0% found this document useful (0 votes)
34 views2 pages

Application Control Framework

It explains the application control framework in IS audit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
34 views2 pages

Application Control Framework

It explains the application control framework in IS audit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
319/24, 8:54 AM Contiol and Governance of Information Systems | Textbooks | Chapters tenia’ 8 ene Management Control Systems (2nd Edition) ea {x eee, Sn Up ee wey Hed eon Details Pricing Buy Now ssuansad Case tues Slecvoie forma, let one 9:42 eral vant or cowrenrs —vovonbsbw on sele= te Basin (Bue Shatac Control and Governance of Information Systems : Overview ‘There is a growing trend in organizations to create and maintain large and complex information systems, And it has become essential for them ta ensure the proper control of Such systems, The main reasons for establisning contral are high cost of loss of data and wrong decision making, possibilty of computer abuse, risk of computer errors, need for protecting the hardware, software, and. personnal, and need for cata privacy and Confidentiality. The main’ objectives’ of information controls are safeguarding of assets, maintenance of data integrity, effectiveness. In achieving organizational objectives, and ‘efficient consumption of resources. TT govemance can be defined as “the organizational capacity exercised by the board, ‘executive, and IT management to control the formulation and implementation of IT strategy ‘and ensure the fusion of business and TT." IT governance consists of relationships and processes that direct and manage an organization, nelp it to achieve kts business goale, and ‘Generate value for ts Investments in I, while minimizing the risks. ‘There are some frameworks that help organizations to implement IT governance, Prominent among them are the IT Infrastructure Library (ITIL) Control Objectives for Information and Related Technology (COBIT), and tie Salanced Scorecard (BSC). ITIL addresses skll requirements and organizational structure, and provides detailed information on how to manage IT operations. The ITIL framework is published ina series of eight books ‘called sets ~ service delivery, service support, planning to implement ‘service management, security management, lnfrastructure management, business perspective, apalications management, and software assets management CCOBIT provides a set of IT control objectives that guide organizations on how to maximize the benefits from IT implementation by developing control and appropriate IT governance in the organization. It describes 34 IT control processes that are covered under four domains - Planning {ané Organization, Acquistion and Implementation, Delivery and Support, and Monitoring. Use of the BSC for IT governance Involves creation of an IT scorecard, whicn aligns the IT strategy and performance managervent framework with the overall organizational svategy and performance management framework, Information systems are normally complex in nature. On an ongoing basis, organizations exercise control over information systems through management controls and applicetion controls. Management cantrals are the managerial functions that nave to be performed for ensuring Banned and controlled development, implementation, operation, and maintenance of information systems. Apalication controls refer to the Central features in each application system, There are seven broad categories of Information system management controls In an organization - top management controls, systems development management controls, programming management controls, data resources menagement contrals, security management contrals, ‘operations management controls, and quality assurance management controls Top management controls involve activites Ike planning, organizing, lading, and monitoring / evaluation. Systems development management controls involve activities like feesillty study and project Initiation, system analysis and specifying user requirements, systems design and development, acceptance testing, implementation and maintenance, and auditing the systems development management function. Programming management contrals Involve activities like planning, control, design, coding, testing, and operation and maintenance. Data resources management controls include defining, creating, recefining, and retiring data, making the database available to the users; informing 2nd servicing users; maintaining the integrity of the database; and monitoring operations and performance. Security management contral involves conducting security programs, Operations management controls indude control of computer and network operations; maintaining data ‘fies, program fles, and cocumentation; help desk anc technical support; and management of outsourced operations. Quality assurance management Contras Inchide establishing quality goals and standards; checking conformity with QA standards; identifying areas for improvement, reporting to the management; and training employees in QA standards ‘The objective of application controls is to ensure that application systems safeguard assets and maintain éata integnty. Application controls are exercised by hardware and software and not by people. The different types of apolication controls are boundary controls, Input. controls, communication controls, processing controls, database controls, ané output controls. Boundary controls include access controls (including exyptocraphic controls), audit trall eortrals, and existence controls. Input contrls include cesign of source documents and data entry screens, data code controls, batch controls, validation of data Input, aucit tall controls, and existence controls. During the communication of information from ene place to another, the information travels from one medium to another, giving rise to three types of exposures - transmission impairments, falure of components, and subversive threats. To prevent, detect, or correct errors caused due {O'transmistion Impairment, various controls can be used such as communication architecture and control, intemnstworking controls, topological [Link]/courseware!management contol [Link] 12 319/24, 8:54 AM Control and Governance of Information Systems | Textbooks | Chapters controls, channel controls, link controls, flow controls, and line error controls. Physical component controls are used to address the issue of component failure, Controls are exercised over subversive threats either by providing a physical bariar across the transmission medium or by encrypting the data transmitted through Processing controls include processor controls, real memory controls, and virtual memory controls, Database controls include access controls, integrity controls, application software controls, eoncurreney controls, cryptographic controls, ile handling controls, aueit tall contols, and feustence controls. Output controls include inference controls, batch output production anc distribution contrals, batch report design controls, ‘online output production and distribution contras, audit tall contvls, and existence controls, Information system auditing can de defined 25 "the process of collecting ang evaluating evidence to determine whether e computer system safeguards assets, maintains cata integrity, allows ‘organizational goals to be achieved effectively, ané uses resources efficiently.” An information systems aucit provides the people who rely on a particular Information system with an authoritative and objective opinion on the extent to which they can safely raly on that system. Information systems auditors may audit both financial items such as transactions and balances, and non-financial Items such as physical access contrals, program change controls, qualty control, ané password generation. The Information systems audit procedures involve tests of controls, fests of transactions, and tests of balances. Tests of controle are done to obtain evidence about the suitably of design and effective operation of the accounting and internal control systems, Tests of transactions are conducted to check the effectiveness and efficiency of the database system. Tests of balances are conducted to make a final evaluation regarding the degree of misstatements that could arise due to any failure of information systems to safeguard assets anc maintain data integrity. There are three ways in which computers can be used in the information systems auc ausiting around the computer, auditing through the computer, and Computer Assisted AU Techniques (CAAT), Business continuity is the organization's ability to carry out its business operations with ngligible disruption or downtime during a natural or manmade clsaster. Susiness continuity management deals with three Broad aspects: availabilty, relabilty, and recoverapilty. Business Continuity Planning (BC) puts In place those processes ane procedures which ensure that there 's 2 continuous flow of the essential business functions’ sefere, during, and after the occurrence of any disastrous event. It tackles all the risks and safeguards the systems that are vital for carrying out the business operations. Tt aims to prevent disruption of the services that are mission ertcal and ensures restoration of the various functions as quickly ané smoothly as possible. Disaster Recovery Planning (ORP) is narrower in scope then BCP. ORP is a plan that ensures that the organization resumes business after the ‘occurrence of a cisvuptive event. In order to ensure consistency, the management of the organization needs to make certain that the disaster recovery plan is in tune with the overall business continuity plan. Before drawing up 2 disaster recovery plan, the organiation should identify {ane priontize its functions based on whether they are critica, vital, sensitive, or non-critical The disaster recovery plan consists of an emergency plan, @ backup plan, recovery plan, anda test plan, Chapter 17 : Overview Overview of Control of Information Systems Need for Control of Information Systems Objectives of Control of Information Systems Quality Assurance Management Controle ‘Application Control of Information Systems Boundary Controls Information Technology Governance TT Infrastructure ubrary (IT1Q) Control Objectives for Information and Related Technology (COBIT) Management Control of Information Systems Top Management Controls ‘systems Development Management Controls Programming Management Controls Data Resouree Management Controls ‘Security Management Contrals Operations Management Controls Home! ‘bout USI Careers| Contact us| News| Services Copyright © 2018 IBS Center for Management Research. Al rights reserved hitps:[Link] contol [Link] Input Controls Communication Controls Processing Controls, Database Controls Output Controts Information Systems Audit Information Systems Audit Procedures Business Continuity and Disaster Recovery Business Continuity Management Disaster Recovery Planning (ORP) (Saare) 22

You might also like