0% found this document useful (0 votes)
8 views10 pages

Essential Computer Control Methods

The document describes IT controls, which are provisions to monitor the functions and systems of information technology to verify that they are carried out in accordance with established programs and principles. The controls aim to preserve the confidentiality, integrity, and availability of information through policies, procedures, structures, and hardware and software systems. There are preventive, detective, and corrective controls in order to avoid errors and irregularities and ensure that they are addressed.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views10 pages

Essential Computer Control Methods

The document describes IT controls, which are provisions to monitor the functions and systems of information technology to verify that they are carried out in accordance with established programs and principles. The controls aim to preserve the confidentiality, integrity, and availability of information through policies, procedures, structures, and hardware and software systems. There are preventive, detective, and corrective controls in order to avoid errors and irregularities and ensure that they are addressed.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Computer Controls

Set of methodical provisions aimed at monitoring functions and attitudes.

for this it allows to verify if everything is done according to the adapted programs, orders

imparted and accepted principles.

Any activity or action performed manually or automatically to prevent,

correct errors or irregularities that can affect the functioning of a system

to achieve their objectives. Control them when they are designed, developed, and implemented.

They should be at least complete, simple, reliable, reviewable, suitable, and cost-effective.

Regarding this last point, the cost-risk of its implementation will need to be analyzed.

[ CITATION Fer162 3082 ]

It can be defined as the system integrated into the administrative process, in the

planning, organizing, directing and controlling operations in order to ensure

the protection of all IT resources and improving the indices of economy, efficiency

and effectiveness of automated operational processes.[ CITATION Jor12 \l 3082 ]

Computer controls refer to the preservation of confidentiality, integrity and

availability of information. This is achieved through the implementation of a group of

controls that include policies, procedures, organizational structures, and systems of

hardware and software. [ CITATION Ped131 3082 ]

According to[ CITATION Nic14 3082 ] information security is not a state

that is reached at a certain point in time and remains unchanged, but is

a continuous process that needs to be managed. The management process of the

information security is described in the ISO/IEC 27001 standard, which

It constitutes an internationally certifiable standard. This standard provides a model

for the design, implementation, operation, monitoring, review and improvement


continues from an information security management system (ISMS). It

It proposes the use of the PDCA model (Plan - plan, Do - do, Check

check, Act - to act) to carry out these objectives, where it is necessary to carry out

the following actions in each phase:

Planning: establishing policies, objectives, processes, and procedures

of relevant cybersecurity to manage risks and improve the

information security, in accordance with the policies and objectives

organization's global goals. In this stage, the risk analysis is carried out and

they select the controls that will ensure cybersecurity.

Make: implement and operate the policies, controls, processes and

established procedures.

Verify: evaluate and measure the performance of the information security system

against the established security policies and objectives, as well as review

the practical experience gained, reporting the results to the maximum

address for your review.

Act: undertake corrective and preventive actions based on the

results of the internal audit of the ISMS and the management review, for

achieve the continuous improvement of the cybersecurity system.

In the computing environment, control primarily materializes in

two types of controls:

Manual controls: those that are executed by the staff of the area

user or computer science without the use of computational tools.


Automatic Controls: they are generally those incorporated in the software,

these are called operation, communication, database management,

application programs, etc.

The control of a Computer System must be an integral part of its design, the

users and software engineers must pay close attention to the controls

throughout the entire life of the system.

Types of Controls

Preventive Controls, to try to avoid the production of errors or events

fraudulent, such as security software that prevents access to

unauthorized personnel. Example: security software that prevents personnel

unauthorized access to the system

Detective controls; they try to discover errors or frauds that have occurred after the fact.

it could have been possible to avoid them with preventive controls. Examples: the registration of

unauthorized access attempts, the daily activity log for

detect errors or omissions.

Corrective controls; aim to ensure that all errors are rectified.

identified through detective controls. Examples: recovery of a

damaged file, from the backups.

Components of IT Internal Control

The control environment

2. Risk assessment

3. Control activities (policies and procedures)

4. Information and communication

5. Supervision
The relationship that exists between control methods and control objectives can be

show through the following example, in which the same set of control methods is

used to satisfy control objectives for both maintenance and security of the

programs: [ CITATION Hec99 \ l 3082 ]

Maintenance control objectives: to ensure that the modifications of the

scheduled procedures are properly designed, tested, approved and

implemented.

Security program control objective: to ensure that they cannot

make unauthorized changes to scheduled procedures.

Importance of Computer Controls

Integrity: Ensure that the data is what it is supposed to be

Availability: Ensures the proper functioning of the systems

information

Avoid Waste: Ensure that an operation carried out cannot be denied.

Confidentiality: Ensure that only authorized individuals have

access to the resources that are exchanged.

Authentication: Ensure that only authorized individuals have access to

the resources.

Areas of Application of Computer Controls

Organization of the IT area: Management, job profiles, division of

work, standards establishments, policies.


Analysis, development, and implementation of systems: Standard methodology of

development, feasibility studies, efficiency and effectiveness of analysis and development,

documents, maintenance and implementation.

System operation: Prevent and correct operational and handling errors.

fraudulent information. Security in operation. Maintain opportunity,

truthfulness reliability, sufficiency in the information process.

Data input processing: Information processing and output

results. Capture procedures. Reliable, truthful, and accurate integral processes

just like the outputs.

System area security

Physical and logical security

About the operation of the systems

About staff

Database security

Telecommunications security

Security in networks and multi-user systems

INTERNAL COMPUTER CONTROL

The IT Internal Control is a function of the IT department of a

organization, whose objective is to monitor that all activities related to the

automated information systems are carried out in compliance with regulations, standards,

procedures and legal provisions established internally and externally.

The internal computer control daily monitors that all activities of

information systems should be carried out in compliance with procedures, standards, and regulations
set by the organization's management and/or the IT management, as well as the

legal requirements.

The role of computer internal control is to ensure that the measures that are

they obtain from the mechanisms implemented by each responsible party that are correct and valid.

Internal IT control is usually a staff organ of the department management.

of IT and is equipped with the personnel and material resources provided to the

tasks assigned to him/her.

Ensure that all activities are carried out in compliance with the procedures
and established rules, evaluate their goodness and ensure compliance with the
legal norms.
Advise on the knowledge of the regulations.
Collaborate and support the work of IT audit, as well as that of the
external audits of the group.
Define, implement, and execute mechanisms and controls to verify achievement
of the appropriate fats of the IT service, which should not be considered
how the implementation of measurement and accountability mechanisms of
achievement of those levels is exclusively placed in the control function
internal, but rather each person responsible for objectives and resources is responsible for

those levels, as well as the implementation of appropriate measurement tools.

Among its specific functions are:

Disseminate and control compliance with the rules, standards, and procedures for

staff of programmers, technicians, and operators.

Design the structure of the Internal Control System of the IT Department in the

following aspects:

Development and maintenance of application software.

Exploitation of main servers


Base Software

Computer Networks

Computer Security

Software licenses

Contractual relationships with third parties

Computer risk culture in the organization

INTERNAL COMPUTER CONTROL (SYSTEM)

An Internal Computer Control System must ensure integrity, availability

and effectiveness of information systems through control mechanisms or activities.

These controls, when designed, developed, and implemented, must be simple,

complete, reliable, verifiable, and economical.

To implement these controls, the configuration of everything must be known in advance.

the system in order to identify the elements, products, and tools that exist and

determine in this way where they can be implemented, as well as to identify the possible

risks.

To know the system configuration, the following should be documented:

Network Environment: schema, hardware and software configuration of

communications and network security scheme.

Configuration of main computers from a physical standpoint,

operating system, program library, and dataset.

Application configuration: transaction process, management system

database and distributed process environment


Products and tools: programming software, design, and documentation,

library management software.

Main computer security: user registration and access system,

identify and verify users, system integrity.

Once this documentation is obtained, it will be necessary to define:

Policies, rules, and techniques for the design and implementation of systems

information and its respective controls.

Policies, standards, and techniques for the management of the computing center and networks

of computers and their respective controls.

Policies and standards that ensure integrity, confidentiality, and availability

of the data and their respective controls.

Policies and regulations governing the procedures for changes, updates, and testing

of programs and their respective controls.

Policies and rules for installation, updating, and use of software licenses

base, network and user and their respective controls.

Policies and standards that allow the implementation of a culture within the organization

cyber risk, which will encompass the following environments:

General Directorate, through general policies on the systems of

information regarding the type of business of it.

IT department, through the creation and dissemination of procedures,

standards, methodologies, and regulations applicable to all areas of computing thus

like users.
Internal Computer Control will define the periodic controls to be carried out in each

one of the computer functions, according to the level of risk of each one of them

They will be preventive, detective, and corrective in nature.

Internal IT Audit; will periodically review the control structure

internal both in its design and in its compliance by each of the

defined areas within it and according to the level of risk.

INTERNAL INFORMATION CONTROL (AREAS OF APPLICATION)

GENERAL ORGANIZATIONAL CONTROLS

They are the basis for planning, control, and evaluation by management.

General activities of the IT Department, and it must contain the

next planning:

Strategic Information Plan made by the IT Committee.

IT Plan, created by the IT Department.

General Security Plan (physical and logical).

Contingency Plan for Disasters.

DEVELOPMENT AND MAINTENANCE CONTROLS OF SYSTEMS

INFORMATION

They allow achieving system effectiveness, economy, efficiency, data integrity.

protection of resources and compliance with laws and regulations through methodologies

like that of the Application Development Life Cycle.

INFORMATION SYSTEMS EXPLOITATION CONTROLS:

They are related to the management of resources at the levels of planning, acquisition, and usage.

of the hardware as well as the procedures for installation and execution of the software.
CONTROLS IN APPLICATIONS: Every application must have controls

incorporated to ensure input, update, output, validity and maintenance

complete and accurate data.

CONTROLS IN DATABASE MANAGEMENT SYSTEMS: They have to

see with the data management to ensure its integrity, availability, and security.

COMPUTER CONTROLS OVER NETWORKS: They are related to

design, installation, maintenance, security, and operation of the networks installed in a

organization be it central and/or distributed.

CONTROLS OVER COMPUTERS AND LOCAL AREA NETWORKS: It

they relate to the policies for acquisition, installation, and technical support, both of the hardware

as well as the user software and the security of the data processed in it.

You might also like