About Us

The Phoenix Story

The Story

PB&SP founder (Robin Basham) began Phoenix with over a decade experience in managing Information Technology and Audit services within public, private and federal/government, banking, education, telcom, defense and manufacturing industries . Designing and implementing ITIL® Service Support and Infrastructure Management programs,  contributing to various Application Life cycle and Database Management initiatives, participating in advance degree and technical committees across areas such as Java Enterprise and Open Source Standards,, leading Process Engineering (as conforming to ISO 9000), delivering Capital Projects Requirements Analysis (as aligned to Department of Defense), completing major OSS Migration across two platforms including SAP, MetaSolve an Remedy (Telcom), and currently delivering project management, ongoing control self assessment programs, SAS 70 and Sarbanes-Oxley internal compliance reporting, supplemented by 100+ workflow process diagrams mapping COBIT®.and ITIL® controls across entire organizations, and facilitating live compliance reporting using mainstream desktop applications.

PB&SP provides regular on line and face to face certified COBIT®.4.0 and ITSM ISEB Foundation level IT Governance and Regulatory Training.

Bringing education, technology and assessment to audit   [Top]

Entering IT a fifteen year veteran to assessment, graduate level training, and the implementation of networking and software to meet special learning in mainstream environments, Ms. Basham discovered that industry efforts to operate at a profit in spite of complex financial, legal, conformity assessment standards presented a familiar challenge. Projects aiding conformity to (ISO 9000, ISO 14000 and ISO17799), and evolving certifications around SDLC and CMM standards, extended programs from utility and data management to facilitating standard practice in development of procedures and guidance toward maintaining acceptable risk and compliance management posture.

Working extensively in the design and data management, projects ranged from:

  • Decision Support Systems (DSS) to
  • Order Management Systems (OMS) and
  • Data Center Management (DCM) according to TMN, ITIL® and FCAPS
  • Operations Support System and
  • Data Integrity between Financial, Service and Network Management Systems.

The following consistent and increasingly normalized elements emerged:

  • Process architecture models must adapt to meet specialized business requirements
  • Any variance from the norm needs policy, work instructions, and monitoring
  • Process Controls Map, aligning Risk to Legal Requirement and control to meeting risk
  • Business case workflow and data validation controls were only as effective as the communication across all phases of the Development Life cycle
  • Role based access is driven by policy, no matter what the condition or product
  • Anything measured is fair game for audit and data retention
  • Performance Metrics are more than executive show and tell

The first storm   [Top]

1996 marked the millennium bug and mounting concerns over business continuity. Career and Education Director for Association for Women in Computing (AWC), Robin pitched a Y2K Conference promoting SDLC and Quality Management standards. Joining AWC forces with ASM (Association for Systems Management) SIM (Society for Information Management), and PMI (Project Management Institute), Robin directed, RoadMap 2001. 30 industry leaders and 400 Babson attendees collaborated on best management and project practice necessary to avert the pending crisis. Unfortunately no one’s vision included the business scandals and failures of ethic that lay ahead.

Banking to Telecommunications [Top]

Codes of Federal Regulation exploded with the onset of on line Banking, but even more demanding were those with responsibility to enforce FCC regulations in an industry evolving technologies and products adapted as mainstream and made obsolete by competition or bad design overnight. Attempts to maintain market position unleashed a frenzy of cutting edge software and devices, always claiming alignment to IEC and TeleManagement Forum (TM Forum) standards, and always released with little or no attention to testing, support, change, security and performance management process. Where small configuration anomalies affected legal and financial requirements, Telcom OSS platforms too came and went, costing the industry billions of dollars, but never providing audit with simple clean answers to inventory and count.   After two unsuccessful OSS migrations, Ms. Basham proposed a grass roots Performance Management Forum, networking metrics to finance and service data, with comparative reports presented monthly to CTO and Executive Board.  People realized the numbers told the truth, and soon after joined the ranks of WorldCom, Global Crossing and MCI.

Ominous clouds and biting wind [Top]

2001 marked by common stories of hidden debt, overstated value and manipulated dates in the name of stock values and ironically keeping share-holders happy, Corporate scandals such as WorldCom and Enron rippled through Wall Street, swelling to an unemployment tsunami.  With so many peers out of work, Ms. Basham took a leap of faith, turning private practice into corporation.   Upholding conformity to legal mandates had been simply a part the last twenty years in professional practice, (See RegWatch), but with Sarbanes-Oxley Act of 2002 there was widespread need of Facilitated Compliance Management™ and documentation of all controls related process.

The SEC asked for internal controls reporting as aligned to The Committee of Sponsoring Organizations of the Treadway Commission (COSO), adding to the implications of the Clinger Cohen act, suggesting efficient balance between business and systems, where IT scores aligned to meeting business objectives.  The accounting oversight mandate aimed to force order out of chaos, but the renaissance came from ISACA in the form of an IT controls assessment roadmap, Control Objectives for Information and related Technology (COBIT®.).   The breakthrough IT governance standard did not’t introduce new methods or technologies.  To the contrary, this IT toolkit provided a comprehensive matrix enabling controls visibility across all enterprise IT functions.  Using language that spoke to an overall business assessment, an underlying organizations resource model and all other form of audit and conformity requirements were now represented with one single compliance standard.

After 9/11 and more than half million technology layoffs, Ms. Basham regarded COBIT®. as the phoenix.  Phoenix Business and Systems Process, (PB&SP) adopted COBIT®., ISO/IEC 17799:2000 and ITIL® (BS15000 and ICT Infrastructure Management Best Practice) standards as comprehensive response to all mandates over IT control.   As Sarbanes-Oxley’s requirements immobilized the United States economy, PB&SP first two years assisted corporations as well known as Siemens, Raytheon and Journal Communication to implement IT Infrastructure and Assessment programs entirely aligned to the measurements found in COBIT®..

Bracing for the big storm [Top]

Released January 2003 to the Association for Women in Computing, “Scoping Sarbanes-Oxley.” urged a lowest common denominator approach, meeting section 404 general control attestation requirements  A full two years in advance of the ISACA, PricewaterhouseCoopers LLC, IIA, AICPA landmark direction “IT Control Objectives for Sarbanes-Oxley, [i]   Ms. Basham’ s strategy stressed a risk based approach, lowest cost and highest return controls, and distributed self assessment activity that would enforce a program of sustainable compliance.

Participation and Contribution [Top]

Avoiding claim to answers, Ms. Basham’s wisdom is aligning questions to authorities, and tools to business, technology and audit requirements.  Firm believer in collaboration, she makes full use of platforms for professional development, offering any new ideas to a team “reality check” on the ISACA list services open forum of technology, audit and legal experts.  Keeping current in definitive rulings, PB&SP leverages collaboration among leaders at IIA, ISACA, OASIS,  their associated committee members and resources, and guidance as provided by the efforts of our Big5 (PricewaterhouseCoopers LLP, Deloitte & Touche LLP, Ernst & Young global, KPMG International, and Protiviti® Inc).   Global Communications by ISACA and direct attention to posted changes by FASB, GASB, AICPA, ISACA, and IFAC, as would affect Information Systems Audit and Control guidelines is of primary focus to PB&SP.

Acting as liaison between OASIS, ISACA, itSMF and the IIA, Ms. Basham’s influence is seen in practical templates, UML proposals and applications for RunBook and Risk Management.  Robin’s most current publication, a satire regarding the struggle to stay current with industry is titled The Perils of Mount Must Read  Introducing a new theory of Compliance Professional Evolution, the story reveals a common mission to unite by way of standards and alignment to the best each has to offer.   The Perils are caused by everyone’s pervasive anxiety in just trying to stay afloat.

What is Facilitated Compliance Management™ (FCM)? [Top]

DoD, Telcom, Securities and Trading, Education, Government and Banking regulations, impact every aspect of systems and operations management.  PMM (Personal Maturity Management) methods guided creation of a process and controls tracking application. Database and grew from Help Desk, to Order Management, to Process Engine and Knowledge Base.  Managing Process Engineering and later Controls Assessment teams the application became known as the SamePage Process Development Tracking, an unofficial and non registered trade mark.  Designed as an evolving compliance prototype, the tool is provided to clients and was never intended to be sold as product.  Discovering that SamePageSolutions had registered and been provided a SamePage trademark, application for FCM, "Facilitated Compliance Management" trademark was immediately filed and the use of SamePage in reference to PB&SP practice is now phased out.  Resisting offers to turn what is now FCM into another compliance product, the tool remains true to its intended purpose, offering open code and data models for use as a compliance prototype, leveraging the portability of Microsoft HTML, BPEL and XML Compliant Microsoft Visio Standard and VBA forms posting to a SQL back end.

Core Value [Top]

PB&SP keeps clients ahead of the compliance curve. Using a combination of best of breed tools and processes for RunBooks, Configuration and Change Management, Enterprise Risk Management, Security Management and Performance Management, PB&SSP emphasizes ITIL® [ii] , and COBIT® frameworks ., prudent examination of existing infrastructure, and technology acquisition recommendations based in a risk and legal context.  PB&SP utilizes partner resources to provide clients with extended requirements in long term data support, network management, software development and staff augmentation.  These are no fee, value add perks and are among the many reasons clients remain satisfied with PB&SP.

Bread Crumbs  [Top]

Presentations in the last year include, Organization for the Advancement of Structured Information Standards (OASIS) 2005 Symposium in New OrleansInformation Technology Service Management Forum, New England (itSMF), Information Systems Audit and Control Association Chicago and Cleveland Chapters (ISACA), Financial Executive and Technology Executive Networking Groups (FENG/ TENG)  Robin is a regular contributor and a founding member of the OASIS Configuration Compliance Technical Committee and an regular contributor the ISACA IT Governance, Information Security and Sarbanes-Oxley Compliance and COBIT®.list services.

Shingles  [Top]

Among Robin's credentials are Certified Information Systems Auditor (CISA), ITIL® Foundations certification (ISEB), Master Degree in Information Technology (M.IT), and a Masters of Education (M.Ed).

All Laws matter - we respectfully suggest that an IT Auditor needs to know... Please feel free to suggest changes to the list.  We try to keep it under 50 items. It is not hard to jump to hundreds more.
Source Title: Short Name: Web

Basel II—Revised International Capital Framework

Basel II

The Application of Basel II to Trading Activities and the Treatment of Double Default Effects

Chief Financial Officers Act of 1990, A Mandate for Federal Financial Management Reform

CFO Act of 1990

GAO/AFMD-12.19.4 CFO Act

Clinger-Cohen Act of 1996

Clinger-Cohen Act

Illinois Land Conservation Act, P.L. 104-106 S.1124

Code of Federal Regulations Full listing at GPO

CFR Full Listing at GPO

Code of Federal Regulations: Main Page

Computer Fraud and Abuse Act of 1986

Computer Fraud and Abuse Act

Computer Fraud & Abuse Act

Cyber Security Research and Development Act of 2002

P.L. 107-305

Cyber Security Research and Development Act of 2002

Data Protection Act 1998

DPA

Data Protection Act 1998

DCI Directive 6/3, Protecting Sensitive Compartmented Information within Information Systems

DCI Directive 6/3

DCID 6/3 - Policy

Director of Central Intelligence Directives

DCID

DCID - Director of Central Intelligence Directives

DoD 5015.2-STD: Design Criteria Standard for Electronic Records Management Software Applications

DoD 5015.2-STD

Design Criteria Standard for Electronic Records Management Software Applications

E-Government Act of 2002

E-Government

H. R. 2458: E-Government Act of 2002

EU Data Protection Directive

EUDPD

EU Directive

Executive Order 13103 of September 30, 1998 - Computer Software Piracy

Executive Order 13103

Executive Order 13103: Computer Software Piracy

Failure of corporate officers to certify financial reports; Title 18 CHAPTER 63 § 1350

§ 1350  

§ 1350. Failure of corporate officers to certify financial reports

Fair and Accurate Credit Transactions Act of 2003

FACTA of 2003

PUBLIC LAW 108–159 - DEC. 4, 2003 - 117 STAT. 1952; 15 U.S.C. § 1601

Fair Credit Reporting Act or Bank Secrecy Act

FCRA or BSCA

Internal Revenue Manual - 4.26.5 Bank Secrecy Act History and Law

Federal Information Security Management Act of 2002

FISMA

Federal Information Security Management Act of 2002, 44 USC 101 note.

Federal Power Act

FPA

Federal Power Act

Federal Trade Commission (FTC) Act of 1914, amended in 1938

FTC ACT of 1914

Federal Trade Commission Act, Title 15 - Commerce and Trade

Final Act of The 1986-1994 Uruguay Round Of Trade Negotiations Agreement On Technical Barriers To Trade

Final Act of the Uruguay Round

WTO- Final Act of the Uruguay Round

FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems

FIPS PUB 199

FIPS Publication 199: Standards for Security Categorization of Federal Information and Information Sys

FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems

FIPS PUB 200

FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems

FIPS Publication 201, Personal Identity Verification (PIV) for Federal Employees and Contractors

FIPS PUB 201

FIPS PUB 201: Personal Identity Verification (PIV) of Federal Employees and Contractors

Foreign Corrupt Practices Act 1977

FCPA

FCPA

Freedom of Information Act

FOIA

Freedom of Information Act

Government Information Security Reform Act (GIRSA)

GISRA

GISRA

Gramm-Leach Bliley Act of 1999

GLBA

Gramm-Leach Bliley Act

Health Insurance Portability and Accountability Act of 1996

HIPAA

PUBLIC LAW 104–13

Personal Information Protection and Electronic Documents Act (Canada)

PIPEDA

Personal Information Protection and Electronic Documents Act

Privacy Act of 1974

Privacy Act

THE PRIVACY ACT OF 1974, 5 U.S.C. § 552a -- As Amended

Ronald W. Reagan National Defense Authorization Act for Fiscal Year 2005

National Defense Authorization Act 2005

PUBLIC LAW 108–375 - OCT. 28, 2004 - 118 STAT. 1811

Safe Harbor Privacy Framework

Safe Harbor

Introduction to the Safe Harbor

Sarbanes-Oxley Act of 2002

Sarbanes-Oxley

PUBLIC LAW 107–204—JULY 30, 2002—116 STAT. 745

Section 17a-4: Final Rule: Applicability of CFTC and SEC Customer Protection, Record keeping, Reporting, and Bankruptcy Rules and the Securities Investor Protection Act of 1970 to Accounts Holding Security Futures Products

SEC Rule 17a-4

Final Rule: Applicability of CFTC and SEC Customer Protection, Record keeping, Reporting, and Bankruptcy Rules and the Securities Investor Protection Act of 1970 to Accounts Holding Security Futures Products

Securities Exchange Act of 1934

Securities Exchange Act

Securities Exchange Act of 1934

State of California Senate Bill 1386

SB-1386

SB 1386 Senate Bill - CHAPTERED

The Malcolm Baldrige National Quality Improvement Act of 1987

Malcolm Baldrige Award

The Malcolm Baldrige National Quality Improvement Act of 1987 - Public Law 100-107

Title 21 Code of Federal Regulations (21 CFR Part 11) Electronic Records; Electronic Signatures

21 CFR Part 11

21 CFR Part 11: Electronic Records; Electronic Signatures

United States Copyright Law, Title 17

Title 17

Circular 92: Copyright Law of the United States of America and Related Laws Contained in Title 17 of the United States Code

United States of America Patriot Act of 2001

US Patriot Act

Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (US Patriot Act) Act of 2001

[i] The IT Governance Institute (ITGI) "exists to assist enterprise leaders in their responsibility to ensure that IT is aligned with the business and delivers value, its performance is measured, its resources properly allocated and its risks mitigated. As summarized by ITGI: is a not-for-profit research organization affiliated with the Information Systems Audit and Control Association® (ISACA), a global not-for-profit professional membership organization focused on IT Governance, assurance and security, with more than 47,000 members in more than 140 countries. ITGI undertakes research and publishes COBIT®. an open standard and framework of controls and best practice for IT governance." www.itgi.org

[ii] ICT Infrastructure Management Manual OGC As explained by the OGC: "is a UK government organization responsible for procurement and efficiency improvements in the UK public sector. OGC has produced world-class best practice guidance, including PRINCE2 (project management), MSP (Managing Successful Programs) and ITIL® (IT service management). ITIL® is used throughout the world and is aligned with the ISO/IEC BS 27000 international standard in service management. OGC

Headlines

CobiTQuiz

PB&SP meets training requirements for COBIT® training -December 2005

Phoenix Business and Systems Process, Inc. listed as sponsoring member to ISACA - February 2006

PB&SP and IP Services announce formal partner agreement...IP Services
leveraging the talents of Kevin Behr, CTO...just for a start

IP Services

The IIA proposes Generally Accepted IT Principles

The IIA’s Advanced Technology Committee has issued an exposure draft on Generally Accepted IT Principles (GAIT) (PDF, 561KB) in an effort to ensure that auditors have the tools and understanding necessary to better evaluate and manage risks related to internal controls for financial reporting. Read more!

mks
MKS Announcing record year and new partners in 2005

Merant Partner, Phoenix Business and Systems Process noted for third year in a row.

Maintaining our record of 100% success in aiding our clients for third party SOX audit and SAS 70 Examinations, we add AON RiskConsole to the score ...full story

AON

Please turn off cookies: These are important information sites, but your personal viewing is tracked by option to CMP Media.  We support reading and considering news information from this source. "COOKIES OFF and SKIP THIS ADD" plus verification on any email entry to avoid email spam agents, are just some of the ways CMP media makes news reading more pleasurable and secure.

Top ten search terms from the TechWeb TechEncyclopediatop-ten-cmp-mediaCopyright © CMP Media LLC

Year end from US-CERT

PB&SP provides CPE training for Change Management, COBIT® and Security - Letter from the President