华南俳烁实业有限公司

考試首頁 | 考試用書 | 培訓課程 | 模擬考場 | 考試論壇  
  當前位置:考試網 >> ACCA/CAT >> 備考指導 >> 文章內容
  

ACCAP3知識點:INFORMATIONTECHNOLOGY(四)

考試網  [ 2016年8月29日 ] 【

  ACCA P3考試:INFORMATION TECHNOLOGY

  CONTROLS IN IT SYSTEMS

  IT poses particular risks to organisations’ internal control and information systems. This can lead to their operations being severely disrupted and subsequently to lost sales, increased costs, incorrect decisions and reputational damage.

  Risks include:

  • Reliance on systems or programs that are inaccurately processing data, processing inaccurate data, reporting inaccurate, misleading results - or all three.

  • Unauthorised access to data leading to destruction of data, improper changes to data, or inaccurate recording of transactions.

  • Particular risks may arise where multiple users access a common database on which everyone in the organisation relies.

  • The possibility of IT personnel gaining access privileges beyond those necessary to perform their assigned duties.

  • Unauthorised changes to data in master files. For example, changing a selling price or credit limit.

  • Unauthorised changes to systems or programs so that they no longer operate correctly and reliably.

  • Failure to make necessary changes to systems or programs to keep them up-to-date and in line with legal and business requirements.

  • Potential loss of data or inability to access data as required. This could prevent, for example, the processing of internet sales.

  Controls in computer systems can be categorised as general controls and application controls.

  GENERAL CONTROLS

  These are policies and procedures that relate to the computer environment and which are therefore relevant to all applications. They support the effective functioning of application controls by helping to ensure the continued proper operation of information systems. General IT controls that maintain the integrity of information and security of data commonly include controls over the following:

  • Data centre and network operations. A data centre is a central repository of data and it is important that controls there include back-up procedures, anti-virus software and firewalls to prevent hackers gaining access. Organisations should also have disaster recovery plans in place to minimise damage caused by events such as floods, fire and terrorist activities. Where IT is critical to an operation’s business these plans might include having a parallel system operating at a remote location that can be switched to immediately.

  • System software acquisition, change and maintenance. System software refers to operating systems, such as Windows or Apple’s OS. These systems often undergo updates as problems and vulnerabilities are identified and it is important for updates to be implemented promptly.

  • Access security. Physical access to file servers should be carefully controlled. This is where the company keeps it data and it is essential that this is safeguarded: data will usually endow companies with competitive advantage. Access to processing should also be restricted, typically through the use of log-on procedures and passwords.

  • Application system acquisition, development, and maintenance. Applications systems are programs that carry out specific operations needed by the company – such as calculating wages and invoices and forecasting inventory usage. Just as much damage can be done by the incorrect operation of software as by inputting incorrect data. For example, think of the damage that could be done if sales analyses were incorrectly calculated and presented. Management could be led to withdraw products that are in fact very popular. All software amendments must be carefully specified and tested before implementation.

本文糾錯】【告訴好友】【打印此文】【返回頂部
將考試網添加到收藏夾 | 每次上網自動訪問考試網 | 復制本頁地址,傳給QQ/MSN上的好友 | 申請鏈接 | 意見留言 TOP
關于本站  網站聲明  廣告服務  聯系方式  站內導航  考試論壇
Copyright © 2006-2019 考試網(Examw.com) All Rights Reserved  營業(yè)執(zhí)照
乐昌市| 萝北县| 邢台市| 界首市| 宜昌市| 和硕县| 兴业县| 浮梁县| 内丘县| 吴川市| 汤原县| 吉隆县| 乌拉特中旗| 东阳市| 澄迈县| 满城县| 东乌珠穆沁旗| 南溪县| 渭南市| 久治县| 齐齐哈尔市| 罗定市| 巴青县| 台北市| 通渭县| 哈巴河县| 调兵山市| 包头市| 原平市| 山东省| 讷河市| 辽中县| 峨眉山市| 郓城县| 泊头市| 台北市| 锡林郭勒盟| 合山市| 都江堰市| 华池县| 甘泉县|