Chapter 2 Flashcards
(67 cards)
- What is data conversion in an IT environment?
The data conversion function transcribes transaction data from hard-copy source documents into computer input. For example, data conversion could involve keystroking sales orders into a sale order application in modern systems, or transcribing data into magnetic media (tape or disk) suitable for computer processing in legacy type systems.
- Why does the temperature in a computer room need to be controlled?
Computers function best in an airconditioned environment, and providing adequate air conditioning is often a requirement of the vendor’s warranty. Computers operate best in a temperature range of 70 to 75 degrees Fahrenheit and a relative humidity of 50 percent. Logic errors can occur in computer hardware when temperatures depart significantly from this optimal range. Also, the risk of circuit damage from static electricity is increased when humidity drops. In contrast, high humidity can cause molds to grow and paper products (such as source documents) to swell and jam equipment.
3-5 Primary IT services/ functions of a centralized data processing structure
- Database administration
- Data processing
- Systems development and maintenance
- The area of the IT department which provides safe storage of offline data files, original copies of commercial software and their licenses.
Data Library
7-9 Technically, who are considered system professionals?
analysts, database designers, and programmers who design and build the system
10 - 11 What are some problems encountered when a client utilizes systems programmers to perform program maintenance functions?
- Inadequate documentation
- Potential for program fraud
- Why is it difficult to hire qualified IT professionals in a DDP?
If the organizational unit into which a new employee is entering is small, the opportunity for personal growth, continuing education, and promotion may be limited.
13 - 15 Give three (3) potential problems arising from implementing DDP.
- Inefficient use of resources
- Destruction of audit trails
- Inadequate segregation of duties
- Difficulty in hiring qualified professionals
- Lack of standards
16 - 17 What does IT governance intend to achieve or what are its objectives?
- To reduce risk
- To ensure that investments in IT resources add value to the corporation
- What is a compensating control
in small organizations or in
functional areas that lack sufficient personnel, management must compensate for the absence of segregation controls with close supervision.
19-22 What are the services / functions of a corporate IT group formed for the purpose of controlling a DDP environment?
- Central Testing of Commercial Software and Hardware
- User Services
- Standard-setting Body
- Personnel Review
23 - 25 Give three (3) audit procedures to verify that the structure of the IT department provides for the segregation of incompatible functions in a CDP.
- Review relevant documentation, including the current organizational chart, mission statement, and job descriptions for key functions, to determine if individuals or groups are performing incompatible functions.
- Review systems documentation and maintenance records for a sample of applications. Verify that maintenance programmers assigned to specific projects are not also the original design programmers.
- Verify that computer operators do not have access to the operational details of a system’s internal logic. Systems documentation, such as systems flowcharts, logic flowcharts, and program code listings, should not be part of the operation’s docu-
mentation set. - Through observation, determine that segregation policy is being followed in practice. Review operations room access logs to determine whether programmers enter the facility for reasons other than system failures.
26 - 28 What IT functions should be segregated? (Give at least 2 incompatible functions in each number)
- Separating Systems Development from Computer Operations
- Separating Database Administration from Other Functions
- Separating New Systems Development from Maintenance
29 - 30 Give some advantages of adapting DDP.
- Cost reductions
- Improved Cost Control Responsibility
- Improved User Satisfaction
- Backup flexibility
- Give the meaning of RAID.
Redundant arrays of independent disks
32 - 35 Give one audit procedure to test the compliance of our client to standards on the computer center on: (what documents to check (reasons why) what items to look for) #s
- physical construction
- RAID
- Access control
- Insurance coverage
What do accountants examine during their annual audit of the computer center?
Accountants routinely examine the physical environment of the computer center as part of their annual audit.
What is the objective of assessing the computer center?
The objective is to present computer center risks and the controls that help to mitigate risk and create a secure environment.
What factors should be considered regarding the physical location of a computer center?
The computer center should be away from human-made and natural hazards, such as processing plants, water mains, airports, high-crime areas, flood plains, and geological faults.
What is the ideal construction for a computer center?
A computer center should ideally be located in a single-story building of solid construction with controlled access.