcziuuqnl

    CizrianuuirEc`dgdiAi`unecdcUglqc,znlcirgn`tcidiecmg`fi

    unk~gdi

    CiucmgkiuL~egc`iOlng`nAcbregiZrntti

    Ctidius~nagxnrcmzcrtndnuucecmg`fcdc

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    3/62

    RNU^MI

    Cei`tg`~gdcdndiu`nkegiunmzrnucrgcgudnzn`dn,nmkrc`dnzcrtn,

    diznrangtia~`egi`cmn`tidnun~uUgutnmcudnG`airmc i&UG'Zcrckcrc`tgr

    nuunznrangtia~`egi`cmn`ti`nenuurgc~mcrgkiriucknutidcunk~rc`cdiu

    UG,knutinuucs~ntnm`cuC~dgtirgcu~mczcrtna~`dcmn`tclC~dgtirgcuui

    angtcudnceirdieim~mcmntidilikgcdnczigi,dn`trncus~cguundnutcecmcu

    mntidilikgcubcundc@BRGUI)GNE3;;77&EdgkidnZrtgeczcrccKnutidc

    Unk~rc`cdcG`airmci'

    Unzir~mlcdi,f ~mcrcxiqnllgtnrct~rcdguzi qnluibrneimi

    mi`tcrc~dgtirgcu,ziri~tri,fnuecuunxdnz~blgecnus~nh~lk~nmcnageegc

    dntcguc~dgtirgcuNutcmi`ikrcagctnmeimiibhntgqizrizir~mergtrgi,ugmzlnu

    ndnaeglczlgeci,zcrccqclgcrcnageegcdnc~dgtirgcudnUG,timc`dieimi

    mtrgeccu~ccdnr`egcc@BRGUI)GNE3;;77Ctrcqudnnut~didnecui

    rnclgxcdinei`ugdnrc`diculgmgtcnuditrcbclfi&aircmc`clgucdcuczn`cutru,

    dcui`xnectnkirgcudc@BR'ei`ugdnrc-uns~naigclec cdiiibhntgqizriziuti

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    4/62

    CBUTRCET

    Tfnei`tg`~gtwiab~ug`nuun`tnrzrgundnzn`du,g`lcrknzcrt,i`tfn

    znranetcetgi`iatfngrG`airmctgi`Uwutnmu&GU'Tizriqgdntfnznranetiznrctgi`gu

    `nenuucrwcGUune~rgtwmc`cknmn`t,bwmnc`uiaC~dgtg`kzrienuunuC~dgtg`ku

    crn mcdn g` ceeirdc`en {gtf c mntfidilikw ti u~zzirt tfnm? cmi`k tfnun

    mntfidilikgnuutc`di~tmntfidilikgnubcundi`@BRGUI)GNE3;;77&Edgki

    dnZrtgeczcrccKnutidcUnk~rc`cdcG`airmci'

    Gatfnrngucrncui`cblnlgtnrct~rncqcglcblni`fi{timi~`tc~dgtg`k,

    z~blgectgi`utfcth~dkntfnnaanetgqn`nuuiau~efc~dgtucrng`can{`~mbnrTfgu

    zcznr zriziunu c ergtnrgi`, ugmzln c`d ncuw ti gmzlnmn`t, ti nutgmctn tfn

    naanetgqn`nuuiaGUc~dgtg`k,bweimzcrg`kgtucdfnrn`entitfn@BRGUI)GNE

    3;;77Tfri~kfecunut~dgnudi`nc`dei`ugdnrg`ktfn{irolgmgtctgi`u&i`lw

    tfrnn, iatfnnlnqn`ectfnkirgnuia@BR{nrnc`clwund' gt guei`ugdnrndtfcttfn

    kiclzriziund{curncefnd

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    5/62

    U^MRGI

    LGUTCDNTCBNLCU......................................................................................... :6

    LGUTCDNAGK^RCU.......................................................................................... :7

    LGUTCDNKRAGEIU........................................................................................ 3:

    LGUTCDNCBRNQGCT^RCU.............................................................................. 33

    3.G@TRID^I............................................................................................... 32

    3.3Dnag`gidizriblnmc........................................................................... 32

    333Is~nUnk~rc`cdcG`airmci 32

    332C~dgtirgcudnUgutnmcudnG`airmci 35335Ei`tnvt~clgxcidizriblnmc 35

    3.2Ibhntgqiuditrcbclfi............................................................................. 34

    323Ibhntgqiknrcl 34

    322Ibhntgqiunuzneageiu 34

    3.5Eimziugiditrcbclfi....................................................................... 3>

    2.A^@DCMN@TCITNRGEC..................................................................... 3;

    2.3Unk~rc cnmUgutnmcudnG`airmci............................................... 3;

    233UgutnmcudnG`airmci&UG' 36

    232Unk~rc`cdiuUG 36

    2.2@irmcunzcdrnudnunk~rc`c.......................................................... 2:

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    6/62

    223Eimmi`Ergtnrgc&GUI3>4:6' 23

    222GUI)GNETR3555> 23

    225EIBGT&Ei`trilIbhnetgqnuairG`airmctgi`c`dRnlctndTnef`ilikgnu' 25

    224GUI)GNE2;::3 25

    2.5C@BRGUI)GNE3;;77............................................................................. 2>

    2.4KnutidcuIznrcnunEim~`geci............................................... 26

    2.>Ei`trilndnCenuui................................................................................ 26

    2.1 Cs~gugi, Dnun`qilqgmn`ti n Mc`~tn`i diu Ugutnmcu dnG`airmci........................................................................................................ 27

    2.;Ei`ugdnrcnuzcregcgu......................................................................... 5:

    5.MNTIDILIKGC............................................................................................. 53

    5.3Imtidi................................................................................................. 53

    5.2S~c`ticiumngiudng`qnutgkci....................................................... 52

    523Znus~gucbgblgikragec 52

    522Nut~didnecui 55

    525U~hngtidcznus~guc 54

    5.5Ecrcetnrgxcidcnmzrnuc................................................................... 54

    5.4Ceilntcdndcdiu................................................................................... 54

    5.>Ergtrgizriziutizcrccqclgcrcnageegcdnc~dgtirgcudnUG............. 5>

    5>3Mi`tcknmdiritngridncqclgci 5>

    5>2Dnag`gidcmtrgeccunr~tglgxcdc 43

    5>5Trctcmn`tidiudcdiu 45

    4.RNU^LTCDIUIBTGDIU.............................................................................. 44

    4.3C`lgundiurnu~ltcdiuibtgdiu............................................................ 44

    433S~c`ticieczt~li;dc@irmc@BRGUI)GNE3;;77,Knrn`egcmn`tidcuiznrcnuneim~`gecnu 4;

    432S~c`ticieczt~li6dc@irmc@BRGUI)GNE3;;77,Ei`trilndn

    cenuuiu 46

    435S~c`ticieczt~li7dc@irmcCB@T@BRGUI)GNE3;;7782::>,

    Cs~gugi,dnun`qilqgmn`tinmc`~tn idnugutnmcudng`airmci 47

    434G`al~`egcdnecdceczt~li`ititcldcznus~guc >:

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    7/62

    43>Rnu~ltcdiknrclibtgdiznlcnmzrnuc >3

    4.2U~knutnuzcrcmnlfirgcdiurnu~ltcdiuibtgdiu.............................. >2

    423U~knutnuzcrcmnlfirgcu`iknrn`egcmn`tidcuiznrcnuneim~`gecnu >5

    422U~knutnuzcrcmnlfirgcu`iuei`trilnudncenuui >4

    425U~knutnuzcrcmnlfirgcu`ccs~gugi,dnun`qilqgmn`tin

    mc`~tn`idnugutnmcudng`airmci >>

    >.EI@EL^UI................................................................................................ >1

    >.3Ei`el~unu............................................................................................. >1

    >.2Lgmgtcnuditrcbclfi.......................................................................... >7

    >.5Trcbclfiua~t~riu................................................................................... >7

    RNANR@EGCUBGBLGIKRAGECU.................................................................. 1:

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    8/62

    LGUTCDNTCBNLCU

    Tcbnlc38Rnlcidcus~nutnueimiueczt~liunectnkirgcu 51

    Tcbnlc28Eirrnlcidcus~nutnuzireczt~li 56

    Tcbnlc58Zi`t~cizcrccurnuziutcuibtgdcu`cznus~guc 42

    Tcbnlc48@qnguunk~rc`c 42

    Tcbnlc>8Rnu~ltcdiuibtgdiuRnuziutcu 44

    Tcbnlc18Rnuziutcuzcrcs~nutnurnlcegi`cdcuciKnrn`egcmn`tidcuiznrcnuneim~`gecnu 4;

    Tcbnlc;8Rnuziutcuzcrcs~nutnurnlcegi`cdcuciEi`trilndncenuuiu 46

    Tcbnlc68Rnuziutcurnlcegi`cdcuccs~gugi,dnun`qilqgmn`tinmc`~tn`idiuUG 47

    Tcbnlc78Titcldns~nutnuzireczt~li >:

    Tcbnlc3:8Elcuugagecizirziuugbglgdcdndnrnuziutcuzcrcititcldns~nutnu >3

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    9/62

    LGUTCDNAGK^RCU

    Agk~rc38Zrg`egzcgucmnccuunk~rc`cdcg`airmci37

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    10/62

    LGUTCDNKRAGEIU

    Kragei38Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li1 46

    Kragei28Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li; 47

    Kragei58Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li6 >:

    Kragei48Dgutrgb~gidneczt~liunmrnlcics~c`tgdcdndns~nutnu >3

    Kragei>8Dgutrgb~gidititcldnrnuziutcu >3

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    11/62

    LGUTCDNCBRNQGCT^RCU

    CB@TCuuiegciBrcuglngrcdn@irmcuTe`gecu

    BUBrgtgufUtc`dcrd

    D@UDimcg`@cmnUnrqnr

    GNEG`tnr`ctgi`clNlnetritnef`geclEimmguugi`

    GUG`tnr`ctgi`clUtc`dcrd

    GUIG`tnr`ctgi`clIrkc`gxctgi`airUtc`dcrtgxctgi`

    @BR@irmcBrcuglngrc

    @GUT@ctgi`clG`utgt~tnairUtc`dcrduc`dTnef`ilikw

    ZDECZlc`,Di,Efneo,Cet

    UGUgutnmcudnG`airmci

    RAERns~nutAirEimn`tu

    TGTne`ilikgcdcG`airmci

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    12/62

    3.G@TRID^I

    3.3Dnag`gidizriblnmc.

    333Is~nunk~rc`cdcg`airmci9

    Cg`airmci~mctgqis~n,eimis~cls~nri~trictgqigmzirtc`tn,

    nuun`egclzcrciu`nkegiudn~mcirkc`gxcinei`unsn`tnmn`tn`nenuugtc

    unrcdns~cdcmn`tnzritnkgdcGutinuznegclmn`tngmzirtc`tn`icmbgn`tndiu

    `nkegiu,ecdcqnxmcgug`tnrei`netcdinnvziutic~mernuen`tn`mnrinc

    ~mckrc`dnqcrgndcdndncmnccunq~l`nrcbglgdcdnu

    Unk~`di@BRGUI)GNE3;;7782::>,cunk~rc`cdcg`airmcic

    zritnidcg`airmciei`trcqrgiutgziudncmnccu,b~uec`dikcrc`tgrc

    ei`tg`~gdcdn di `nkegiznlcmg`gmgxcidnrgueiunznlcmcvgmgxcidi

    rntir`iuibrniug`qnutgmn`tiundcuizirt~`gdcdnudn`nkegiCUnk~rc`cdc

    G`airmci ibtgdcczcrtgrdcgmzlnmn`tcidn~mei`h~`tidnei`trilnu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    13/62

    35

    cdns~cdiu, g`el~g`di ziltgecu, zrienuuiu, zriendgmn tiu, nutr~t~rcu

    irkc`gxcegi`cguna~`nudnuiat{crnn fcrd{crnNutnuei`trilnuzrnegucmunr

    nutcbnlnegdiu, gmzlnmn tcdiu, mi`gtircdiu, c`clgucdiu ergtgecmn tn n

    mnlfircdiu,`iudgqnruiuugutnmcuziri`dnal~gcg`airmci,zcrckcrc`tgrs~n

    iuibhntgqiudi`nkegindnunk~rc`cdcirkc`gxci unhcm ctn`dgdiu &@BR

    GUI)GNE3;;7782::>'

    332C~dgtirgcunmUgutnmcudnG`airmci

    C~dgtirgcuuictgqgdcdnus~nmi`gtircm,c`clgucm,ergtgecmncqclgcm

    ia~`egi`cmn`tinantgqidiuei`trilnudcunk~rc`cdiuugutnmcudng`airmci

    dn~mcg`utgt~giCuC~dgtirgcuqgucmch~dcrcuznuuicurnuzi`u qnguznliu

    zrienuuiucclec`criumnlfirnurnu~ltcdiu,znlcqnrgagecidia~`egi`cmn`ti

    diuct~cguei`trilnu,bnmeimiair`nen`di~mcbcunzcrcch~dcrcmnlfircrc

    nantgqgdcdndccidnuunuei`trilnu&@BRGUI)GNE3;;7782::>'

    335Ei`tnvt~clgxcidizriblnmc

    C~dgtirgcuuiangtcudnceirdieim~mcmntidilikgcdnczigi,dn`trn

    cus~cguundnutcecmcumntidilikgcubcundc@BRGUI)GNE3;;77&Edgkidn

    ZrtgeczcrccKnutidcUnk~rc`cdcG`airmci'Unzir~mlcdi,f ~mc

    rcxiqnl lgtnrct~rc dguzi qnl uibrn eimi mi`tcr c~dgtirgcu, zir i~tri, f

    nuecuunxdnz~blgecnus~nh~lk~nmcnageegcdntcguc~dgtirgcu,timc`dieimi

    mtrgec c cdnr`egc dc c~dgtirgc u `irmcu n zcdrnu g`tnr`cegi`cgu dn

    unk~rc`cdnugutnmcudng`airmci,eimicu~zrcegtcdc&Ecuecrg`i,2::;'

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    14/62

    34

    3.2Ibhntgqiuditrcbclfi

    Nutc mi`ikrcagc tnm eimi ibhntgqi, ctrcqu di nut~di dn ecui

    rnclgxcdinei`ugdnrc`diculgmgtcnuditrcbclfi&aircmc`clgucdcuczn`cutru,

    dcui`xnectnkirgcudc@BR',iunk~g`tn8

    323Ibhntgqiknrcl

    Zrizir~mergtrgi,ugmzlnundnaeglczlgeci,zcrccqclgcrcnageegc

    dnc~dgtirgcudnugutnmcudng`airmc i,timc`dieimimtrgeccu~ccdnr`egc

    c@BRGUI)GNE3;;77

    322Ibhntgqiunuzneageiu

    -Rnclgxcr~mcrnqguidclgtnrct~rcuibrnunk~rc`cdnugutnmcudn

    g`airmcinuibrnclk~mcudcu`irmcug`tnr`cegi`cgus~nrneimn`dcmcu

    mnlfirnuzrtgecuzcrcinutcbnlnegmn`tidnei`trilnunantgqiuzcrcmg`gmgxcr

    zriblnmcudnunk~rc`c,nmnuznegclc@BRGUI)GNE3;;77?

    - Mi`tcknmdn~mritngris~ngmzlnmn`tn~mergtrgizcrccqclgcri

    krc~dncdnr`egcc@BRGUI)GNE3;;77diuzrienuuiudn~mcc~dgtirgcdn

    ugutnmcudng`airmci?

    -Czlgecriritngrizriziuti,nm~mnut~didnecuiugmzlnu,tn`di

    eimiclqi~mcnmzrnucs~ntnmcc~dgtirgcdnugutnmcudng`airmcieimi

    ~mcdnu~cuctgqgdcdnu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    15/62

    3>

    3.5Nutr~t~rcdiTrcbclfi

    Nutntrcbclfinutnutr~t~rcdinmeg`eieczt~liu,cucbnr8

    &3'Nutcg`trid~i,eimcei`tnvt~clgxcidizriblnmc,iuibhntgqiu

    ditrcbclfincu~cnutr~t~rci?

    &2'Ieczt~liA~`dcmn`tciTnrgecs~nczrnun`tciuei`engtiu

    bugeiunnuun`egcguciceimzc`fcmn`tiditrcbclfins~ntcmbmunrqndn

    nmbcucmn ti tnrgei zcrc c ei`utr~i di ergtrgi ibhntgqi zrg`egzcl dc

    mi`ikrcagc@nuuneczt~liuiczrnun`tcdiu8iuei`engtiubugeiudcrncdc

    unk~rc`cdnugutnmcudng`airmci?uiqgutcu,dnairmcrnu~mgdc,clk~mcu

    dcuzrg`egzcgu`irmcug`tnr`cegi`cgus~ncbirdcmicuu~`ti,nmnuznegclc@BR

    GUI)GNE3;;7782::>ntrudnun~ui`xneczt~liu Ei`ugdnrc`di qcutgdidi

    cuu~`tinculgmgtcnug`nrn`tnuc~mTrcbclfidnEi`el~uidnE~rui,i

    trcbclfi lgmgti~-un c 5, diu 33 eczt~liu nvgutn`tnu `c `irmc, c ucbnr8

    Knrn`egcmn`ti dcu Iznrcnu n Tnlneim~ gecnu, Ei triln dn Cenuuiu n

    Cs~gugi, Dnun`qilqgmn ti n Mc`~tn`i dn Ugutnmcu dn G airmci I

    zrg egzcl ergtrgi~tglgxcdizcrcunlnidiueczt~liu&nziutnrgirunlnidn

    clk~mcudcuu~cuectnkirgcu'aigcrnlnq`egcn)i~g`tnrcidiucuu~`tiuclg

    trctcdiu eim iu zrg`egzcgu ziuuqngu ec~ucdirnu dn aclfcu `c knuti dn

    unk~rc`cdcg`airmci,iu~u~rgiu ~tglgxcdirnu diu gtn`u czi tcdiu `cu

    efnecknmdiuei trilnurnlcegi`cdiu`iritngridncqclgci?

    &5'@ieczt~litru&Mntidilikgc'uidgue~tgdiumtidinmngiudn

    g`qnutgkci,angtccecrcetnrgxcidcnmzrnucclqidinut~didnecuinui

    czrnun`tcdiuius~ctrizcuuius~nei`utgt~nmiergtrgidncqclgci,ibhntgqi

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    16/62

    31

    zrg`egzclditrcbclfi?

    &4'Ieczt~liRnu~ltcdiuIbtgdiutcb~lciurnu~ltcdiuibtgdiuznlc

    czlgecidiergtrgiuibrnclk~`udiuzrienuuiudnc~dgtirgc~tglgxcdiuzir~mc

    nmzrnucdnei`u~ltirgc`crncdnunk~rc`cdnugutnmcudng`airmcil~x

    dctcb~lci,dgue~tnm-uniudcdiuibtgdiununctrgb~gikrc~dncdnr `egcc

    @BR GUI)GNE 3;;77 diu zrienuuiu dn c~dgtirgc dc nmzrnuc clqi, nm ltgmc

    c`lgun,cnageegcdcc~dgtirgch~lkcdcl~xdcs~nlcu`irmcu

    &>'Zira gm,ieczt~li eg ei &Ei`el~ui' ug tntgxc iu rnu~ltcdiu

    ibtgdiu,czi`tcculgmgtcnudinut~diangtinczi`tczcrcziuuqngua~t~riu

    trcbclfiuuibrnicuu~`ti

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    17/62

    2.A^@DCMN@TCITNRGEC

    2.3Unk~rc`cnmUgutnmcudnG`airmci

    @ieczt~lic`tnrgir&gtnm33'czrnun`ti~-uniei`engtidnUnk~rc` c

    dcG`airmci,l~xdcu@BRGUI)GNE3;;77

    Izrnun`tneczt~lizrntn`dndcrcilngtir~mnmbcucmn`tinuun`egcl

    s~c`ticicuu~`tiUnk~rc`cnmUgutnmcudnG`airmcins~c`tiu@irmcu

    s~nrnk~lcmitnmc,nmnuznegclcrnanrgdc@BRGUI)GNE3;;77

    Ei`ugdnrc`dicurcxnunvziutcu`igtnm35&2',nutntrcbclfiagecr

    lgmgtcdiciutzgeiu8Knrn`egcmn`tidcuiznrcnuneim~`gecnu,Ei trilndn

    cenuuinCs~gugi,Dnun`qilqgmn`tinMc`~tn`idnUgutnmcudnG`airmci

    dc@BRGUI)GNE3;;77

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    18/62

    36

    233UgutnmcudnG`airmci&UG'

    UgutnmcudnG`airmci&UG'zidnmunrdnag`gdiueimiceimbg`ci

    dn rne~ruiu f~mc`iu n eimz~tcegi`cgu s~n g tnr rnlcegi`cm c eilntc, i

    crmcxn`cmn`ti,crne~znrci,cdgutrgb~gini~uidndcdiu,eimiibhntgqi

    dn nageg`egc knrn`egcl &zlc`nhcmn`ti, ei`triln, eim~`geci n timcdc dn

    dnegui'`cuirkc`gxcnuCdgegi`clmn`tn,iuUGzidnmtcmbmch~dcrciu

    knrn`tnun~u~rgiucc`clgucrzriblnmcu,ergcr`iqiuzrid~tiui~unrqgiun

    qgu~clgxcrs~nutnueimzlnvcu&Dnag`giMNE&76')UBE'

    232Unk~rc`cdiuUG

    C@irmcGUI;476-2,irgkg`clmn`tnGU;476-2,di@GUT&@ctgi`cl

    G`utgt~tn air Utc`dcrdu c`d Tnef`ilikw' nvgkn eg`ei zrg ezgiu bugeiu zcrc

    ibtn`idcunk~rc`cdiuUG8

    &3'Ei`agdn`egclgdcdniugutnmcdnqndguzirdnei`dgnuzcrcmc`tnriu

    dcdiuei`agdn`egcgurnutrgtiuczn`cucicenuuidiu~u~rgiuc~tirgxcdiu

    &2'G`tnkrgdcdndiudcdiuzriqzritniei`trccmnccuqclgdcdnn

    ei`ugut`egcdiudcdiu

    &5'Dguzi`gbglgdcdncuunk~rcs~niurne~ruiudng`airmtgecnutnhcmnm

    ei`dgnu`irmcgudniznrcindguzi`qnguzcrci~u~rgi,`imimn`tinm

    s~nairnmuilgegtcdiu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    19/62

    37

    &4'C~tn`tgegdcdncuunk~rccs~nm rnenbn~~mcmn`ucknm,c enrtnxc

    dcgdn`tgdcdndns~nmcn`qgi~

    &>'@irnzdgi &Grrntrctcbglgdcdn' b~uec nqgtcr s~n i rnmntn`tn i~

    dnutg`ctrgi`nk~nin`qgii~rnenbgmn`tidcmn`ucknm

    ^mactig`tnrnuuc`tnaigibunrqcdi`cznus~gucs~ncbrc`kn>:.dcu

    3:::mcgirnunmzrnucubrcuglngrcu,rnclgxcdcznlcM d~liUne~rgtwUil~tgi`u8

    ecdc qnx mcgu zrnie~zc`tn i acti diu a~`egi`rgiu g`uctguangtiu zriqiecrnm

    znrdcun)i~dc`iu`cunmzrnucunms~ntrcbclfcmi~trcbclfcrcm

    Agk~rc38Zrg`egzcgucmnccuunk~rc`cdcg`airmci

    Ai`tn8Znus~guc@cegi`cldnUnk~rc`cdcG`airmci&MD^LI'

    Crnqguidncenuuiu i~triactirdntnrmg`c`tn`cunk~rc cdc

    g`airmciEcr~ui&3775'dgxs~ndnqgdicactirnunvtnr`iu,tcgueimiargcui~

    lgen`c,zriqiecmczcuucknmdntcrnacudn~ma~`egi`rgizcrci~triS~c`dii

    zrgmngri rntir`c, `c mcgirgc dcu qnxnu, iu cenuuiu di u~butgt~ti `i ui

    ec`enlcdiun,imcguzrnie~zc`tn,nlnhrnenbn~tidiei`fnegmn`ti`nenuurgi

    zcrc~tglgxcrcs~nlcug`airmcnus~nh`iuimcguznrtg`n`tnucnln

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    20/62

    2:

    Kgl &3774' efcmc c ctn`izcrcccdmg`gutrcidcunk~rc`cn

    zrizn~mmidnli,dgqgdgdinmtru&:5'acunu,zcrcnvne~t-li8

    &3'Zlc`nhcmn`ti8

    -Nutcbnlnenrrnuzi`ucbglgdcdnuciun`qilqgdiueimcrncdnunk~-

    rc`c?

    -Dnag`gr~mcziltgecdnunk~rc`c?

    -Lnqc`tcrrgueiu

    &2'Iznrcegi`clgxci8-Cqclgcriurgueiu?

    -Czlgecrcziltgecdnunk~rc`c?

    -Nutcbnlnenr~mzlc`idnei`tg`k`egc?

    -Trng`cr

    &5'Ceimzc`fcmn`ti8

    -C`clgucriurnlctrgiuiznrcegi`cgu,ttgeiunnutrctkgeiudnunk~-

    rc`c?

    -Cqclgci8

    -Ei`ari`tcriurnu~ltcdiurnclgxcdiueiminuznrcdi

    2.2@irmcunzcdrnudnunk~rc`c

    Ugutnmcu dn G`airmci, nm knrcl, ui ugutnmcu fntnrik`niu,

    airmcdiu zir dganrn`tnu zlctcairmcu dn fcrd{crn n uiat{crn &Ugutnmcu

    Iznrcegi`cgu&UI'nczlgectgqiu'Cnvzlircidcuaclfcudnunk~rc`c,dn`tri

    dn~mcmbgn`tneimz~tcegi`clfntnrik`niecdcqnxmcgirnmcguuiagutgecdc

    nangtc,nuun`egclmn`tn,ctrcqudns~ctriqntirnu8

    &3' UnrF~mc`i?

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    21/62

    23

    &2' Ugutnmcuczlgectgqiu?

    &5' Ugutnmcuiznrcegi`cgun

    &4' Rndn

    F ~mcrcxiqnlbgblgikrcagcuibrncknutidcUnk~rc`cdiuUG

    &dguunrtcnu, tnunu, lgqriu n crtgkiu' tn`di eimi bcun dgqnrucu @irmcu

    g`tnr`cegi`cgu,tcgueimi8

    223Eimmi`Ergtnrgc&GUI3>4:6'

    CGUI3>4:6,tcmbm ei`fnegdi eimi Eimmi`Ergtnrgc, trctc dcu

    dnag`gnudneimzi`n`tnu&te`geiu'dnunk~rc cqguc`di~mzrienuuidn

    cqclgcidnugutnmcu

    I Eimmi`Ergtnrgcznrmgtneimzcrcnun`trnzrid~tiuair`nen`di

    ~mei`h~`tidnrns~gugtiudnunk~rc`cnmndgdcudnkcrc`tgcczlgecdcuc nlnu

    d~rc`tn c cqclgci Liki, ci ag`cl dc cqclgci dn digu zrid~tiu zidn-un

    eimzcrcrcua~`nudnunk~rc`cniu`qngudnkcrc`tgcair`negdiuzircmbiu,

    dnairmccnueilfnrizrid~tis~nmcguuncdns~cru`nenuugdcdnudielgn`tn.

    2.2.2 GUI)GNETR3555>

    C`irmcGUI)GNE3555>eimziutcdn>zcrtnu,dn`triditnmcknrcl

    dn Tne`ilikgc dc G airmci n efcmcdc dn KMGTU &K~gdnlg`nu airt fn

    Mc`cknmn`tiaGTUne~rgtw'Cueg`eizcrtnuui8

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    22/62

    22

    Zcrtn38Ei`enztuc`dmidnluairGTune~rgtw

    Z~blgecdcnm3771,air`nen~mcqguiknrcldiuei`engtiunmidnliu

    a~`dcmn`tcgu~ucdiuzcrcdnuernqnrcknutidnunk~rc`cdnTG

    Zcrtn28Mc`ckg`kc`dzlc``g`kGTUne~rgtw

    Z~blgecdcnm377;,trctcdirnlcegi`cmn`tidcrncdnunk~rc`cdc

    g`airmcieimcudnmcgurncu dc irkc`gxci, zrg`egzclmn tn c rncdn

    unk~rc`ceirzirctgqc

    Zcrtn58Tnef`gs~nuairtfnmc`cknmn`tiaGTUne~rgtw

    Z~blgecdcnm3776,dnuernqnte`gecudnknutidnunk~rc`czcrcc

    rncdnTne`ilikgcdcG`airmci,trctc`dinmnuznegcldcknutidnrgueieim

    te`gecudnc`lgundnrguei

    Zcrtn48Unlnetgi`iaucank~crdu

    Z~blgecdcnm2:::Air`nen~mectlikidnei`trcmndgdcu,n~m

    k~gczcrccunlnidnutcu

    Zcrtn>8Mc`cknmn`tk~gdc`eni``nt{iroune~rgtw

    Z~blgecdc nm 2::3 Eimzlnmn`tc c zcrtn s~ctri dnutc GUI,

    cernuen`tc`diactirnurnlnqc`tnuzcrccei`nvidnUGnmrndnu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    23/62

    25

    225 EIBGT &Ei`tril Ibhnetgqnu air G`airmctgi` c`d Rnlctnd

    Tnef`ilikgnu'

    Ibhntgqc air`nenr bicu zrtgecu zcrc c knuti dn zrienuui dn

    tne`ilikgc dc g`airmci nlgmg`c`di dgqnrk`egcu n`trn rgueiu dn `nkegiu,

    s~nutnute`gecu,ei`trilnunmndgdcudndnunmzn`fi

    CmntidilikgcEIBGTei`ugutnnm1z~blgecnu,eimiaiei`i`c

    unk~rc`c dc G airmci, mcu ugm `i zlc`nhcmn ti dcu tne`ilikgcu dc

    g`airmci dn ceirdi eim i ibhntgqi dc irkc`gxci Ziuu~g, cg dc clk~`u

    ei`trilnunuzneageiuzcrcunk~rc`cdcg`airmci,dn`trnnutnei`trilnutnm-un

    canrrcmn`tcMct~rgtwMidnlu,midnliuzcrcc`lgundnmct~rgdcdndnzrienuuiu,

    s~nzidnunr~tglgxcdc`izrihntidnunk~rc cdcg`airmci

    224GUI)GNE2;::3

    C`irmcGUI2;::382::> ~mcnqil~idizcdribrgt`geiBU

    ;;77-282::2,s~ndnag`nrns~gugtiuzcrc~mUgutnmcKnutidnUnk~rc`cdc

    G`airmciIzcdri aig g`eirzircdi znlc Tfn G`tnr`ctgi`cl Irkc`gxctgi` air

    Utc`dcrdgxctgi` &GUI', irkc`gxcis~nnutcbnlnenzcdrnu g`tnr`cegi`cgu dn

    enrtgagecinmdgqnrucurncu

    C`irmcGUI2;::382::>c`irmcBU;;77-282::2rnqgucdc,eim

    mnlfirgcuncdcztcnu,ei`tnmzlc`dii egeliZDECdnmnlfirgcuncqguidn

    zrienuuius~ncu`irmcudnugutnmcudnknutihg`eirzircrcm

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    24/62

    24

    Cbcgvi,~mbrnqnfgutrgeidcnqil~idc`irmcctefnkcrcGUI

    2;::38

    377>8 zrgmngrc qnrui dc BU ;;77-3 &BU ;;77-38377> - Tne`ilikgc dc

    G`airmci-Edgkidnzrtgeczcrcknutidcunk~rc`cdcg`airmci'

    37768zrgmngrcqnruidcBU;;77-2&BU;;77-283776-Ugutnmcdnknutidc

    Unk~rc`cdcG`airmci-Nuznegagecnunk~gczcrc~ui'

    37778 rnqguidcBU;;77-3&BU;;77-383777-Tne`ilikgcdcG`airmc i -

    Edgkidnzrtgeczcrcknutidcunk~rc`cdcg`airmci'

    2:::8z~blgecidc@irmcGUI)GNE3;;77&GUI)GNE3;;7782:::-Tne`ilikgc

    dcG`airmci - Edgkidnzrtgeczcrcknutidcunk~rc`cdcg`airmci

    tcmbmrnanrn`egcdceimiBUGUI)GNE3;;7782:::'

    2::38zrgmngrcqnruidc`irmc`iBrcugl,@BRGUI)GNE3;;77&@BRGUI)GNE

    3;;7782::3 - Tne`ilikgc dc G`airmci - Edgkidnzrtgeczcrcknutidc

    unk~rc`cdcg`airmci'

    2::28rnqguidc`irmcBU;;77zcrtn2&BU;;77-282::2-Ugutnmcdnknut i

    dcUnk~rc`cdcG`airmci-Nuznegagecnunk~gczcrc~ui'

    Ckiuti)2::>8unk~`dcqnruidc`irmc`iBrcugl,@BRGUI)GNE3;;77&@BR

    GUI)GNE3;;7782::>-Tne`ilikgcdcG`airmci-Edgkidnzrtgeczcrcknuti

    dcunk~rc`cdcg`airmci'

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    25/62

    2>

    I~t~bri)2::>8 `irmc GUI 2;::3 &GUI)GNE 2;::382::> - Tne`ilikgc dc

    G`airmci - Te gecu dn unk~rc`c-UgutnmcdnknutidcUnk~rc`cdc

    G`airmci-Rns~gugtiu'

    Ceimzc`fc`diizrienuuidnnqil~ifgutrgecczrnun`tcdicegmc,

    zidn-un ibunrqcr s~nc `irmcGUI)GNE3;;77, s~ncnqil~idcBU;;77-3,

    g`eirzircdcznlcGUInm2:::,tcmbmaigrnqgucdc,ncmbcucu`irmcu,c

    GUI)GNE2;::3ncGUI)GNE3;;77,hnuticlg`fcdcuIzrvgmizcuuiunrc

    ei`qnrui dc GUI)NE 3;;7782::> nm GUI)GNE 2;::2, zrnqguti zcrc 2::6,

    airmc`dicuugmcacmlgcGUI)GNE2;:::s~ntrctcrcuznetiumcgucmzliudn

    Unk~rc`cdcG`airmci

    2.5C@BRGUI)GNE3;;77

    C@BRGUIGNE3;;7782::> ~medgkidnzrtgecudnknutidn

    unk~rc`cdcg`airmciU~cgmzirt`egczidnunrdgmn`ugi`cdcznli`mnri

    ernuen`tndnznuuicunqcrgndcdnudncmnccucs~ncg`airmcinvziutc`c

    rndndneimz~tcdirnuIibhntgqinvzlegtidc`irmcnutcbnlnenr~mrnanrn`egcl

    zcrccuirkc`gxcnudnun`qilqnrnm,gmzlnmn`tcrnmncqclgcrnmcknutidc

    unk~rc`cdng`airmci

    Nmu~cdie~mn`tcic@BR-GUI)GNE-3;;7782::>cbirdc33t zgeiu

    zrg`egzcgu8

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    26/62

    21

    3. Ziltgecdnunk~rc`cdcg`airmci -i`dndnuernqncgmzirt`egcn

    rnlcegi`c iu zrg`egzcgu cuu~`tiu s~n dnqnm unr cbirdcdiu `~mc ziltgecdn

    unk~rc`c

    2. Irkc`gxc`di c unk~rc`cdcg`airmci -cbirdccnutr~t~rcdn~mc

    knr`egczcrccunk~rc`cdng`airmci,cuugmeimicbirdcinutcbnlnegmn`ti

    dnrnuzi`ucbglgdcdnug`el~g`ditnrengriunair`nendirnudnunrqgiu

    5.Knutidnctgqiu -trcbclfccelcuugageci,irnkgutriniei`trilndiu

    ctgqiudcirkc`gxci

    4.Unk~rc`cnmrne~ruiuf~mc`iu-tnmeimiaieiirgueidneirrn`tndn

    ctiug`tn`egi`cgui~cegdn`tcguangtiuzirznuuicuTcmbm uicbirdcdiu8c

    g`el~uidnrnuzi`ucbglgdcdnurnlctgqcuunk~rc`c`cdnuergidiuecrkiu,c

    airmcdnei`trctcinitrng`cmn`tinmcuu~`tiurnlcegi`cdiuunk~rc`c

    >.Unk~rc`caugec ndi cmbgn`tn -cbirdcc`nenuugdcdndnundnag`gr

    rncudnegre~lcirnutrgtcnc`nenuugdcdndnzritnknrns~gzcmn`tiuncg`arc-

    nutr~t~rcdntne`ilikgcdnG`airmci

    1.Knrn`egcmn`tidcuiznrcnuneim~`gecnu -cbirdccuzrg`egzcgu

    rncus~ndnqnmunribhntidnnuznegclctn`idcunk~rc`cDn`trnnutcu

    rncu dnutcecm-un cu s~nutnu rnlctgqcu c zriendgmn tiu iznrcegi`cgu n

    rnuznetgqcurnuzi`ucbglgdcdnu,fimilikcingmzlc`tcidnugutnmcu,knr`egc

    dnrndnu,ei`trilnnzrnqn i d n qr~u,ei`trilndnm~dc`cu,nvne~i n

    k~crdcdnbceo~z,ei`trilndndie~mn`tci,unk~rc`cdneirrnginlntr`gei,

    n`trni~trcu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    27/62

    2;

    ;.Ei`trilndncenuui-cbirdciei`trilndncenuuicugutnmcu,cdnag`gi

    dneimznt`egcu,iugutnmcdnmi`gtircidncenuuin~ui,c~tglgxcidn

    un`fcu,dn`trni~triucuu~`tiu

    6.Cs~gugi,dnun`qilqgmn`tinmc`~tn`idnugutnmcudng`airmci-

    cbirdc iu rns~gugtiu dn unk~rc`c diu ugutnmcu, ei`trilnu dn ergztikrcagc,

    ei`trilndncrs~gqiununk~rc cdidnun`qilqgmn`tinu~zirtndnugutnmcu

    7.Knutidng`egdn`tnudnunk~rc`cdcg`airmci -g`el~dc`cqnrui

    2::>,czrnun`tcdigugtn`u8@itgagecidnarckglgdcdnunnqn`tiudnunk~rc`cdc

    g`airmcinknutidng`egdn`tnudnunk~rc cdcg`airmcinmnlfirgcu

    3:.Knutidcei`tg`~gdcdndi`nkegi -rnaircc`nenuugdcdndnuntnr

    ~mzlc`idnei`tg`~gdcdnnei`tg`k`egcdnun`qilqgdi,gmzlnmn tcdi,tnutcdin

    ct~clgxcdi

    33.Ei`airmgdcdn-cbirdcc`nenuugdcdndnibunrqcriurns~gugtiulnkcgu,

    tcgueimiczrizrgndcdng`tnlnet~clnczritnidcug`airmcnudnelgn`tnu

    Izlc`nhcmn`tidcucnu rnlctgqcu `irmcdnqnctn`dnrc~m

    ei`h~`tidnrns~gugtiu,dn`trnius~cgu~mrns~gugtibugei8C~dgtirgcu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    28/62

    26

    2.4KnutidcuIznrcnunEim~`geci

    Iibhntgqizrg`egzcldiknrn`egcmn`tidcuiznrcnuneim~`gecnu kcrc`tgrciznrci unk~rc n eirrntc diu rne~ruiu dn zrienuucmn`ti dc

    g`airmciZcrctclzrneguikcrc`tgr,cl~xdc@irmc@BRGUI)GNE3;;7782::>,

    s~niuei`trilnuczlgecdiuuctguac cmcuei`dgnudnunhcdcuCuectnkirgcu

    unlnegi`cdiu`nutneczt~lidc@irmcuicuunk~g`tn8

    Zritniei`trcedgkiumclgegiuiunmqngu8 Zritniei`trcqr~u,

    {irmu, uzw{crnu, trihc`u, i~ s~cls~nr edgki mclgegiui eczcx dn dc`gagecr,

    rnmiqnr,eczt~rcr,dgq~lkcrn~tglgxcrrne~ruiueimz~tcegi`cgui~g`airmcnuunm

    iei`fnegmn`tidi~u~rgizcrcag`uglnkcgui~`iznrmgtgdiu

    Ezgcudnunk~rc`c8 Tidc zritni ei`trc znrdcu g`nuznrcdcu,

    dnucutrnunctmnumizriblnmcueimmc`~tn ii~nrridi~u~rgi

    Triecdng`airmcnu8 Dnag`gnunmndgdcudnunk~rc`czcrctidc

    ns~cls~nrtriecdng`airmciirgkg`cdci~dnutg`cdcirkc`gxci,dnudnc

    triecdnn-mcglctitrc`uzirtndcumdgcudnbceo~z

    2.>Ei`trilndnCenuui

    Iei`trilndncenuuiu,eimiizrzrgi`imndnag`n,rnuzi`uqnl

    zirei`trilcricenuuig`airmci,rne~ruiudnzrienuucmn`tidcug`airmcnu

    nzrienuuiudn`nkegiueimbcun`iurns~gugtiudnunk~rc cdcg`airmci

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    29/62

    27

    Curnkrcudnei`trilndncenuuidnqnmlnqcrnmei`ugdnrcicu

    ziltgecu zcrc c~tirgxci n dguunmg`ci dc g`airmci C unk~gr ui

    rnlcegi`cdcucuectnkirgcuunlnegi`cdiu`nutneczt~lidc@irmc

    Knrn`egcmn`tidncenuuidi~u~rgi8 Knrn`egcmn`ti dn

    eimirnclgxcdiicenuuidi~u~rgi,s~cguun~uzrgqglkgiu,dgrngtiudncenuuin

    eimiknrn`egcdcu~cun`fcdncenuuiTcmbmtrctcdcc`lgundnrnkgutriu

    &liku'dns~nei`u~ltcdi,nvne~tcdincltnrcdiznli~u~rgi

    Eimz~tcimqnlntrcbclfirnmiti8cbirdceimiuidnag`gdiun

    knrn`egcdiuitrcbclfirnmitinceimz~tcimqnl,eimirndnu{grnlnuu,znlc

    irkc`gxciTrctctcmbmdneimii~u~rgiibtmcenuuinct is~n

    ziuuqnlcenuucrczcrtgrdnrndnunvtnr`cui~mqngu

    2.1Cs~gugi,Dnun`qilqgmn`tinMc`~tn idiuUgutnmcudn

    G`airmci

    Ccs~gugi,dnun`qilqgmn`tinmc`~tn i,dnqnmkcrc`tgrs~nc

    unk~rc`c zcrtn g tnkrc tn diu ugutnmcu dn g airmci Ugutnmcu dn

    g`airmcig`el~nmugutnmcuiznrcegi`cgu,g`arc-nutr~t~rc,czlgecnudn`nkegi,

    zrid~tiudnzrctnlngrc,unrqgiunczlgecnuCectnkirgc~tglgxcdc`iritngrizcrc

    c~dgtirgcdnutneczt~lidgxrnuzngti knutidnq~l`nrcbglgdcdnute`gecu,cu

    s~cguuinuznegclmn`tnqgucdcuzirziuuqnguctcec`tnu,ziguzidnmznrmgtgri

    cenuui n c mc`gz~lci dn g airmcnu qgtcgu zcrc i `nkegi dn ~mc

    irkc`gxci

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    30/62

    5:

    Knutidnq~l`nrcbglgdcdnute`gecu8a~`dcmn`tclrnei`fnenrnuucu

    q~l`nrcbglgdcdnu nm tnmzi fbgl zcrc cqclgcidcirkc`gxcintimcrcu

    mndgdcuczrizrgcdcuzcrclgdcreimiurgueiucuuiegcdiu

    2.;Ei`ugdnrcnuzcregcgu

    Nutn eczt~li b~uei~ dcr i nmbcucmn`ti tnrgei `nenuurgi ci

    ceimzc`fcmn`tiditrcbclfi,cbirdc`diiucuu~`tiu8zcznldcuc~dgtirgcu,c

    @irmc @BRGUI)GNE3;;7782::>,nmnuznegcltrudiuun~ui`xntzgeiuC

    unlnidnuunutrutnmcu&KnutidcuIznrcnunEim~`geci?Ei`trilndn

    Cenuui n Cs~gugi, Dnun`qilqgmn`ti n Mc`~tn`i diu Ugutnmcu dn

    G`airmci'aigh~utgagecdc`igtnm35&2'

    @ i z rvgmi eczt~li unr dgue~tgdc c mntidilikgc ~ucdc n unr

    czrnun`tcdiiergtrgizriziutizcrccqclgcrcnageegcdnc~dgtirgcudcunk~rc`c

    dnugutnmcudng`airmci,ibhntgqizrg`egzcldnutntrcbclfi

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    31/62

    5.MNTIDILIKGC

    Nutn eczt~li czrnun`tc i Ritngri zriziutc zcrc c cqclgci d c

    nageegcdnc~dgtirgcudnugutnmcudng`airmc i,dnuernqn`dis~climtidin

    tgzidnznus~guc~tglgxcdc`itrcbclfi,iumngiudng`qnutgkci~tglgxcdiuzcrcc

    eilntcnitrctcmn`tidiudcdiudn`tridi~`gqnruidcznus~guc

    5.3IMtidi

    Mtidiig`utr~mn`tidiei`fnegmn`tis~nzriziregi`cirgn`tci

    knrclzcrcaceglgtcrizlc`nhcmn`tidn~mcznus~guc,zcrceiirdn`crg`qnutgkcnu

    ng`tnrzrntcriurnu~ltcdiu,dnqn`diunrcdns~cdicitgzidnznus~guc&Acefg`,

    2::5'Tcmbm ei`ugdnrcdi~mecmg`fi,~mcairmclkgecdnzn`ucmn`ti

    &Qnrkcrc,2::4'

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    32/62

    52

    Nutntrcbclfiaigdnun`qilqgdiczcrtgrdimtidi an`imn`ilkgei

    dnan`dgdi zir F~uunrl &36>7-3756', s~n ei`ugutn nm guilcr `~m an`mn`icu

    g`al~`egcu `nenuurgcu zcrc nut~d-li n ~u-li, zidn`di ei`ugdnrcr

    ziutnrgirmn`tnlgkcnucbc`di`cdcu

    Imtididnqcrnhi~tglgxcdiaigieimzcrctgqiEi`airmnKgl&3777',

    nutnmtidizriendnznlcg`qnutgkcidn_]an`mn`iui~actiu,eimqgutcc

    rnuucltcrcudganrn`cunugmglcrgdcdnun`trnnlnu

    5.2S~c`ticiumngiudng`qnutgkci

    Cznus~gucaigdnun`qilqgdcdnairmcdnuergtgqcnczlgecdcDnuergtgqc,

    ziguczrnun`tccdnuergidcuecrcetnrutgecudndntnrmg`cdcziz~lcii~

    an`mn`ii~inutcbnlnegmn`tidnrnlcnun`trnqcrgqngu&Kgl,3777?Qnrkcrc,

    2::4'Czlgecdc,dcdis~nunzriznc~mcag`clgdcdnzrtgec,znlcgmzlc`tci

    `c nmzrnuc c`clgucdc dn ~m zlc`i nutrctkgeinma~`idcuqcrgqngun

    ecrcetnrutgecuczrnun tcdcuczcrtgrdn~mmidnlizriziuti&Qnrkcrc,377;'Iu

    mngiudng`qnutgkci~tglgxcdiu`nutntrcbclfiaircmiuunk~g`tnu

    523Znus~gucBgblgikragec

    Dnun`qilqgdcczcrtgrdnmctnrgclhnlcbircdi,ei`utgt~didnlgqriun

    mi`ikrcagcu &Kgl, 3777', bnm eimi rnqgutcu, hir`cgu, g`tnr`nt, `n{ulnttnru,

    znrgdgeiu,rns~nutaireimn`tuRAEu,@irmcCB@T@BRGUI)GNE3;;7782::>,

    ntidimctnrgcldguzi qnlcizblgeinmknrcl&Qnrkcrc,2::4'

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    33/62

    55

    522Nut~didnEcui

    Inut~didnecuilgmgtcdinm~mci~zi~ecu~`gdcdnu,n`tn`dgdcu

    nuucueimi~mcznuuic,~mcacmlgc,~mzrid~ti,~mcnmzrnuc,~mrki

    zblgei,~mceim~`gdcdni~mnumi~mzcuTnmecrtnrdnzria~`dgdcdnn

    dntclfcmn`ti&Qnrkcrc,2::4'

    @irmclmn`tninut~didnecui~ucdis~c`diiznus~gucdirtnm

    ~mei`trilnuibrniucei`tnegmn`tiuns~c`tiiaieiunn`ei`trcnman` mn`iu

    g`unrgdiunmclk~mei`tnvtidcqgdcrncl&Wg`,2::>'Cg`dc,unk~`diAnr`c`dnu

    &3715',nln ~ucdis~c`diundnunhcc`clgucrugt~cnuei`erntcu,`cuu~cu

    zcrtge~lcrgdcdnu

    Nutn nut~didn ecui aig dnun`qilqgdinm ~mcnmzrnucdn zns~n`i

    zirtnugt~cdcnmLchncdi,RgiKrc`dndiU~lCnmzrnucclqitrcbclfc`crncdn

    cuunuuirgc tne`ilkgec n zrnutci dn unrqgi u ` c rnc dn tne`ilikgc dc

    g`airmci n,qgc dnrnkrc, g gegcun~utrcbclfiu zir mngi dn~mc c~dgtirgc dc

    unk~rc`cdiuugutnmcudng`airmcidielgn tn,qguc`diibtnr~m dgck`utgei

    dcugt~ciEimiizrid~tiag`cldcnmzrnucznus~gucdciair`negmn`tidn

    unrqgiu`crncdnTG,zcrcnmzrnucus~nc ~tglgxcmeimimngizcrcqgcbglgxcr

    un~u`nkegiu,dnnvtrnmcgmzirt`egcs~ncnmzrnucVnutnhcclg`fcdceim

    zcdrnug`tnr`cegi`cgu,eimic@BRGUI)GNE3;;7782::>,zcrcs~nidgck`utgei

    zir nlc rnclgxcdc qgc c~dgtirgc unhc nagecx n gl~utrn c rnclgdcdn dc nmzrnuc

    c~dgtcdc

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    34/62

    54

    525U~hngtidcznus~guc

    Iuu~hngtiudcznus~gucuicuznuuicus~nair`nenmiudcdius~ni

    znus~gucdir`nenuugtc&Qnrkcrc,2::4'

    @nutn nut~di, i u~hngti dcznus~gucia~`dcdirnzrizrgntrgidc

    nmzrnuc s~n nut eimzlntc`di ; c`iu dn nvgut`egc, trcbclfc `cu rncu

    cdmg`gutrctgqcu,eimnregclnte`gecAirmcdinmC`lgundnUgutnmcune~ruc`di

    zu-krcd~cinmKnutiNmzrnn`dndircdn@nkegiu

    5.5Ecrcetnrgxcidcnmzrnuc

    Ct~clmn`tncnmzrnucei`tceim4eilcbircdirnu,un`di2t e`geiueim dndgeci nvel~ugqc zcrc ctn`dgmn`ti c elgn`tnu, ~mc unerntr g c n i

    zrizrgntrgi n cdmg gutrcdir s~n trcbclfc `crnceimnregcl)cdmg`gutrctgqcn

    nqn`t~clmn`tn`crncte`gecCnueilfcaigangtcdnqgdiciactidnnvgutgrei`tcti

    dgrntin`trniznus~gucdirniu~hngtidcznus~guc

    5.4Ceilntcdndcdiu

    I g`utr~mn`ti zcrc c eilntc dn dcdiu aig ~mc n`trnqgutc unmg-

    nutr~t~rcdc

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    35/62

    5>

    Cn`trnqgutc~mzriendgmn`ti`is~cliznus~gucdiracxznrk~`tcu

    ciu~hngtidcznus~gucCn`trnqgutczidnunrg`airmcli~cbnrtc,s~n ~mc

    ei`qnrucg`airmclntnmziribhntgqieilntcriudcdiuzcrccznus~guc,i~cg`dc

    zirzc~tc,i`dnuickn`dcdiuqrgiuzi`tiuzcrcunrnmnvzlircdiueimi

    n`trnqgutcdi&Qnrkcrc,2::>'

    C n trnqgutc aig rnclgxcdc zir n-mcgl n ziutnrgirmn`tn dgue~tgdc

    znuuiclmn`tndnmc`ngrcg`airmclzcrcrncqclgci

    5.>Ergtrgizriziutizcrccqclgcrnageegcdnc~dgtirgcudnUG

    Iergtrgizrizns~ctrizcuuiu,cucbnr8&3'Mi`tcknmdiritngridn

    cqclgci?&2'Dnag`gidcmtrgeccunr~tglgxcdc?&5'Trctcmn`tidiudcdiu?&4'

    C`lgundiurnu~ltcdiuibtgdiu

    5>3Mi`tcknmdiRitngridncqclgci

    Nutn gtnm nvzlgec iu ergtrgiu ~tglgxcdiu zcrc c mi`tcknm di

    s~nutgi`rgi,eimziutizir4:&s~crn`tc's~nutnuns~nunrqgr dnbcunzcrc

    canrgidikrc~dncdnr`egcu@BRGUI)GNE3;;77,diuzrienuuiudnc~dgtirgc

    ~tglgxcdiuznlcnmzrnucclqi

    Cuznus~gucudnecmzindie~mn`tclaircmrnclgxcdcueimbcun`c

    knutidnunk~rc`cdcg`airmcidnag`gdc`c@BRGUI)GNE3;;7782::>n`c

    Rns~nutAirEimn`tnu2371-RAE2371-UgtnUne~rgtwFc`dBiio,s~ndnag`nm

    tne`gecmn`tneimicb~uecdcug`airmcnudnqnunrei`d~xgdcniuergtrgiudn

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    36/62

    51

    g`tnrzrntci diu dcdiu ibtgdiu C ~tglgxci dn zcdrnu dn unk~rc`c

    ei`fnegdiu nutcbnlnen mnlfirnu zrtgecu zcrc c gmzlc`tcidcknuti d n

    unk~rc`cdcg`airmci

    ^mcbiczcrtndiuzrienuuiudnc~dgtirgcnmzrnkcdiuznlcnmzrnuc

    clqidinut~didnecuiunbcungcnmei`trilnudcuiznrcnudnn`trcdcnucdc

    dndcdiun,nmdneirr`egc,dnei`trilnudicenuuiciudcdiu^mci~trc

    zrnie~zci diu zrienuuiu dn c~dgtirgc nvcmg cdiu eim q~l nrcbglgdcdnu

    te`gecuczrnun`tcdcuzirugutnmcu,s~nrugutnmcudnun`qilqgdiunmedgkilgqrn,

    s~nrnmuiat{crnzrizrgntrgi

    Ei`ugdnrc`di iu actirnu cegmc egtcdiu, izti~-un zir mi`tcr cu

    s~crn tc s~nutnu bcun diu eczt~liu n rnuznetgqcu ectnkirgcu cbcgvi

    g`dgecdcu

    Eczt~liudcGUI)GNE3;;7782::>

    Ectnkirgc S~nutnu

    1KnutidcuIznrcnunEim~`geci

    14Zritniei`trcedgkiumclgegiuiunmqngu

    3ct>

    1>Ezgcudnunk~rc`c 1n;

    16Triecdng`airmcnu 6ct37

    ;Ei`trilndnCenuui ;2Knrn`egcmn tidncenuuidi~u~rgi

    2:ct5:

    ;;Eimz~tcimqnlntrcbclfirnmiti

    53ct51

    6Cs~gugi,Dnun`qilqgmn`tinMc`~tn`idiUgutnmcudnG`airmci

    61Knutidnq~l`nrcbglgdcdnute`gecu

    5;ct4:

    Tcbnlc38Rnlcidcus~nutnueimiueczt~liunectnkirgcu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    37/62

    5;

    Kgl&3777'eimn`tcs~nclk~`uc~tirnunutcbnlnenmeimirnkrcknrcl

    s~ni`mnridnznrk~`tcudn~ms~nutgi`rgi`idnqn~ltrczcuucrctrg`tcI

    s~nutgi`rgizcrccanrgidikrc~dnunk~rc cnms~ncnmzrnucznus~gucdc

    un n`ei`trc ziuu~g 4: s~nutnu Nutn `mnri aig nutcbnlnegdi dnqgdi i

    dntclfcmn`ti`nenuurgizcrcilnqc`tcmn`tidng`airmcnunuun`egcguzcrc

    s~nccanrgidikrc~dnunhcdiei`tnvt~clgxnirnu~ltcdimcguzrvgmiziuuqnl

    dcrnclgdcdnn`ei`trcdc,znrmgtg`dicuugm~mcrncqclgcidizlc`nhcmn`tidn

    trcbclfi `iu zi`tiu mcgu ertgeiu n mnlfirgc `iu rnu~ltcdiu czu unk~gdcu

    czlgecnudis~nutgi`rgi

    Zcrcnutns~nutgi`rgiaig~tglgxcdieimibcunitrcbclfidn C`dnrln

    &2::4' @irnanrgditrcbclficc~tirc~tglgxi~c@BR GUI)GNE 3;;77,zirm`i

    zrizu`n`f~mcmtrgec s~n ziuugbglgtcuun cqclgcr i rnu~ltcdi ibtgdi Eimi

    rnanr`egczcrccergci d c mtrgecdncqclgciaig~tglgxcdiitrcbclfidn

    Agnkn`bc~m&2::1'

    Cbcgvi unridnmi`utrcdiunvnmzliudneimiis~nutgi rgi aig

    ei`utr~dizcrccknrcidiritngri8

    -Zcrccergcidczrgmngrcs~nuti,crnanr`egc~tglgxcdcaigi

    eczt~li;dcCB@T@BRGUI)GNE3;;7782::>,s~nzrnq czritniei`trc

    edgkiu mclgegiuiu n mqngu, eimi zir nvnmzli, c nvgut`egc airmcl dn

    zriendgmn`tiucunrnmtimcdiucuugms~n~medgkimclgegiuin`ei`trcdi

    -Zcrccs~nuti23,aig~tglgxcdiieczt~li6dcCB@T@BRGUI)GNE

    3;;7782::>,s~nu~knrnirnkgutri&lik'airmcldntidcucnunvne~tcdcuznli

    ~u~rgi

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    38/62

    56

    -Zcrccs~nuti56,aig~tglgxcdiieczt~li7dcCB@T@BRGUI)GNE

    3;;7782::>,s~ntrctcdcucnucunrnmtimcdcucuugms~n~mcq~l`nrcbglgdcdn

    te`gecgdn`tgagecdc

    @ Eczt~li S~nuti

    3 ;43 Fdnag`gnudie~mn`tcdcundnei`fnegmn`tidiu~u~rgiu

    uibrn zriendgmn tiu s~n dnqnm unr timcdiu cuugm s~n air

    n`ei`trcdiclk~medgkimclgegiui2 ;43 Ui g`utclcdiu n ct~clgxcdiu rnk~lcrmn tn uiat{crnu dn

    dntneinrnmiidnedgkimclgegiuiuzcrcinvcmndn

    eimz~tcdirnunmdgcumck`tgecu,dnairmczrnqn`tgqci~dn

    airmcritg`ngrc

    5 ;43 F qnrgageci, c`tnu di ~ui, dc nvgut`egc dn edgkiu

    mclgegiuiu`iucrs~gqiunmm dgcuztgecui~nlntr`gecu,bnm

    eimicrs~gqiutrc`umgtgdiunrnenbgdiuctrcqudnrndnu,n

    qnrgagecidcnvgut`egcdnmcl{crnnmzkg`cu{nb4 ;42 I~uidnedgkimqnlei`trilcdiniznrcdnceirdieim

    ~mcziltgecdnunk~rc`cdcg`airmcielcrcmn`tndnag`gdcn

    dgq~lkcdczcrc~u~rgiudnedgkiumqngu

    > ;42 Edgkimqngu c~tirgxcdiu ziuu~nmei trilnu ergztikrageiu

    dnc~tn`tgecinvel~ugqczcrcnvne~i

    1 ;>3 Nvgutn~mcziltgecrnk~lcrzcrccnvne~idiuzriendgmn`tiu

    dnezgcdnunk~rc`c

    ; ;>3 Nvgutnm qrgcu ezgcu dn unk~rc`c nm dganrn`tnu liecgu,

    g`el~ugqnaircdcudnzn`d`egcudcirkc`gxci

    6 ;63 Nvgutnm zriendgmn tiu dnag gdiu zcrci ~ui dneim~`geci

    unmagi&{grnlnuu',lnqc`dinmei`tciurguein`qilqgdiu

    7 ;63 Ui~tglgxcdcute`gecu,eimicudnergztikrcagc,zcrczritnknr

    c ei`agdn`egclgdcdn, c g`tnkrgdcdn n c c~tn`tgegdcdn dcu

    g`airmcnu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    39/62

    57

    3: ;62 Uimc`tgdiu nrnuzngtcdiuiu zriendgmn`tiu dnag`gdiuzcrc

    cuunk~rcrcrcutrncbglgdcdndiunqn`tiuni`i-rnzdgi,eimi

    nvnmzlite`geizcrci`i-rnzdgi,c~tglgxcieirrntcdn

    D@U rnqnrui zcrc cengtci diu nmcglu irgkg`cdiu `c

    irkc`gxci znliu unrqgdirnu dn i~trcu irkc`gxcnu, zcrc

    nmzrnucus~ntnmzi~ec~tglgxcidcTGnc~tglgxcidn

    ugutnmcu dn rnei`fnegmn ti dn cuug ct~rc nlntr`gec zcrc

    nmzrnucus~nnuti`~mzctcmcrmcgunlnqcdi`c~tglgxci

    dcTG'

    33 ;63 Ui~tglgxcdcu`irmcute`gecuzcrcckrcqcinlngt~rcdcu

    g`airmcnu knrcdcu zir uiat{crnu &lik' s~n trc`umgtnm

    mn`uckn`uzirrndnu

    32 ;65 Ui nutcbnlnegdiu zriendgmn tiu zcrc c qnrgageci dc

    gdn`tgagecidiutrc`umguuirnudng`airmcnu

    35 ;65 I mngi dn trc`umguui dn g`airmcnu ei agdn`egcgu

    ei`agqnl

    34 ;65 Uicditcdiumtidiu dn ei`agrmcidnrnenbgmn`tidn

    mn`ucknm

    3> ;64 Ui cditcdiu zriendgmn tiu s~n cuunk~rcm i eirrnti

    n`dnrncmn`tintrc`uzirtndcumn`uckn`u31 ;64 Ui ~tglgxcdiu mtidiu dn zritni dcu mn`uckn`u

    nlntr`gecu ei`trc cenuui `i c~tirgxcdi, midgageci i~

    `nkcidnunrqgi

    3; ;64 Ui~tglgxcdcute`gecu,eimicuug ct~rcudgkgtcgu,zcrcqclgdcr

    cuznetiulnkcgu`ctrc`ucidnmn`uckn`unlntr`gecu

    36 ;6> Nvgutnm zriendgmn tiu dn gdn`tgageci n trctcmn ti dcu

    q~l`nrcbglgdcdnu ei`fnegdcu `iu ugutnmcu cdmg gutrctgqiu n

    ei`tbngu i`dn cu g airmcnu ui eimzcrtglfcdcu eimdganrn`tnurncudcirkc`gxci

    37 ;6> Frnutrgidicenuuicg`airmcidntrcbclfirnlcegi`cdi

    eim g`dgqd~iu nuzneageiu, eimi zir nvnmzli, kr~zi dn

    trcbclfizirzrihntiui~untir

    2

    :

    623 ~tglgxcdigdn`tgagecdirdn~u~rgi&GDdn~u~rgi'`geizcrc

    cuunk~rcrcrnuzi`ucbglgdcdndnecdc~u~rgiziru~cucnu

    23 623 mc`tgdi~mrnkgutri&lik'airmcldntidcucnunvne~tcdcu

    znli~u~rgig`el~ugqn`iecuidnrnhngidncenuui

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    40/62

    4:

    22 623 Uicditcdiuzriendgmn`tiugmndgctiudnrnmii,blis~ngi

    i~cltnrcidndgrngtiudncenuuidn~u~rgius~nm~dcrcm

    dnecrkiui~a~`nu,i~dngvcrcmcirkc`gxci

    25 622 Iu zrgqglkgiu ui ei`endgdiu ciu ~u~rgi ei`airmn`nenuugdcdndn~uineimbcunnmnqn`tiuclg`fcdiueimc

    ziltgecdnei`trilndncenuui,qnrgagec`dicuugmuni~u~rgi

    tnm c~tirgxcidizrizrgntrgidiugutnmczcrci~uidi

    ugutnmcdng`airmcii~unrqgi

    24 622 Iu zrgqglkgiuuiei`endgdiuci~u~rgicuugms~ntidii

    zrienuuidnc~tn`tgeci ei`el~dintidiuzrgqglkgiudi

    ~u~rgirnkgutrcdi&lik'

    2> 625 Nvgutnm zriendgmn tiu zcrcqnrgagecr c gdn tgdcdndi ~u~rgic tnu dn air`nenr ~mc un`fc tnmzirrgc,dnu~butgt~gii~

    `iqc

    21 625 Ui ~tglgxcdcu te gecu dn nvzgrci dn un`fcu, airc`di

    cuugm s~n iu ~u~rgiu diu ugutnmc tris~nm u~cu un`fcu

    znrgidgecmn`tn

    2; 625 Cu un`fcu `~`ec ui crmcxn`cdcu `iu ugutnmcu dn ~m

    eimz~tcdirdnairmcdnuzritnkgdc

    26 624 Iudgrngtiudncenuuidn~u~rgiuuirnqgucdiunc`clgucdiu

    ergtgecmn tn nm g tnrqcliu rnk~lcrnu, n rncliecdiu s~c`di

    miqgdiudn~mtgzidnctgqgdcdnzcrci~trcdn`tridcmnumc

    irkc`gxcii~`iecuidnn`enrrcmn`tidnei`trcti

    27 624 Cu cliecnu dn zrgqglkgiu ui qnrgagecdcu nm g tnrqcliu

    rnk~lcrnu dn tnmzi zcrc kcrc`tgr s~n zrgqglkgiu `i

    c~tirgxcdiuaircmibtgdiu

    5: 624 Cu midgagecnudnzrgqglkgiuzcrcei`tcudn~u~rgiuui

    rnkgutrcdcu&lik'zcrcc`lgunertgecznrgdgec

    53 6;3 C ~tglgxcidneimz~tcimqnlnutdnag`gdcnmziltgecn

    g`el~g rns~gugtiu dn zritni augec, ei`trilnu dn cenuui,

    te`gecudnergztikrcagc,ezgcudnunk~rc`cnzritniei`trc

    qr~uelcrcundnei`fnegmn`tidnun~u~u~rgiu

    52 6;3 I cenuui rnmiti ug`airmcnudcirkc`gxcictrcqudn

    rndnuzblgecu, ~uc`di iu rne~ruiu dn eimz~tci mqnl,

    ieirrn czn`cu czu i u~enuui dc gdn`tgageci n dc

    c~tn`tgecidi~u~rgi

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    41/62

    43

    55 6;3 C~tglgxcidnrndnuunmagi&{grnlnuu'angtceimzritieiliu

    dn unk~rc`c rib~utiu n s~n `i ziuu~cm arckglgdcdnu

    nvzlirqngu

    54 6;2 Icenuui rnmiticiu ugutnmcu g tnr`iun ug`airmcnudcirkc`gxciangtictrcqudnlg`fcdneim~`geciunk~rc

    5> 6;2 I cenuui ci ns~gzcmn`ti dn zrizrgndcdn zcrtge~lcr

    kcrc`tgdizirmngilnkclzcrcqnrgagecrcunk~rc`cdcms~g`c

    i~ d~rc`tn g`qnutgkci dnqgdi c cmnc dn cenuui `i

    c~tirgxcdi g`airmcidcirkc`gxciziri~trcuznuuicu

    s~n ~tglgxcm i liecl i~ ns~gzcmn ti, eimi acmglgcrnu zir

    nvnmzli

    51 6;2 Ns~gzcmn`tius~nui~tglgxcdiuzcrccenuuirnmitictn`dnmiurns~gugtiudnzritniei`trcqr~unrns~gugtiudnagrn{cll

    5; 713 Nvgutnm ~mc ns~gzn rnuzi`uqnl znlc knuti dn

    q~l nrcbglgdcdnu te gecu, g`el~g di i mi`gtircmn`ti dn

    q~l`nrcbglgdcdnu, c c`lgun)cqclgci dn rgueiu dn

    q~l`nrcbglgdcdnu, zctefnu, ceimzc`fcmn ti diu ctgqiu n

    s~cls~nreiirdn`cidnrnuzi`ucbglgdcdnurns~nrgdcu

    56 713 Cuugms~n~mcq~l nrcbglgdcdnte`gecgdn`tgagecdc,cns~gzn

    rnuzi`uqnlcqclgciurgueiucuuiegcdiuncucnucunrnm

    timcdcu

    57 713 Zctefnuzcrcugutnmcu~tglgxcdiu`cirkc`gxci uitnutcdiu

    n cqclgcdiu c tnu dn unrnm g`utclcdiu zcrc cuunk~rcr c

    nantgqgdcdnns~n itrckcmnangtius~n`iziuucmunr

    tilnrcdiu

    4: 713 mc`tgdi~mrnkgutridnc~dgtirgcdntidiuiuzriendgmn`tiu

    rnclgxcdiu znlc ns~gzn rnuzi`uqnl znlc knuti dn

    q~l`nrcbglgdcdnute`gecu

    Tcbnlc28Eirrnlcidcus~nutnuzireczt~li

    5>2Dnag`gidcmtrgeccunr~tglgxcdc

    Fs~ctri&4'ziuugbglgdcdnudnzi`t~cizcrccurnuziutcuibtgdcu8

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    42/62

    42

    Rnuziutc G`dgecs~ncnmzrnuc Zi`t~ci

    Dnuei`fni Dnuei`fnencnvgut`egcdcbiczrtgec

    rneimn`dcdcznlcCB@T@BRGUI)GNE3;;7782::>

    :

    Dgueirdi Tnmei`fnegmn`tidcbiczrtgecmcu`ic

    cditc

    3

    Ei`eirdi

    zcregclmn`tn

    Cditczcregclmn`tncbiczrtgec 2

    Ei`eirdi Nutdnceirdieimcbiczrtgec 4

    Tcbnlc58Zi`t~cizcrccurnuziutcuibtgdcu`cznus~guc

    Czlgecdiis~nutgi`rgiibtgdi~mkrc~M,dcdiznlcarm~lc8

    M=&TZI(3:')ZM,u~knrgdizirC`dnrln&2::4',i`dn8

    TZI8TitcldnZi`tiuIbtgdiunZM8Zi`t~c iMvgmcZiuuqnl

    Ei`airmnikrc~Mibtgdi,cnageegcdcc~dgtirgc&i~unhc,cu~ccdnr`egc

    u @BR GUI)GNE3;;77' unr elcuugagecdcei`airmncmtrgeccbcgvi,u~knrgdc

    znli c~tirdnutntrcbclfi,eimbcun`iuKrc~u dnMct~rgdcdn zriziutiuznli

    EIBGT8

    @qnl Gdn`tgageci Krc~

    : @~li Dnuei`fnen cu bicu zrtgecuzcrcc

    knuti dn unk~rc`c dc g`airmci

    rneimn`dcdcuznlc@irmcCB@T@BR

    GUI)GNE3;;7782::>

    N`trn:n3

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    43/62

    45

    3 Bcgvi F~mcei`ueg`egcknrcldcknutidn

    unk~rc`cdcg`airmci,zirm `i

    ctn`dncuzrtgecurneimn`dcdcuznlc

    @irmcGUI

    N`trn2n4&`i

    g`el~di'

    2 Mdgi Iu zrienuuiu ui zcdri gxcdiu,

    die~mn`tcdiu n gmzlc tcdiu, zirm

    `nmtidiuiu qngu dc irkc`gxci

    n`tn`dnmc`nenuugdcdndcknutidn

    unk~rc`cdcg`airmci

    N`trn4n;&`i

    g`el~di'

    5 Clti Fin`tn`dgmn`tidntidiuiu` qngu

    dc irkc`gxci uibrn c `nenuugdcdndcknutidnunk~rc`cdcg`airmci

    Iu zrienuuiu ui mi gtircdiu n

    ei`utc`tnmn`tncqclgcdiuF ig`egi

    dizrienuuidnmnlfirgcei`t`~c

    N`trn;n7&`i

    g`el~di'

    4 Mvgmi Tidiu iu rgueiu ui gdn`tgagecdiu n

    dnqgdcmn`tn knrn`egcdiu Iu

    zrienuuiu ui ei`utc`tnmn`tn

    mnlfircdiunrnag`cdiuzcrckcrc`tgrc

    knutidcunk~rc`cdcg`airmci

    N`trn7n3:

    Tcbnlc48@qnguunk~rc`c

    5>5Trctcmn`tidiudcdiu

    Itrctcmn`tidiudcdiu`itrcbclfiaigs~clgtctgqi,i`dniudcdiu

    aircm c`clgucdiu n g`tnrzrntcdiu dn ceirdi eim c n trnqgutc n c znus~guc

    bgblgikragec, nuznegclmn tn eim bcun `iu eczt~liu ;, 6 n 7 dc @BRGUI)GNE

    3;;7782::>

    @izrvgmieczt~liunriczrnun`tcdiuiurnu~ltcdiudcczlgeci

    diritngricinut~didnecui

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    44/62

    4.RNU^LTCDIUIBTGDIU

    @nutn eczt~li ui czrnun`tcdiu iu rnu~ltcdiu ibtgdiu czu c

    czlgecidiritngrizriziutizcrcc~dgtirgc,bnmeimieimn`trgiurnlctgqiuc

    c`lgundiurnu~ltcdiunu~knutnuzcrcu~cumnlfirgcu

    4.3C`lgundiurnu~ltcdiuibtgdiu

    S~nuti Rnu~ltcdi Eimn`trgiu

    3 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    143dc@BRGUI)GNE3;;77

    2 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li143dc@BRGUI)GNE3;;77

    5 4 cnmzrnucVnutdnceirdieimieczt~li143dc

    @BRGUI)GNE3;;77

    4 : cnmzrnucVdnuei`fnenieczt~li142 dc@BRGUI)GNE3;;77

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    45/62

    4>

    > : cnmzrnucVdnuei`fnenieczt~li142 dc@BR

    GUI)GNE3;;77

    1 4 cnmzrnucVnutdnceirdieimieczt~li1>3dc

    @BRGUI)GNE3;;77

    ; 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li1>3dc@BRGUI)GNE3;;77

    6 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li163dc@BRGUI)GNE3;;77

    7 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    163dc@BRGUI)GNE3;;77

    3: 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li162dc@BRGUI)GNE3;;77

    33 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li162dc@BRGUI)GNE3;;77

    32 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li165dc@BRGUI)GNE3;;77

    35 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    165dc@BRGUI)GNE3;;77

    34 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li165dc@BRGUI)GNE3;;77

    3> 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li164dc@BRGUI)GNE3;;77

    31 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li164dc@BRGUI)GNE3;;77

    3; 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li164dc@BRGUI)GNE3;;77

    36 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    16>dc@BRGUI)GNE3;;77

    37 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li16>dc@BRGUI)GNE3;;77

    2: 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;23dc@BRGUI)GNE3;;77

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    46/62

    41

    23 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;23dc@BRGUI)GNE3;;77

    22 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;23dc@BRGUI)GNE3;;77

    25 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;22dc@BRGUI)GNE3;;77

    24 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;22dc@BRGUI)GNE3;;77

    2> 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;25dc@BRGUI)GNE3;;77

    21 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;25dc@BRGUI)GNE3;;77

    2; 4 cnmzrnucVnutdnceirdieimieczt~li;25dc

    @BRGUI)GNE3;;77

    26 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;24dc@BRGUI)GNE3;;77

    27 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;24dc@BRGUI)GNE3;;77

    5: 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;24dc@BRGUI)GNE3;;77

    53 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;;3dc@BRGUI)GNE3;;77

    52 4 cnmzrnucVnutdnceirdieimiecz t~li;;3dc

    @BRGUI)GNE3;;77

    55 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li;;3dc@BRGUI)GNE3;;77

    54 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li;;2dc@BRGUI)GNE3;;77

    5> 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;;2dc@BRGUI)GNE3;;77

    51 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    ;;2dc@BRGUI)GNE3;;77

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    47/62

    4;

    5; 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li613dc@BRGUI)GNE3;;77

    56 2 c nmzrnuc V ibunrqc zcregclmn`tn i zrnuergti `i

    eczt~li613dc@BRGUI)GNE3;;77

    57 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    613dc@BRGUI)GNE3;;77

    4: 3 c nmzrnuc V `iibunrqcizrnuergti`ieczt~li

    613dc@BRGUI)GNE3;;77

    Titcl ;:Zi`t~cimvgmc=31:

    Krc~M 4,5;>

    @qnldn

    unk~rc`c2 Mdgi

    Tcbnlc>8Rnu~ltcdiuibtgdiuRnuziutcu

    Cunk~grunritrctcdiuiurnu~ltcdiuibtgdiu`iritngridncqclgci

    433Rnu~ltcdiuibtgdius~c`ticiecz t~li;dc@irmc@BRGUI)GNE

    3;;77,Knrn`egcmn`tidcuiznrcnuneim~`gecnu

    Ctcbnlc1nikragei3dnmi`utrcmiurnu~ltcdiuibtgdiu`cuni

    uibrnKnrn`egcmn`tidcuiznrcnuneim~`gecnu@nutcunuuiuitrctcdcu

    s~nutnus~nb~uecmiei`fnenruncnmzrnucziuu~gzil tgecunzriendgmn`tiu

    nutr~t~rcdiu airmclmn`tn n dn ei`fnegmn ti dn tidiu eilcbircdirnu uibrnzritniei`trcedgkiumclgegiuiunmqngu,ezgcudnunk~rc`cntriecdn

    g`airmcnu

    Tcbnlc 18 Rnuziutcu zcrc s~nutnu rnlcegi`cdcu ci Knrn`egcmn`ti dcu iznrcnu n

    eim~`gecnu

    Eczt~li 1 dc CB@T @BR GUI)GNE 3;;7782::>Ziuugbglgdcdnu Rnuziutcu Znren`t~cl di eczt~li Znren`t~cl di titcl

    Ei`eirdi 2 3:,>5 >Ei`eirdi zcregclmn`tn 3: >2,15 2>Dgueirdi > 21,52 32,>Dnuei`fni 2 3:,>5 >

    Titcl 37 3:: 4;,>

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    48/62

    46

    Kragei38Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li1

    C c `lgundcurnuziutcuzcrc cus~nutnurnlctgqcucieczt~li1

    &Knrn`egcmn ti dcu iznrcnuneim~`gecnu' dc GUI)GNE 3;;7782::> `i

    ritngri nutcbnlnegdi, dnag n i krc~ dn nageegc dn 4,542 nm rnlci c

    ei`agcbglgdcdndcc~dgtirgczrnutcdcznlcnmzrnucV,n`ecgvc`di-ccuugmci` qnl

    2nmrnlciciu`qngudnunk~rc`c

    432Rnu~ltcdiuibtgdius~c`ticieczt~li6dc@irmc@BRGUI)GNE

    3;;77,Ei`trilndncenuuiu

    Ctcbnlc;nikragei2dnmi`utrcmiurnu~ltcdiuibtgdiu`cuni

    uibrnEi`trilndncenuuiu@nutcunuuiuitrctcdcus~nutnus~nb~uecmi

    ei`fnenr un c nmzrnuc ziuu~g ziltgecu n zriendgmn tiu nutr~t~rcdiu

    airmclmn`tnndnei`fnegmn`tidntidiueilcbircdirnuuibrnknrn`egcmn`tidn

    cenuuidi~u~rgi,eimz~tcimqnlntrcbclfirnmiti

    Tcbnlc;8Rnuziutcuzcrcs~nutnurnlcegi`cdcuciEi`trilndncenuuiu

    3:,>5

    >2,15

    21,52

    3:,>5

    S~nutnu rnlcegi`cdcu ci eczt~li 1 dc @irmc nm

    Ei`eirdi

    Ei`eirdi zcregclmn`tnDgueirdi

    Dnuei`fni

    Eczt~li ; dc CB@T @BR GUI)GNE 3;;7782::>Ziuugbglgdcdnu Rnuziutcu Znren`t~cl di eczt~li Znren`t~cl di titcl

    Ei`eirdi 2 33,;1 >Ei`eirdi zcregclmn`tn 6 4;,:1 2:Dgueirdi ; 43,36 3;,>Dnuei`fni : : :

    Titcl 3; 3:: 42,>

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    49/62

    47

    Kragei28Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li;

    C c `lgundcurnuziutcuzcrc cus~nutnurnlctgqcucieczt~li;

    &Ei`triln dn cenuuiu' dcGUI)GNE3;;7782::>`i ritngrinutcbnlnegdi, dnag`ni

    krc~dnnageegcdn4,>>6nmrnlcicei`agcbglgdcdndcc~dgtirgczrnutcdcznlc

    nmzrnucV,n`ecgvc`di-ccuugmci qnl2nmrnlciciu`qngudnunk~rc`c

    435Rnu~ltcdiuibtgdius~c`ticieczt~li7dc@irmcCB@T@BR

    GUI)GNE3;;7782::>,Cs~gugi,dnun`qilqgmn`tinmc`~tn`idnugutnmcudn

    g`airmci

    Ctcbnlc6nikragei5dnmi`utrcmiurnu~ltcdiuibtgdiu`cuni

    uibrn Cs~gugi, dnun`qilqgmn`ti n mc`~tn`idnugutnmcudng`airmci

    @nutcunuui uitrctcdcus~nutnus~nb~uecmiei`fnenruncnmzrnuc

    ziuu~gziltgecunzriendgmn`tiunutr~t~rcdiuairmclmn`tnndnei`fnegmn`tidn

    tidiueilcbircdirnuuibrnknutidnq~l`nrcbglgdcdnute`gecu

    Tcbnlc68Rnuziutcurnlcegi`cdcuccs~gugi,dnun`qilqgmn`tinmc`~tn`idiuUG

    33,;1

    4;,:1

    43,36

    S~nutnu rnlcegi`cdcu ci eczt~li ; dc @irmc nm

    Ei`eirdi

    Ei`eirdi zcregclmn`tn

    Dgueirdi

    Dnuei`fni

    Eczt~li 6 dc CB@T @BR GUI)GNE 3;;7782::>Ziuugbglgdcdnu Rnuziutcu Znren`t~cl di eczt~li Znren`t~cl di titcl

    Ei`eirdi : : :Ei`eirdi zcregclmn`tn 2 >: >Dgueirdi 2 >: >

    Dnuei`fni : : :Titcl 4 3:: 3:

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    50/62

    >:

    Kragei58Dgutrgb~gidnrnuziutcu`cus~nutnurnlcegi`cdcucieczt~li6

    C c `lgundcurnuziutcuzcrc cus~nutnurnlctgqcucieczt~li6

    &Cs~gugi,Dnun`qilqgmn`tinMc`~tn`idiuUG'dcGUI)GNE3;;7782::>`i

    ritngrinutcbnlnegdi,dnag`nikrc~dnnageegcdn5,;5nmrnlcicei`agcbglgdcdn

    dcc~dgtirgczrnutcdcznlcnmzrnucV,n`ecgvc`di-ccuugmci`qnl3nmrnlci

    ciu`qngudnunk~rc`c

    434G`al~`egcdnecdceczt~li`ititcldcznus~guc

    Ctcbnlc7nikragei4dnmi`utrcmiurnu~ltcdiuibtgdiulnqc`dinm

    ei`ugdnrcis~c`tidititcldis~nutgi rgiaigie~zcdizirecdceczt~lidc

    @irmc@BRGUI)GNE3;;77

    Tcbnlc78Titcldns~nutnuzireczt~li

    >: >:

    S~nutnu rnlcegi`cdcu ci eczt~li 6 dc @irmc nm

    Ei`eirdiEi`eirdi zcregclmn`tn

    Dgueirdi

    Dnuei`fni

    S~c`ti ecdc eczt~li rnzrnun`tc di titclEczt~liu Znren`t~cl di titcl @mnri dn S~nutnu

    Ecz. 1 4;,> 37Ecz. ; 42,> 3;Ecz. 6 3: 4

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    51/62

    >3

    Kragei48Dgutrgb~gidneczt~liunmrnlcics~c`tgdcdndns~nutnu

    43>Rnu~ltcdiknrclibtgdiznlcnmzrnuc

    Ctcbnlc3:nikragei>dnmi`utrcmiurnu~ltcdiuibtgdiunmecdc

    ziuugbglgdcdndnrnuziutczcrcititcldns~nutnuczlgecdcu`cznus~guc

    Tcbnlc3:8Elcuugagecizirziuugbglgdcdndnrnuziutcuzcrcititcldns~nutnu

    Kragei>8Dgutrgb~gidititcldnrnuziutcu

    Elcuugageci zir ziuugbglgdcdn dn rnuziutc zcrc i titclZiuugbglgdcdnu Rnuziutcu Znren`t~cl

    Ei`eirdi 4 3:Ei`eirdi zcregclmn`tn 2: >:Dgueirdi 34 5>Dnuei`fni 2 >Titcl 4: 3::

    4;,>

    42,>

    3:

    S~c`di ecdc eczt~li rnzrnun`tc di titcl nm

    Ecz. 1

    Ecz. ;

    Ecz. 6

    3:

    >:

    5>

    >

    S~c`ti ecdc rnuziutc rnzrnun`tc di titcl nm

    Ei`eirdiEi`eirdi zcregclmn`tn

    DgueirdiDnuei`fni

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    52/62

    >2

    ziuuqnlibunrqcr`ikragei>,s~ncnmzrnucVczrnun`tc3:.diu

    gtn`unmtitclceirdieimcubicuzrtgecurneimn`dcdcuznlc@irmcCB@T

    @BRGUI)GNE 3;;7782::>,i rnutc`tndi rnu~ltc`di nutdgqgdgdinm>:.zcrc

    ei`eirdizcregclmn`tn,5>.zcrcdgueirdin>.zcrcdnuei`fni Nutc

    qgu~clgxciznrmgtnnutcbnlnenrcnageegcdcc~dgtirgczrnutcdcznlcnmzrnucV

    lnqc`dinmei`ugdnrcicei`airmgdcdndnun~uei`trilnunmrnlcic@BR

    GUI)GNE3;;77Iritngrinutcbnlnegdidnag`nikrc~dnnageegcdn4,5;>nm

    rnlcicei`agcbglgdcdndcc~dgtirgczrnutcdcznlcnmzrnucVs~c`ticunk~rc c

    dcg`airmcizcrciuun~uelgn`tnu,n`ecgvc`di-ccuugmci`qnl2,mdgi,nm

    rnlciciu`qngudnunk~rc`cNmi~trcuzclcqrcucnmzrnucziuu~gzrienuuiu

    zcdri gxcdiu, die~mn`tcdiu n gmzlc`tcdiu, zirm`nmtidiuiu`qngu dc

    irkc`gxcin`tn`dnmc`nenuugdcdndcknutidnunk~rc`cdcg`airmciC

    dgue~uuiuibrniu qngudcirkc`gxcin`tn`dnrnmc`nenuugdcdndcknuti

    dnunk~rc`cdcg`airmciunrcbirdcdcmcgudntclfcdcmn`tn`cei`el~ui

    4.2U~knutnuzcrcmnlfirgcdiurnu~ltcdiuibtgdiu

    Nuungtnmei`tceimu~knutnuzcrcmnlfirgcdiurnu~ltcdiuibtgdiu

    czu i trctcmn`ti diudcdiu eilntcdiu Dnqnm unrctcecdiuzrgmngrcmn tniu

    zgirnurnu~ltcdiuibtgdiuNeimaiei`nuunurnu~ltcdiudnqnmunrtimcdcucu

    dnegunu uibrn i`dn iu g`qnutgmn`tiu dn tnmzi n rne~ruiu, tc`ti ag c`engri

    s~c`dif~mc`i,unriczlgecdiu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    53/62

    >5

    423U~knutnuzcrcmnlfirgcu`iknrn`egcmn`tidcuiznrcnun

    eim~`gecnu

    Ei`airmncc`lgundcus~nutnu,diritngridnc~dgtirgc,rnanrn`tnci

    eczt~lidnknrn`egcmn`tidcuiznrcnuneim~`gecnuziuuqnlqnrgagecrs~n

    iuzgirnurnu~ltcdiunuti`cus~nutnu4n>,s~nuidnuei`fnegdcuznli

    u~hngtidcznus~guc,n`cus~nutnu3,7,35,3;n36,cus~cguiu~hngtidgueirdc

    dcubicuzrtgecudnag`gdcuznlc@BRGUI)GNE3;;77

    Cbrg`dicus~nutnuegtcdcucegmcnun~urnu~ltcdiu,eimnc`di

    znlcus~nutnus~nibtgqnrcmiuzgirnurnu~ltcdiu, u~knrgdieimizi`tidn

    zcrtgdc zcrc ~m zlc`i dn trcbclfi s~n qgun c mnlfirgc dnutnu rnu~ltcdiu cu

    unk~g`tnucnu8

    3 C nlcbirci n dgq~lkci dn ~mc ziltgec airmcl zcrcrnk~lcmn`tcri~uiedgkimqnlei`trilcdi

    2 Gmzlnmn tci dn ei`trilnu ergztikrageiu dn c~tn`tgeci

    nvel~ugqczcrcnvne~idnedgkimqnguc~tirgxcdiu

    5Nlcbirci airmcl dn zriendgmn tiu s~n dnqnm unr timcdiu

    cuugms~nairn`ei`trcdiclk~medgkimclgegiui

    4 Gmzlnmn tci dn te`gecu ergztikragecu, zcrc zritnknr c

    ei`agdn`egclgdcdn,cg`tnkrgdcdnncc~tn`tgegdcdndcug`airmcnu

    >Gmzlc`tcidnmngiuunk~riuzcrcctrc`umguuidng`airmcnu

    ei`agdn`egcgu

    1^tglgxcidncuug`ct~rcudgkgtcgu,zcrcqclgdcrcuznetiulnkcgu`c

    trc`ucidnmn`uckn`unlntr`gecu

    ;Ergcidnzriendgmn`tiudngdn`tgagecintrctcmn`tidcu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    54/62

    >4

    q~l nrcbglgdcdnu ei`fnegdcu `iu ugutnmcu cdmg`gutrctgqiu n ei tbngui`dncu

    g`airmcnuuieimzcrtglfcdcueimdganrn`tnurncudcirkc`gxci

    422U~knutnuzcrcmnlfirgcu`iuei`trilnudncenuui

    @cus~nutnurnanrn`tnucieczt~liuibrnei`trilndncenuuiudc

    @BRGUI)GNE3;;77,cuunk~g`tnuu~knutnuzcrcmnlfirgczidnmunrtimcdcu

    eimizrnmguucuzcrcnlcbircidn~mzlc`idntrcbclfis~nqgucairtclnenrc

    unk~rc`cdcg`airmcinmrnlciciei`trilndncenuuiu

    3Gmzlnmn`tcidnzriendgmn`tiuzcrcqnrgagecrcgdn`tgdcdndi

    ~u~rgic`tnudnair`nenr~mcun`fctnmzirrgc,dnu~butgt~gii~`iqc

    2^tglgxcidnte`gecudnnvzgrcidnun`fcu

    5Qnrgagecnudnzrgqglkgiunmg`tnrqcliurnk~lcrnudntnmzi

    4Rnkgutridnmidgagecnudnzrgqglkgiuzcrcei`tcudn~u~rgiu

    >C~tglgxcidnrndnuunmagi&{grnlnuu'dnmc`ngrcei`trilcdcn

    eim~tglgxcidiumnlfirnudnzritieiliudnunk~rc cdguzi`qngu

    1Kcrc`tgrzirmngilnkclicenuuicins~gzcmn`tidnzrizrgndcdn

    zcrtge~lcrzcrcqnrgagecrcunk~rc`cdcms~g`ci~d~rc`tng`qnutgkci

    ; ^tglgxci dn ns~gzcmn`tiu s~n ctn`dnm iu rns~gugtiu dn

    zritniei`trcqr~unrns~gugtiudnagrn{cllzcrccenuuirnmiti

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    55/62

    >>

    425 U~knutnu zcrc mnlfirgcu `c cs~gugi, dnun`qilqgmn`ti n

    mc`~tn`idnugutnmcudng`airmci

    @cus~nutnurnanrn`tnuccs~gugidnun`qilqgmn`tinmc`~tn`i

    dnugutnmcudng`airmci,ltgmieczt~lidc@BRGUI)GNE3;;77~tglgxcdi`c

    nlcbircidiritngridnc~dgtirgc,nvgutn~mczcrtge~lcrgdcdnI`mnridn

    s~nutnurnlcegi`cdcucnutneczt~li g`anrgirciudnmcguecz t~liutimcdiu

    eimi rnanrn`egc zcrc nlcbirci di s~nutgi`rgiGuuiundnqnciactidc

    rnlnq`egcs~nieczt~liczrnun`ti~s~c`diei`ari`tcdieimizrg`egzclergtrgi

    zcrcunlni,czrnun`tcdi`ieczt~lic`tnrgir&gtnm5>3',mcu iziuuqnl

    nutcbnlnenr~m qnldnei`agc`cnmrnlcicunk~rc`cdcg`airmciunm

    cqclgcriei`trilnuibrnq~l`nrcbglgdcdnute`gecuCuunk~g`tnuu~knutnuui

    zriziutcu zcrc c mnlfirgc diu rnu~ltcdiu ibtgdiu nm rnlcicus~nutnu

    c`clgucdcu

    3Nutcbnlnenrzriendgmn`tiudntnutnunmZctefnuzcrcugutnmcu

    ~tglgxcdiu`cirkc`gxcic`tnudnunrnmg`utclcdiu

    2Mc`tnr~mrnkgutrizcrctidiuiuzriendgmn`tiurnclgxcdiuznlc

    ns~gznrnuzi`uqnlznlcknutidnq~l`nrcbglgdcdnute`gecu

    Cuu~knutnuzcrcmnlfirgcag`clgxcmcczrnun`tcidiurnu~ltcdiu

    ibtgdiueimcznus~guc@izrvgmieczt~liuiczrnun`tcdcucuei`el~unu

    Dnutcairmcag`clgxcdccczrnun`tcidiurnu~ltcdiuibtgdiueimc

    znus~guc@izrvgmieczt~liuiczrnun`tcdcucuei`ugdnrcnuag`cgu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    56/62

    >.EI@EL^UI

    Nutneczt~liczrnun`tccuei`el~unudnutcmi`ikrcagc,bnmeimi

    culgmgtcnuditrcbclfincuu~knutnuzcrctrcbclfiua~t~riu

    >.3Ei`el~unu

    I ibhntgqi knrcl dnutn trcbclfi aig zrizir ~mc mntidilikgc zcrc

    cqclgcidns~inagecx~mcc~dgtirgcnmunk~rc`cdcg`airmci,l~xdc

    @BRGUI)GNE3;;7782::>,nm~mcnmzrnucdnLchncdi,s~ntnmeimictgqgdcdn

    agmczrnutcidnunrqgi`crncdnTG

    Iuibhntgqiunuzneageiuaircm8

    &3'Rnqguidclgtnrct~rczcrcnutcbnlnenr~mnmbcucmn`titnrgei

    egn`tagei zcrc i n tn`dgmn ti dc `nenuugdcdn dn unk~rc`cdcg`airmci,

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    57/62

    >;

    ei`fnegmn ti dn `irmcu n zcdrnu rnei`fnegdiu, cditcdiu n nvgkgdiu

    g`tnr`cegi`clmn`tn,zcrcirkc`gxcnus~nct~cmdgrntcmn`tn`crnc

    &2'Mi`tcknmdn~mritngrizcrccqclgcrcnageegcdcc~dgtirgc

    &5'Czlgecidinut~didnecuidn`tridn~mcnmzrnucdnLchncdi

    s~ntn`fceimictgqgdcdnagmczrnutcidnunrqgi`crncdnTGnzcrccqclgcr

    c`nenuugdcdndiuelgn`tnu`cergcidiuzlc`iudnunrqgiuzriziutiu

    Zcrc ctg`kgr iu ibhntgqiu i trcbclfi czrnun`ti~ c gmzirt`egc dc

    g`airmci zcrc c uibrnqgq`egc diu `nkegiu dn ~mc irkc`gxci n c

    gmzirt`egcnutrctkgecdcrncdnTGzcrccmnumc

    Izrienuuidngmzlc`tcidcunk~rc`cdcg`airmcidguzn`dn

    krc`dnunuairiuzirzcrtndcirkc`gxcinzcrctc`titidiuieilcbircdirnu,

    zcrtg`didccltcdgrntirgc,dnqnmnutcrn`qilqgdiu

    Cmntidilikgczcrccqclgcidcnageegcdnc~dgtirgcuzriziutcaig

    bcuncdc`cCB@T@BRGUI)GNE3;;7782::>Tne`ilikgcdcg`airmc i

    Te`gecudnunk~rc`c Edgkidnzrtgeczcrccknutidcunk~rc`cdc

    g`airmciNznrmgtncibtn`idn~mcmtrgeczcrccanrgrikrc~dnnageegc

    dnc~dgtirgcunmunk~rc`cdcg`airmci

    Cznus~gucaigrnclgxcdceimirnuzi`uqnlzir~mcnmzrnucs~n

    ct~c`crncdnzrnutcidnunrqgiunmTGNuucnmzrnuctnmeimizrid~ti

    ag`cliair`negmn`tidnuil~nunmTGzcrcnmzrnucus~n~tglgxcmcTGeimi

    mngizcrcefnkcrnmciuun~uzrid~tiuag`cgu

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    58/62

    >6

    C mi`ikrcagc czrnun`ti~ ~mritngrizcrc c cqclgcidcnageegcdn

    c~dgtirgcu N unk~`di iu rnu~ltcdiu ibtgdiu czucczlgecidiritngrin

    trctcmn`tidiudcdiuaigziuuqnlcagrmcrs~n8ikrc~dnnageegcdcuc~dgtirgcu

    angtcuznlcnmzrnucnut~dcdcdn4,5;>Ziugegi`c`dicnmzrnuc`i`qnlmdgi

    dn czlgecidnbicuzrtgecuzcrckcrc`tgrcunk~rc`cdcg`airmcinm

    ei airmgdcdneimc @BR GUI)GNE 3;;77,i~nm i~trcu zclcqrcu, c nmzrnuc V

    ziuu~gzrienuuiuzcdri`gxcdiu,die~mn`tcdiungmzlc`tcdiu,zir m`nmtidiu

    iu`qngudcirkc`gxcin`tn`dnmc`nenuugdcdndcknutidnunk~rc`cdc

    g`airmci

    F,zirtc`tic`nenuugdcdndnei`uegn`tgxcriu5`qngudcnmzrnucV

    &dgrni,czigicdmg`gutrctgqinczigite`gei'dc`nenuugdcdndc~tglgxcizln`c,

    nmun~uzrienuuiudnc~dgtirgc,dcubicuzrtgecu rneimn`dcdcu znlc @BR

    GUI)GNE3;;77@iecuidcnmzrnucVguti`i tcrnacdgaegl,nmqgrt~dndi

    zns~n`i`mnridneilcbircdirnuNm~mcnmzrnuceimmcgir mnridn

    eilcbircdirnutcltcrnaczirenrtiunrgcmcgueimzlgecdc

    Igtnm42,s~nzriznmnlfirgcu`cibtn idiurnu~ltcdiuibtgdiu

    dnqnunrtimcdieimizi`tidnzcrtgdczcrccnlcbircidn~mzlc`idn

    trcbclfi,s~nqgunn`s~cdrcrcnmzrnucc~dgtcdcciuei`trilnuzriziutiuznlc

    @irmcUnmzrnlnqc`dinmei`ugdnrcis~ncg`airmcicbrc`kntidiuiu

    eilcbircdirnu dc irkc`gxci n zir nutn mitgqi tidiu dnqnm ei`fnenr cu

    ziltgecunzriendgmn`tiuairmcguzcrckcrc`tgrcunk~rc cdcg`airmci

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    59/62

    >7

    >.2Lgmgtcnuditrcbclfi

    Itrcbclficzrnun`ti~cuunk~g`tnulgmgtcnu8

    -@ilnqcnmei`ugdnrciactiufgutrgeiu,zirtnrugdicditcdii

    mtidian`imn`ilkgei

    -Iurnu~ltcdiuibtgdiuuiczlgecdiuuimn`tncnmzrnucznus~gucdc

    n`izidnmunrkn`nrclgxcdiu

    -Is~nutgi`rgizcrccanrgrikrc~dnnageegcdnc~dgtirgcu i

    ~tglgxi~tidiuiueczt~liudc@irmcCB@T@BRGUI)GNE3;;7782::>

    >.5Trcbclfiua~t~riu

    Eimiu~knutizcrc`iqiutrcbclfiunutnnut~diznrmgtnccqclgc i

    zrikrnuugqcdnc~dgtirgcuzcrcimnlfircmn`tiei`t`~idi`qnldnunk~rc`cdc

    g`airmcineimzriqcidnu~cnageegcZirtc`ti,u~knrn-un~tglgxcrimtidi

    dncqclgcirnk~lcrmn`tnzcrcefnecknmdiuei`trilnunnlcbirc idnzlc`i

    dntrcbclfiu`crncdnTG

    Zrvgmiunut~diudnqnmunrbcuncdiu`cGUI)GNE2;::3i~`c

    GUI)GNE2;::2,zrnqgutczcrc2::6,lnqc`dinmei`ugdnrci~mrncqclgcidiu

    eczt~liunei`trilnu~tglgxcdiuzcrccnlcbircidiritngridncqclgci

  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    60/62

    RNANR@EGCUBGLGIKRAGECU

    CB@T @BR GUI)GNE 3;;7782::>. Tne`ilikgc dc g airmci Te gecu dn

    unk~rc`cEdgkidnzrtgeczcrccknutidnunk~rc`cdcg`airmciRgidn

    Hc`ngri,2::>

    C@DNRLN, C`knlgtc Unk~rc`c`iZrienuuidnG`tnkrcidnUgutnmcudn

    G`airmci8CzlgecidcGUI)GNE3;;77UiLnizildi,2::4

    CUEG^TTG,EucrC~k~utiClg`fc`diCB@T-@BR-GUI)GNE3;;77n2;::3zcrc

    cCdmg`gutrciZblgec^UZ

    Dguzi`qnlnm8fttz8)){{{une~rgtw~uzbr)crtgkiu)2-NUNEIMY^UZ-:7-33-2::1-

    Crtgki-Bw-Cueg~ttg-Enucr-C-Q3-:4zda

    BUG GUI3;;77Gawi~rg`airmctgi`+u`itucqn,wi~ra~t~rn+u`itune~rn.

    Dguzi`qnlnm8fttz8)){{{bugcmnrgecueim

    ECUECRG@I, Rgefcrd N. C~dgtir+u k~gdn ti g`airmctgi` uwutnmu c~dgtg`k

    NdgtircHif`[glnw!Ui`u,G`e@n{Hnrunw,2::;

    ECR^UI,EcrliuCC?UTNAAN@,Alqgi D Unk~rc`cnmG`airmtgecndn

    g`airmcnu2ndUiZc~li8UN@CE,3777

    EC^BGT, Riu`knlc I s~n c GUI 2;::3 cag`cl9 Dguzi`qnl nm8

    fttz8)){{{mid~lieimbr)efneo~ztiil)crtgkiY31ftmCenuuinm82;)3:)2::;

    http://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.bsiamericas.com/http://www.modulo.com.br/checkuptool/artigo_16.htmhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.bsiamericas.com/http://www.bsiamericas.com/http://www.bsiamericas.com/http://www.modulo.com.br/checkuptool/artigo_16.htmhttp://www.modulo.com.br/checkuptool/artigo_16.htmhttp://www.modulo.com.br/checkuptool/artigo_16.htmhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdfhttp://www.security.usp.br/artigos/2-ESECOM_USP-09-11-2006-Artigo-By-Asciutti-Cesar-A-V1-04.pdf
  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    61/62

    ACEFG@, Idlgc A~`dcmn tiu dn Mintidilikgc 4 n d Ui Zc~li Ucrcgqc,

    2::5

    ANR@C@DNU, Alirnutc` Cuiegndcdn`~mcnrcdnrnqil~iuiegcl. UiZc~li@cegi`cl,3715

    AGNKN@BC^M, C`c Zc~lc Mct~rgdcdn dc Knuti dn Unk~rc`c dn

    G`airmci,eimbcun`c@BRGUI)GNE3;;77Lchncdi,2::1

    KGL,C`t`giLi~rngriUnk~rc`cnmG`airmtgec8cmbgn`tnumcg`arcmnndn

    mgerig`airmtgec, unk~rc`c nmzrnucrgcl n zctrgmi`gcl Ui Zc~li Ctlcu,

    3774

    KGL,C`t`giEcrliuMtidiunte`gecudnznus~gucuiegcl>ndUiZc~li

    Ctlcu,3777

    F^UUNRL, Ndm~`d "G`qnutgkcnulkgecu8unvtcg`qnutgkci8nlnmn`tiu

    dn ~mc nl~egdci an`imn`ilkgec di ei`fnegmn ti". Eilni Iu

    Zn`ucdirnu,UiZc~li,@iqcE~lt~rcl,3766

    LCQGLLN, Efrgutgc` n DGI@@N, Hnc C ei`utr~i di ucbnr8mc`~cldn

    mntidilikgcdnznus~gucnmeg`egcuf~mc`cuZirtiClnkrnuNdgtirc^AMK

    3777

    MCRTG@U,Clcdn Bcrbiuc ^MCCBIRDCKNMMNTIDILKGECBCUNCDC

    NM@IRMCUNZCDRNUDNUNK^[email protected]^DIDNECUIENTRNL

    U)C Dguzi`qnl nm8

    fttz8)){{{lg`irkegrz~uzbr)UUG)UUG2::4)Ziutnr)Z:5Yuug:4zda

    RAE2371UgtnUne~rgtwFc`dbiioDguzi`qnlunm fttz8)){{{rae`nt)Cenuui

    nm836unt2::1

    QNRKCRC, Uwlqgc E ZrihntiunRnlctrgiudnZnus~gucnmCdmg`gutrci

    UiZc~liCtlcu,377;

    QNRKCRC,UwlqgcEZrihntiunRnlctrgiudnZnus~gucnmCdmg`gutrci>

    ndUiZc~liCtlcu,2::4

    http://www.linorg.cirp.usp.br/SSI/SSI2004/Poster/P03_ssi04.pdfhttp://www.rfc.net/http://www.rfc.net/http://www.linorg.cirp.usp.br/SSI/SSI2004/Poster/P03_ssi04.pdfhttp://www.linorg.cirp.usp.br/SSI/SSI2004/Poster/P03_ssi04.pdfhttp://www.linorg.cirp.usp.br/SSI/SSI2004/Poster/P03_ssi04.pdfhttp://www.rfc.net/http://www.rfc.net/http://www.rfc.net/
  • 7/23/2019 AUDITORIA DE SISTEMAS DE INFORMAO: (PROPOSTA DE CRITRIO PARA AVALIAR A EFICCIA)

    62/62

    QNRKCRC,UwlqgcE Mtidiudnznus~gucnmCdmg`gutrci > n d Ui

    Zc~liCtlcu,2::>

    WG@,RibnrtONut~didnecui8zlc`nhcmn`tinmtidiu5ndZirtiClnkrnBiiomc`,2::>