Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-1
Turner/Accounting Information Systems, 2e
Solutions Manual
Chapter 4
Concept Check
1. d
2. b
3. c
4. a
5. a
6. a
Discussion Questions
14. (SO 1) What is the difference between general controls and application controls?
General controls are internal controls that apply overall to the IT accounting
complete and that outputs are properly distributed, controlled, and disposed.
15. (SO 1) Is it necessary to have both general controls and application controls to have
a strong system of internal controls? Yes, it is necessary to have both types of
16. (SO 2) What kinds of risks or problems can occur if an organization does not
authenticate users of its IT systems? If an organization does not authenticate users
of its IT systems, a security breach may occur in which an unauthorized user may be
able to gain access to the computer system. If hackers or other unauthorized users
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-2
17. (SO 2) Explain the general controls that can be used to authenticate users. In order
to authenticate users, organizations must limit system log-ins exclusively to
authorized users. This can be accomplished by requiring login procedures, including
user IDs and passwords. Stronger systems use biometric identification or security
18. (SO 2) What is two-factor authentication with regard to smart cards or security
tokens? Two-factor authentication limits system log-ins to authorized users by
19. (SO 2) Why should an organization be concerned about repudiation of sales
transactions by the customer? Repudiation is the attempt to claim that the customer
was not part of a sales transaction that has taken place. Organizations may suffer
losses if customers repudiate sales transactions. If companies do not have adequate
20. (SO 2) A firewall should inspect incoming and outgoing data to limit the passage of
unauthorized data flow. Is it possible for a firewall to restrict too much data flow?
Yes, it is possible for a firewall to restrict legitimate data flow as well as unauthorized
21. (SO 2) How does encryption assist in limiting unauthorized access to data?
Encryption is the process of converting data into secret codes referred to as cipher
text. Encrypted data can only be decoded by those who possess the encryption key
Chapter 4 Solutions Internal Controls and Risks in IT Systems
22. (SO 2) What kinds of risk exist in wireless networks that can be limited by WEP,
WPA, and proper use of SSID? WEP, WPA, and SSIDs can limit the risk of
unauthorized access to wireless networks, which transmit network data as high
23. (SO 2) Describe some recent news stories you have seen or heard regarding
computer viruses. Student responses will vary greatly depending upon the date this
24. (SO 2) What is the difference between business continuity planning and disaster
recovery planning? How are these two concepts related? Business continuity
planning is a proactive program for considering risks to the continuation of business
and developing plans and procedures to reduce those risks so that continuation of
25. (SO 2) How can a redundant array of independent disks (RAID) help protect the data
of an organization? RAID accomplishes redundant data storage by setting up two or
more disks as exact mirror images. This provides an automatic backup of all data. If
one disk drive fails, the other (maintained on another disk drive) can serve in its
place.
26. (SO 2) What kinds of duties should be segregated in IT systems? In an IT system,
27. (SO 2) Why do you think the uppermost managers should serve on the IT
governance committee? An IT governance committee should be comprised of top
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-4
28. (SO 3,4) Why should accountants be concerned about risks inherent in a complex
software system such as the operating system? Accountants need to be concerned
29. (SO 4) Why is it true that increasing the number of LANs or wireless networks within
an organization increases risks? Increasing the number of LANs or wireless
30. (SO 4) What kinds of risks are inherent when an organization stores its data in a
database and database management system? Since a database management
system involves multiple use groups accessing and sharing a database, there are
31. (SO 4) How do telecommuting workers pose IT system risks? The network
equipment and cabling that enables telecommuting can be an entry point for hackers
32. (SO 4) What kinds of risks are inherent when an organization begins conducting
business over the Internet? The Internet connection required to conduct web-based
business can expose the company network to unauthorized use. The sheer volume
of users of the World Wide Web dramatically increases the potential number of
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-5
33. (SO4) How does the use of public cloud computing reduce costs? Since cloud
34. (SO4) Why is a private cloud less risky than a public cloud? A private cloud is
developed, owned, maintained, and used by the user company; therefore, the
company controls the security, availability, processing integrity, and confidentiality of
its data. Accordingly, there is significantly less risk of losing data and applications.
35. (SO 4) Why is it true that the use of EDI means that trading partners may need to
grant access to each other’s files? EDI involves transferring electronic business
36. (SO 5) Why is it critical that source documents be easy to use and complete?
37. (SO 5) Explain some examples of input validation checks that you have noticed
when filling out forms on websites you have visited. Student responses are likely to
38. (SO 5) How can control totals serve as input, processing, and output controls?
Control totals can be used as input controls when they are applied as record counts,
39. (SO 5) What dangers exist related to computer output such as reports? Output
reports contain data that should not fall into the wrong hands, as the information
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-6
Brief Exercises
40. (SO 2,5) Categorize each of the following as either a general control or an
application control:
a. validity check application control (input)
b. encryption general control
41. (SO 5) Each of the given situations is independent of the other. For each, list the
programmed input validation check that would prevent or detect the error.
a. The zip code field was left blank on an input screen requesting a mailing
address. Completeness check
b. A state abbreviation of “NX” was entered in the state field. Validity check
42. (SO 3) For each AICPA Trust Services Principles category shown, list a potential
risk and a corresponding control that would lessen the risk. An example is provided.
In a similar manner, list a risk and control in each of the following categories:
a. Security. Risk: an unauthorized user could record an invalid transaction.
Control: security token to limit unauthorized users.
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-7
43. (SO 4) For each of the following parts of an IT system of a company, write a one
sentence description of how unauthorized users could use this as an “entry point”:
a. A local area network (LAN). Each workstation or the network wiring on the
LAN are access points where someone could tap into the system.
44. (SO 5) Explain the risk categories for cloud computing and how these risks may
differ from a company that maintains its own IT hardware, software, and data.
Security All processing, storing, and reading data occur over the Internet under
a cloud computing model; therefore, the third party provider must maintain good
security controls. For a company that maintains its own data, it is responsible for
its own security.
Availability In a cloud computing model, any service interruptions are under the
45. (SO 5) Application controls include input, processing, and output controls. One type
of input control is source document controls. Briefly explain the importance of each
of the following source document controls:
a. Form design. A well-designed form will reduce the chance of erroneous or
incomplete data. It could also increase the speed at which the form is
completed.
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-8
46. (SO 5) Explain how control totals such as record counts, batch totals, and hash
totals serve as input controls, processing controls, and output controls. Control totals
47. (SO 6) Briefly explain a situation at your home, university, or job in which you think
somebody used computers unethically. Be sure to include an explanation of why you
Problems
48. (SO 1, 2) Explain why an organization should establish and enforce policies for its IT
systems in the following areas regarding the use of passwords for login:
a. Length of password. Passwords should be at least eight characters in
length. This would make it difficult for a hacker to guess the password in
order to gain unauthorized access to the system.
d. Rotation of passwords. Passwords should be changed periodically,
approximately every 90 days. This will limit the access of a hacker who
has gained unauthorized access.
49. (SO 2) The use of smart cards or tokens is called two-factor authentication. Answer
the following questions, assuming that the company you work for uses smart cards
or tokens for two-factor authentication.
Required:
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-9
a. What do you think the advantages and disadvantages would be for you as
a user? As a user, the advantages of two-factor authentication would be
the security of the information in the system that I am using. I would know
that it would be difficult for an unauthorized user to alter a system that
uses two-factor authentication, so I have more confidence in the data
b. What do you think the advantages and disadvantages would be for the
company? From the company’s perspective, the advantage of two-factor
authentication is the strength of the extra level of security. The company
50. (SO 4) Many IT professionals feel that wireless networks pose the highest risks in a
company’s network system.
Required:
a. Why do you think this is true? Wireless networks pose the highest risks in
a company’s network computer system because the network signals are
transported through the air (rather than over cables). Therefore, anyone
who can receive radio signals could potential intercept the company’s
51. (SO 5) Control totals include batch totals, hash totals, and record counts. Which of
these totals would be useful in preventing or detecting IT system input and
processing errors or fraud described as follows?
a. A payroll clerk accidentally entered the same time card twice. Any of the
three control totals could be used: A batch total could detect that too many
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-10
d. To create a fictitious employee, a payroll clerk removed a time card for a
recently terminated employee and inserted a new time card with the same
hours worked. A record count could detect this fraud only if there was a
control in place to compare the number of records processed with the
number of active employees and the number of active employees had
been updated to reflect a reduction for the recently terminated employee.
52. (SO 5) Explain how each of the following input validation checks can prevent or
detect errors:
a. A field check examines a field to determine whether the appropriate type
of data was entered. This will detect mistakes in input, such as erroneous
d. A range check verifies field inputs by making sure that they fall within a
pre-established range limit. This prevents gross overstatements and
understatements of the data beyond the acceptable limits.
e. A reasonableness check compares the value in a field with similar,
related fields to determine whether the value seems reasonable. This can
detect possible errors by identifying “outliers”.
f. A completeness check assesses the critical fields in an input screen to
make sure that an entry has been input in those fields. This detects
possible omissions of critical information.
Chapter 4 Solutions Internal Controls and Risks in IT Systems
i. A self-checking digit is an extra digit added to a coded identification
number, determined by a mathematical algorithm. This detects potential
errors in input data.
53. (SO 2) The IT governance committee should comprise top level managers.
Describe why you think that is important. What problems are likely to arise with
regard to IT systems if the top level managers are not involved in IT governance
committees? It is important for an IT governance committee to be comprised of
54. (SO 2) Using a search engine, look up the term “penetration testing.” Describe the
software tools you find that are intended to achieve penetration testing. Describe the
types of systems that penetration testing is conducted upon. Software tools that
55. (SO 2) Visit the AICPA website at www.aicpa.org. Search for the terms “WebTrust”
and “SysTrust.” Describe these services and the role of Trust Services Principles in
these services. WebTrust services are professional services that build trust and
56. (SO 2) Using a search site, look up the terms “disaster recovery,” along with “9/11.”
The easiest way to search for both items together is to type into the search box the
following: “disaster recovery” “9/11.” Find at least two examples of companies that
have changed their disaster recovery planning since the terrorist attacks on the
World Trade Center on September 11, 2001. Describe how these companies
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-12
program was not effective.
57. (SO 5) Go to any website that sells goods. Examples would be BestBuy, Staples,
and J.Crew. Pretend that you wish to place an order on the site you choose and
complete the order screens for your pretend order. Do not finalize the order;
otherwise, you will have to pay for the goods. As you complete the order screens,
58. (SO4) Using an Internet search engine, search “cloud computing” and create a list of
at least ten companies that provide cloud computing services. List the names of the
Cases
59. Authentication and hacking controls at an environmental consulting company.
Required:
a. From the list of general controls shown in Exhibit 4-5, list each
authentication and hacking control that you think the EnviroCons
Company should have in place. Any of the Authentication controls could
Chapter 4 Solutions Internal Controls and Risks in IT Systems
Page 2-13
be used, including user IDs, passwords, security tokens or smart cards,
that EnviroCons serves.
b. Explain how each control that you list can prevent IT related risks for
EnviroCons. Login procedures, including passwords, security tokens or
smart cards, and biometric devices, are needed to limit access to the
system to authorized users. Login procedures should always include
passwords, and may be strengthened to include two-factor authentication
by requiring a security token or smart card in addition to the password. In
addition, the company’s system policies should be documented and
administered consistently, including authority tables and establishment of
appropriate access levels and securities breach resolutions, and the
maintenance of computer logs. This will provide for limiting access to
c. Are there any general controls that you think would not be cost-beneficial?
Biometric devices, such as fingerprint or retina scans or voice recognition
software is probably not cost beneficial in the case of EnviroCons, as
other forms of two-factor authentication could be used just as effectively at
a lower cost.
60. Consideration of Internet EDI in a plastics manufacturing company. Required:
a. Describe the extra IT system risks that Plaskor should consider as it evaluates
whether to buy or develop an Internet EDI system. As Plaskor converts to an
Internet EDI system, it will become susceptible to a wide range of risks
Chapter 4 Solutions Internal Controls and Risks in IT Systems
b. Describe the IT internal controls that should be incorporated into an Internet
EDI system. In a well-controlled Internet EDI system, the external users should
be required to log with a user ID and password. Security tokens, smart cards,
61. Fraud at PT&T. Required: List and describe internal controls from this chapter that
may helped prevent or detect Jerry Schneider’s fraud. Keep in mind that this case
occurred before there was an Internet and large company computer networks.