IT Flashcards
(285 cards)
Elements of Accounting Systems
- People
- Procedures
- Hardware
- Software
- Data
Risks in Computer-Based Systems
Systems, programs and people (FUNI) •Reliance on FAULTY systems or programs •UNAUTHORIZED changes in master files, systems, or programs •Failure to make NEEDED changes •Inappropriate INTERVENTION (by people)
COBIT purpose
Align IT and business goals/strategies
Link business risks, control needs and IT
Common language for users, auditors, management, and business process owners in identifying risks and structuring controls.
Determine how much to invest in IT control
COBIT Framework Defined
To provide the information that the organization needs to achieve its objectives, IT resources needed to be managed by a set of naturally grouped processes.
Process orientation to exercise responsibilities, achieve goals and manage risks.
CIRCLE (a) IT processes (b) Business requirements (c) IT resources
COBIT Information Attributes
- Effective
- Efficient
- Confidential
- Integrity
- Available
- Compliant
- Reliable
COBIT and COSO
Both concerned with monitoring of organizational processes
FOCUS:
•COSO: organizational control and processes
•COBIT: IT controls and processes
According to the COBIT model, identify 5 physical resources that, together, comprise an IT system
- People
- Applications
- Technology
- Facilities
- Data
According to the COBIT model, what are the four IT domains?
- Planning and organization
- Acquisition and implementation
•the process of identifying automated solutions. - Delivery and support
•the process of ensuring security and continuous service. - Monitoring
What are the three major components of the COBIT model?
- Domains and processes
- Information criteria
- IT resources
ERP Goals
- Integration (goal visibility): Integrate all data into 1 data base with user-Defined views
- Cost Savings: decrease system maintenance costs (only one system to maintain)
- Employee Empowerment: Improves Communication and decision making by increasing information availability
- “Best Practices”: include most successful business processes of an industry.
Enterprise Architecture Defined
An organizations enterprise architecture is its efforts to understand, manage, and plan for IT assets. An organizations IT security governance plan must articulate with, and be informed by, the organizations enterprise architecture plan.
Enterprise-Wide or Enterprise Resource Planning (ERP) Systems Defined
ERPS provide transaction processing, management support, and decision-making support in a single, integrated, organization-wide package. By integrating all data and processes of an organization into a unified system, ERPs attempt to manage and eliminate the organizational problem of consolidating information across departments, regions, or divisions.
Online Transaction Processing (OLTP) System
The modules comprising the core business functions: sales, production, purchasing, payroll, financial reporting, etc. These functions collect the operational day for the organization and provide the fundamental motivation for the purchase of an ERP.
Online analytical Processing (OLAP) System
Incorporates data warehouse and data mining capabilities within the ERP.
*provides an integrated view of transactions in all parts of the system.
•primarily concerned with collecting data (not analyzing it) across the organization.
PaaS Defined
The use of the cloud to CREATE (not access) software.
SaaS Defined
The use of the cloud to ACCESS software.
Three important functions (segregate) of IT department rolls
- Application Development: SAFEGUARD ASSETS (applications in development)
- Systems Administration and Programming: Grant AUTHORIZATION (access)
- Computer Operations: EXECUTE events, safeguard archived IP
Segregation of Duties: Data Control (Clerk)
Control document flows, schedule batches for data entry and editing, reconcile control totals (reconciling + authorizing function)
Segregation of Duties: Computer Operators
Operate the (mainframe) computer, load program and data files, run programs (execute transactions)
Segregation of Duties: File Librarian
Maintain files and data that are not online in file library, check files in and out to support scheduled jobs. Should not have access to operating equipment or data outside of library.
Inadequate Scope and Agility
IT investments in business units, inadequately scaled to meet changing business needs
Digitization Defined
Moving data to electronic form.
Governance Defined
The processes and structures, to oversee the activities of the organization in pursuit of organizational objectives.
Oversight Defined
Process of managing and monitoring an organizations operations to achieve internal control and effectively manage risk.