Test 2 Flashcards
What are some threats to AIS?
Natural and Political Disasters
Software errors and equipment malfunctions
Unintentional acts - human errors and omissions
Intentional acts - computer crimes/sabotage
What is the greatest risk to information systems and causes the greatest cumulative dollar losses?
Unintentional acts - human errors and omissions
What is Fraud?
Any and all means a person uses to gain an unfair advantage over another person
What are the two most common types of fraud?
Misappropriation of assets (e.g. theft of company assets by employees)
Fraudulent financial reporting (e.g. intentional or reckless conduct)
What are the Three Keys parts of the Fraud Triangle?
Pressure: person’s incentive or motivation for committing fraud
Rationalization: excuse that person uses to justify their illegal behavior
Opportunity: condition or situation that allows a person or organization to commit and conceal fraud
Why is a high percentage of fraud not recorded?
Don’t want adverse publicity resulting from copycat fraud
What is the simplest and most common way to commit computer fraud?
Input
E.g. alter source documents
What is unauthorized system use?
Processor
What is tampering with computer software, copying software illegally, using software in an unauthorized manner, and developing software to carry out an unauthorized activity?
Computer instructions
What is illegally using, copying, browsing, searching, or harming company data (“data breach”)?
Data
What is displayed or printed output that can be stolen, copied, or misused unless properly safeguarded?
Output
Why is control needed?
Threat/event - potential adverse occurrence
Exposure/impact - potential dollar loss
Likelihood/risk - probability
What are Internal Controls?
Ongoing processes/procedures implemented to provide reasonable assurance that control objectives are met
What are some of the control objectives?
Safeguard assets
Maintain records
Provide accurate and reliable information
Prepare financial reports in accordance with established criteria
Promote and improve operational efficiency
Encourage adherence to prescribed managerial policies
Comply with applicable laws and regulations
What are the 2 categories of Internal Controls?
General - make sure control environment is stable and well managed
Application - preventative, detective, and corrective with problems