1/150
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Information system
Consists of interrelated components (hardware, software, databases, and networks)
An Information system
captures raw and unorganized data, which is the input
processes and stores that data (action)
reports information in formats that are useful to users, which is the output
Accounting Information system
Performs the same process as Info system but specifically focuses on the exchange of economic resources. Collects, processes, stores, and analyzes data and reports information.
Data Analytics
The process of transforming data into useful information
Business processes
a group of related business events designed to accomplish the strategic objectives of the business
Business events/Activities generate data
data is then transformed into useable information
Four Basic business events/activities
Operating, Financing, Investing these three involve the exchange of economic resources, Information does not
Information Quality
refers to the suitability of information for a particular purpose in a specific task.
Data Integrity
which is the completeness, accuracy, reliability, and consistency of data throughout its life cycle in the information system is a high priority.
Fundamental Characteristics of Useful Information
Relevance & Faithful Representation (accuracy)
Relevance
Information must be capable of influencing a decision. Relevent information has three ingredients: predictive value, confirmatory value, materiality
Predictive value
Applicable to future events
Confirmatory Value
Ability to either confirm or change previous decisions.
Materiality
Signifiant impact on the decision (not including it would influence the decision)
Faithful Representation
Information must be unbiased and accurate. Faithfully represented information has three ingredients. Completeness, neutrality, free from error
Completeness
All information necessary is included
Neutrality
Not favoring a particular outcome
Free from Error
Does NOT mean information is perfectly accurate – just means there are no errors or omissions in the description of the phenomenon and that the process used to produce the information presented was selected and applied without errors in the process
Enhancing Characteristics of Useful Information
Verifiability, Timeliness, Understandability, Comparability
Verifiability
Information results in the same conclusions by independent and knowledgeable individuals.
Timeliness
Information is recent and available in time to influence relevant decisions.
Understandability
Information is easy to understand by being properly classified and
presented clearly.
Comparability
Information presents similar items in the same manner to make it easy to identify similarities and differences when necessary.
Risk
Is a likelihood of an unfavorable event occurring
Risk Assessment
identify, categorize, and prioritize risks so companies can determine how to manage the risks
Enterprise Risk Management (ERM)
is the comprehensive process of identifying, categorizing, prioritizing, and responding to a company’s risks
Four Basic Steps of ERM
1) Risk Identification 2) Risk Categorization 3) Risk Prioritization 4) Risk Response
A risk statement
contains two parts the issue and the possible outcome. Example: Drivers not receiving road safety training (the issue) may result in injuries to drivers and others (the possible outcome)
Internal Risks
occur throughout a company’s operations and arise during normal operations. Operational: Technology & Cyber, Financial, Reputational
o May relate to an external party but the risk arose from normal operations (e.g., reputation with customers arose from late deliveries). Can involve both internal and external risks.
External Risks
are risks that come from outside the company. Compliance, Strategic, Physical
o While external risks are often unpredictable, companies still prepare for them to the best of their abilities
Risk severity
Is the likelihood of risks occurring and their potential impact on the company
Likelihood
Is the estimated probability of risk occurrence
Impact
Is the estimation of damage that could be caused if the risk occurs
Risk Management
is a complex part of a business. It requires critical thinking and decision-making skills to understand the entire situation and come up with the appropriate combination of risk responses
Risk Appetitie
is the amount of risk a company is willing to take on at a particular time
Inherent Risk
is the natural level of risk in a business process or activity if there are no risk responses in place. Inherent risk consists of two parts—likelihood and impact
Residual Risk
is the remaining risk posed by a process or activity once a plan to respond to the risk is in place
The Four Traditional Risk Responses
Accept, Mitigate, Transfer, Avoid
Accept
Occurs when an inherent risk is present but the organization chooses not to act
Mitigate
Accept, but minimize its impact if it occurs, by internally implementing controls etc.
Transfer
Shifting of a risk to a third party
Avoid
Eliminates the risk by completely avoiding the events causing the risk
Can a company mitigate a residual risk to a zero?
NO
Internal Control
is a process that specifically mitigates risk to the company’s financial information
Proper Internal Controls can
Create quality information, identify financial issues, measure business objectives and goals, lessen the risk of financial misstatements, safeguard assets from theft and waste, ensure compliance with applicable laws and regulations, prevent fraud, increase operating efficiency, provide investors with reassurance
Management performs self assessments to determine the effectiveness of its own controls
The function of a control is to do one of the following
Prevent-prevent problems from happening (seg. of duties)
Detect-alert management to an issue once it has occurred
Correct-change undesirable outcomes and occur after a risk has occurred
Physical Controls-only one that does not regard a computer environment
governs human behavior. Examples: What to dress, what to do in emergencies. How you are supposed to act. Think of HR activities.
Information Technology General Controls
applies to the entire operation of the full system and its environment
IT General-Access Controls
password policies, multi-factor authentication (MFA)
IT general Controls-System development life cycle (SDLC) Controls
Change Management
IT General controls-Backup and recovery controls
Incremental, full
IT general controls-Controls over the data center
• Access – use of biometric devices to restrict access
• Location & Design: Raised floors, Fire detection & suppression, Air conditioning, Uninterruptible power supply (UPS)
Information Technology Application Controls
When a control only applies to a specific application – including all the business processes and accounts that are linked to it – it is known as an application control. Application controls are reliant on the ITGCs
**If there is a name of the system that is an application control
Several Benefits to application controls
• Reliability – because they are considered ‘programmed’ controls, once established, a company can rely on the control until a change occurs
• Benchmarking – if ITGCs covering change management and access are effective then so would any application controls – no need to test again and again and again
• Time & Cost Savings – not tied to frequency like manual controls – either the control is working or not – sampling is not needed
Three Classifications of Application Controls
Inputs-Fields & Records
Processing
Outputs
Field
Individual piece of data, columns
Record
Group of Fields becomes a record. Rows
Field Interrogation
involves programmed procedures to examine the characteristics of the data in the field:
o Common data input errors are (1) transcription (addition, truncation, or substitution) and (2) transposition errors.
o Check digits can help detect transcription and transposition errors. Need different check digits depending on what type of error you are trying to detect.
Check Digit
value calculated from the other digits and used to help validate the integrity of data when it is entered, before processing. Calculated value that is derived from the other digits to make sure we have good data integrity.
Transcription Error
a system could calculate and store the sum of digits as a check digit/value. For example: account #12345 would have a stored check digit/value of 15. When the account number is entered, the system recalculates the check digit/value before accepting the input for processing. An added or omitted non-zero digit will not result in a check digit/value of 15 and the error has been detected.
**Can apply many different controls to a single field
Transposition Error
popular check digit is called modulus 10. Let’s use universal product codes (UPCs) as an example. happens when two adjacent digits are accidentally reversed or swapped during data entry
Record Interrogation
procedures validate records by examining the interrelationship of its field values.
Reasonableness Check
determines if a value is reasonable when considered with other data fields.
Completeness Test
Is used to determine that required data items have been entered
Implementation: Manual
requires human judgement or physical interaction
Implementation: Automated
uses technology to implement a control activity
Difference between physical and manual controls
Manual controls are performed by people while physical controls mitigate risk related to people and their actions..
Manual controls are done by people, physical controls relate to people
A Framework
is a published set of specifications and criteria that defines a strategy to achieve certain objectives. Help provide a set of instructions for businesses to follow
o They are often referred to as a roadmap (path to follow but don’t specify what mode of transportation to use)
o They are not prescriptive - they only give an outline for companies to follow regarding how to approach a topic
Software sourcing
Whether they need systems software or application software,
companies must decide where to acquire it
Cloud Computing
provides access to shared resources over the internet, such as computer processing, software applications, data storage, and other services.
software as a service (SaaS)
Utilizes the internet to provide customers with applications that are managed by the third party provider. The software leverage that the providers data storage and IT infrastructure
User has little control
Platform as a Service (PaaS)
Provides customers a platform for software development that is delivered remotely. Developers have access to maintained operating systems, servers, storage, and networks and focus on design and building of application software. Middle control
Infrastructure as a service (IaaS)
Provides customers with fully self service computers, networking, storage, and operating systems through virtualized environments. Customers are responsible for managing all of their own operating systems, data, and applications. User has most control.
Opportunities of using the cloud
Cost savings, speed of deployment, reliability & scalability, decreased effort in managing own technology, hardware efficiency
Risks of using the cloud
Multi-tenant risks, lack of transparency, cloud service provider lock in, cyber attack target, data leakage, CSP viability, data location, shadow IT
Private Cloud
Exclusive for one business and always maintained on a private network. Least risky
Hybrid Cloud
Mixture between private and public cloud with a divider between the two.
Public Cloud
Available to public through a provider. Network is secured, however the user accesses these services through a web browser. Most risky.
Relational Database
Store structured data in two-dimensional tables of rows and columns. Tables in a relational database are connected in a specific order. Are designed to create meaningful connections between tables that can be leveraged for information creation.
Redundant Data
Not completely eliminated but greatly reduced
Update anomaly
Change the address only once
Delete Anomaly
Example: an invoice can be deleted while keeping data about the customer.
Insert anomaly
can add inventory items without having a lot of wasted blank fields.
Entity Relationship Diagram (ERD)
Need to diagram relationships among entities
Step 1: the conceptual ERD: Identifies high level entities and relationships. Identify the entities (concepts) the database will need to capture. Performed by business users/analysts to model the plans for the database.
Step 2: The Logical ERD: Adding Details. the conceptual ERD is enhanced by adding the field names and associated descriptions within each entity
Step 3: The Physical ERD: Implementing the Designed Model. Performed by the database designer
Primary Key
If a field uniquely identifies each record in a table. Primary Key can not be null (blank) which enforces Entity Integrity
Foreign Key
When a primary key from one table is referenced in another table. Foreign key can be null (blank) but if not blank, must have a value that corresponds to a value of a PK in another table which enforces Referential Integrity.
Business Rules
are written statements that precisely capture the business event occurring during a process as it relates to the entities in the database
• When written correctly, business rules define the entities, relationships, cardinalities, and constraints of the database
Data
Consists of facts and statistics about a person or object that are collected for reference or analysis
Structured Data
General ledger data, payroll info, tax returns, inventory records, etc.
Unstructured Data
emails, texts, PDFs, social media posts, photos, voice recordings. It is the vast majority of data being generated
Data Lake
Type of Data: unstructured and structured data from across the company (raw data)
Purpose: Cost-effective storage or big data
Users: Data scientists
Activities: Storing big data, Big data analytics (data science)
Scope of data: all of data in company
Data Warehouse
Type of Data: Historical data in a structured format designed for a relational database (processed data)
Purpose: Aggregated big data for analytics and business decissions
Users: Data Analysts
Activities: Supporting business analysis, read only queries for aggregating or extracting data
Scope of Data: Only relevant to analysis
5Vs of Big Data
1) Veracity: accuracy and truthfulness of data
2) Volume: huge amounts of data
3) Variety: Different formats of data from various sources
4) Value: Extract useful data
5) Velocity: High speed of accumulation of data
NoSQL Databases
responds to the increasingly velocity of big data and need for faster processing of unstructured data.
Stores each item individually, rather than in rows and columns, and retrieves items by using key values.
There is no structured schema.
Ideal for storing user generated content
provide more scalability than relational databases, designed to scale automatically when data volume is growing
Java Script Object Notation (JSON) used in NoSQL databases
JSON=human readable format to represent complex data structures
Each record can have its own set of fields (these records are not alike)
No rigid structure (its flexible)
Risk of NoSQL
Big data, NoSQL, and modern databases give organizations powerful tools but those tools must be designed and implemented correctly.
Poorly built systems create bad data, control failures, and business risks such as:
Inadequate system design may result in inaccurate, incomplete, or unreliable data (i.e., poor data integrity)
The Systems Development Lifecycle
Is a widely accepted framework used in software engineering and project management with stages/phases for creating and deploying new systems. Customized for a company’s unique risks and operations. Part of a company’s Information Technology General Controls (ITGC)
Robotic Process automation (RPA)
involves software that can be programmed and managed easily, using a drag and drop interface that does not require coding knowledge
Artificial Intelligence
involves computer systems that are trained to perform tasks that typically require human intelligence.
COSO Internal Control Internal Framework
Focused on controlling Risk: 3 Control Objectives: Operations, reporting, compliance