1/49
Flashcards covering Distributed Data Planning, Centralized IT functions, Computer Center Security, Fault Tolerance, and Audit Objectives based on Accounting Information Systems (James Hall, 2016).
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is Distributed Data Planning (DDP)?
It involves reorganizing the IT function into small units that are distributed to end users and placed under their control.
In what two areas can Distributed Data Planning (DDP) reduce costs?
(1) Data can be entered and edited locally, eliminating centralized tasks of data conversion and data control; and (2) application complexity can be reduced, which reduces development and maintenance costs.
How does Distributed Data Planning (DDP) improve cost responsibility?
Management is empowered with the authority to make decisions about resources in their unit.
What three factors contribute to improved user satisfaction in a Distributed Data Planning (DDP) environment?
(1) Control of the resources that influence profitability, (2) more responsive systems professionals, and (3) active involvement in development.
What is the argument against Distributed Data Planning (DDP) regarding resource management?
Opponents argue that distributing responsibility for IT resources will inevitably lead to mismanagement and suboptimal utilization.
How can hardware and software incompatibilities affect an organization in a Distributed Data Planning (DDP) setup?
Dissimilar and incompatible operating systems, technology platforms, spreadsheets, word processors, and database packages can degrade and disrupt communications between organizational units.
Why do redundant tasks occur in Distributed Data Planning (DDP)?
Autonomous systems development activities distributed throughout the firm can result in each user area reinventing the wheel.
Why might Distributed Data Planning (DDP) lead to the consolidation of incompatible activities?
Distributing the IT function to individual user areas creates many very small units that may not permit the necessary separation of incompatible functions.
What difficulty do end-user managers face when hiring IT professionals in a Distributed Data Planning (DDP) environment?
End user managers may lack the knowledge to evaluate the technical credentials and relevant experience of candidates applying for computer professional positions.
In what areas do standards tend to be lacking in a Distributed Data Planning (DDP) environment?
Standards for developing and documenting systems, choosing programming languages, and acquiring hardware and software.
What is the mission of the centralized corporate IT function in a DDP structure?
It acts as a leaner unit providing technical advice and expertise to the various IT functions.
What is the corporate IT group's role regarding commercial software and hardware testing?
It evaluates the merits of competing vendor software and hardware, testing features, controls, and compatibility with standards, and making acquisition recommendations to user areas.
What assistance does the user services function of corporate IT provide?
It provides technical help to users during the installation of new software and in troubleshooting hardware and software problems.
How does the corporate IT group function as a standard setting body?
It establishes and distributes compliant standards for systems development, programming, and documentation to user areas.
Why is the corporate IT group better suited for personnel review than end users?
The corporate group is better equipped than users to evaluate the technical credentials of prospective system professionals.
What is the auditor's objective relating to organizational structure in a CIS environment?
To ascertain whether individuals serving in incompatible areas are segregated in accordance with the acceptable level of risk and in a manner that promotes an effective working environment.
What step should an auditor take regarding the corporate policy on computer security?
Obtain and review the corporate policy on computer security and verify that it is communicated to responsible employees and supervisors.
What documentation should an auditor review to identify incompatible functions?
Current organizational chart, mission statement, and job descriptions for key functions.
What must an auditor verify when reviewing system documentation and maintenance records for sample applications?
Verify that maintenance programmers assigned to specific projects are not also the original design programmers.
Why do auditors review operation room access logs?
To determine whether programmers enter the facility for reasons other than system failures.
Why do auditors review user roles?
To verify that programmers have access privileges consistent with their job description.
What double impact does an organization suffer if a computer center disaster occurs?
It loses its investment in data processing facilities and, more importantly, its ability to do business.
Why are physical computer center security weaknesses considered a control issue?
Because they have a potential impact on the functions of application controls related to the financial reporting process.
How should the physical location of a computer center be selected?
It should be located away from human-made and natural hazards.
What construction features are ideal for a computer center?
A single-story building of solid construction with controlled access, underground utility/communication lines, unopenable windows, and an air filtration system capable of excluding pollens, dust, and dust mites.
To whom should access to the computer center be strictly limited?
To the operators and other employees who work there.
What requirement is placed on programmers and analysts entering the computer center?
When occasionally needing to correct program errors, they must be required to sign in and sign out.
What main entrance security controls are recommended for a computer center?
Access through a single door monitored by closed-circuit cameras and video recording systems.
Why is adequate air conditioning often mandatory for mainframe computers?
Because providing adequate air conditioning is often a requirement of the vendor's warranty.
What are the optimal temperature and humidity levels for computer operation?
A temperature range of 70 to 75 degrees Fahrenheit and relative humidity of 50 percent.
What happens to computer hardware when temperatures depart significantly from the ideal range?
Logic errors can occur in the computer hardware.
What is the effect of low humidity on computer equipment?
It increases the risk of circuit damage from static electricity.
What are the effects of high humidity in a computer center?
It can cause molds to grow and paper products to swell and jam equipment.
What is the most common threat to a firm's computer center, and what is its consequence?
Fire is the most common threat; half of the companies that suffer fires go out of business due to the loss of critical records such as accounts receivable.
Where should automatic and manual fire alarms be connected?
They should be connected to a permanently staffed fire station.
Why must a computer center building be built to withstand water damage?
To withstand water damage that fire suppression equipment causes.
How should fire exits in a computer center be maintained?
They should be clearly marked and illuminated during a fire.
What is fault tolerance?
The ability of the system to continue operation when part of the system fails because of hardware failure, application program error, or operator error.
How does a Redundant Array of Independent Disks (RAID) work?
It uses parallel disks containing redundant elements of data and applications; if one disk fails, lost data are automatically reconstructed from redundant components on other disks.
What is the purpose of an Uninterruptible Power Supply (UPS)?
It helps prevent data loss and system corruption by providing short-term backup power during a power failure, allowing a controlled system shutdown.
What are the three audit objectives relating to computer center security?
(1) Determine if controls adequately protect from physical damage/losses; (2) determine if equipment insurance coverage is adequate; and (3) determine if operator documentation is adequate for system failures and routine operations.
What should an auditor inspect when testing the physical construction of a computer center?
Architectural plans to ensure fireproof material construction, adequate drainage under raised floors, and location away from fire, civil unrest, and hazards.
What elements should a computer center's fire detection system detect?
Smoke, heat, and combustible fumes.
How can an auditor obtain evidence that fire detection/suppression equipment is tested regularly?
By reviewing official fire marshal records of tests stored at the computer center.
How can an auditor verify the veracity of visitor access logs?
By covertly observing the processes by which access is permitted.
What risk exists if an organization does not employ RAID?
A potential single point of system failure exists.
What must an auditor verify regarding backup power supplies?
Verify from test records that periodic tests of the backup power supply are performed to ensure sufficient capacity to run the computer and air conditioning.
What procedure must an auditor follow annually regarding insurance coverage?
Annually review insurance coverage on hardware, software, and physical facilities, ensuring new acquisitions are listed and obsolete items deleted.
What is a run manual, and why is it important?
It is documentation used by computer operators to run systems (especially batch systems), and it must be sufficiently detailed to guide operators in their tasks.
What specific documentation items should an auditor verify are excluded from operator documentation?
Systems flowcharts, logic flowcharts, and program code listings.