IT/Technology Detailed Assessment IT/Technology Note to the user This assessment is intended to assist existing and prospective Trustees/Directors/Estate Management/Office bearers/Third Party Managers of Body Corporates/Home Owners Associations/Retirement Villages or Shareblock Schemes (Community Schemes) to identify the existing level of governance, areas of weakness/vulnerability and the risks in these bodies and to offer advice on how to better manage these risks and improve overall governance. This assessment will also assist in helping Trustees/Directors/Estate Management/Office bearers/Third Party Managers in carrying out their fiduciary roles and responsibilities. IT/Technology Body Corporate/Complex/Property Name/Home Owners Association Name of Responsible Party/Trustee/Director/Estate Manager: Where the Community Scheme and/or Estate Management make use of the internet, banking systems and other software, are robust IT controls and disciplines in place? * Yes, very much so. We use a reputable internet service provider, have good anti-virus controls in place and have put preventative measures in place around a variety of potential attacks and threats, including the theft of computers (laptops/tablets/desktops), loss of data, cyber fraud and have issued best practice guidelines to staff. We have made IT disciplines and security and cyber-crime awareness a core focus and an integral part of our risk management process. Yes, to a large degree - we have robust IT policies and data security controls and back-up disciplines in place. As part of on-going staff education and training, a specific focus is placed on IT security, IT disciplines, data back-up, password controls, cybercrime awareness, social media and internet usage and the threat of data theft, hacking and phishing. Yes, while tried-and-tested IT best practice policies and procedures are followed and that password disciplines are tightly maintained and followed, we still seem to struggle with IT security. To a limited extent. While some controls (e.g. anti-virus software, patch updates, physical security, firewall and password controls) to protect the IT systems and data integrity/confidentiality are in place, we have limitations around password controls/access to the accounting and banking systems and customer data. No, almost no real IT security policy or IT controls/disciplines are in place, and that policies (e.g. password changes and data back-up) are not followed by Trustees/Directors/Estate Management or office bearers. No. We rely totally on basic anti-virus software and operating system security and have not taken any other specific security measures. We are vulnerable. We rely entirely on the security measures in place/used by third party service providers e.g. Managing Agents/Accountants/Third party service providers. Don't know/Can't establish Do you ensure that the Trustees/Directors/Community Scheme/Estate Management/Managing Agent/Third Party service providers update their virus protection or anti-virus software, operating software and other associated security controls on a regular basis? * Yes – all key aspects pro-actively attend to by all parties Yes to a degree – but they are not pro-active in all areas No, not really - we rely entirely on third parties/service providers being proactive here No - we are very slack in this area and are vulnerable as a result Don't know/Can't establish Does the Community Scheme/Estate Management/Developer/Operator have access to qualified people to support and maintain the technology and/or IT systems being used by the Community Scheme? * Yes – all parties have qualified dedicated staff to ensure continuity and support of their systems Yes to a degree – parties are largely reliant on outsourced/contracted service providers for support No, not really - we are totally reliant on third parties/service providers having the required support No – all parties are totally reliant on ad-hoc third parties for support Don't know/Can't establish Do the Trustees/Directors/Community Scheme/Estate Management/Operator only make use of credible licensed software in its operations/service provision? * Yes - we are very strict around this Yes to a degree No, we are non-compliant here Don't know/Can't establish Does the Community Scheme have a Facebook site and/or their own secure web-site? * Yes, secure hosted web-site/facebook presence which is actively managed. Yes - main means of communication but could be improved/better managed Yes, but no clear "ownership/management" of the site/pagess. Yes, but site/page is often down and/or is not maintained or monitored/content is stale/site being abused for personal gain No - nothing in place Does the Community Scheme make active use of social media/Facebook site and/or messaging services for its communication to owners/residents and is this well managed? * Yes - main means of continuous communication and all platforms/group very well managed Yes - to some degree but no clear control/management of platforms/groups No, not really - contact details/e-mail addresses stale/appears ineffective/too much work to maintain/badly managed No, not at all - main reliance still on traditional means i.e. notices/word of mouth/circulars/notice board Don't know/Can't establish If you are human, leave this field blank. Submit Δ Navigation Return to Dashboard Return to Output View Return to Members Tools