Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-13
be used, including user IDs, passwords, security tokens or smart cards,
that EnviroCons serves.
b. Explain how each control that you list can prevent IT related risks for
EnviroCons. Login procedures, including passwords, security tokens or
smart cards, and biometric devices, are needed to limit access to the
system to authorized users. Login procedures should always include
passwords, and may be strengthened to include two-factor authentication
by requiring a security token or smart card in addition to the password. In
addition, the company’s system policies should be documented and
administered consistently, including authority tables and establishment of
appropriate access levels and securities breach resolutions, and the
maintenance of computer logs. This will provide for limiting access to
c. Are there any general controls that you think would not be cost-beneficial?
Biometric devices, such as fingerprint or retina scans or voice recognition
software is probably not cost beneficial in the case of EnviroCons, as
other forms of two-factor authentication could be used just as effectively at
a lower cost.
60. Consideration of Internet EDI in a plastics manufacturing company. Required:
a. Describe the extra IT system risks that Plaskor should consider as it evaluates
whether to buy or develop an Internet EDI system. As Plaskor converts to an
Internet EDI system, it will become susceptible to a wide range of risks