E-business

Controls in an Information System environment

Information system/Information Technology Controls are subset of Organization’s Internal conrol system.

IS/IT control objectives relate to the confidentiality, integrity, and availability of data and the overall management of the IT function of the business enterprise.

Information System Control
General controls: 

These review the reliability of the data generated by the IT systems and check that they are operating correctly.

– Physical controls – these involve controls to avoid unauthorised access to computer equipment, such as security personnel, door locks and card entry systems. They will also include safeguards against possible environmental damage to the computer equipment, such as surge protectors in case of lightning strikes or other power surges.

 

– Hardware and software configuration – these controls are designed to ensure that any new IT is tested and installed correctly into the system to minimise the risk of errors or damage to the systems.

 

– Logical access – these controls are designed to prevent unauthorised access to the organisation’s information systems. These could include password systems.

 

– Disaster recovery – these will ensure that the organisation will be able to continue operating despite adverse conditions. For example, off-site backup may be kept of all systems.

 

– Output controls – these ensure that the outputs from the system are both complete and secure. This could include controls over who outputs (such as reports or lists) are distributed to within the organisation.

 

– Technical support – it is important that all the users of the organisation’s IT systems are competent. Training policies and technical support for workers can be a valuable control.

 

Application controls:

These controls are fully automated and tend to be designed to ensure that the data input into the system is complete and accurate. 

These controls will vary from system to system, but are often designed to ensure: 

– Completeness – has all necessary data been input?

 

– Authorisation – is the person inputting the data authorised to do so?

 

– Identification – can the person inputting the information be uniquely identified?

 

– Validity – is the information being input by the user valid?

 

– Forensic checks – is the information being input by the user mathematically accurate?

 

Software controls:

Software control prevents making or installing unauthorised copies of software. Illegal software is more likely to fail, comes without warranties or support, can place systems at risk of viruses and the use of illegal software can result in significant financial penalties. 

Software can be controlled by:

– Buying only from reputable dealers.

 

– Ensuring that the original disks come with the software.

 

– Ensuring that licences are received for all software.

 

– Retaining all original disks and documentation.

 

Network controls:

Risks on networks 

The increase in popularity of the LAN (local area network) has brought concerns in relation to system security. A LAN allows for many more breaches of security than does a single computer. 

The main areas of concern are:

– Tapping into cables

 

– Unauthorised log in

 

– Computer viruses

 

– File copying

 

– File server security.

 

Request Callback Say Hi! on WhatsApp