myoasis
About the author
Sabtu, 02 Juli 2011
Office mandatory training
Yesterday, I joined some mandatory training provided by my company, the training it's about SAP. Actually, I was in the middle of engagement that require me to be on the client site, and it have a tight rundown schedule of meetings. It is not the matter of the training that I was concerned, but I pretty much don't agree with the way of my company compel all of their employees to joined some sudden training. I understand that this is required to support continues improvement for the employees itself as we are working on the industries of knowledge, but honestly it give a lil bit impression of expulsion because it make our planned schedule with client become screwed. We can't just cancel or absence on the training as we will be a subject of company training policy (and need to fill various forms and give explanation to our partner why we not attend the training X_X). Anyway, I think maybe company can make fixed annual training schedule for their employees, and published it on the beginning of the year so we can adjust the right time to with our work schedule.
Sabtu, 25 Juni 2011
I'm back!
Well, long time no see pals. Now, almost two year I have been working in the field of IS advisory. Alhamdulilah, it seems my wish and ambition to working on one of the Big 4 Accounting Firm and obtained one of the popular certification among those industry has come true. I’m still remember back when I’m just graduated from college and admired with this job and want to be like mas Anjar Priandoyo (because his writing on his blog make me want to do this ). I like the working environment, my friends, my bosses, as they are still young and ambitious. Can’t believe that there are many great persons out there, and suddenly you will realize that you’re just a small things and powerless. But, all of these make me feel grateful, thanks to God which giving me the opportunities to develop myself and reach my dreams. Starting from now, I will try to adapt and learn everything I need to know to survive in this fast and crazy environment. Wish me a good luck .
Minggu, 06 Desember 2009
SOX, is a need for compliances or just some set of disturbing rules?
For the last 5 months, I have been working with Sarbanes Oxley section 404 especially in IT General Control. I Conduct the control testing and working with the Risk Control Matrices (RCM). So far my conclusion about SOX RCM Guidance is multi interpretation, is very difficult to define the best way/solution for some cases because the different perspective from the SOX auditor and the IT auditee. We are use the SOX RCM as the guidance to checking the process within the IT department, but somehow there's something in reality that can't be matched up with the RCM. It can be very stressful for both the SOX auditor and the IT auditee, because it's hard to find the solution, and sometimes we are being uncertain wirh the RCM design. So, either SOX, is a need for compliances or just some set of disturbing rules? You can choose.
Minggu, 08 November 2009
Come and goes
Life is a never ending cycle, earth always rotate, day changes into night and vice versa, we always breathing, so does people come and goes. Some friends would be disappear and some friends still there beside us. Some stories give us happiness and some stories give us sadness. But this cycle make us grow wiser and stronger, thanks God we could participate to this beautiful never ending cycle of life.
Sabtu, 17 Oktober 2009
Busy sunday
Hari minggu kali ini penulis dibanjiri dengan schedule yang padat. Mulai dari kerjaan kantor yang harus dicicil karena sudah mendekati deadline, motong rumput depan rumah, mandiin anjing2nya yg bandel, mencari tempat jual motor bekas, meeting keluarga besar untuk membicarakan silsilah, sampai keinginan penulis sendiri yang berhasrat ngapelin pacar. Kykna memang byk hal yg harus dilakukan, namun ada tips dari penulis jika menghadapi schedule padat di hari minggu seperti ini;
-Urutkan skala prioritas
Betapa banyaknya hal yang harus dilakukan membuat Anda mau tidak mau harus mengorbankan beberapa hal yang kurang penting dan mengutamakan yang penting. Dalam kasus ini penulis dengan pertimbangan sedalam-dalamnya membatalkan jadwalnya untuk motong rumput depan rumah dan memandikan anjing2nya.
-Bangun lebih pagi
Waktu adalah hal yang sangat berharga, 24 jam saja tidak akan pernah cukup jika kita tidak menggunakannya dengan efektif. Dalam kasus ini penulis bangun di waktu subuh dan tidak tidur lagi. Karena dalam kesempatan lain, penulis selalu menggunakan waktu jeda antara subuh sampai dhuha sebelum berangkat kerja untuk tidur. Tentunya setelah solat subuh.
-Jangan manja
Minggu memang waktu buat santai untuk kebanyakkan orang, yah kebanyakkan orang. Tukang bubur didekat rumah penulis tidak pernah libur di hari minggu. Jadi, jangan jadi manja deh (dengan nada sedikit sombong)
-Jauhkan interuptor2
TV, internet, sampai nyamuk dapat menjadi momok bagi kita yang sedang dituntut untuk fokus dalam melakukan sesuatu. Sebisa mungkin siapkan mental Anda untuk mencegah interuptor ini mengalahkan Anda.
Satrio Arto Santoso
-Stres sendiri di hari minggu-
-Urutkan skala prioritas
Betapa banyaknya hal yang harus dilakukan membuat Anda mau tidak mau harus mengorbankan beberapa hal yang kurang penting dan mengutamakan yang penting. Dalam kasus ini penulis dengan pertimbangan sedalam-dalamnya membatalkan jadwalnya untuk motong rumput depan rumah dan memandikan anjing2nya.
-Bangun lebih pagi
Waktu adalah hal yang sangat berharga, 24 jam saja tidak akan pernah cukup jika kita tidak menggunakannya dengan efektif. Dalam kasus ini penulis bangun di waktu subuh dan tidak tidur lagi. Karena dalam kesempatan lain, penulis selalu menggunakan waktu jeda antara subuh sampai dhuha sebelum berangkat kerja untuk tidur. Tentunya setelah solat subuh.
-Jangan manja
Minggu memang waktu buat santai untuk kebanyakkan orang, yah kebanyakkan orang. Tukang bubur didekat rumah penulis tidak pernah libur di hari minggu. Jadi, jangan jadi manja deh (dengan nada sedikit sombong)
-Jauhkan interuptor2
TV, internet, sampai nyamuk dapat menjadi momok bagi kita yang sedang dituntut untuk fokus dalam melakukan sesuatu. Sebisa mungkin siapkan mental Anda untuk mencegah interuptor ini mengalahkan Anda.
Satrio Arto Santoso
-Stres sendiri di hari minggu-
Kamis, 08 Oktober 2009
Seperti padi, makin matang makin merunduk
Lama tidak mem-posting tulisan di blog saya sendiri, jd kangen rasanya. Tanpa terasa sudah hampir 4 bulan bekerja di bidang audit. Disela-sela waktu saya sempatkan diri tuk melihat profile orang2 yang sukses di bidangnya (terutama IS audit), saya senang melihat perjalanan karier seseorang yg jika ditelusuri ternyata mereka memulai sesuatunya dari nol hingga dapat sukses seperti sekarang. Ada kesamaan dari profile org2 yang saya lihat, yaitu kerja keras dan tidak lupa doa kepada Yang Maha Esa. Kebetulan di klien saya yg skrg, saya memiliki akses tuk mengetahui informasi org2 besar (pejabat) yg memegang peranan di perusahaan klien saya. Sy menemukan informasi seseorang yg sekarang berpangkat tinggi (sekelas GM)di bidang IS audit, lalu iseng2 saja cari tahu mengenai org tersebut. Lalu ketemu blog beliau, setelah baca2 sedikit kemudian sy jd tersenyum sendiri. Ternyata org ini memang ditakdirkan jd org besar. Pada blog beliau yg saya lihat kebanyakkan hanya doa2 dan curhat beliau kepada Yang Maha Kuasa. Memang seperti padi, makin matang makin merunduk.
Seperti ini doa2 yg dipanjatkan beliau,
Yaa Rabb,
BumiMu ini luas, masih banyak yang belum diolah.
Padahal Engkau ciptakan kami manusia sebagai khalifah untuk mengolah
dan memakmurkan bumi ini. Maafkan kami Rabb, karena belum menunaikan
tugas yang Engkau berikan. Ampuni kami wahai Rabb yang Maha Agung yang
telah menciptakan alam yang luas dan indah ini. Tiada kemampuan dan
tiada kekuatan yang kami miliki, kecuali dari Mu, Rabb. Laa hawla wa
laa quwwata illa billah. Maha suci Allah.
Satrio Arto Santoso
-Yang sedang belajar arti kesuksesan-
Seperti ini doa2 yg dipanjatkan beliau,
Yaa Rabb,
BumiMu ini luas, masih banyak yang belum diolah.
Padahal Engkau ciptakan kami manusia sebagai khalifah untuk mengolah
dan memakmurkan bumi ini. Maafkan kami Rabb, karena belum menunaikan
tugas yang Engkau berikan. Ampuni kami wahai Rabb yang Maha Agung yang
telah menciptakan alam yang luas dan indah ini. Tiada kemampuan dan
tiada kekuatan yang kami miliki, kecuali dari Mu, Rabb. Laa hawla wa
laa quwwata illa billah. Maha suci Allah.
Satrio Arto Santoso
-Yang sedang belajar arti kesuksesan-
Sabtu, 19 September 2009
3 Important security assessment
To provide a good system security there many ways we could do. IT professionals has developed some sort things to secure your system, one of them are the security assessment. The risk assessment, threat assessment and vulnerability assessment are part of the security assessment. Although it's resemble each other, but each is valuable for its own reasons and applicable to solving different problems.
A risk assessment is performed to determine the most important potential security breaches to address now, rather than later. Analyzing risk can give valued information to management for manage appropriate security budget for both time and money.
A threat assessment is performed to determine the best approaches to securing a system against a particular threat, or class of threat. Analyzing threat can give valued information about attackers resource, penetration testing are some method use to know how to countermeasure attacks by the given threat.
Vulnerability assessment should be performed on an ongoing basis by the parties responsible for resolving such vulnerabilities, and helps to provide data used to identify unexpected dangers to security that need to be addressed. Analyzing vulnerabilities helps to fix flaws on ongoing system security and warn the people to be aware and responsible about security of one resource.
Applying these assessment isn't just give valued information and help you understand the dangers, it also help to develop good policies and making prioritize for your system security.
A risk assessment is performed to determine the most important potential security breaches to address now, rather than later. Analyzing risk can give valued information to management for manage appropriate security budget for both time and money.
A threat assessment is performed to determine the best approaches to securing a system against a particular threat, or class of threat. Analyzing threat can give valued information about attackers resource, penetration testing are some method use to know how to countermeasure attacks by the given threat.
Vulnerability assessment should be performed on an ongoing basis by the parties responsible for resolving such vulnerabilities, and helps to provide data used to identify unexpected dangers to security that need to be addressed. Analyzing vulnerabilities helps to fix flaws on ongoing system security and warn the people to be aware and responsible about security of one resource.
Applying these assessment isn't just give valued information and help you understand the dangers, it also help to develop good policies and making prioritize for your system security.
Langgan:
Entri (Atom)
