NAO carries out an IT audit of the Armed Forces of Malta

Email item Email item Print item Print item

NAO carries out an IT audit of the Armed Forces of MaltaAnother Information Technology (IT) audit has been carried out by the Auditor General, this time within the Armed Forces of Malta (AFM). This audit sought to examine AFM’s IT operations and investments and their alignment or otherwise with the AFM’s strategic objectives.

In line with other IT audits, one of the principal aims of this Report was to collect and analyse evidence to determine whether the AFM has the necessary controls to ensure that their IT and Information Systems maintain data integrity, safeguard assets, allow organisational goals to be achieved effectively and assist in making efficient use of the Government IT related resources.

“The AFM IT Strategy highlights, amongst other things, the importance of having an autonomous operational Wide Area Network, which would have sufficient bandwidth to eventually support the AFM operations and administration.”

The NAO said that “in this regard, the National Audit Office (NAO), which incidentally this year will be celebrating the 200th anniversary since the establishment of a public auditing institution in Malta, recommends that the Headquarters AFM Communications Information Systems Section (CIS) should ensure that this plan is followed through and implemented.”

The NAO said that it “also observed that although the AFM maintain the overall IT inventory in a very efficient and structured way, the AFM should ideally invest in an electronic IT inventory application. Overall, the NAO commended the number of IT related internal policies and operating procedures that were issued by the AFM.”

Moreover, it said, “although the AFM took a number of initiatives to mitigate the risks involved in the event of a disruption or total failure in the IT systems within the organisation, the NAO noted that the AFM, like various other entities, which have been audited, does not have formalised IT Business Continuity plans.”

Thus, the NAO recommended that the AFM carries out a Business Impact Analysis to identify the business and operational impacts of IT related incidents in order to determine a recovery strategy. The NAO also recommended that the AFM carry out a risk assessment to analyse critical IT assets to identify possible threats to those assets and assess the level of vulnerability.

This Audit Report may be accessed through the National Audit Office website (www.nao.gov.mt).

  • Permalink: NAO carries out an IT audit of the Armed Forces of Malta
  • You may also like...

    Leave a Reply

    Your email address will not be published. Required fields are marked *