8 - IT Systems and Controls Flashcards
What is an information system?
System for processing data and information that may involve people based activities and or computer based functions
What are separate systems?
Wholly separate IT systems in place
Integration only though transfers initiated by staff
Simpler
Significant and costly human intervention
Scope for error, omission and duplication
Some IT controls but mostly manual
What are enterprise systems?
Systems from across different areas of a business that are connected to a central data system
E.g oracle
Integrates everything
Performed quickly so minimised errors and waste
IT controls in place over central data
Manual controls over inputs and outputs
What is straight through processing?
Removes need for human intervention
Fully automated
Almost entirely IT controls
Manual controls only for exceptions and reviewing
Remit of IT department?
Develop IT strategy Develop IT policy Procedures and address controls Reporting lines Scope Monitor Integration
4 steps to develop IT Strategy?
Starting position GOT
Identify ideal systems WANT
Analyse gaps GAP
Project plan PLAN - bridge gaps
What are the elements of ITGCs?
Access to programs and data
Programme changes and development
computer Operations
Continuity of operations
What are ITGCs?
Manual, automated or a combination of both
Within info systems and end user computing
What are IT application controls?
Automated procedures that typically operate at a transaction level and are designed to ensure integrity of data
Used to initiate, authorise, record, process and report transactions
E.g audit logs Batch controls Programmed editing Calculation Check digits
What is a master file?
Standing or permanent source data needed to process transactions
May affect more than one processing cycle
Master file change controls?
Changes recorded on a change request form and authorised
Records of before and after position kept and reviewed
Segregation of duties between those who amend and process transactions
Audit log, reviewed
Batch controls
Complete listing reviewed periodically
Program changes and development considerations?
Development
Authorisation
Testing
Approval
Changes should be made in separate test environment
How to mitigate risk of program changes?
Separate test environment Migration to production environment Configuration changes Emergency changes Program development
Project management controls applicable ?
Initiation Planning Risk management approach Execution Completion
Stages of systems development life cycle?
Business analysis - want from new Feasibility study - what’s on offer System analysis - whether will suit Design - detail process Development - off shelf or bespoke Testing Implementation - methods Maintenance Wish list / enhancement - future upgrades
(Bopping Frank Sometimes Dances Down To Indie Pop Music Well)