L3 contemp tech note


Threats Faced by an AIS

  • Natural and Political Disasters: Risks arising from climate change and conflicts.

  • Software Errors and Hardware Malfunctions: Potential issues from hardware/software failures, software bugs, system crashes, power outages, and undetected data transmission errors.

  • Unintentional Acts: Accidents due to human error, poorly trained personnel, lost or erroneous data, and systems not meeting company needs (e.g., logic errors and design flaws).

  • Intentional Acts: Risks from sabotage, unauthorized data disclosure, asset misappropriation, and cyber threats like malware and social engineering.

Organizations must establish adequate controls to mitigate these threats.

Overview of Control Concepts

What is Control?

  • Control can be defined as "to order, limit, or rule something, or someone's actions or behaviour".

  • In an organizational context, this definition emphasizes controlling the actions or behaviors of staff to achieve the organization’s aims.

  • In the context of an Accounting Information System (AIS), control refers to limited actions/behaviours of people both inside and outside the organization, as well as controlling how systems function, including who has access to data and system features.

Internal Controls

An organization needs internal controls to:

  • Safeguard assets.

  • Maintain records for external reporting.

  • Provide reliable and accurate information from its records.

  • Prepare financial reports and any legally required reports.

  • Ensure managers have information to make decisions and run operations efficiently.

  • AIS is an integral part of such a control system.

Types of Internal AIS/IT Controls

  1. General Controls: Cover overall IT security, software acquisition, and development controls.

  2. Application Controls: Focus on preventing, detecting, and correcting errors and fraud in applications.

    • Preventative Controls: Deter problems before they arise.

    • Detective Controls: Detect problems when they arise.

    • Corrective Controls: Identify and correct problems, recovering from resulting errors.

General Controls

  • Control systems start with the recruitment of suitable staff and ensuring they are trained

Overview of Control Concepts

Control Concepts

Control concepts are essential for effective management within an organization, particularly in the context of an Accounting Information System (AIS). They can be categorized into three main types:

  1. Preventative Controls:

    • These controls are designed to deter problems before they occur. They aim to minimize the risk of errors or fraud by implementing procedures and policies. Examples of preventative controls include:

      • Security Policies: Establishing guidelines that protect organizational data and resources against unauthorized access.

      • Identity Verification: Utilizing passwords and biometric systems to ensure that only authorized personnel have access to sensitive information.

      • Authorization Levels: Implementing a principle of least privilege, where users are granted the minimum level of access necessary for their roles. Segregation of dutieso, Central trusted authentication systemso, systems development – restricted developer access e.g. only to test data,

      • System Development and Documentation: Ensuring that systems are developed with adequate documentation and controls from the beginning to mitigate potential risks.

  2. Detective Controls:

    • These controls are put in place to identify and respond to issues after they have arisen. The objective is to detect problems early to minimize their impact. Examples include:

      • Trial Balances: Regularly preparing these to ensure account balances are accurate and match expected values.

      • Internal Audits: Conducting periodic audits to review systems and controls, assessing compliance and effectiveness.

      • Log Analysis: Monitoring system logs for abnormal activities that might indicate security breaches or operational issues.

      • the review of policy procedures and controls•

      • periodic physical stock takes•

      • periodic reconciliations of balances

      • Continuous data auditing - real- time evaluation of systems to verify that they are operating in line with expected norms.

  3. Corrective Controls:

    • Once a problem has been detected, corrective controls are implemented to address issues and provide solutions. This type of control includes:

      • Software Patches: Applying updates to software to fix vulnerabilities or bugs that could be exploited.

      • Data Recovery Plans: Establishing procedures for restoring lost or corrupted data to ensure continuity of operations after a failure.

Organizations must effectively integrate these control concepts to safeguard assets, ensure reliable reporting, and facilitate efficient decision-making.


COSO Internal Control Framework

Internal Control and AIS

  • According to COSO (2013), the Accounting Information System (AIS) is a key element of internal control.

  • In 1992, COSO issued the Internal Control—Integrated Framework (IC), widely accepted as an authority on internal controls to control business activities.

COSO IC Framework 2013

The COSO Internal Control Framework consists of five components and 17 principles:

  1. Control Environment

  2. Risk Assessment

  3. Control Activities

  4. Information and Communication

  5. Monitoring

COSO – Control Environment

  • Reflects management’s philosophy, operating style, and risk appetite.

  • Commitment to integrity, ethical values, and competence.

  • Oversight of internal control by the Board of Directors.

  • Clear organizational structure and methods for assigning authority and responsibility.

  • Established human resource standards/policies.

COSO – Risk Assessment

Risk assessment is conducted from two perspectives:

  • Likelihood: Probability that an event will occur.

  • Impact: Estimate of the potential loss if the event occurs.

Types of Risk:
  • Inherent Risk: Risk that exists before any controls are implemented.

  • Residual Risk: Risk that remains after controls are put in place.

Response Options:
  • Reduce: Implement effective internal controls.

  • Accept: Accept the likelihood and impact of the risk without action.

  • Share: Utilize insurance, outsourcing, or hedging.

  • Avoid: Do not undertake the activity that poses the risk.

COSO – Control Activities

Key aspects include:

  • Proper authorization of transactions/activities.

  • Segregation of duties.

  • Controls over project development/acquisition.

  • Change management controls.

  • Appropriate design and use of documents and records.

  • Safeguarding of assets, records, and data.

  • Independent checks on performance.

COSO – Information/Communication

The information and communication process has three principles:

  1. Obtain or generate relevant, high-quality information to support internal control.

  2. Internally communicate the information, including objectives and responsibilities, to support the other components of internal control.

  3. Communicate relevant internal control matters to external parties.

COSO – Monitoring

Monitoring the control process is essential, and modifications should be made as necessary. Types of monitoring include:

  • Internal control evaluations (e.g. internal audits).

  • Effective supervision.

  • Use of responsibility accounting systems (e.g. budgets).

  • Monitoring system activities.

  • Tracking purchased software and mobile devices.

  • Conducting periodic audits (e.g. external, internal, network security).

  • Engaging AIS/IS security officers and forensic specialists.

  • Installing fraud detection software and setting up a fraud hotline.

Control Activities

  • Essential to ensure the effective functioning of internal controls within an AIS.

  • Types of controls include prior authorization of activities, segregation of duties, safeguarding assets, and independent checks.

Change Management Controls

  • Resistance to Change: Systems change may encounter resistance due to factors such as fear, poor communication, how change is introduced, and individual personalities.

    • Alleviation Strategies:

      • User involvement in the change process.

      • Good communication regarding changes.

      • Comprehensive training for users.

      • Support from top management.

  • Coverage of Change Management: It also encompasses actual system changes, such as user requests and modifications. Changes to systems functionality should be thoroughly tested and clearly documented.

Design and Use of Documents and Records

  • Proper design and use of input documents helps reduce errors.

    • The Input Design aspect of systems development focuses on how input documents and methods can achieve this. Considerations include:

      • Can input be automated (e.g., RFID, QR codes, voice input)?

      • Can data be logically grouped?

      • Is it easy to switch modes on input screens?

      • Are screens designed to minimize clutter?

      • Can errors be corrected easily, with informative error messages for incorrect data?

Safeguarding Assets, Records, and Data

  • Essential policies and procedures should be in place, such as:

    • Encrypting sensitive data.

    • Maintaining records of all computer and IT assets.

    • Restricting access to sensitive assets.

    • Protecting data through off-site storage and fire-proof measures.

Independent Checks on Performance

  • Management should perform regular reviews of organizational and AIS performance. Additional methods include:

    • Conducting internal and external audit tests.

    • Implementing continuous auditing of systems.

    • Employing double-entry systems; utilizing trial balances can provide useful summarized data.

Information Security Controls

Fundamental Information Security Concepts

  • Security is a Management Issue

    • Senior management involvement and support is essential.

  • People are a Critical Factor

    • Can be the "weakest link" in security or an important asset.

  • Time-based Model of Information Security

    • A combination of preventive, detective, and corrective controls protects information assets long enough to enable an organization to take steps before data/information is lost or compromised.

    • Security is effective if:

      • D + C

        • D = time it takes to break through preventive controls

        • C = time it takes to detect an attack in progress

        • Time it takes to respond to the attack and take corrective action.

Detecting Attacks on an AIS

  • Log Analysis: Examining logs to identify possible attacks.

  • Intrusion Detection Systems: Create logs of network traffic and analyze them for signs of attempted or successful intrusions.

  • Honeypots: Decoys used to provide early warning of attempts to search for confidential information.

  • Continuous Monitoring: Monitoring compliance with information security policies and overall performance of business processes, typically near-real-time monitoring.

  • Penetration Tests: Authorized attempts to break into the AIS.

  • Cloud Computing Security: Generally considered more secure than in-house solutions, with more sophisticated methods for detecting attacks and hacking.

Sophos MDR – An IDS Example

  • MDR = Managed Detection and Response

    • Cybersecurity-as-a-Service product offering industry solutions.


Maintaining Confidentiality and Privacy

Identifying and Classifying Information to be Protected

  • Determine what sensitive information needs protection.

  • Identify where sensitive information is located and who has access to it.

  • Classify the value of the information to the organization.

Protecting Sensitive Information with Encryption

  • Use encryption to protect sensitive information in transit and in storage.

Controlling Access to Sensitive Information

  • Information Rights Management (IRM): Manage who has access to sensitive content.

  • Data Loss Prevention (DLP): Systems to prevent the loss of sensitive data.

  • Digital Watermarks: Use watermarks for tracking and protecting sensitive information.

  • Data Masking: Hide sensitive data during processing and development.

  • Tokenization: Substitute sensitive data with non-sensitive token equivalents.

Training

  • Regularly train employees on data privacy and security practices.

Privacy Regulations

  • European Union’s General Data Privacy Regulation (GDPR):

    • Imposes fines up to €20 million or 4% of annual global revenue for non-compliance.

    • Requires organizations to demonstrate a proactive approach to privacy protection.

Key GDPR Rules

  • Personal data must be processed in a lawful and transparent manner ('lawfulness, fairness, and transparency').

  • Clearly indicate the specific purposes for which data is processed (e.g., 'purpose limitation').

  • Collect only the personal data necessary for its intended purpose ('data minimisation').

  • Ensure personal data is accurate and up-to-date ('accuracy').

  • Do not use personal data for incompatible purposes ('purpose compatibility').

  • Store personal data only as long as necessary ('storage limitation').

  • Implement appropriate safeguards to ensure data security ('integrity and


Encryption

  • Preventative Control: Encryption is classified as a preventative control that helps protect sensitive information from unauthorized access.

Factors Influencing Encryption Strength:
  • Key Length: Longer keys generally provide stronger encryption.

  • Algorithm: The type of encryption algorithm used can affect the strength.

Types of Encryption:
  1. Symmetric Encryption:

    • Single Key Use: Utilizes one key for both encryption and decryption.

    • Key Distribution: Both parties must know the key, necessitating secure communication of the shared key.

    • Unique Keys for Parties: Cannot share the same key with multiple parties; each party receives a unique key from the organization.

  2. Asymmetric Encryption:

    • Dual Key Use: Employs a pair of keys - a public key and a private key.

    • Public Key: Accessible by everyone; used for encrypting messages.

    • Private Key: Only known by the owner; used to decrypt messages encrypted with the public key.

    • Security Considerations: The protection of the private key is crucial for maintaining security.

    • Public Key Utility: Can be used by trading partners for secure communications.

    • Digital Signatures: Asymmetric encryption allows for the creation of digital signatures.

  • Understanding Encryption: It is important to be aware of the types of encryption but not necessarily how they operate in detail.

Virtual Private Network (VPN)

  • Definition: A VPN is an encrypted tunnel through the internet, providing secure communication.

  • Usage in Organizations: Most organizations implement VPNs to facilitate remote access to systems, including accounting systems.


Data/Systems Integrity and Availability

  • Ensuring accuracy and reliability of information processed.

  • Implementing controls to maintain data integrity and system availability crucial for operational continuity.


Input Controls

Data entry controls are safeguards designed to ensure that the information being entered into the system is accurate, authorized, and complete:

  • Field Check: Ensures that the characters in a field are of the proper type (e.g., numbers, letters).

  • Sign Check: Verifies that the data in a field has the appropriate sign (positive or negative).

  • Limit Check: Tests a numerical amount against a fixed value to ensure it does not exceed specified limits.

  • Range Check: Tests a numerical amount against defined lower and upper limits to validate that it falls within an acceptable range.

  • Size Check: Confirms that input data fits within the allocated field size, preventing overflow.

  • Completeness Check: Verifies that all required data fields are filled before processing.

  • Validity Check: Compares data from the transaction file to that of the master file to ensure the entered data exists and is valid.

  • Reasonableness Test: Evaluates the logical relationship between two data items to confirm their accuracy.

  • Check Digit Verification: Involves recalculating a check digit to verify that a data entry error has not occurred.

Data Processing Controls

Data processing controls focus on the proper handling, manipulation, and processing of data after it has been entered:

  • Data Matching: Requires items to match before an action takes place, ensuring authenticity and accuracy.

  • File Labels: Ensures that the correct and most updated file is used during processing to avoid errors.

  • Cross-Footing: Verifies accuracy by comparing two alternative methods of calculating the same total, helping to identify discrepancies.

  • Zero-balance tests For control accounts (e.g., wages control a\c)

  • Write-protection mechanisms Protect against overwriting or erasing data

  • Concurrent update controls- Prevent error of two or more users updating the same record at the same time


Output Controls

  • User Review: Periodic review by users to ensure data accuracy and process integrity.

  • Reconciliation Procedures:

    • Procedures to reconcile control reports (e.g., comparing the general ledger to accounts receivable ledger).

  • Data Transmission Controls:

    • Checksums: Verifies the integrity of data during transmission.

    • Parity Bits (Check Bit): Ensures that the number of bits with the value one is even or odd, detecting errors in data transmission.

    • Blockchain: A decentralized ledger technology ensuring secure and transparent transactions (covered in more detail in later lectures).

Systems Availability

  • Increasingly important for all organizations, illustrated by services like AWS that host applications such as Sage accounting software.

  • % Uptime Calculation: ( \text{uptime} / (\text{uptime} + \text{downtime}) )

  • Downtime:

    • Can be planned (for maintenance), but unplanned downtime is more concerning.

Systems Availability Controls

  • Preventive Maintenance: Regular maintenance to prevent failures.

  • Fault Tolerance:

    • Use of redundant components to ensure continued operation despite failures.

  • Data Center Location and Design:

    • Raised Floor: Facilitates cooling and cable management.

    • Fire Suppression: Systems in place to manage fire hazards.

    • Air Conditioning: Maintains optimal operating temperatures for equipment.

    • Uninterruptible Power Supply (UPS): Provides backup power during outages.

    • Surge Protection: Safeguards against voltage spikes.

    • Experience: Example of Tennessee bunker as a unique data center design.

  • Training: Ensuring staff are well-equipped to handle systems effectively.

  • Patch Management and Antivirus Software: Regular updates to safeguard against vulnerabilities.

  • Backup Procedures:

    • Incremental Backup: Copies only items that have changed since the last partial backup.

    • Differential Backup: Copies all changes made since the last full backup.

  • Disaster Recovery Plan (DRP):

    • Procedures to restore IT functions after a disruption.

    • Cold Site: A backup facility with minimal equipment.

    • Hot Site: Fully operational facility ready for immediate use.

  • Business Continuity Plan (BCP):

    • Comprehensive strategies to resume all operational aspects, not just IT.

  • Periodic Testing:

    • Regular testing of DRP and BCP to ensure effectiveness and readiness for actual events.

    • Helps identify weaknesses and areas for improvement for both plans.