From the inspection of the company’s IT/IS policies, the IT/IS policies were in place; however, there were some topics not covered as following:
• Password Control and Guidance
• Program Change and Program Development
• Disaster Recovery Plan (DRP) or Business Continuity Plan (BCP)
Without formal written some area of IT/IS policies and procedures, it could result in incorrect and inefficient practices. It is also difficult for the IT personnel to administer the day-to-day operations since there are not enough guidelines. Hence, there is no assurance that the proper procedures are consistently met during the normal courses of action.