Вы находитесь на странице: 1из 12

Internal Control

FCPA ( Foreign Corrupt Practice Act)


Prevents Payments of corporate funds for
purposes that congress has determined to be
contrary to public polices.

Internal Control n Ethics.
Systems Controls
Segregation of Accounting duties for
authorization/ record keeping/custody.
Info Security
availability to use of computers by authorized
employees.
Confidentiality.
Integrity.


Internal Control n Ethics.
Threats to Info systems Malicious software/Malware.
Input Manipulation
Program Alteration
Direct File alteration
Data Theft
Sabotage
Viruses
Logic Bombs
Worms
Trojan
Back doors
Theft
Internal Control n Ethics.
System development Controls
4 basic functions on info input / processing
/ output/storage.
Setting of priorities - as new system are
aligned with strategic plans n conform with
organizational standards.
Changing to existing systems must be
authorized properly. Working Copy/ Testing
/code comparison / stirage.




Internal Control n Ethics.
Physical Controls
Physical access / environmental controls,
o Logical Controls
o Authentication IDs n PW.
o Authorization.


Internal Control n Ethics.
Input / Processing/Output Controls.
Input controls
Online Input controls when data is keyed in an input
screen
Performatting
Edit Checks
Limit Checks
Check Digits
Batch input controls
Mgt Release
Record Count
Financial Total
Hash Totals

Internal Control n Ethics.
Processing Controls
Validation
Completeness
Arithmetic controls
Sequence check
Run to run control total
Key integrity



Internal Control n Ethics.
Output controls
Audit trail
Error listings
Storage controls
Dual write routines
Validity checks
Physical controls

Internal Control n Ethics.
Security measures
Internet risks
PW attacks Brute force
attack/Spoofing/Sniffing
Man in middle attack
Denial of service attack
Use of data encryption
Encryption converts data into code.
Internal Control n Ethics.
Firewalls
Flow charting
Vertical flowchart - top bottom
Horizontal/ systems flowchart shows area of
responsibility.

Internal Control n Ethics.
Routine backup n offsite rotation
Disaster Recovery Planning
Contingency planning
Disaster recovery
Business continuity
Power Failure
Virus
Natural calimities. Hot/Warm/cold site.


Ethics
4 principles
H - Honesty
F - Fairness
O objectivity
R responsibility
4 standards
C competence
C confidentiality
I Integrity
C - Credibility

Вам также может понравиться