Macau New Technologies Incubator Centre

 

Manetic aims at awaking the technology potential of Macau.

You are here: About Manetic arrow IS Audit & Security Home | Contact Us  
IS Audit & Security
Briefing on IS Audit & Security
Manetic realizes the importance in having a suitable skill set in Macau for information systems auditing, security and governance stems from the growing infrastructure and the complexity of IT solutions that are being provided and used not only by larger corporations that have shifted into Macau but also the growing sector of small to medium businesses that are modernizing their work habits through the use of technology. This reliance on more sophisticated use of technology in Macau signals Manetic that careful application and verification of the technology should be performed. This sometimes becomes apparent when problems with information technology happen. Fortunately, this kind of events is rare although costly to anyone who experiences them. On the other hand, the provision for information systems, verified at the same time as they are implemented, avoids costly mistakes or future issues in security and governance. Therefore, IS Audit & Security, both in the work performed as well as to promotion of the profession, has become a prominent area in Manetic.

In order to promote IS Audit & Security, as well as increase the public awareness to the wireless environment of Macau, Manetic has been organizing the WARDRIVING event with the related professional associations of Hong Kong and Macau annually since 2007. Also, through our support to non-profit association “ISACA Macau Chapter”, Manetic has not only ensured Macau to have a growing selection of professionals that are trained in specifically performing IS Audit function, but also been able to introduce the IS Audit & Security practices and technologies from overseas to Macau.

Meanwhile, Manetic has also established a non-profit organization Macau International Food Safety Association (MIFSA) to enhance public assurance, for domestic and overseas enterprises on their food origination, quality and the safety under a standardized system under the motto of “fair, accurate, authoritative, specialized”. Now, customers of food and other products are provided with alternate, verified way to check the supply chain of the specific product item bought in a store through the efforts of MIFSA.

ISACA
With the efforts of consultation by Manetic, Information Systems Audit and Control Association (Macao Chapter) was established in October, 2007. ISACA is an authority of IS auditing and IS control. The Headquarter was founded in 1967 with more than 86,000 members in more than 160 countries. The establishment of local Chapter has placed Macau into one of 175 chapters established in over 70 countries worldwide. The purpose of ISACA (Macao Chapter) is to enhance the IS auditing skills in Macau and provide a better service and support for the IS auditing and control professionals.

2008 has been the first year of full operation with the service up and running as a chapter. The chapter has started small, as the first step is always the most difficult to take on any journey, even for a chapter. Yet with the international support and the local support that ISACA Macau Chapter has received from MANETIC, the following items were fulfilled.

Certification Exams
ISACA International ensures that there are two certification exam opportunities, per year, in the location of where a local Chapter is based. These exams are performed on the same day all around the world. This is performed for the sole purpose to ensure that the uniquely selected questions that are on the exam are not leaked out, or allowed time to be distributed through brain-dumps style forums. This ensures the quality of the exam and in turn the certification.

The attendance of the exam has had growing popularity in Macau by doubling the number of participants when comparing the June and the December exam 2008. It is with no doubt that without an ISACA Chapter being present in Macau, the nearest test center would still be in Hong Kong. Now people in Macau do not need to take the six o’clock ferry in the morning to attend the exam in Hong Kong and have the convenience of the exam brought to Macau twice a year, every year.

Continual Professional Education
ISACA Macau chapter recognizes that the field of IS audit, security and governance is ever changing. Not only that techniques changes but there is also a great range of skills sought by individual practitioners of IS audit, security and governance. Therefore, the Macau Chapter offers the members, and interested non-members, during the year the possibility of acquiring professional education from people whom are working in the industry.

Seminars are performed every quarter and provide at a minimum, four (4) hours of continual professional education in various aspects of IS audit, security and governance. These seminars are not enough for certified professionals under the scheme of CISA, CISM or CGEIT, so this is tied in with online events that take place every month for members. Every month, three (3) hours of professional education can be acquired online. In total, throughout the year, the chapter’s efforts as well as the international association’s efforts produce a total of 40 hours attainable professional education.

CISA Review Course.
The Official CISA Review course was run in Macau twice in 2008, five (5) speakers provided the support needed in delivering the CISA review course work. The speakers were source from ISACA Macau Chapter members and it was encouraging that the membership was contributing back to the Macau Chapter. In turn, the Chapter as an association provided back to the professional members and non-members, that are seeking to take the CISA exam, through the offering of the official CISA review course.

The Official CISA Review Course has a stronger impact in able to deliver precisely the help and assistance that the exam candidates require for their chosen exam. Having a variety of speakers, allowed the experience of the individual speakers to resonate through the delivery of the official material. This access to the speaker’s experience provided the precise assistance to maximize the exam candidate’s chance at succeeding the CISA exam.

The composition of the students, taking the review course, ranged from the gaming industry, banking to the public services. This is the wide range of the types of profession that benefit from having individuals as Certified Information Systems Auditor.

CISM and CGEIT Review course
The Macau Chapter is working hard to ensure that courses in the other certifications are brought to the local members as soon as possible, so as to ensure that members seeking the same level of support that they have found for the CISA exam, may, be enjoyed for the CISM and CGEIT exam.

Wardriving
Being an annual event, Manetic has again organized the Wardriving event with the related professional associations of Hong Kong and Macau in 2008 to promote IS Audit & Security, as well as to increase the public awareness to the wireless environment of Macau.

Security of WLAN environment in Macau is getting better by a huge leap. This can be answered only from the data that was collected last year and a comparison made with this year’s result. The wider use of encryption technology is an indication that an effort to bring public awareness and use of the security features is working well. Although the exact source of the increase is not able to be determined from the report, it can be said without a doubt that the use of the security feature of WLAN is being promoted and that this promotion is working well.

From the data collected two most important values were discovered:
  1. >75%, better than three (3) out of four (4) access points detected are using the built-in security settings in 2008.
  2. >15%, increase in the use of built-in security features of WLAN access points comparing with 2007.
These numbers, although encouraging, allows for improvement in the use of encryption.
The following is a tabulated comparison of the merged data over the past two years.
 

Open(#/%)

Encrypted (#/%)

Total #

2008

23.23

76.77

4632

2007

34.88

65.12

2923

It can be seen that Macau in 2008 has a broader use of security features of WLAN.

MIFSA
Macau International Food Safety Association has continued to provide the necessary service of providing verifiable information to consumers about the supply chain of manufactures and retailers listed in the MIFSA website www.mifsa.com. These manufactures and retailers enjoy the fact that customers can check that due and proper verification was performed on their product. The supply chain covered may reach back from the time that the product has left the store of the manufacturer all the way to the store where the customer has bought the product.

MIFSA, enabling customers, to be able to trace the path of their purchased product allow the customer to not only make a more informed decision before purchase but also assures that the product purchased is the original. In the case of food stuffs, it assists in ensuring that the food was tested by the expected authority and that it is still safe from tampering before being purchased. MIFSA prides itself in being the only system in Macau and in the region to offer this service and looks forward to continuing the service for customers and manufactures alike.

In the year of 2008 the Macau Food Safety Association took part in the annual China International Food Exposition (Guangzhou). The bakery industry of Macau has been invited to either participate in taking a booth or to visit the exhibition. The event was a success with the food industry from around China converging to see the latest products in a chance to expand their brand names.