Jason was concerned about the effectiveness of controls designed to ensure systems availability, however. He noted that although Northwest Industries had developed a disaster recovery and business continuity plan in the fall 2001, it had not been reviewed or updated since then. Of even greater concern was the fact that many portions of the plan, including arrangements for a cold site located in California, had never been tested. Jason’s biggest concern, however, related to backup procedures. All files were backed up weekly, on Saturdays, onto DVDs, and incremental backups were made each night. No one had ever practiced restoring the data, however, In addition, the backups were not encrypted and one copy was stored on-site in the main server room on a shelf by the door.
Jason concluded his report with specific recommendations for improving the weaknesses he had identified in controls pertaining to systems availability. He felt confident that once those recommendations were implemented, management could be reasonably assured that northwest Industries’ information systems had satisfied the AICPA’s Trust Services framework criteria and principles for systems reliability.