ISACA® sets forth this Code of
Professional Ethics to guide the
professional and personal conduct of
members of the association and/or its
certification holders.
Members and ISACA certification holders
shall:
1- Support the implementation of, and
encourage compliance with, appropriate
standards, procedures and controls for
information systems.
.
2- Perform their duties with
objectivity, due diligence and
professional care, in accordance with
professional standards and best
practices..
3- Serve in the interest of stakeholders
in a lawful and honest manner, while
maintaining high standards of conduct
and character, and not engage in acts
discreditable to the profession..
4- Maintain the privacy and
confidentiality of information obtained
in the course of their duties unless
disclosure is required by legal
authority. Such information shall not be
used for personal benefit or released to
inappropriate parties.
5- Maintain competency in their
respective fields and agree to undertake
only those activities, which they can
reasonably expect to complete with
professional competence.
6- Inform appropriate parties of the
results of work performed; revealing all
significant facts known to them.
7- Support the professional education of
stakeholders in enhancing their
understanding of information systems
security and control.
Failure to comply with this Code of
Professional Ethics can result in an
investigation into a member's, and/or
certification holder's conduct and,
ultimately, in disciplinary measures.
|