Comprehensive Study Notes on CIS Audit, Distributed Data Planning, Computer Center Security, and Controls

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/49

flashcard set

Earn XP

Description and Tags

Flashcards covering Distributed Data Planning, Centralized IT functions, Computer Center Security, Fault Tolerance, and Audit Objectives based on Accounting Information Systems (James Hall, 2016).

Last updated 1:45 AM on 9/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

50 Terms

1
New cards

What is Distributed Data Planning (DDP)?

It involves reorganizing the IT function into small units that are distributed to end users and placed under their control.

2
New cards

In what two areas can Distributed Data Planning (DDP) reduce costs?

(1) Data can be entered and edited locally, eliminating centralized tasks of data conversion and data control; and (2) application complexity can be reduced, which reduces development and maintenance costs.

3
New cards

How does Distributed Data Planning (DDP) improve cost responsibility?

Management is empowered with the authority to make decisions about resources in their unit.

4
New cards

What three factors contribute to improved user satisfaction in a Distributed Data Planning (DDP) environment?

(1) Control of the resources that influence profitability, (2) more responsive systems professionals, and (3) active involvement in development.

5
New cards

What is the argument against Distributed Data Planning (DDP) regarding resource management?

Opponents argue that distributing responsibility for IT resources will inevitably lead to mismanagement and suboptimal utilization.

6
New cards

How can hardware and software incompatibilities affect an organization in a Distributed Data Planning (DDP) setup?

Dissimilar and incompatible operating systems, technology platforms, spreadsheets, word processors, and database packages can degrade and disrupt communications between organizational units.

7
New cards

Why do redundant tasks occur in Distributed Data Planning (DDP)?

Autonomous systems development activities distributed throughout the firm can result in each user area reinventing the wheel.

8
New cards

Why might Distributed Data Planning (DDP) lead to the consolidation of incompatible activities?

Distributing the IT function to individual user areas creates many very small units that may not permit the necessary separation of incompatible functions.

9
New cards

What difficulty do end-user managers face when hiring IT professionals in a Distributed Data Planning (DDP) environment?

End user managers may lack the knowledge to evaluate the technical credentials and relevant experience of candidates applying for computer professional positions.

10
New cards

In what areas do standards tend to be lacking in a Distributed Data Planning (DDP) environment?

Standards for developing and documenting systems, choosing programming languages, and acquiring hardware and software.

11
New cards

What is the mission of the centralized corporate IT function in a DDP structure?

It acts as a leaner unit providing technical advice and expertise to the various IT functions.

12
New cards

What is the corporate IT group's role regarding commercial software and hardware testing?

It evaluates the merits of competing vendor software and hardware, testing features, controls, and compatibility with standards, and making acquisition recommendations to user areas.

13
New cards

What assistance does the user services function of corporate IT provide?

It provides technical help to users during the installation of new software and in troubleshooting hardware and software problems.

14
New cards

How does the corporate IT group function as a standard setting body?

It establishes and distributes compliant standards for systems development, programming, and documentation to user areas.

15
New cards

Why is the corporate IT group better suited for personnel review than end users?

The corporate group is better equipped than users to evaluate the technical credentials of prospective system professionals.

16
New cards

What is the auditor's objective relating to organizational structure in a CIS environment?

To ascertain whether individuals serving in incompatible areas are segregated in accordance with the acceptable level of risk and in a manner that promotes an effective working environment.

17
New cards

What step should an auditor take regarding the corporate policy on computer security?

Obtain and review the corporate policy on computer security and verify that it is communicated to responsible employees and supervisors.

18
New cards

What documentation should an auditor review to identify incompatible functions?

Current organizational chart, mission statement, and job descriptions for key functions.

19
New cards

What must an auditor verify when reviewing system documentation and maintenance records for sample applications?

Verify that maintenance programmers assigned to specific projects are not also the original design programmers.

20
New cards

Why do auditors review operation room access logs?

To determine whether programmers enter the facility for reasons other than system failures.

21
New cards

Why do auditors review user roles?

To verify that programmers have access privileges consistent with their job description.

22
New cards

What double impact does an organization suffer if a computer center disaster occurs?

It loses its investment in data processing facilities and, more importantly, its ability to do business.

23
New cards

Why are physical computer center security weaknesses considered a control issue?

Because they have a potential impact on the functions of application controls related to the financial reporting process.

24
New cards

How should the physical location of a computer center be selected?

It should be located away from human-made and natural hazards.

25
New cards

What construction features are ideal for a computer center?

A single-story building of solid construction with controlled access, underground utility/communication lines, unopenable windows, and an air filtration system capable of excluding pollens, dust, and dust mites.

26
New cards

To whom should access to the computer center be strictly limited?

To the operators and other employees who work there.

27
New cards

What requirement is placed on programmers and analysts entering the computer center?

When occasionally needing to correct program errors, they must be required to sign in and sign out.

28
New cards

What main entrance security controls are recommended for a computer center?

Access through a single door monitored by closed-circuit cameras and video recording systems.

29
New cards

Why is adequate air conditioning often mandatory for mainframe computers?

Because providing adequate air conditioning is often a requirement of the vendor's warranty.

30
New cards

What are the optimal temperature and humidity levels for computer operation?

A temperature range of 70 to 75 degrees Fahrenheit and relative humidity of 50 percent.

31
New cards

What happens to computer hardware when temperatures depart significantly from the ideal range?

Logic errors can occur in the computer hardware.

32
New cards

What is the effect of low humidity on computer equipment?

It increases the risk of circuit damage from static electricity.

33
New cards

What are the effects of high humidity in a computer center?

It can cause molds to grow and paper products to swell and jam equipment.

34
New cards

What is the most common threat to a firm's computer center, and what is its consequence?

Fire is the most common threat; half of the companies that suffer fires go out of business due to the loss of critical records such as accounts receivable.

35
New cards

Where should automatic and manual fire alarms be connected?

They should be connected to a permanently staffed fire station.

36
New cards

Why must a computer center building be built to withstand water damage?

To withstand water damage that fire suppression equipment causes.

37
New cards

How should fire exits in a computer center be maintained?

They should be clearly marked and illuminated during a fire.

38
New cards

What is fault tolerance?

The ability of the system to continue operation when part of the system fails because of hardware failure, application program error, or operator error.

39
New cards

How does a Redundant Array of Independent Disks (RAID) work?

It uses parallel disks containing redundant elements of data and applications; if one disk fails, lost data are automatically reconstructed from redundant components on other disks.

40
New cards

What is the purpose of an Uninterruptible Power Supply (UPS)?

It helps prevent data loss and system corruption by providing short-term backup power during a power failure, allowing a controlled system shutdown.

41
New cards

What are the three audit objectives relating to computer center security?

(1) Determine if controls adequately protect from physical damage/losses; (2) determine if equipment insurance coverage is adequate; and (3) determine if operator documentation is adequate for system failures and routine operations.

42
New cards

What should an auditor inspect when testing the physical construction of a computer center?

Architectural plans to ensure fireproof material construction, adequate drainage under raised floors, and location away from fire, civil unrest, and hazards.

43
New cards

What elements should a computer center's fire detection system detect?

Smoke, heat, and combustible fumes.

44
New cards

How can an auditor obtain evidence that fire detection/suppression equipment is tested regularly?

By reviewing official fire marshal records of tests stored at the computer center.

45
New cards

How can an auditor verify the veracity of visitor access logs?

By covertly observing the processes by which access is permitted.

46
New cards

What risk exists if an organization does not employ RAID?

A potential single point of system failure exists.

47
New cards

What must an auditor verify regarding backup power supplies?

Verify from test records that periodic tests of the backup power supply are performed to ensure sufficient capacity to run the computer and air conditioning.

48
New cards

What procedure must an auditor follow annually regarding insurance coverage?

Annually review insurance coverage on hardware, software, and physical facilities, ensuring new acquisitions are listed and obsolete items deleted.

49
New cards

What is a run manual, and why is it important?

It is documentation used by computer operators to run systems (especially batch systems), and it must be sufficiently detailed to guide operators in their tasks.

50
New cards

What specific documentation items should an auditor verify are excluded from operator documentation?

Systems flowcharts, logic flowcharts, and program code listings.