IS 414 CH. 12 (Threats and Controls) Flashcards
1
Q
General issues throughout the cycle
A
- Inaccurate or invalid master data
- Unauthorized disclosure of sensitive information
- Loss or destruction of data
- Poor performance
2
Q
- Inaccurate or invalid master data
A
- 1 Data processing integrity controls
- 2 Restriction of access to master data
- 3 Review of all changes to master data
3
Q
- Unauthorized disclosure of sensitive information
A
- 1 Access controls
2. 2 Encryption
4
Q
- Loss or destruction of data
A
3.1 Backup and disaster recovery plan procedures
5
Q
- Poor performance
A
4.1 Managerial reports
6
Q
Sales Order Entry
A
- Incomplete/inaccurate orders
- Invalid orders
- Uncollectible accounts
- Stockouts or excess inventory
- Loss of customers
7
Q
- Incomplete/inaccurate orders
A
- 1 Data entry controls
5. 2 Restriction of access to master data
8
Q
- Invalid orders
A
6.1 Digital signatures or written signatures
9
Q
- Uncollectible accounts
A
- 1 Credit limits
- 2 Specific authorization to approve sales to new customers or sales that exceed a customer’s credit limit
- 3 Aging of A/R
10
Q
- Stockouts or excess inventory
A
- 1 Perpetual inventory system control
- 2 Use of barcode or RFID
- 3 Training
- 4 Periodic physical counts of inventory
11
Q
- Loss of customers
A
9.1 CRM systems, self-help websites, and proper evaluation of customer service ratings
12
Q
Shipping
A
- Picking the wrong items
- Theft of inventory
- Shipping errors (delay or failure to ship, wrong quantities, wrong items, wrong addresses, duplication)
13
Q
- Picking the wrong items
A
- 1 Barcode & RFID
10. 2 Reconciliation of picking lists to sales order details
14
Q
- Theft of inventory
A
- 1 Restriction of physical access to inventory
- 2 Documentation of all inventory transfers
- 3 RFID and barcode
- 4 Periodic physical counts of inventory and reconciliation to recorded quantities
15
Q
- Shipping errors (delay or failure to ship, wrong quantities, wrong items, wrong addresses, duplication)
A
- 1 Reconciliation of shipping documents with sales orders, picking lists, and packing slips
- 2 Use RFID systems to identify delays
- 3 Data entry via bar-code scanners and RFID
- 4 Data entry edit controls (if shipping data entered on terminals)
- 5 Configuration of ERP system to prevent duplicate shipments