Des nouvelles défaillances de "Data Integrity"...
Des nouvelles injonctions de l'agence américaine mettent à jour des pratiques frauduleuses liées à la "data integrity" : Pour cette société allemande : 4. Failure to exercise sufficient controls over computerized systems to prevent unauthorized access or changes to data, and to provide adequate controls to prevent omission of data. Our investigator found that your (b)(4) system used for (b)(4) and (b)(4) testing lacked access controls and audit trail capabilities. For example, all employees had administrator privileges and shared one user name, so actions could not be attributed or traced to specific individuals . This exposed your electronic data to manipulation and/or deletion without traceability. Our investigator also noted that your firm copied raw data to a CD (b)(4), and then deleted the data from the (b)(4) system to free space on the hard drive. Files copied to the CD were selected manually; the selection process was not supervised. Without audit tra...