INTERNAL CONTROLS FOR SYSTEM OPERATION
Definitions
The Information Internal Control can be defined as the system integrated into
administrative process, in the planning, organization, direction, and control of
operations with the aim of ensuring the protection of all resources
IT professionals and improve the indices of economy, efficiency, and effectiveness of the
automated operational processes. (IT Audit - Applications in
Production - José Dagoberto Pinilla
The COSO Report defines Internal Control as 'The standards, the
procedures, practices, and organizational structures designed to
provide reasonable assurance that the company's objectives are
will be achieved and that unwanted events will be anticipated, detected, and
they will correct.
Internal Control can also be defined as any activity or
action performed manually and/or automatically to prevent, correct errors or
irregularities that may affect the operation of a system for
achieve their objectives. (IT Audit - A Practical Approach - Mario
G. Plattini) Types
In the computer environment, internal control is materialized.
fundamentally in two types of controls:
•Manual controls; those executed by the staff in the area
user or computer science without the use of computational tools.
•Automatic Controls; are generally those incorporated into the software,
let these be operation, communication, database management,
application programs, etc.
Controls are classified according to their purpose as:
Preventive controls, to try to avoid the production of errors or
fraudulent acts, such as security software that prevents the
access to unauthorized personnel.
•Detective Controls; it aims to discover errors or frauds that occurred in the past.
it has been possible to avoid them with preventive controls.
Corrective controls; they aim to ensure that all issues are addressed.
errors identified through detection controls.
Main objectives:
Monitor that all activities are carried out in compliance with the procedures
and established standards, evaluate their goodness and ensure compliance with the
legal norms.
Advise on knowledge of the regulations
Collaborate and support the work of internal/external IT auditing
• Define, implement, and execute mechanisms and controls to verify the degree
compliance with IT services.
• Carry out control in the different computer systems and environments of the
different activities that are carried out.
Internal IT control (function)
The Internal Computer Control is a function of the IT department.
of an organization, whose objective is to control that all activities
related to automated information systems are carried out
complying with norms, standards, procedures, and legal provisions
established internally and externally.
Among its specific functions are:
Disseminate and control compliance with the rules, standards and
procedures for programming staff, technicians, and operators.
• Design the structure of the Internal Control System of the Directorate of
Informatics in the following aspects:
Development and maintenance of application software.
Exploitation of main servers
Base Software
Computer Networks
Cybersecurity
Software licenses
Contractual relationships with third parties
• Culture of cybersecurity risk in the organization
IT internal control (areas of application)
General organizational controls
They are the basis for planning, control, and evaluation by the General Management.
of the activities of the IT Department, and must contain the
next planning:
Strategic Information Plan made by the IT Committee.
• Computer Plan, prepared by the IT Department.
General Security Plan (physical and logical).
Contingency Plan for Disasters.
Development and maintenance controls of information systems
They allow for achieving system effectiveness, economy, efficiency, integrity of
data, resource protection, and compliance with laws and regulations to
through methodologies such as the Development Life Cycle
applications.
Information system exploitation controls
They have to do with the management of resources both at the planning level,
acquisition and use of hardware as well as the installation procedures and
software execution.
Controls in applications
Every application must include built-in controls to ensure input,
complete and accurate update, release, validity, and maintenance of the
data.
Controls in database management systems
They are related to data management to ensure its integrity.
availability and security.
Computer controls over networks
They need to address design, installation, maintenance, security and
operation of networks installed in an organization whether these are
centralized and/or distributed.
Controls over computers and local area networks
They relate to the policies for acquisition, installation, and technical support, both
of hardware as well as user software, as well as data security
that are processed in them.
Control Function;
In the IT audit; it has the function of monitoring and evaluation
through reports, the auditors have different objectives than those of
they assess efficiency, costs, and safety with greater insight, and
they carry out qualitative assessments.
IT internal control; They perform dual control functions in the
different departments, which may include regulations, legal framework, the
The functions of internal control are as follows: to determine the owners and the
profiles according to the type of information, allow two people to intervene as
control measure, create contingency plans, establish regulations
computer security, controls software quality, costs,
heads of each department, license control, management of keys
ciphered, they monitor compliance with regulations and controls, it is clear that this
measure allows for cybersecurity.
Information classification and retrieval methodologies
control procedures;
It is to establish which information entities need to be protected, depending on
the degree of importance of information for the establishment of
countermeasures.
Control tools;
The control tools are of two types, logical and physical, from the point
Logically, they are programs that provide security; the main tools are
["logical system security","complementary logical security"]
from the system, logical security in distributed environments, physical access control,
copy control, management of magnetic support, management of control of
printing and sending listings by network, project and version control, management
of independence and change control. And physically the ciphers.
INTERNAL INFORMATION CONTROL
The IT internal control checks daily that all activities of
information systems should be carried out in accordance with the procedures,
standards and norms set by the organization management and/or the management
computer science, as well as the legal requirements.
The function of IT internal control is to ensure that the measures
that are obtained from the mechanisms implemented by each responsible party are
correct and valid.
Internal computer control is usually a staff body of the management of
computer science department and is equipped with people and resources
materials provided for the tasks assigned to him/her.
The main objectives can be indicated as follows:
Ensure that all activities are carried out in compliance with the
procedures and established rules, evaluate their goodness and ensure
compliance with legal regulations.
Advise on the knowledge of the regulations.
Collaborate and support the work of IT auditing, as well as of the
external audits to the group.
Define, implement and execute mechanisms and controls to verify the
achievement of the appropriate fats in the IT service, which should not
to consider the implementation of measurement mechanisms as
responsibility for achieving those levels lies exclusively with
the internal control function, but rather each person responsible for objectives and
resources is responsible for those levels, as well as for the implementation of
the appropriate measuring tools.
La auditoría informática es el procesode recoger, agrupar y evaluar
evidence to determine if a computerized system safeguards assets,
maintains the integrity of the data, effectively carries out the purposes of the
organize and use resources efficiently.
DEFINITION AND TYPE OF INTERNAL CONTROLS
Internal control can be defined as 'any activity or action undertaken
manually and/or automatically to prevent, correct errors or irregularities
that can affect the functioning of a system to achieve or obtain
its objectives.
Internal controls are classified into the following:
Preventive controls: To try to avoid the fact, like software for
security that prevents unauthorized access to the system.
Detective controls: When preventive measures fail to try to understand
as soon as the event. For example, the logging of access attempts does not
authorized, the daily activity log to detect errors
and omissions, etc.
Corrective controls: They facilitate the return to normalcy when there have been
produced incidents. For example, recovering a damaged file to
starting from the backups.
IMPLEMENTATION OF A SYSTEM OF INTERNAL CONTROLS
IT professionals
To get to know the system configuration, it is necessary to document the
network details, as well as the different levels of control and elements
related:
Network environment: network diagram, hardware configuration description
of communications, description of the software used as access to the
telecommunications, network control, general situation of the computers
base environments that support critical applications and related considerations
to the network security.
Base computer configuration: Physical support configuration, around
of the operating system, software with partitions, environments (testing and real)
program libraries and dataset
Application environment: Transaction processes, management systems
databases and distributed process environments.
Products and tools: Software for program development, software
of library management and for automated operations.
Base computer security: Identify and verify users, control of
access, registration and information, system integrity, oversight controls,
etc.
For the implementation of a computer internal control system
it will be necessary to define:
Information system management: policies, guidelines, and technical standards that
serve as a foundation for the design and implementation of information systems
and the corresponding controls.
System administration: Controls over the activity of the centers of
data and other support functions for the system, including administration of
the networks.
Security: includes the three fundamental classes of controls implemented in
system software, system integrity, confidentiality (control of
access) and availability.
Change management: separation of testing and production at the level of
software and controls for the migration of programs
approved and tested software.
The 8 phases to implement an internal control system
We could define the generic concept of control as a potential action oriented
to achieve a defined objective. If we focus on internal control, we specify
it is a process carried out by the executives of an organization,
designed to ensure adequate security, aimed at achieving the objectives
in different aspects: that operations are carried out efficiently and
effective, that the financial information is reliable and that regulations are complied with
opportune.
Phases for implementing the internal control system
There is a series of phases that must be followed sequentially to ensure a
correct implementation of internal control. They are the following:
Phase 1: Create a culture of control through communication, motivation, and
the training
Before starting with the implementation of the internal control system, it is
It's important to prepare the ground. This preparation involves communicating to the people.
what is wanted to be done and to know how to convey the importance of control and its benefits for
the organization and even for each person individually. One possible way of
to instill these concepts is through training at the departmental level or
department. In this training, the roadmap will be presented for the
development of the remaining phases.
Phase 2: Gather information
Once we have introduced the culture of control among the members of the
organization, the time comes to collect data. In this phase, it must intervene
all staff actively, coordinated by a designated responsible person, either
external or internal, coming from the organization's strategy area.
There are different methods to carry out this collection, for example:
Narration: Through an interview or document, each employee makes a
description of the work, tasks, processes carried out, regardless of
if these are formally established. The coordinator collects these testimonies.
Checklists: Another method could be the creation of preliminary questionnaires by
part of the person responsible for gathering the information, who is presumed to have a
prior knowledge in internal control systems. These checklists contain
issues aimed at understanding the internal dynamics of each area of the organization.
Observation: Through observation, useful information can also be extracted for
supplement aspects that need to be documented.
Flowcharts are often used to complete the information gathered with the methods.
previous. The steps taken to carry out a
determined operation.
Phase 3: Classify the obtained information
Since the person in charge has gathered all the necessary information through some of
the mentioned ways, it is time to digitize and classify it in the way
as orderly as possible to facilitate its consultation and correct interpretation.
Phase 4: Diagnose
At this point, the necessary information is already available to make a diagnosis.
of the state of multiple aspects of management: the fulfillment of objectives, the
roles and their functions, the policies, etc.
Phase 5: Review the procedures
Under the legal regulations, the total quality perspective, the reengineering parameters and
administrative guidelines, a thorough review of the procedures is carried out with
the goal of making them more efficient. Unnecessary steps are eliminated, they are centralized
repeated processes and communication channels are opened.
Phase 6: Evaluate internal and management control
A way must be established to evaluate the internal control system among all.
the members of the organization. Each one of them must contribute their vision and
to get involved, committing to undergo continuous self-control that promotes
continuous improvement.
Phase 7: Implement, monitor, and adjust
At this point, the internal control system is already designed. The time has come.
that those responsible take charge of implementing it in each of the areas and
ensure compliance. The person in charge must monitor
I continue with the support of internal audit. It is also the occasion to take
necessary corrective actions and make final adjustments.
Phase 8: Evaluate indicators and make further adjustments
Collective management KPIs should be designed to analyze them. These indicators
they can be stored and systematized in Balanced Scorecard dashboards.
preferably in an automated way. This allows obtaining information in real time
real.
Another evaluation method that is frequently used is the systems of
risk management, based on which dashboards can be built
visuals, in numerical terms and with colorimetry.
To carry out the evaluation of the internal control system
byMaria Camila Arévaloon October 05, 2020
Within risk management, havingan internal control systemit's something
fundamental that all organizations should have. This process must
to be led by the senior management or board of directors and those responsible for each
area to ensure compliance with the objectives, but above all to
the effectiveness of processes, the reliability of financial information and the
compliance with legal requirements.
It should be taken into account that ainternal control cash depends on a
good organization. Reducing the level of errors and threats helps to ensure that the
objectives of the control system are met correctly as
we mentioned earlier.
In the following article, we present some tips you should keep in mind.
account to carry out acorrect evaluation of internal control.
Whatisinternalcontrol?
The internal control environment is the setting that influences the members of
an organization and in the control of its activities. This environment is the basis
from the management of corporate risks, as it provides discipline and
structure also impacts all components of therisk management.
It is composed of plans, methods, principles, standards, procedures
and mechanisms that allow to verify and evaluate all the operations that
the company carries out, likewise, to identify how it is stored
information and resources from it and if this meets the objectives of the
company.
This is where the company decidesestablish a methodologyto paraprotector the
organization and its reputation, thus preventing any type of risk that the
may jeopardize or prevent the fulfillment of its objectives.
You must keep in mind that this is a task that involves everyone.
company personnel.
Methodologyyoucanapply
To deeply understand the processes carried out by the company to
its habitual development.
Identify the irregularities that are occurring.
Investigate how the current operation of internal controls is.
How do these influence financial information and information?
general of the company.
Identify if a failure in one of these controls can affect the
company operations.
Define the purposes of each of the controls.
Carry out tests to determine if the operation of the
controls is the appropriate one.
Evaluate the effectiveness of the controls.
Si se encuentran deficiencias trabajar en la mejora o proponer nuevos
controls.