Control
Control
It is essential that the entity’s “IS” must design and maintain an information security. It must
include not only computer hardware and software but all of an organization’s information,
regardless of medium.
1
- Vandalism
2. Risk Assessment – determine the impact of the attack multiplied by the likelihood of a
vulnerability being exploited.
ACCOUNTING CONTROLS
These are controls to ensure the reliability of recorded data such as:
Batch totals
Control Accounts
Voiding/ Cancelation
Feedback Controls
Feedforward preventive controls
2
2. Disaster Recovery Policies
It is a process of resuming normal information processing operations after the
occurrence of a major interruption. The objectives are (a) to secure temporary/permanent
alternative office space; (b) protect well-being of employees or business facilities (c)
protect company legally (d) protect electronic and hardcore records (e ) return to normal
operations as quickly as possible (f) ensure data is not lost and protected and (g) develop
alternative offsite working arrangement.
Types of Disasters
Power Failure, random and deliberate intrusion – this type of disaster will not
affect the data centers physically. Thus, internal control for power failure is installing
back-up generator and for virus attacks is purchasing and installing antivirus software
and well-trained IT staff to handle it.
Flood, Hurricanes, earthquake – this type of disaster will affect the data centers
physically thus there is a need to configure sites for a quick restart. There are three
different types of configure sites, these are:
Hot Sites – with hardware and software configured already for immediate use.
Warm Sites – with hardware and software are ready in a short period of time.
Cold Sites – only facility in case of emergency but no network or hardware
capabilities.
3
c. use of firewalls – these are hardware, software or a combination of both
designed to prevent unauthorized use of company network and to limit the
access of internet users to designated sites.
Network Firewall – regulate the traffic to an entire network, such as an
organization LAN.
Application Firewall – regulate the traffic to a specified application,
such as email or file transfer application.
d. Testing the computer system weaknesses
Vulnerability Testing – also known as “vulnerability scanning” which
identifies weaknesses in the IT Infrastructure (OS, outdated application,
missing patches, obsolete protocols and certificates, physical access or
open ports).
Penetration Testing – also known as “pen test” which uses tools and
techniques of hackers to gain access to an application, system or network
by circumventing features.
Exercises
1. Increasing complexity of the information technology systems often blurs the boundaries
that separate the authorization, record keeping, and custody functions performed by the
information technology (IT) department and the system users. For example, when a sales
agent enters a customer's order online, the computer plays a significant role in authorizing
the sales transaction based on its comparison of preset customer credit limits in the
master file and consequently posting all approved sales transactions in the sales journals
and related sub-ledgers. In this scenario, what would be an example of the control that
would best minimize the lack of segregation of duties on the part of the computer system?
a. Responsibility for designing and controlling accounting software programs that
contain the sales authorization and posting controls should be under the authority
of the credit approval department; and the ability to update all the information in
the master file of customer credit limits should be under the authority of the IT
department.
b. In such situations, it is best to outsource such tasks to eliminate risking the lack of
segregation of duties.
c. Since the transaction is processed in an automated fashion, it really does not matter
which department performs a particular function.
d. Responsibility for designing and controlling accounting software programs that
contain the sales authorization and posting controls should be under the authority
of the IT department; and the ability to update all the information in the master file
of customer credit limits should be under the authority of the credit approval
department.
3. Data encryption:
a. converts data from easily read local language into a secret code and helps prevent
unauthorized usage of sensitive information.
b. converts graphics into binary code that can be more easily transmitted over the
Internet.
c. is less necessary over the Internet than on a local area network (LAN) or wide area
network (WAN) because e-mail and FTP cannot be intercepted.
d. is not necessary unless a business is working on government defense contracts.
5. All of the following are examples of effective internal controls over the data and
intellectual property of an organization except:
a. Installing, and keeping up to date, the antivirus and other such software tools.
b. Implementing mandatory password changes.
c. Limiting access to sensitive information to key people in the organization who need
access to properly perform their responsibilities.
d. Conducting training programs to ensure employee compliance.
6. The most critical aspect of the separation of duties within a mainframe information
systems environment is between:
a. programmers and users.
b. programmers and project leaders.
c. programmers and systems analysts.
d. programmers and computer operators.
7. The most appropriate control to verify that a user is authorized to execute a particular on-
line transaction is a:
a. password. c. closed-loop verification.
b. challenge/response system. d. compatibility check.
8. Which of the following statements concerning disaster recovery planning is not correct?
a. A “hot site” is more expensive to set up and maintain than is a “cold site.”
b. A company would take longer to continue operations after a natural disaster if it had
a “warm site” than if it had a hot site.
c. The main difference between a warm site and a cold site is that the computers in a
warm site are fully configured while the computers in a cold site are not yet
configured.
d. A company would be able to continue operations after a natural disaster sooner if it
had a warm site than if it had a cold site.
9. Which of the following risks can be minimized by requiring all employees accessing the
information systems to use passwords?
a. Collusion c. Failure of server duplicating function
b. Data entry errors d. Firewall vulnerability
[Link] of the options below would best be categorized as a general accounting system
control in a control environment?
a. Mandating that all employees update their passwords every 45 days to ensure data
security
b. Securing inventory with RFID tags and other identifying information to maintain
control
c. Requiring employees to attend ethics and control training led by members of the
senior management team on an annual basis
d. Instituting a two-layer review process over all account reconciliations
5
d. Automated backup systems are often ineffective; backups should be instituted
every day by an authorized computer manager
13.A company has in its disaster recovery plan a process to store in a secure, offsite
warehouse building a backup of its current financial operating systems. What type of
backup location is the company most likely using?
a. A hot site
b. A cold site
c. A mirrored data center
d. A recovery operations center
[Link] of the following best describes the relationship between business continuity
planning and corporate governance?
a. These two areas are not usually related because business continuity planning is
internally focused, and corporate governance is externally focused.
b. These two areas are not usually related because business continuity planning is
performed by management, and corporate governance is performed by the board.
c. The two areas are closely related because both business continuity planning and
corporate governance are only concerned with external activities, specifically
shareholder-oriented actions and engagements.
d. The two areas are closely related because both business continuity planning and
corporate governance have to do with navigating changes and forces on both an
internal and external basis.
15.A computer virus is different from a "Trojan Horse" because the virus can:
a. replicate itself.
b. erase executable files.
c. alter programming instructions.
d. corrupt data.
[Link] process of maintaining the last three backups so that data files can be recreated from
any one of them should a disaster occur is called:
a. Grandfather-father-son backup
b. Rollback backup
c. Tri-level backup
d. Checkpoint backup
[Link] of the following are included in the systems implementation process except:
a. training. c. conversion
b. systems design. d. testing
[Link] inherent risk specifically related to conducting business over the internet includes:
a. website denial of service attack.
b. exposure to viruses.
c. unauthorized access by hackers, exposure to viruses, and website denial of service
attacks.
d. unauthorized access by hackers.
[Link] is an unhappy employee, and he writes a line of code into the company's software
system that will erase every tenth transaction entered into the system. Which of the
following is this called?
a. Trojan horse. c. Revenge line
b. Virus. D. Saboteur
6
[Link] of the following represents a possible negative implication of having a system with
single sign-on functionality within an organization?
a. If an employee password is hacked or stolen, an unauthorized person can gain
access to multiple systems or datasets within the organization.
b. A system with single sign-on functionality will only improve the efficiency and speed
with which data is accessible, so none of these options represent a potential
negative implication of a system with single sign-on functionality.
c. The only negative implication of establishing a single sign-on system is that it is
very expensive, and another type of system will protect the organization’s
information just as well.
d. Single sign-on systems are only applicable to certain classes of information and
organizations, so there are no negative implications for the organization as a whole.
[Link] opens an e-mail that she doesn't realize contains a line of code that enters the
company local area network (LAN) via her computer. Three days later, all the data files on
the LAN and everybody's computers are erased. This is an example of:
a. a computer spam. c. a Trojan horse
b. a computer virus. D. a prototype
[Link] of the following provides the best definition of the primary purpose of network
controls?
a. Network controls are used to identify an organization’s exposure to internal and
external threats.
b. Network controls are used to prevent unauthorized people both inside and outside
of the organization from accessing and altering critical information.
c. Network controls are used to prevent or detect and correct errors in transactions
that are processed by accounting systems.
d. Network controls are used to prevent unauthorized people outside of the
organization from accessing and altering critical information.
[Link] order to properly segregate duties, which function within the computer department
should be responsible for reprocessing the errors detected during the processing of data?
a. Computer programmer. c. Department manager
b. Systems analyst. d. Data control group
7
[Link] is the backup facility that can be up and running at a short notice called?
a. VAN b. Hot site c. Remote site d. Cold site
[Link] to limit the physical access to information systems hardware include all of the
following except:
a. requiring swipe card access to restricted areas.
b. requiring dual control of valuable assets
c. employing security guards
d. sending confirmations to satellite offices.
INPUT CONTROLS
These are controls that provides reasonable assurance that data submitted are authorized,
complete and accurate.
Batch Controls – these are input controls that can be used when data are grouped
for processing in batches.
o Management Release – a batch is not release for processing until a manager
reviews and approve it.
o Record Count – counting the number of records in a batch or lines in a
document and the batch will not be released for processing if the record as
reported by the system will not be the same with the amount calculated by
the user.
o Control Totals – the batch will not be released for processing if the sum of
the dollar amounts of individual items (or any financial field) will not match
the amount calculated by the user.
o Hash Totals – the batch will not be released for processing if the sum of the
numeric field (ex. SSS number), which has no meaning by itself, will not
match as calculated by user.
Online Input Controls – these are input controls when data are keyed into an input
screen.
o Supervisor Confirmation – Supervisor must confirm the accuracy of source
data before employee input into AIS
o Preformatting – the data entry screen mimics the old hardcopy document,
forcing data entry in all necessary fields.
o Approved Mechanism – appropriate approval procedure adopted by the
organization.
o Redundant Data Review – a check digit is used to check redundant digits to
ascertain the accuracy of digits when employee manually enter long strings
of numbers.
o Dual Review – dual review/ observation of data before inputting to the
Accounting information system.
o Interactive Edits – these are controls that ensures data entered into the
system meet certain requirements. Examples of interactive edits are
8
Character checks – requires certain fields contain alphanumeric texts
Completeness checks – ensuring that there is no missing fields
Limit/Reasonable checks – comparing entered check with certain
requirements
Validity checks – comparing entered text with pre-specified data stored
within the company’s information system.
o Prompting – asking questions of the user to ensure proper data entry
o Source Document Design – the design of source document must be
considered to reduce the probability of error.
PROCESS CONTROLS
These are controls that provides reasonable assurance that data submitted for processing are
processed and only approved data are processed.
o Balancing – confirming the balance of subsidiary ledger equals to the general ledger
(example Accounts Receivable).
o Redundant Process – implementing redundant processing of data to ensure the
same answers. Independent processing and data review reduce the data error or
fraudulent activity.
o Matching – Matching source document to processing records (ex. receiving report,
supplier invoice and purchase order). This will show the proper authority and
valuation of transactions.
o Standardization – using standard and consistent procedures for processing. Same
process to reduce the possibility of error (using a chart of accounts to identify
normal debit and credit for each account).
o Batch Balancing – balancing the processing totals against source document batch
totals to ensure all records have been processed and record accurately. (Cashier
deposit tickets to totals of cash remittances).
o Automation/ Mechanization – automating the process as much as possible to reduce
the human error and increase employee efficiency.
o Default Option – use predefined value as appropriate, such as a default of 40 hours
per week for labor, to reduce or eliminate repetitive entry of information.
o Clearing Accounts – balancing the processing totals against source document batch
totals to ensure all records have been processed and record accurately.
o Automated Error Correct – this control automatically corrects errors in transactions
or records that violate a detective control. (ex. a system that automatically issue a
credit memo if the customers will overpay their accounts).
o Run to Run Totals – using output totals from previous process as input control totals
over subsequent process. (beg AR less collection plus credit sales = ending AR).
o Tickler File – a control file consists of items sequenced by date for processing or
follow up. (A file for invoices received and arranged by their due dates).
o Trailer Label – provides a control total for comparison with accumulated counts or
values of records process. (The last record in a receivable file can be trailer label
that contain a count of the number of records in the file).
OUTPUT CONTROLS
These are controls that provides reasonable assurance that processing was complete and
accurate.
o Controls for Validating Process Result – activity reports can be that provides a
detailed information about the changes in the master file to ascertain the validity,
accuracy and completeness of output.
o Controls Regulating Distribution of Outputs – controls on the access, storage and
disposal of output and how these processes must be done.
o Specific Controls
Periodic Audit – independent parties should audit files, processes or accounts
periodically to detect internal control issues (AR or AP confirmation).
Aging – provides report on the movement and age of AR.
Reconciliation – analyzes the differences between the values contained in a
detail file and a control total to identify errors (bank reconciliation).
Discrepancy Report – a report that contains a list of items that have violated
a control and require further investigation. (A list of employees who have
exceeded overtime limits).
9
Suspense File – a file containing unprocessed or partially complete
transactions for further review. (Back ordered raw materials awaiting for
receipt).
Suspense Account – This is a control total for items that needs further
processing (total of general and subsidiary ledger must be equal).
Exercises
1. Data processed by a computer system are usually transferred to some form of output
medium for storage. However, the presence of computerized output does not, in and of
itself, ensure the output's accuracy, completeness, or authenticity. For this assurance,
various controls are needed. The major types of controls for this area include:
a. input controls, tape and disk output controls, and printed output controls.
b. hash totals, tape and disk output controls, and printed output controls.
c. tape and disk output controls and printed output controls.
d. transaction controls, general controls, and printout controls.
2. Which of the following best describes why input controls are needed in an accounting
information system?
a. Input controls are needed to help prevent incorrect data from being entered into an
accounting information system.
b. Input controls are needed to monitor how an accounting information system
processes input data into information output.
c. Input controls are needed to monitor the various stages of the accounting
information system development life cycle.
d. Input controls are needed to monitor whether an accounting information system
provides useful output for decision making.
4. Ellen is processing a group of transactions and indicates as she begins running the
program that there are 15 transactions in the batch, totaling $150,000 in orders. This
batch control is related to all of the following except:
a. a processing control c. an input control
b. an output control d. a program access control
5. Which of the following computer documentation would an auditor most likely utilize in
obtaining an understanding of the internal control structure?
a. Systems flowcharts c. Program listings
b. Record counts d. Record layouts
8. Which of the following statements regarding auditor documentation of the client's system
of internal control is correct?
a. Documentation must include flowcharts.
b. No one form of documentation is required, and the extent of documentation may
vary.
c. Documentation must include procedural write-ups.
d. No documentation is necessary, although it is desirable.
[Link] of the following best describes why output controls are needed in an accounting
information system?
a. Output controls are needed to help prevent incorrect data from being entered into
an accounting information system.
b. Output controls are needed to monitor how an accounting information system
processes input data into information output.
c. Output controls are needed to protect an organization’s information and data.
d. Output controls are needed to monitor whether an accounting information system
provides useful output for decision making.
[Link] needs to send a check to a contract worker. The check number is on the check, and
the computer program adds a second number while printing the check to aid in tracking
the transaction. This is an example of:
a. an input control c. a program access control
b. a processing control d. an output control
[Link] situations where it is crucial that data be entered correctly into an accounting
information system, the best method of data control would be to use:
a. compatibility tests c. reasonableness tests
b. limit checks d. key verification
14.A software program prompts the input clerk that an account number is incorrect. This
prompt is most likely based on what input control?
a. Hash total c. Formatted input
b. Reasonableness test d. Check Digit
11
d. Is a graphical description of the flow of documents and information between
departments or areas of responsibility.
[Link] is entering a transaction on the screen and receives an error message telling her the
account number does not match the customer name. This is an example of:
a. a program access control c. an input control
b. an output control. D. a processing control
[Link] procedures may include a variety of computerized programs and accuracy tests to
confirm that the data processed by computer applications post to the correct general
ledger accounts. These procedures are referred to as:
a. input controls c. output controls
b. processing controls d. security controls
[Link] order to prevent, detect, and correct errors and unauthorized tampering, a payroll
system should have adequate controls. The best set of controls for a payroll system
includes:
a. passwords and user codes, batch totals, employee supervision, and record counts of
each run.
b. batch and hash totals, record counts of each run, proper separation of duties,
passwords and user codes, and backup copies of activity and master files.
c. employee supervision, batch totals, record counts of each run, and payments by
check.
d. batch totals, record counts, user codes, proper separation of duties, and online edit
checks.
[Link] controls provide reasonable assurance that data is complete, accurate, and
authorized?
a. Output controls c. Physical Controls
b. Input controls. D. Processing Controls
[Link] one of the following groups of controls are generally considered the most cost-
effective controls? I – Preventive; II – Corrective; III – Feedback; IV – Feedforward; V –
Detective
a. I, II and III c. I, III and V
b. I, II and V d. III, IV and V
23.A company has designed its accounting system to have an automated reconciliation
between its payroll and general ledger systems. Which type of control has the company
implemented?
a. Output control c. Processing control
b. Input control d. Transaction control
[Link] controls provide assurance that processing is complete and accurate. Which of the
following controls is not an output control?
a. Password protection of document.
b. Reasonableness check.
12
c. Error listing.
d. Audit trail.
[Link] entering the billing address for a new client in Emil Company's computerized database,
a clerk erroneously entered a nonexistent zip code. As a result, the first month's bill
mailed to the new client was returned to Emil Company. Which one of the following would
most likely have led to discovery of the error at the time of entry into Emil Company's
computerized database?
a. Limit test c. Parity test
b. Validity test d. Record count test
13