0 évaluation0% ont trouvé ce document utile (0 vote)
8 vues37 pages
C)2003 prentice hall business publishing, accounting information systems, 9 / e, Romney / Steinbart 8-3 The Criteria Used To Evaluate Reliability Principles. Each of the four principles of reliability, three criteria are used to evaluate whether or not the principle has been achieved.
C)2003 prentice hall business publishing, accounting information systems, 9 / e, Romney / Steinbart 8-3 The Criteria Used To Evaluate Reliability Principles. Each of the four principles of reliability, three criteria are used to evaluate whether or not the principle has been achieved.
Droits d'auteur :
Attribution Non-Commercial (BY-NC)
Formats disponibles
Téléchargez comme PPT, PDF, TXT ou lisez en ligne sur Scribd
C)2003 prentice hall business publishing, accounting information systems, 9 / e, Romney / Steinbart 8-3 The Criteria Used To Evaluate Reliability Principles. Each of the four principles of reliability, three criteria are used to evaluate whether or not the principle has been achieved.
Droits d'auteur :
Attribution Non-Commercial (BY-NC)
Formats disponibles
Téléchargez comme PPT, PDF, TXT ou lisez en ligne sur Scribd
Accounting Information Systems, 9/e, Romney/Steinbart
8-3 The Criteria Used To Evaluate Reliability Principles or each of the four principles of reliability, three criteria are used to evaluate whether or not the principle has been achieved. 1. The entity has defined, documented, and communicated performance objectives, policies, and standards that achieve each of the four principles. 2. The entity uses procedures, people, software, data, and infrastructure to achieve each principle in accordance with established policies and standards. 3. The entity monitors the system and takes action to achieve compliance with the objectives, policies, and standards for each principle. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-4 Controls Related to More Than One Reliability Principle Strategic Planning & Budgeting Developing a Systems Reliability Plan Documentation 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-5 Controls Related to More Than One Reliability Principle Documentation may be classified into three basic categories: Administrative documentation: Describes the standards and procedures for data processing. Systems documentation: Describes each application system and its key processing functions. Operating documentation: Describes what is needed to run a program. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-6 Availability Availability Minimizing Systems Downtime Preventive maintenance UPS ault tolerance Disaster Recovery Plan Minimize the extent of disruption, damage, and loss Temporarily establish an alternative means of processing information Resume normal operations as soon as possible 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-7 Availability Disaster Recovery, continued Train and familiarize personnel with emergency operations Priorities for the recovery process nsurance Backup data and program files Electronic vaulting Grandfather-father-son concept Rollback procedures Specific assignments Backup computer and telecommunication facilities Periodic testing and revision Complete documentation 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-8 Developing a Security Plan Developing and continuously updating a comprehensive security plan is one of the most important controls a company can identify. What questions need to be asked? o needs access to wat information? en do they need it? On wic systems does the information reside? 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-9 Segregation of Duties Within the Systems unction n a highly integrated AS, procedures that used to be performed by separate individuals are combined. Any person who has unrestricted access to the computer, its programs, and live data could have the opportunity to both perpetrate and conceal fraud. To combat this threat, organizations must implement compensating control procedures. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-10 Segregation of Duties Within the Systems unction Authority and responsibility must be clearly divided among the following functions: 1. Systems administration 2. Network management 3. Security management 4. Change management 5. Users 6. Systems analysis 7. Programming 8. Computer operations 9. nformation system library 10. Data control 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-11 Segregation of Duties Within the Systems unction t is important that different people perform these functions. Allowing a person to perform two or more of them exposes the company to the possibility of fraud. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-12 Physical Access Controls How can physical access security be achieved? Place computer equipment in locked rooms and restrict access to authorized personnel Have only one or two entrances to the computer room Require proper employee D Require that visitors sign a log Use a security alarm system Restrict access to private secured telephone lines and terminals or PCs. nstall locks on PCs. Restrict access of off-line programs, data and equipment Locate hardware and other critical system components away from hazardous materials. nstall fire and smoke detectors and fire extinguishers that don not damage computer equipment 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-13 Logical Access Controls Users should be allowed access only to the data they are authorized to use and then only to perform specific authorized functions. What are some logical access controls? passwords physical possession identification biometric identification compatibility tests 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-14 Protection of PCs and Client/Server Networks Many of the policies and procedures for mainframe control are applicable to PCs and networks. The following controls are also important: Train users in PC-related control concepts. Restrict access by using locks and keys on PCs. Establish policies and procedures. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-15 Protection of PCs and Client/Server Networks Portable PCs should not be stored in cars. Keep sensitive data in the most secure environment possible. nstall software that automatically shuts down a terminal after its been idle for a certain amount of time. Back up hard disks regularly. Encrypt or password protect files. Build protective walls around operating systems. Ensure that PCs are booted up within a secure system. Use multilevel password controls to limit employee access to incompatible data. Use specialists to detect holes in the network. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-16 nternet and e-Commerce Controls Why caution should be exercised when conducting business on the nternet. the large and global base of people that depend on the nternet the variability in quality, compatibility, completeness, and stability of network products and services 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-17 nternet and e-Commerce Controls access of messages by others security flaws in Web sites attraction of hackers to the nternet What controls can be used to secure nternet activity? passwords encryption technology routing verification procedures 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-18 nternet and e-Commerce Controls Another control is installing a firewall, hardware and software that control communications between a company's internal network (trusted network) and an external network. The firewall is a barrier between the networks that does not allow information to flow into and out of the trusted network. Electronic envelopes can protect e-mail messages 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-19 Maintainability Two categories of controls help ensure the maintainability of a system: Project development and acquisition controls Change management controls 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-20 Project Development and Acquisition Controls Project development and acquisition controls include: Strategic Master Plan Project Controls Data Processing Schedule System Performance Measurements Postimplementation Review 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-21 Change Management Controls Change management controls include: Periodically review all systems for needed changes Require all requests to be submitted in standardized format Log and review requests form authorized users for changes and additions to systems Assess the impact of requested changes on system reliability objectives, policies and standards 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-22 Change Management Controls, continued Categorize and rank all changes using established priorities mplement procedures to handle urgent matters Communicate all changes to management Require T management to review, monitor, and approve all changes to software, hardware and personnel responsibilities Assign specific responsibilities to those involved in the change and monitor their work. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-23 Change Management Controls, continued Control system access rights to avoid unauthorized systems and data access Make sure all changes go through the appropriate steps Test all changes Make sure there is a plan for backing our of any changes in the event they don't work properly mplement a quality assurance function Update all documentation and procedures when change is implemented 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-24 ntegrity A company designs general controls to ensure that its overall computer system is stable and well managed. Application controls prevent, detect and correct errors in transactions as they flow through the various stages of a specific data processing program. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-25 ntegrity: Source Data Controls Companies must establish control procedures to ensure that all source documents are authorized, accurate , complete and properly accounted for, and entered into the system or sent ot their intended destination in a timely manner. Source data controls include: 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-26 ntegrity: Source Data Controls orms design Prenumbered forms sequence test Turnaround documents Cancellation and storage of documents Authorization and segregation of duties Visual scanning Check digit verification Key verification 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-27 ntegrity: nput Validation Routines nput validation routines are programs the check the integrity of input data. They include: Limit check Range check Reasonableness test Redundant data check Sequence check ield check Sign check Validity check Capacity check 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-28 ntegrity: On-line Data Entry Controls The goal of on-line data entry control is to ensure the integrity of transaction data entered from on-line terminals and PCs by minimizing errors and omissions. They include: 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-29 ntegrity: On-line Data Entry Controls ield, limit, range, reasonableness, sign, validity, redundant data checks User D numbers Compatibility tests Automatic entry of transaction data, where possible Prompting Preformatting Completeness check Closed-lop verification Transaction log Error messages Retain data for legal purposes 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-30 ntegrity: Data Processing and Storage Controls Controls to help preserve the integrity of data processing and stored data: Policies and procedures Data control function Reconciliation procedure External data reconciliation Exception reporting 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-31 ntegrity: Data Processing and Storage Controls, continued Data currency checks Default values Data matching ile labels Write protection mechanisms Database protection mechanisms Data conversion controls Data security 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-32 Output Controls The data control functions should review all output for reasonableness and proper format and should reconcile corresponding output and input control totals. Data control is also responsible for distributing computer output to the appropriate user departments. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-33 Output Controls Users are responsible for carefully reviewing the completeness and accuracy of all computer output that they receive. A shredder can be used to destroy highly confidential data. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-34 Data Transmission Controls To reduce the risk of data transmission failures, companies should monitor the network. How can data transmission errors be minimized? using data encryption (cryptography) implementing routing verification procedures adding parity using message acknowledgment techniques 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-35 Data Transmission Controls Data Transmission Controls take on added importance in organizations that utilize electronic data interchange (ED) or electronic funds transfer (ET). 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-36 Data Transmission Controls n these types of environments, sound internal control is achieved using the following control procedures: 1 Physical access to network facilities should be strictly controlled. 2 Electronic identification should be required for all authorized network terminals. 3 Strict logical access control procedures are essential, with passwords and dial-in phone numbers changed on a regular basis. 2003 Prentice Hall Business Publishing, Accounting Information Systems, 9/e, Romney/Steinbart 8-37 Data Transmission Controls Control procedures, continued 4 Encryption should be used to secure stored data as well as data being transmitted. 5 Details of all transactions should be recorded in a log that is periodically reviewed.