0 ratings0% found this document useful (0 votes) 34 views2 pagesApplication Control Framework
It explains the application control framework in IS audit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here.
Available Formats
Download as PDF or read online on Scribd
319/24, 8:54 AM Contiol and Governance of Information Systems | Textbooks | Chapters
tenia’
8 ene
Management Control Systems (2nd Edition)
ea {x eee, Sn Up ee wey Hed
eon
Details Pricing Buy Now
ssuansad Case tues Slecvoie forma, let one
9:42 eral vant or cowrenrs —vovonbsbw on sele= te Basin
(Bue Shatac
Control and Governance of Information Systems : Overview
‘There is a growing trend in organizations to create and maintain large and complex
information systems, And it has become essential for them ta ensure the proper control of
Such systems, The main reasons for establisning contral are high cost of loss of data and
wrong decision making, possibilty of computer abuse, risk of computer errors, need for
protecting the hardware, software, and. personnal, and need for cata privacy and
Confidentiality. The main’ objectives’ of information controls are safeguarding of assets,
maintenance of data integrity, effectiveness. In achieving organizational objectives, and
‘efficient consumption of resources.
TT govemance can be defined as “the organizational capacity exercised by the board,
‘executive, and IT management to control the formulation and implementation of IT strategy
‘and ensure the fusion of business and TT." IT governance consists of relationships and
processes that direct and manage an organization, nelp it to achieve kts business goale, and
‘Generate value for ts Investments in I, while minimizing the risks.
‘There are some frameworks that help organizations to implement IT governance, Prominent among them are the IT Infrastructure Library (ITIL)
Control Objectives for Information and Related Technology (COBIT), and tie Salanced Scorecard (BSC). ITIL addresses skll requirements and
organizational structure, and provides detailed information on how to manage IT operations. The ITIL framework is published ina series of eight
books ‘called sets ~ service delivery, service support, planning to implement ‘service management, security management, lnfrastructure
management, business perspective, apalications management, and software assets management
CCOBIT provides a set of IT control objectives that guide organizations on how to maximize the benefits from IT implementation by developing
control and appropriate IT governance in the organization. It describes 34 IT control processes that are covered under four domains - Planning
{ané Organization, Acquistion and Implementation, Delivery and Support, and Monitoring. Use of the BSC for IT governance Involves creation of
an IT scorecard, whicn aligns the IT strategy and performance managervent framework with the overall organizational svategy and performance
management framework,
Information systems are normally complex in nature. On an ongoing basis, organizations exercise control over information systems through
management controls and applicetion controls. Management cantrals are the managerial functions that nave to be performed for ensuring
Banned and controlled development, implementation, operation, and maintenance of information systems. Apalication controls refer to the
Central features in each application system,
There are seven broad categories of Information system management controls In an organization - top management controls, systems
development management controls, programming management controls, data resources menagement contrals, security management contrals,
‘operations management controls, and quality assurance management controls
Top management controls involve activites Ike planning, organizing, lading, and monitoring / evaluation. Systems development management
controls involve activities like feesillty study and project Initiation, system analysis and specifying user requirements, systems design and
development, acceptance testing, implementation and maintenance, and auditing the systems development management function. Programming
management contrals Involve activities like planning, control, design, coding, testing, and operation and maintenance. Data resources
management controls include defining, creating, recefining, and retiring data, making the database available to the users; informing 2nd
servicing users; maintaining the integrity of the database; and monitoring operations and performance. Security management contral involves
conducting security programs, Operations management controls indude control of computer and network operations; maintaining data ‘fies,
program fles, and cocumentation; help desk anc technical support; and management of outsourced operations. Quality assurance management
Contras Inchide establishing quality goals and standards; checking conformity with QA standards; identifying areas for improvement, reporting
to the management; and training employees in QA standards
‘The objective of application controls is to ensure that application systems safeguard assets and maintain éata integnty. Application controls are
exercised by hardware and software and not by people. The different types of apolication controls are boundary controls, Input. controls,
communication controls, processing controls, database controls, ané output controls. Boundary controls include access controls (including
exyptocraphic controls), audit trall eortrals, and existence controls. Input contrls include cesign of source documents and data entry screens,
data code controls, batch controls, validation of data Input, aucit tall controls, and existence controls.
During the communication of information from ene place to another, the information travels from one medium to another, giving rise to three
types of exposures - transmission impairments, falure of components, and subversive threats. To prevent, detect, or correct errors caused due
{O'transmistion Impairment, various controls can be used such as communication architecture and control, intemnstworking controls, topological
[Link]/courseware!management contol [Link] 12319/24, 8:54 AM Control and Governance of Information Systems | Textbooks | Chapters
controls, channel controls, link controls, flow controls, and line error controls. Physical component controls are used to address the issue of
component failure, Controls are exercised over subversive threats either by providing a physical bariar across the transmission medium or by
encrypting the data transmitted through
Processing controls include processor controls, real memory controls, and virtual memory controls, Database controls include access controls,
integrity controls, application software controls, eoncurreney controls, cryptographic controls, ile handling controls, aueit tall contols, and
feustence controls. Output controls include inference controls, batch output production anc distribution contrals, batch report design controls,
‘online output production and distribution contras, audit tall contvls, and existence controls, Information system auditing can de defined 25 "the
process of collecting ang evaluating evidence to determine whether e computer system safeguards assets, maintains cata integrity, allows
‘organizational goals to be achieved effectively, ané uses resources efficiently.” An information systems aucit provides the people who rely on a
particular Information system with an authoritative and objective opinion on the extent to which they can safely raly on that system.
Information systems auditors may audit both financial items such as transactions and balances, and non-financial Items such as physical access
contrals, program change controls, qualty control, ané password generation. The Information systems audit procedures involve tests of controls,
fests of transactions, and tests of balances. Tests of controle are done to obtain evidence about the suitably of design and effective operation of
the accounting and internal control systems, Tests of transactions are conducted to check the effectiveness and efficiency of the database
system. Tests of balances are conducted to make a final evaluation regarding the degree of misstatements that could arise due to any failure of
information systems to safeguard assets anc maintain data integrity. There are three ways in which computers can be used in the information
systems auc ausiting around the computer, auditing through the computer, and Computer Assisted AU Techniques (CAAT),
Business continuity is the organization's ability to carry out its business operations with ngligible disruption or downtime during a natural or
manmade clsaster. Susiness continuity management deals with three Broad aspects: availabilty, relabilty, and recoverapilty. Business
Continuity Planning (BC) puts In place those processes ane procedures which ensure that there 's 2 continuous flow of the essential business
functions’ sefere, during, and after the occurrence of any disastrous event. It tackles all the risks and safeguards the systems that are vital for
carrying out the business operations. Tt aims to prevent disruption of the services that are mission ertcal and ensures restoration of the various
functions as quickly ané smoothly as possible.
Disaster Recovery Planning (ORP) is narrower in scope then BCP. ORP is a plan that ensures that the organization resumes business after the
‘occurrence of a cisvuptive event. In order to ensure consistency, the management of the organization needs to make certain that the disaster
recovery plan is in tune with the overall business continuity plan. Before drawing up 2 disaster recovery plan, the organiation should identify
{ane priontize its functions based on whether they are critica, vital, sensitive, or non-critical The disaster recovery plan consists of an emergency
plan, @ backup plan, recovery plan, anda test plan,
Chapter 17 : Overview
Overview of Control of Information
Systems
Need for Control of Information Systems
Objectives of Control of Information Systems
Quality Assurance Management Controle
‘Application Control of Information Systems
Boundary Controls
Information Technology Governance
TT Infrastructure ubrary (IT1Q)
Control Objectives for Information and Related
Technology (COBIT)
Management Control of Information
Systems
Top Management Controls
‘systems Development Management Controls
Programming Management Controls
Data Resouree Management Controls
‘Security Management Contrals
Operations Management Controls
Home!
‘bout USI
Careers|
Contact us|
News|
Services
Copyright © 2018 IBS Center for Management Research.
Al rights reserved
hitps:[Link] contol [Link]
Input Controls
Communication Controls
Processing Controls,
Database Controls
Output Controts
Information Systems Audit
Information Systems Audit Procedures
Business Continuity and Disaster Recovery
Business Continuity Management
Disaster Recovery Planning (ORP)
(Saare)
22