
Since 2002, Kevin Ricci has been director of management information systems at the Providence-based accounting firm Lefkowitz, Garfinkel, Champi & DeRienzo P.C. Ricci talked with Providence Business News recently about the hard work of getting certified as an IT systems auditor, a security mistake made by many firms – and his history as a comedian.
PBN: In February, you received the Certified Information Systems Auditor (CISA) certification. What is that? Why did you decide to obtain it?
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
RICCI: The Computer Information Systems Auditor (CISA) certification, first issued in 1978, is globally recognized as the gold standard qualification in the field of systems audit. The qualification entails the study of the Information Technology audit process, IT governance, systems and infrastructure lifecycle management, information asset protection, IT service delivery and support, and business continuity.
The reason I pursued this credential was to provide a level of service to LGC&D’s clients that is not normally found in a Providence-based regional accounting firm. Being able to put all that I learned during the certification process into action during the course of our audits greatly increases the service value received by our clients.
PBN: What did you have to do to get the CISA certification? How much work was it?
RICCI: In order to prepare for the exam, I supplemented my existing on-the-job experience with nightly studying sessions and several weeks of intense training programs until I felt ready for the exam. After sitting through the five-hour exam, the worst was yet to come – waiting several weeks for the results to arrive! Thankfully, the hard work and all of the support from our firm paid off.
PBN: You have run the IT audit division of LGC&D since it was started in 2006. What exactly is entailed in an IT audit? What do you look at? Why would companies want to have one done?
RICCI: Our IT auditors, collectively known as LGC&D Solutions, assist client companies with fortifying their company’s general computer controls related to areas such as physical and logical security, and disaster recovery. Our objective is to help them keep their data safe and secure. Our process includes a series of interviews based on proprietary documentation and testing matrices that help identify potential issues. When control deficiencies are identified, we work with the client to develop the solutions that strengthen their controls over critical financial data.
PBN: What is the most common problem or mistake you encounter when you do these audits?
RICCI: An issue that I often encounter is a lack of coordination between the Human Resources and IT departments concerning terminated employees. I have seen several situations in which terminated employees retain access to the company’s computer network. Even after a separated employee has been escorted off the premises, they can wreak havoc if their remote access and user accounts remain active. If solid notification policies and procedures are not in place, IT may not know that the user account needs to be disabled, allowing the former employee to log in from home and access – and potentially alter – sensitive company data.
PBN: Your bio says you were named Rhode Island’s Funniest Comedian in 2004. How did you get into stand-up comedy? And do you know any good tech jokes?
RICCI: Inspired by my dad, who was constantly making everyone laugh at family parties and cookouts, I always wanted to give comedy a try. I did my first show in college, and before I even knew what I was doing, I was the opening act at the Warwick Musical Theater for acts like the Temptations and the Four Tops. After a year or so, I learned the unfortunate fact that stand-up just doesn’t pay the bills, so comedy sat on the back burner for a decade until an opportunity presented itself back in 2004. I wrote some new material, dusted off the microphone, bribed several of the judges, and the rest is history.
Do I have any good tech jokes? I have several that are extraordinarily funny, but I am obligated under IT bylaws to maintain a boring and humorless personality at all times, so I can’t share them with you. •












