Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Management Information System Expert

Problem 1

Segregation of duties in the personal computing environment:

What role should the HR organization play in this space? Also, what about the culture of the organization and its role in ensuring compliance?

Problem 2

Provide examples (include citations) of how control activities (access control, segregation of duties, transaction authority, supervision, accounting records, for example) have been implemented along with how they have helped or failed to mitigate risks within an organization.

Problem 3

Look at the specifics in the changes made between SAS 70 and SSAE 16. Select a specific change and share your thoughts on whether the change makes an improvement or not. Support your assertion.

Problem 4

Reply to the reading below:

• What is the purpose behind segregation of duties in the personal computing environment?

Special considerations should be taken when auditing the personal computer environment. The challenge arises from the mobility or fluidity attributed to personal computing and the lack of internal control features usually found in larger, enterprise-wide systems. In this context, the general purpose behind segregation of duties (SoD) is to prevent unauthorized access or modification to the operating system(s), applications, or data found in a multi-user computer system by a single individual or party. For example, management can employ different techniques to prevent unauthorized access to a specific resource including the use of hidden files or secret file names, and employing passwords and cryptography (Gupta, 2005). In particular, these controls can be specifically divided into preventive, detective, and corrective. As aforementioned, preventive controls include aspects such as usernames (IDs) and passwords used by all modern operating systems prior to granting access to a particular user. Additional preventive controls may inhibit the same individual from being in charge of developing, maintaining, and running a specific financial software. Detective controls can be achieved by restricting access via physical security measures as well as logical approaches such as detecting inaccurate data being uploaded to a financial application. Corrective controls can be achieved via audit trails and exception reports. If any control weaknesses are found in the SoD process, direct supervision and work reviews should be enforced to counteract the deficiencies.

• Why is inadequate segregation of duties a problem in the personal computing environment?

Without proper SoD, unauthorized access to data and applications can occur in a variety of ways. For example, there is an inherent risk in having a single individual in charge of data processing also possess the ability to change program files. This increases the chances of errors going undetected or, in the worst cases, the potential for concealment and fraud. An employee may also have access to multiple applications that process incompatible transactions. For example, a single individual may be responsible for entering all transaction data, including sales orders, cash receipts, invoices, and disbursements. This degree of authority would be similar, in a manual system, to assigning accounts receivable, accounts payable, cash receipts, cash disbursement, and general ledger responsibility to the same person (Hall, 2011).

Problems 5

Reply to the reading below:

What is the purpose behind segregation of duties in the personal computing environment?

The personal computer (PC) is intended to be used by a single user. The user has individual applications, files, and access to the computer. However, a company could have general PCs available to all employees with applications that store and manipulate customer data, keep inventory, handle accounting functions, access on-line applications, and surf the internet. Separation of duties is a key internal control concept. (Hall, 2011) The purpose of segregation of duties is to minimize incompatible functions. No single person should have control over an entire transaction. For example, the secretary should not have access to accounting information. The accountant shouldn't have access to inventory and customer information. The duties of authorization, custody of assets and record-keeping should be the responsibility of three different people - each trained in that particular duty. Duties are considered to be incompatible if one person can get into the system and hide irregularities while performing day-to-day activities without detection.

Why is inadequate segregation of duties a problem in the personal computing environment?

Many small companies may have access to multiple applications that perform incompatible tasks. For example, one person may be in charge of entering employee and customer information, invoices, payments, and other such transactions. If all of these transactions are performed on a general company PC, the other employees could access the applications and manipulate the data. Also, other employees that are not trained in the applications could inadvertently change information and data on the PC. Without individualized password protection on the PC itself and each application, there is no way to tell who is responsible for any errors that occur.

Management Information System, Management Studies

  • Category:- Management Information System
  • Reference No.:- M9130914
  • Price:- $35

Priced at Now at $35, Verified Solution

Have any Question?


Related Questions in Management Information System

Ransomwareto pay or not to pay when it comes to corporate

Ransomware: To pay or not to pay? When it comes to corporate data, should corporations pay? Can you trust paying? What can be done to protect against ransomware? Would you pay if it were your own personal data? How can y ...

Discussionnbsp 300 words with 2 referencesyou have been

Discussion  : 300 Words with 2 references You have been working for four years in a bank branch located in the front section of a large grocery store. For the last two years, the branch has been underperforming and a poo ...

Distributive bargainingany of the parties involved in the

Distributive Bargaining Any of the parties involved in the negotiation tries to get the maximum advantage by applying the tactics. According to Batra, generally, the negotiation processes are handled by using two approac ...

Project titlesecurity lapses and data breaches an

Project title:Security Lapses and Data Breaches: An Examination of the Failures to Protect Business Data and their Consequences Write up 3 problems/questions that related to the project title. I wrote some details in pro ...

Assessment instructionspreparationuse the organization and

Assessment Instructions Preparation Use the organization and characteristics, described in the Mega-Corp Case Study as the context in which to answer the bullet points in this assessment. Additional Background Mega-Corp ...

Assignmentaccording to kirk 2016 viewers need some

Assignment According to Kirk (2016), viewers need some assistance consuming visualizations. Annotations can be used to help explain certain features of a visualization. To aid viewers with understanding what the project ...

Question - are ltc beds the only place to put us are there

Question - Are LTC beds the only place to put us? Are there other alternatives that are more cost-efficient? Given issues of quality -- either perceived or actual -- in many LTCs, do we really even want to keep tradition ...

1-consider how deming and tqm would have dealt with the

1- Consider how Deming and TQM would have dealt with the problems at Boeing () 2 - What Does a TQM initiative look like in an IT dept? 3 - How would IT support total quality at Boeing? (can summarize these above 3 questi ...

Suppose we have the following context-free grammar which

Suppose we have the following context-free grammar which accepts a list of variable initializations. Goal ::= single | Goal single single ::= VAR "=" exp ";" exp ::= VAR | INT | exp + exp Here each V AR terminal can be m ...

Assignmentthe operating system os of an information system

Assignment The operating system (OS) of an information system contains the software that executes the critical functions of the information system. The OS manages the computer's memory, processes, and all of its software ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As