Accounting Information Systems
1. Administrative Security Controls management constraints, as well as operational and
accountability procedures fall under this category; include security policies and
procedures, security awareness and training, adequate supervision of employees, and
security reviews and audits
2. Application service provider a third party entity that deploys, hosts and manages access
to a packaged application and delivers software-based services and solutions to customers
across a wide area network from a central data center
3. Application Service Provider Benefits Less costly than purchasing software outright
increased flexibility; potentially improved customer service; and role in disaster recovery
plans
4. Application Service Provider Risks Psychological and behavioral factors; service
interruptions; compromised data; and inability to pay monthly fees
5. Availability Achieved when the required data can be obtained within the required time
frame
6. Availability the information is available when required by the business process, now and
in the future, it also concerns the safeguarding of necessary resources and associated
capabilities; which of CoBIT’s seven information crieteria does this decribe?
7. Benefits of E-Business Marketing: geographic market expansion, hard-to-reach markets,
more targeted marketing; reduced operating costs: marketing, telecommunications,
transaction processing; streamlined operations; quicker easier product and service delivery
8. A Business Process a set of procedures and policies designed to create value for some
organizational stakeholder, those stakeholders might include customers, stockholders,
employees or vendors
9. Business Risks and Threats to Information Systems Fraud; error; Service interruption
and delays; Disclosure of confidential information; Intrusions; Information Theft;
information manipulation; malicious software; denial-of-service attacks; web site
defacements; and extortion
10. Carter’s Four-Part Taxonomy for Computer Crime Target (crimes where the criminal
targets the system or its data); Instrumentality (uses the computer to futher a criminal end);
Incidental (crimes where the computer is not required for the crime but is related to the
criminal act); and associated (technological growth essentially creates new crime targets
and new ways of reaching victims)
11. Causes of ERP implementation failures poor leadership from top management;
automating existing redundant or non-value-added processes in the new system; unrealistic
expectations; poor project management; inadequate education and training; trying to
maintain the status quo; a bad match between ERP software and organizational processes;