Computer Controls
Set of methodical provisions aimed at monitoring functions and attitudes.
for this it allows to verify if everything is done according to the adapted programs, orders
imparted and accepted principles.
Any activity or action performed manually or automatically to prevent,
correct errors or irregularities that can affect the functioning of a system
to achieve their objectives. Control them when they are designed, developed, and implemented.
They should be at least complete, simple, reliable, reviewable, suitable, and cost-effective.
Regarding this last point, the cost-risk of its implementation will need to be analyzed.
[ CITATION Fer162 3082 ]
It can be defined as the system integrated into the administrative process, in the
planning, organizing, directing and controlling operations in order to ensure
the protection of all IT resources and improving the indices of economy, efficiency
and effectiveness of automated operational processes.[ CITATION Jor12 \l 3082 ]
Computer controls refer to the preservation of confidentiality, integrity and
availability of information. This is achieved through the implementation of a group of
controls that include policies, procedures, organizational structures, and systems of
hardware and software. [ CITATION Ped131 3082 ]
According to[ CITATION Nic14 3082 ] information security is not a state
that is reached at a certain point in time and remains unchanged, but is
a continuous process that needs to be managed. The management process of the
information security is described in the ISO/IEC 27001 standard, which
It constitutes an internationally certifiable standard. This standard provides a model
for the design, implementation, operation, monitoring, review and improvement
continues from an information security management system (ISMS). It
It proposes the use of the PDCA model (Plan - plan, Do - do, Check
check, Act - to act) to carry out these objectives, where it is necessary to carry out
the following actions in each phase:
Planning: establishing policies, objectives, processes, and procedures
of relevant cybersecurity to manage risks and improve the
information security, in accordance with the policies and objectives
organization's global goals. In this stage, the risk analysis is carried out and
they select the controls that will ensure cybersecurity.
Make: implement and operate the policies, controls, processes and
established procedures.
Verify: evaluate and measure the performance of the information security system
against the established security policies and objectives, as well as review
the practical experience gained, reporting the results to the maximum
address for your review.
Act: undertake corrective and preventive actions based on the
results of the internal audit of the ISMS and the management review, for
achieve the continuous improvement of the cybersecurity system.
In the computing environment, control primarily materializes in
two types of controls:
Manual controls: those that are executed by the staff of the area
user or computer science without the use of computational tools.
Automatic Controls: they are generally those incorporated in the software,
these are called operation, communication, database management,
application programs, etc.
The control of a Computer System must be an integral part of its design, the
users and software engineers must pay close attention to the controls
throughout the entire life of the system.
Types of Controls
Preventive Controls, to try to avoid the production of errors or events
fraudulent, such as security software that prevents access to
unauthorized personnel. Example: security software that prevents personnel
unauthorized access to the system
Detective controls; they try to discover errors or frauds that have occurred after the fact.
it could have been possible to avoid them with preventive controls. Examples: the registration of
unauthorized access attempts, the daily activity log for
detect errors or omissions.
Corrective controls; aim to ensure that all errors are rectified.
identified through detective controls. Examples: recovery of a
damaged file, from the backups.
Components of IT Internal Control
The control environment
2. Risk assessment
3. Control activities (policies and procedures)
4. Information and communication
5. Supervision
The relationship that exists between control methods and control objectives can be
show through the following example, in which the same set of control methods is
used to satisfy control objectives for both maintenance and security of the
programs: [ CITATION Hec99 \ l 3082 ]
Maintenance control objectives: to ensure that the modifications of the
scheduled procedures are properly designed, tested, approved and
implemented.
Security program control objective: to ensure that they cannot
make unauthorized changes to scheduled procedures.
Importance of Computer Controls
Integrity: Ensure that the data is what it is supposed to be
Availability: Ensures the proper functioning of the systems
information
Avoid Waste: Ensure that an operation carried out cannot be denied.
Confidentiality: Ensure that only authorized individuals have
access to the resources that are exchanged.
Authentication: Ensure that only authorized individuals have access to
the resources.
Areas of Application of Computer Controls
Organization of the IT area: Management, job profiles, division of
work, standards establishments, policies.
Analysis, development, and implementation of systems: Standard methodology of
development, feasibility studies, efficiency and effectiveness of analysis and development,
documents, maintenance and implementation.
System operation: Prevent and correct operational and handling errors.
fraudulent information. Security in operation. Maintain opportunity,
truthfulness reliability, sufficiency in the information process.
Data input processing: Information processing and output
results. Capture procedures. Reliable, truthful, and accurate integral processes
just like the outputs.
System area security
Physical and logical security
About the operation of the systems
About staff
Database security
Telecommunications security
Security in networks and multi-user systems
INTERNAL COMPUTER CONTROL
The IT Internal Control is a function of the IT department of a
organization, whose objective is to monitor that all activities related to the
automated information systems are carried out in compliance with regulations, standards,
procedures and legal provisions established internally and externally.
The internal computer control daily monitors that all activities of
information systems should be carried out in compliance with procedures, standards, and regulations
set by the organization's management and/or the IT management, as well as the
legal requirements.
The role of computer internal control is to ensure that the measures that are
they obtain from the mechanisms implemented by each responsible party that are correct and valid.
Internal IT control is usually a staff organ of the department management.
of IT and is equipped with the personnel and material resources provided to the
tasks assigned to him/her.
Ensure that all activities are carried out in compliance with the procedures
and established rules, evaluate their goodness and ensure compliance with the
legal norms.
Advise on the knowledge of the regulations.
Collaborate and support the work of IT audit, as well as that of the
external audits of the group.
Define, implement, and execute mechanisms and controls to verify achievement
of the appropriate fats of the IT service, which should not be considered
how the implementation of measurement and accountability mechanisms of
achievement of those levels is exclusively placed in the control function
internal, but rather each person responsible for objectives and resources is responsible for
those levels, as well as the implementation of appropriate measurement tools.
Among its specific functions are:
Disseminate and control compliance with the rules, standards, and procedures for
staff of programmers, technicians, and operators.
Design the structure of the Internal Control System of the IT Department in the
following aspects:
Development and maintenance of application software.
Exploitation of main servers
Base Software
Computer Networks
Computer Security
Software licenses
Contractual relationships with third parties
Computer risk culture in the organization
INTERNAL COMPUTER CONTROL (SYSTEM)
An Internal Computer Control System must ensure integrity, availability
and effectiveness of information systems through control mechanisms or activities.
These controls, when designed, developed, and implemented, must be simple,
complete, reliable, verifiable, and economical.
To implement these controls, the configuration of everything must be known in advance.
the system in order to identify the elements, products, and tools that exist and
determine in this way where they can be implemented, as well as to identify the possible
risks.
To know the system configuration, the following should be documented:
Network Environment: schema, hardware and software configuration of
communications and network security scheme.
Configuration of main computers from a physical standpoint,
operating system, program library, and dataset.
Application configuration: transaction process, management system
database and distributed process environment
Products and tools: programming software, design, and documentation,
library management software.
Main computer security: user registration and access system,
identify and verify users, system integrity.
Once this documentation is obtained, it will be necessary to define:
Policies, rules, and techniques for the design and implementation of systems
information and its respective controls.
Policies, standards, and techniques for the management of the computing center and networks
of computers and their respective controls.
Policies and standards that ensure integrity, confidentiality, and availability
of the data and their respective controls.
Policies and regulations governing the procedures for changes, updates, and testing
of programs and their respective controls.
Policies and rules for installation, updating, and use of software licenses
base, network and user and their respective controls.
Policies and standards that allow the implementation of a culture within the organization
cyber risk, which will encompass the following environments:
General Directorate, through general policies on the systems of
information regarding the type of business of it.
IT department, through the creation and dissemination of procedures,
standards, methodologies, and regulations applicable to all areas of computing thus
like users.
Internal Computer Control will define the periodic controls to be carried out in each
one of the computer functions, according to the level of risk of each one of them
They will be preventive, detective, and corrective in nature.
Internal IT Audit; will periodically review the control structure
internal both in its design and in its compliance by each of the
defined areas within it and according to the level of risk.
INTERNAL INFORMATION CONTROL (AREAS OF APPLICATION)
GENERAL ORGANIZATIONAL CONTROLS
They are the basis for planning, control, and evaluation by management.
General activities of the IT Department, and it must contain the
next planning:
Strategic Information Plan made by the IT Committee.
IT Plan, created by the IT Department.
General Security Plan (physical and logical).
Contingency Plan for Disasters.
DEVELOPMENT AND MAINTENANCE CONTROLS OF SYSTEMS
INFORMATION
They allow achieving system effectiveness, economy, efficiency, data integrity.
protection of resources and compliance with laws and regulations through methodologies
like that of the Application Development Life Cycle.
INFORMATION SYSTEMS EXPLOITATION CONTROLS:
They are related to the management of resources at the levels of planning, acquisition, and usage.
of the hardware as well as the procedures for installation and execution of the software.
CONTROLS IN APPLICATIONS: Every application must have controls
incorporated to ensure input, update, output, validity and maintenance
complete and accurate data.
CONTROLS IN DATABASE MANAGEMENT SYSTEMS: They have to
see with the data management to ensure its integrity, availability, and security.
COMPUTER CONTROLS OVER NETWORKS: They are related to
design, installation, maintenance, security, and operation of the networks installed in a
organization be it central and/or distributed.
CONTROLS OVER COMPUTERS AND LOCAL AREA NETWORKS: It
they relate to the policies for acquisition, installation, and technical support, both of the hardware
as well as the user software and the security of the data processed in it.