Maxis Berhad | Annual Report 2012
Maxis Berhad // Annual Report 2012 215 FINANCIAL STATEMENTS CORPORATE GOVERNANCE ANALYSIS OF SHAREHOLDINGS OTHER INFORMATION ANNUAL GENERAL MEETING 13. Systems and Information Security The Systems and Information Security department ("SIS") is responsible for continuously monitoring and resolving security threats to the Company both internally and externally. This includes conducting security awareness, vulnerability assessment and penetration test programmes, and compliance audits on the IT systems and Networks of Maxis to reduce the impact of service interruption due to attacks, negligence and malware. The effectiveness of the security programme is validated by external security consulting companies. Apart from the internal security compliance programmes, SIS is also required to maintain and assist in the compliance of the following regulatory and industry security programmes, namely: MS/ISO27001:2007, Payment Card Industry/Data Security Standard, and the Personal Data Protection Act 2010. SIS is governed by a group of Maxis Senior Leadership team members who meet quarterly to direct and approve the corporate security policies and standards set by the department and security projects undertaken by the team. It is also responsible for updating the Audit Committee at least annually on the Company’s security status. MONITORING AND REVIEW The processes that monitor and review the effectiveness of the system of risk management and internal controls include: 1. Management Representation to the Board by the Chief Executive Officer ("CEO") and Chief Financial Officer ("CFO"), based on representations made to them by Management on the adequacy and effectiveness of the Group’s risk management and internal control system in their respective areas. Any material exceptions identified are highlighted to the Board. 2. Internal Audit in their quarterly report to the Audit Committee and Senior Management continues to highlight significant issues and exceptions identified during the course of their review on processes and controls compliance. 3. The Defalcation Committee meets and deals regularly on matters pertaining to fraud and unethical practices. All issues arising from work carried out by the investigation team within the Internal Audit department and Management are channeled to this committee for deliberation. Appropriate actions are then taken based on the findings. 4. Enterprise Risk Management department reports to the Board on a half-yearly basis through the Audit Committee on the risk profile of the Group and the progress of action plans to manage and mitigate the risks. Management has taken the necessary actions to remedy weaknesses identified for the period under review. The Board and Management will continue to monitor the effectiveness and take measures to strengthen the risk management and internal control environment. CONCLUSION For the financial year under review and up to the date of issuance of the financial statements, the Board is satisfied with the adequacy, integrity and effectiveness of the Group’s system of risk management and internal control. No material losses, contingencies or uncertainties have arisen from any inadequacy or failure of the Group’s system of internal control that would require separate disclosure in the Group’s Annual Report. The CEO and CFO have provided assurance to the Board that the Group’s risk management and internal control system, in all material aspects, is operating adequately and effectively. REVIEW OF THE STATEMENT BY EXTERNAL AUDITORS As required by paragraph 15.23 of the Main Market Listing Requirements of Bursa Malaysia Securities Berhad, the external auditors have reviewed this Risk Management and Internal Control Statement. Their review was performed in accordance with Recommended Practice Guide ("RPG") 5: Guidance for Auditors on the Review of Directors’ Statement on Internal Control, issued by the Malaysian Institute of Accountants. Based on their review, the external auditors have reported to the Board that nothing has come to their attention that causes them to believe that this statement is inconsistent with their understanding of the process the Board has adopted in the review of the adequacy and integrity of the risk management and internal control of the Group. RPG 5 does not require the external auditors to, and they did not, consider whether this statement covers all risks and controls, or to form an opinion on the adequacy and effectiveness of the Group’s risk management and internal control systems.
Made with FlippingBook
RkJQdWJsaXNoZXIy ODU0MjU5