Accounting Information Systems Controls and Processes, 1st Edition BY Turner, Weickgenannt
Chapter 1 - Introduction To AIS Instructors Manual ➢ Introduction To Business Processes. A business process is a prescribed sequence of work steps performed in order to produce a desired result for the organization. In accounting information system, business processes can be categorized into four types: revenue (or sales) processes; expenditure processes; conversion processes; and administrative processes. Employees, work steps, and transaction recording systems must be established to insure that business processes occur, and the accounting effects of these processes are captured and recorded. ➢ The Accounting Information System. The accounting information system is the set of processes, procedures, and systems that capture, record, process, summarize, and report accounting information. There are five important components to an accounting information system. 1. Work steps to capture accounting data as transactions occur 2. Recording of accounting data in manual or computerized records 3. Work steps that are internal controls to prevent or detect errors and fraud 4. Work steps to process, classify, summarize, and consolidate raw accounting data 5. Work steps that generate internal and external reports from the processed accounting data ➢ Business Processes Throughout The Supply Chain. A business has many linkages with external suppliers, distributors, and customers. These linkages are called the supply chain. A business should monitor and control the entire set of processes throughout the supply chain to improve efficiency. IT enablement of these processes can lead to improved efficiency. ➢ IT Enablement Of Business Processes And The AIS. IT Enablement is the application of information technology to accomplish any or all of the following three: improve the efficiency of business processes, reduce cost of business processes, or increase the accuracy of data from business processes. Often the IT enablement is accompanied by Business Process Reengineering (BPR), which is the redesign of business processes to make them more efficient. BPR should leverage the capabilities of IT to improve business processes. IT Capabilities should support the business process, and the business process should be designed to match the capabilities of the IT system. ➢ Basic Computer And IT Concepts o Basic Computer Data Structures. A computer data hierarchy is bit, byte, field, record, file, database. A relational database stores data in tables joined in ways that can represent many different relationships among the data. A master file is the set of relatively permanent records for major processes. A transaction file is the set of relatively temporary records that will be processed to update the master file.
1
o File Access And Processing Modes. Files may be stored in sequential access, random access, or index sequential access method. How files are stored ad processed is inter-related. Processing can be accomplished via batch processing, online processing, or online, real-time processing. o Data Warehouse And Data Mining. A data warehouse is an integrated collection of enterprise-wide data that includes five to ten years of nonvolatile data. Data mining is used to search and analyze the dat6a warehouse for identifiable patterns that can be used to predict future behavior. o Networks And The Internet. A network is two or more computers linked together to share information or resources. A LAN is a local area network, a WAN is a wide area network. The Internet is the global network often described as the World Wide Web. An intranet is a private network within the company accessible only by employees. An extranet is an network accessible only to internal employees and external members of the supply chain, but not the entire public. ➢ Examples Of IT Enablement. The following are examples of using IT systems to improve business processes. o E-Business. E-business encompasses all forms of online electronic trading – consumer-based e-commerce and business-to-business electronic trading and business-to-business process integration, as well as the internal use of IT and related technologies for process integration inside organizations. IT systems, Internet, and websites, as well as wireless networks, are the common means of enabling e-business to occur. o Electronic Data Interchange. EDI is the inter company, computer-tocomputer transfer of business documents in a standard business format. EDI is used to transmit purchase orders, invoices, and payments electronically between trading partners. o Point Of Sale Systems. A point of sale system (POS) is a system of hardware and software that captures retail sales transactions by standard bar coding. These processes occur in real time, and through POS-captured data the store can provide to its managers or home office daily summaries of sales by cash register or by product. o Automated Matching. Automated matching is a computer hardware and software system in which the software matches an invoice to its related purchase order and receiving report. The system can access the online purchase order and receiving files and verify that the items, quantities, and prices match. The system will not approve an invoice for payment unless the items and quantities match with the packing slip and the prices match the purchase order prices. o Evaluated Receipt Settlement. Evaluated receipt settlement (ERS) is an invoice-less system in which computer hardware and software complete an invoice-less match that is a comparison of the purchase order with the goods received. The name ERS signifies that the receipt of goods is carefully evaluated and, if it matches the purchase order, settlement of the obligation occurs through this system.
2
o E-Payables And Electronic Invoice Presentment And Payment. Epayables and electronic invoice presentment and payment (EIPP) are both terms that refer to Web-enabled receipt and payment of vendor invoices. EIPP enables a vendor to present an invoice to its trading partner via the Internet, eliminating the paper, printing, and postage costs of traditional paper invoicing. o Enterprise Resource Planning Systems. Enterprise resource planning (ERP) is a multi-module software system designed to manage all aspects of an enterprise. ERP systems are usually broken down into modules such as financials, sales, purchasing, inventory management, manufacturing, and human resources. The modules are designed to work seamlessly with the rest of the system and to provide a consistent user interface between modules. ➢ The Control Environment Of Organizations. Managers can undertake steps to lessen the risks faced by the organization. This ability to lessen risks or risk impacts is true of nearly all risks that organizations face. Management can undertake steps to lessen the risk or reduce the impact of the risk. These processes are called controls. Accountants have a long history of being the professionals within the organization who help design and implement controls to lessen risks that have an impact on the financial standing of the organization. o Enterprise Risk Management. Enterprise Risk Management (ERM) is defined as a process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives. o A Code Of Ethics. A company should develop and adhere to a code of ethics to reduce opportunities for managers or employees to conduct fraud. A code of ethics is most effective if top management emphasizes this code of ethics and disciplines or discharges those who violate it. Managers who emphasize and model ethical behavior are more likely to encourage ethical behavior in their employees. o COSO Accounting Internal Control Structure. COSO identifies five interrelated components of internal control: the control environment, risk assessment, control activities, information and communication, and monitoring. o IT Controls. IT controls can be divided into two categories, general controls and application controls. General controls apply overall to the IT accounting system; they are not restricted to any particular accounting application. An example of a general control is the use of passwords to allow only authorized users to log into an IT- based accounting system. Without regard to processing data in any specific application, passwords should be employed in the IT system. Application controls are used specifically in accounting applications to control inputs, processing, and output. o Corporate Governance. Corporate governance is an elaborate system of checks and balances whereby a company’s leadership is held accountable for
3
building shareholder value and creating confidence in the financial reporting processes. This system of checks and balances includes several corporate functions that are interrelated within the corporate governance system. These functions include management oversight, internal controls and compliance, financial stewardship, and ethical conduct. o IT Governance. IT governance is a structure of relationships and processes to direct and control the enterprise in order to achieve the enterprise’s goals by adding value while balancing risk versus return over IT and its processes. IT governance provides the structure that links IT processes, IT resources and information to enterprise strategies and objectives. ➢ The Accountant’s Role In AIS. All career paths within accounting will in some manner involve the use of an accounting information system. Accountants have several possible roles related to accounting information systems: They may be users of the AIS, part of the design or implementation team of an AIS, and/or auditors of an AIS. o Users Of The AIS. Accountants within any organization must use the accounting information system to accomplish the functions of accounting, generating accounting reports, and using accounting reports. Accountants must therefore understand AIS concepts in order to perform these accounting jobs. o Design And Implementation Teams. Accountants are usually part of a multiple-discipline team that designs and/or implements accounting information systems. When an organization considers a change to its AIS, accountants must be involved in decisions related to such matters as evaluating which software to purchase, how to design software or systems, and the implementation of software or systems. o An Auditor Of The AIS. Auditors conduct assurance services such as a financial audit. To conduct an audit, the auditor must collect evidence and make judgments regarding the completeness and accuracy of accounting information. The auditor cannot make informed decisions necessary to complete the audit without an understanding of the accounting information system. ➢ Ethics And The AIS. Accounting information systems can be misused to assist in committing unethical acts or helping to hide unethical acts. That is, the AIS is often the tool used to commit or cover up unethical behavior. Examples of some potential unethical behaviors are: fraudulent financial reporting; revenue inflation; expense account fraud; inflating hours worked for payroll purposes; computer fraud; hacking; browsing confidential data.
4
Chapter 2 - Foundational Concepts Of The AIS Instructors Manual ➢ Interrelationship Of Business Processes And The AIS. Business processes occur so that organizations may serve its customers. As the many business processes occur, all of the data generated must be collected and processed by the accounting information system. The accounting information system collects detailed information from these business processes. In manual systems, this collection is through the use of source documents, special journals, and subsidiary ledgers. As this detailed information is processed, it is summarized in the general ledger accounts. Whether the system is manual or computerized, it must collect the data from business processes, summarize and process this data, and provide outputs. ➢ Types Of Accounting Information Systems. o Manual Systems are those systems that use manual record keeping processes and paper-based records. Usually, that includes only very small organizations. These manual systems use paper-based documents such as source documents, turnaround documents, general ledger, general journal, special journals, subsidiary ledgers, and employees follow certain processes to record transactions in the documents. Even in a computerized system, some of these manual steps may still occur. For example, a human may write information on a source document before it is entered into an IT system. o Legacy Systems. Legacy systems are older IT systems that may have been in place within the organization for many years. These are usually systems based on mainframe host computers and older technology. They were written in computer languages such as COBOL or Basic. In 2002, an estimate indicated that at least 80% of organizations had legacy systems. There are both advantages and disadvantages to legacy systems. When the benefits of newer systems outweigh the advantages of the legacy systems, many companies replace the legacy systems with newer technology. As an alternative to replacing legacy systems, some organizations may just enhance them. Two methods of enhancing legacy systems are screen scrapers and enterprise application integration. o Modern, Integrated Systems. These systems are based on current technology and fall into three categories. These systems are purchased software, rather than software developed internally. Purchased software has the advantages of lower costs, fewer bugs, and a shorter implementation time. ➢ Accounting Software Market Segments. Accounting software can be categorized according to the type of enterprise is its intended market. The four categories of accounting software types are small companies, midmarket companies, beginning ERP, and high end or tier 1 ERP. Small company accounting software is intended for companies with revenue of approximately $250,000 or less. Midmarket accounting software is targeted to companies with revenue between $250,000 and
1
$10 million. Beginning ERP is intended for companies with revenue between $10 and $100 million. Tier 1 ERP systems are targeted to companies with revenue in excess of $100 million. Software companies are consistently trying to expand the market they serve and this leads to software vendors trying to serve the category above or below them. Thus, a single software system might be targeted to companies slightly larger or smaller than the original, intended market. ➢ Input Methods For AIS. Almost all business processes generate some type of accounting data. There are many different types of processes, and many different ways to capture the data from these processes. o Source Documents And Keying. Transaction data is often captured on pre-printed, sequentially numbered source documents. From this source document, the data is keyed (typed in) into an IT system. This process is time consuming and error prone. Many companies have replaced this source document and keying approach with newer technology. o Bar Codes. Bar codes are symbols on product packaging. You see these bar codes on products you buy at department stores. Bar codes can be used with a bar code reader to input inventory movement and employee time. o Point Of Sale Systems. The most well-known use of bar codes is in Point of Sale Systems. The Universal Product Code on products is read by a bar code scanner at the cash register. Many retail establishments use point of sale systems. o Electronic Data Interchange. The intercompany, computer-to-computer transfer of business documents in a standard format. EDI permits the electronic transmission of purchase orders, invoices, and payments between trading partners. o E-Business And E-Commerce. E-business includes all forms of online electronic business transactions and processing, whereas, e-commerce is online buying and selling by consumers. When data is exchanged electronically, much of the manual processing is eliminated, thereby reducing time, cost, and errors. ➢ Processing Methods o Batch Processing. In batch processing, all similar transactions within a specified time are grouped together and processed as a batch. This method is efficient for large volumes of like transactions; it has a better audit trail and is easier to control, the hardware and software systems can be cheaper and simpler, and personnel become specialized. However, data duplication is likely; it is not well suited to changes in only a few records; maintenance of files can be more time consuming; integration across the enterprise is more difficult; and there is an inherent time lag. o Online And Real Time Processing. Each transaction is entered and processed as it occurs, in real-time. This eliminates the time lag inherent in batch systems; input errors can be checked as data is entered; files are updated in real-time, and integration of business processes is easier. However, the hardware and software is more expensive and complex; there may be more susceptibility to unauthorized access; ad they are more difficult to audit.
2
➢ Outputs Of The AIS. There are many kinds of outputs and only a few are described here. Some outputs are documents exchanged with trading partners such as invoices, statements, or purchase orders. Some are internal documents such as credit memorandums. Some outputs are in the form of reports for either internal or external users. These could include financial statements or aged receivables reports. Internal reports might be printed, viewed on a screen, or customizable queries. ➢ Documenting Systems. A picture of a system in the form of a chart or map is a concise, complete, and easy-to-understand way to view a process or system. o Process Maps. It is a pictorial representation of a business process using five symbols. It shows the steps and sequence of a business process and may show flow through individual departments. o System Flowcharts. It shows inputs, computerized processing, and outputs of a computer system. It displays the sequence of processes and the media used in processing and storage. It uses standard flowchart symbols. o Document Flowcharts. It also uses standard flowchart symbols, but shows only the flow of documents among or between departments or units. They are useful in understanding document flow and some aspects of internal controls. o Data Flow Diagrams. It shows the logical design of a system using four symbols. They re used by system professionals in structured design to show successive exploded levels of detail. o Entity Relationship Diagrams. It is a pictorial representation of the logical structure of a database. It shows the entities, the attributes of those entities, and the cardinality, or the relationships between entities. ➢ Client-Server Computing. In a client-server system, two types of computers are networked together to accomplish processing. Client computers are “smart” terminals that can share some of the processing tasks. The server manages ad stores the large database and runs complex application programs. Tasks are assigned to either the client or server on the basis of which can handle the task most efficiently. In distributed presentation, the client manipulates data for presentation, but does not do any other significant processing. In distributed applications, the client PC does participate in processing beyond presentation of data. Many ERP systems use a web browser and individual PCs as the client computers. ➢ Ethical Considerations At The Foundation Of AIS. An AIS can be used as a tool to conduct or cover up fraud or theft. If the IT systems are not closely monitored, these frauds could go undetected for long periods. As companies choose and implement IT systems, they must consider the ability to monitor these systems for fraud or unethical behavior. ➢ Appendix A: Resources, Events, Agents In AIS. The REA model views accounting systems as data about resources, events, and agents. Resources are assets such as cash or inventory. Events are the business processes, and agents are parties such as the customer or vendor. REA is used as a model to understand accounting systems, but as of yet is limited in the practical application.
3
Chapter 3 - Ethics, Fraud, And Internal Control Instructors Manual ➢ Introduction To The Need For A Code Of Ethics And Internal Controls. If the top management of a company emphasizes ethical behavior, models ethical behavior, and hires ethical employees, the chance of fraud or ethical lapses can be reduced. In addition to acting ethically, the management of any organization has an obligation to maintain a set of processes and procedures that assure accurate and complete records and protection of assets. Management has a stewardship responsibility, which is the careful and responsible oversight and use of the assets entrusted to management. The stewardship and reporting obligations point to need to maintain accurate and complete accounting systems and to protect assets. To fulfill these obligations, management must maintain internal controls and enforce a code of ethics. ➢ Accounting Related Fraud. Fraud is the theft, concealment and conversion to personal gain of another's money, physical assets, or information. There is a distinction between misappropriation of assets and misstatement of financial records. Misappropriation of assets involves theft of any item of value. Misstatement of financial records involves the falsification of accounting reports. For fraud to occur, three conditions must exist: incentive to commit the fraud, opportunity to commit the fraud, and rationalization of the fraudulent action. This is called the fraud triangle. Understanding the nature of fraud helps accounts create effective systems to prevent or detect fraud. o Categories Of Accounting Fraud. The four categories of fraud are management fraud, employee fraud, customer fraud, and vendor fraud. o The Nature Of Management Fraud. It is conducted by one or more top-level managers within the company, and it usually is misstating financial statements through elaborate schemes or complex transactions. The incentive for managers can include to increase incentive pay, or stock price, opportunities for promotion, or the delay of cash flow or bankruptcy problems. Some fraud involves circumventing internal controls, or management override. o The Nature Of Employee Fraud. It is usually the theft of assets, or the theft of cash through false or fraudulent documentation. An example would be a false or inflated time card. Cash receipts theft is the most common type of employee fraud. It is often pulled off through a technique known as skimming, where the organization’s cash is stolen before it is entered into the accounting records. Larceny is stealing the company’s cash after it has been recorded in the accounting records. Collusion means that two or more people work together to commit a fraud. Collusion is the most difficult to prevent or detect because it compromises the effectiveness of internal controls o The Nature Of Customer Fraud. Customer fraud occurs when a customer improperly obtains cash or property from a company, or avoids a liability
1
through deception. Although customer fraud may affect any company, it is an especially common problem for retail firms and companies that sell goods through internet-based commerce. Examples of customer fraud include credit card fraud, check fraud, and refund fraud. o The Nature Of Vendor Fraud. Vendor fraud occurs when vendors obtain payments to which they are not entitled. Unethical vendors may accomplish this by submitting duplicate or incorrect invoices, intentionally sending shipments in which the quantities are short, or sending lower quality goods than ordered. Vendor fraud may also be perpetrated through collusion. For example, an employee of a company could make an agreement with a vendor to continue the vendor relationship in the future if the employee receives a kickback. Vendor audits involve the reviewing supporting documentation for these labor or other expenses incurred by its vendor. This could reveal whether or not the vendor is honest in reporting expenses. o The Nature Of Computer Fraud. The computer system can be used as a tool to commit fraud. A computer fraud can be conducted by someone internal, or external to the company. Internal fraud can be conducted by input manipulation, program manipulation, or output manipulation. Input manipulation is altering or falsifying data that is input into the system. Program manipulation is the alteration of a program to commit a fraud. Some methods of program manipulation are the salami technique, Trojan Horse, and trap door alteration. Altering reports or outputs such as checks would be output manipulation. An outsider who gains unauthorized access is an external source of fraud. Three popular kinds are hacking, denial of service (DoS) attacks, and spoofing. A hacker breaks in to steal, alter, or browse data or programs. A DoS attack is intended to shut down the computer system. Spoofing occurs when an unauthorized user pretends to be an authorized user. ➢ Policies To Assist In The Avoidance Of Fraud And Errors. There are three main policies an organization can undertake to help prevent or detect fraud. The three are: maintain and enforce a code of ethics, maintain a system of accounting internal controls, and maintain a system of IT controls. ➢ Maintain A Code Of Ethics. While it has always been a good idea to have and enforce a corporate code of ethics, the Sarbanes-Oxley act of 2002 requires publicly traded companies to maintain one. To be of effect, the code should be adhered to by top management and enforced throughout the company. ➢ Maintain A System Of Internal Controls. Internal controls have four objectives: (1) safeguard assets, (2) maintain accuracy and integrity of data, (3) promote operational efficiency, and (4) ensure compliance with management directives. The internal control system to meet these objectives should have preventive controls, detective controls, and corrective controls. However, no internal control system can prevent or detect all errors or fraud. Human error, human nature, and cost considerations limit the ability of internal controls to detect or prevent all fraud and errors. o The Details Of The COSO Report. The COSO report has become the standard definition and description of internal control. It identifies five
2
interrelated components: the control environment; risk assessment; control activities; information and communication; and monitoring. The control environment sets the tone of an organization and influences the control consciousness of its employees. The factors that are part of the control environment are: the integrity, ethical values, and competence of the people; management’s philosophy and operating style; the way management assigns authority and responsibility; the way management organizes and develops its people; the attention and direction provided by the board of directors. Each of these factors influence whether an organization has a more risky environment, or a less risky environment. Risk assessment is the continual monitoring of the risks from external and internal sources. In order for management to maintain control over threats to its business, it must constantly be engaged in risk assessment. It is important that management develop a systematic and ongoing way to: Identify the sources of risks, both internal and external; Determine the impact of such risks in terms of finances and reputation; Estimate the chance of such risks occurring; Develop an action plan to reduce the impact or probability of these risks; Execute the action plan and continue the cycle beginning again with the first step above. Control activities as the policies and procedures that help ensure that management directives are carried out and that management objectives are achieved. A good internal control system must include control activities that occur at all levels and in all functions within the company. The control activities include a range of activities that can be divided into the following categories: Authorization of transactions; Segregation of duties; Adequate records and documents; Security of assets and documents; Independent checks and reconciliation. Authorization can be general authorization, or specific authorization. Segregation of duties means that for any given business process, no single person or department should authorize, record, and have custody of the assets. Supervision is a compensating control when segregation cannot be fully achieved. Adequate records and documents means that there must be an audit trail as verifiable information about the accuracy of the accounting records. Security of assets and documents includes physical controls to limit access to assets, and policies and practices to limit who has access to assets. Independent checks and reconciliations are procedures to verify the accuracy and completeness of accounting information. Information and communication is a set of systems and processes that ensuring formation flows down, across, and up the organization. It includes the accounting system and the reports that result from it. It also includes the procedures to disseminate reports and information throughout the enterprise.
3
Monitoring is the ongoing review and evaluation of the system. This includes both continuous and periodic monitoring of the accounting system and controls. Continuous review of reports and information by managers and periodic audits are part of monitoring. o Reasonable Assurance Of Internal Controls. The whole set of internal control must be established and monitored with the idea of reasonable assurance in mind. Reasonable assurance means that the controls achieve a sensible balance of reducing risk when compared to the cost of the control. ➢ Maintain A System Of Information Technology Of Controls. Information technology increases the efficiency and effectiveness of organizations that use them, but at the same time, it increases vulnerability. The risks include unauthorized access, hackers, business interruption, and data inaccuracies. These extra risks of computer systems call attention to the need for internal controls over and above those described in the COSO report. One way to organize these risks and controls is the Trust Services Principles. These principles divide IT risks and controls into five categories: security; availability, processing integrity; online privacy; and confidentiality. Security risk is the unauthorized physical or logical access to the IT system. Availability risk is the risk of hardware or software failure. Processing integrity risk is the risk of inaccurate, incomplete, or improperly authorized information entering the IT system. Online privacy risk is that personal information about customers will be accessed in an unauthorized manner. Confidentiality risk is the risk that sensitive information about the company or its business partners may be subject to unauthorized access. IT controls can be designed and implemented to limit risks in each of these five categories. ➢ Appendix A: Recent History Of Internal Control Standards. The 1977 Foreign Corrupt Practices Act (FCPA) included a requirement that corporations that sell stock in an SEC regulated stock exchange maintain a system of internal controls. In 1988 the AICPA issued SAS 55 which further emphasized management’s obligation to maintain internal controls. In 1992, the COSO report was issued by the Committee of Sponsoring Organizations (COSO). This report details the findings of a comprehensive study of internal control and is recognized within the accounting industry as the definition and description of internal control. Since that time, the AICPA has rewritten SAS guidelines to incorporate COSO concepts. SAS 55 was replaced by SAS 78 in 1994, and in 2002 SAS 78 was amended by SAS 94. This current internal control guide in SAS 94 maintains the COSO internal control concepts. In addition, SAS 99 expands the auditor’s duties with regard to internal control and fraud. The Sarbanes-Oxley Act of 2002 attempted to curb the fraud and stock market abuses of the previous two years. Section 302 of this bill designates management (specifically, the chief executive officer, chief financial officer and others performing similar functions) of the company as having responsibility for the establishment and maintenance of an effective system of internal controls. Section 404 of the Sarbanes-Oxley Act requires companies to include an internal control report within its annual report to stockholders. Thus, not only is the establishment
4
and operation of an internal control system a good practice, it has become mandatory for publicly traded companies. ➢ Appendix B: Control Objectives For Information Technology (COBIT). The COBIT framework is a comprehensive description of the risks and controls in IT environments. The framework establishes what COBIT terms four domains of “High Level Control Objectives”. The domains are: Planning and organization; Acquisition and implementation; Delivery and support; Monitoring. For each domain, controls over processes can be categorized as to the information criteria that apply to the process and the IT resources managed by the process. COBIT defines information criteria as effectiveness, efficiency, confidentiality, integrity, availability, compliance, and reliability. COBIT defines IT resources as people, application systems, technology, facilities, and data.
5
Chapter 4 - Internal Controls In IT Systems Instructor Manual ➢ Introduction To Internal Controls For IT Systems. It is important to consider possible threats that can disrupt or stop IT systems, and to implement controls that can help prevent these threats. It is important to understand general and application controls, the nature of risks in IT systems, and how these controls can reduce the risks. The AICPA Trust Services Principles is a structure to help organize these risks and controls. Controls can also be categorized into general controls and application controls. General controls apply to the overall IT accounting system. Application controls are input, processing, and output controls within IT applications. ➢ General Controls In IT Systems o Authentication Of Users And Limiting Unauthorized Users. Authentication is intended to ensure that users trying to access the IT system are valid, authorized users. There are many ways to authenticate users, including log-in procedures using a user ID and password, smart cards, security tokens, and biometric devices. User ID and password combinations are authentication based on what as person knows. Two factor authentication is based on what a user knows and what he has. Examples are smart cards and security tokens. Biometric authentication uses unique physical characteristics of a person such as a finger print. Even with these controls, an unauthorized user may be able to get access to the system. Thus, additional controls are needed such as a computer log, and a user profile in an authority table that determines each user’s access level. o Hacking And Other Network Break-Ins. The more extensive the network system, the more openings there are for hackers and unauthorized users. A firewall is hardware, software, or a combination of both that blocks instances of unauthorized network traffic. The firewall examines network packets of data and tries ton allow authorized data to flow through, yet block unauthorized packets of data. Encryption of data, either through symmetric or public key encryption converts data into cipher text that is not readable unless the user has the correct key. Wireless networks should be encrypted through either Wired Equivalency Privacy (WEP) or Wireless Protected Access (WPA). The Service Set Identifier (SSID) of a wireless network should be unique. Other methods to protect network traffic are virtual private network (VPN) and secure sockets layer (SSL). Other methods to increase authentication control are antivirus software, vulnerability assessment, intrusion detection, and penetration testing. These methods help monitor and prevent unauthorized access. o Organizational Structure. The manner in which a company establishes, delegates, and monitors IT system functions is part of the general controls. For companies with extensive IT systems, this would include at IT governance committee of top executives. The IT governance committee should: (1) align IT strategy with business strategy; (2) budget funds and personnel for IT; (3) develop, monitor; and review all IT policies; and (5) develop, monitor, and review security policies. It is also important that IT duties be properly segregated.
1
Systems analysts and programmers, operators, and database administrator duties should be segregated. As major changes are made to an IT system, the changes should follow a process that controls the initiation, approval, development, and maintenance of IT systems. Often, the process followed is a System Development Life Cycle (SDLC). o Physical Environment And Security. An IT system should have controls over the physical environment and physical access controls to the IT system. Physical access controls are intended to prevent malicious acts or vandalism to the system. The physical environment, such as temperature and humidity should be controlled to prevent system problems. There should also be dust and fire prevention systems. Uninteruptble power supplies and emergency power supplies can keep the system operating in the event of power failures. Physical access controls include: (1) ID badges or key cards to limit access, (2) video surveillance equipment, (3) logs of those entering the area, and (4) locked storage of data storage. o Business Continuity. Business continuity planning is a proactive program to consider risks to business continuation and developing plans to limit those risks. The business continuity plan should include a strategy for backup and restoration of IT systems, and a disaster recovery plan. The system can use redundant servers and redundant arrays of independent disks (RAID) to guard against system failure. There should also be regular backups of data and an off-site storage of backups. A disaster recovery plan includes the plan of steps necessary to continue IT operations after a disaster, ➢ General Controls From An AICPA Trust Principles Perspective. The AICPA Trust Services Principles are a framework that categorizes risks and controls into five categories: (1) security, (2) availability, (3) processing integrity, (4) online privacy, and (5) confidentiality. o Risks In Not Limiting Unauthorized Users. There are eight IT controls that can lessen the risk of unauthorized users gaining access to the IT system. Those eight are: user ID, password, security token, biometric devices, log-in procedures, access levels, computer logs, and authority tables. Without such controls, there are security risks, availability risks, processing integrity risks, and confidentiality risks. Security risks are from external persons, as well as employees of the organization who may try to access data for which they do not need access. Unauthorized access to the IT system can allow persons to browse through data, alter data in an unauthorized manner, destroy data, copy the data with the intent to steal and perhaps sell to competitors, or record unauthorized transactions. Availability risks result when a person gains unauthorized access, and may allow him to tamper with the IT system in a manner that may shut down systems and or programs to make the system or program temporarily unavailable for its intended use. If unauthorized users are able to access the IT system, they pose processing integrity risks in that they may be able to alter data to change the results of processing. This alteration of data could occur prior to the transaction being processed, during processing, or after the processing is complete. Confidentiality risks, or the risk of confidential data being available to unauthorized users, can occur if authentication controls
2
are weak. An unauthorized user who gains access can browse, steal, or destroy confidential data. o Risks From Hacking Or Other Network Break-Ins. Whether the threat is from an insider or outsider, efforts should be made to reduce the threat of hacking or network break-ins and to limit the potential harm that can be done by hacking and break-ins. The security risks related to hacking and network break-ins are the same as those identified in the previous section on unauthorized users. The availability risks are that the network break-in can allow systems or programs to be shut down, altered or sabotaged. The person who breaks in may also plant a virus or worm into the system. The processing integrity risks are that the person breaking in can alter the data or programs to compromise the accuracy or completeness of the data. Recording nonexistent or unauthorized transactions will also compromise data accuracy or completeness, as could a virus or worm. Again there is a confidentiality risk since the person breaking in may access, browse, steal or change confidential data. o Risks From Environmental Factors. Any environmental changes that affect the IT system can cause availability risks and processing integrity risks. These risks are that systems can be shut down or errors and glitches in processing can occur that cause lost or corrupted data. Backup power supply systems allow IT systems to be gradually shut down without the loss or corruption of data o Physical Access Risks. The security risk is that an intruder who gains physical access may change user access levels so that he or she can later access data or systems through any network attached system. The availability risks are that unauthorized physical access would allow an intruder to physically shut down, sabotage, destroy hardware or software, or insert viruses or worms from diskette, CD or other media. An intruder may interrupt processing and thereby affect the accuracy or completeness of processing, causing processing integrity risks. Viruses and worms can also affect the accuracy and completeness of processing. An intruder poses confidentiality risks in that an intruder may be able to gain access to confidential data to browse, alter, or steal the data. o Business Continuity Risks. The security risk is that an unauthorized person may gain access to the backup data. The availability risk is that as disasters or events interrupt operations, the system becomes unavailable for regular processing. The processing integrity risk is that business interruptions can lead to incomplete or inaccurate data. The confidentiality risk is that unauthorized persons may gain access to confidential data if they are able to gain access to backup data. ➢ Hardware And Software Exposures In IT Systems. There are many possible configurations of hardware and software that could be used in organizations. This section describes some typical hardware and software systems and the corresponding risks and controls. o The Operating System. The operating system is the software that controls the basic input and output activities of the computer. The operating system can be an “entry point” for unauthorized users or hackers. Operating system access allows a user access to all the important aspects of the IT system. Since all application software and database software works through the operating system,
3
o
o
o
o
o
o
access to the operating system also allows access to applications and the database. In addition, all read/write data functions are controlled by the operating system and any person who has access to the operating system can have access to data. Essentially, access to the operating system opens access to any data or program in the IT system. If a knowledgeable person is able to access and manipulate the operating system, that person potentially has access to all data passing through the operating system, and all processes or programs. Thus the operating system poses security risks, availability risks, processing integrity risks, and confidentiality risks. The Database. The database is an exposure area because any unauthorized access to the data can compromise the security and confidentiality of the data, and potentially interfere with the availability and normal processing of the IT system. An unauthorized user who gains access to the data base can browse through the data, compromising the security and confidentiality of the data in the database. The unauthorized user could also destroy or erase data, thereby affecting the accuracy of processing, and perhaps making processing unavailable since some data has been erased. The Database Management System. As is true of the data, the DBMS poses security, confidentiality, availability, and processing integrity risk exposures. Since the database management system reads and writes data to the database, unauthorized access to the DBMS is another exposure area. An unauthorized user who is able to access the DBMS may be able to browse, alter, or steal data. LANS And WANS. Since LANs and WANs are connected into the larger network of servers and computers within a company, the LANs represent risk exposure areas because anyone who has access to a workstation on the LAN can have access to data and devices on the entire network within the organization. LANs pose security, confidentiality, availability, and processing integrity risks. An unauthorized user on the LAN may browse, alter or steal data and thereby compromise the security and confidentiality of data. Any unauthorized manipulation of data or programs through the LAN can affect availability and processing integrity of the IT system. Wireless Networks. The wireless network does represent another potential “entry point” of unauthorized access and therefore poses the same four risk exposures of security, confidentiality, availability, and processing integrity. The wireless network has the same kind of exposures as described in the LAN section above. These network signals are similar to radio signals and therefore anyone who can receive those radio signals may gain access to the network. The Internet And World Wide Web. The Internet connection required to conduct Internet based business can open the company network to unauthorized users, hackers and other network break-ins. An unauthorized user can compromise security and confidentiality, and affect availability and processing integrity by alter data or programs or inserting virus or worm programs. Telecommuting Workers. Telecommuting workers cause two sources of risk exposures to their organizations. First, the network equipment and cabling that is necessary can be an “entry point” for hackers and unauthorized users. Secondly, the teleworker’s computer is also an “entry point” for potential
4