1
Chapter 4 – Internal Controls and Risks in IT Systems
Instructor Manual
Overview Of Internal Controls For IT Systems. It is important to consider
possible threats or risks that can disrupt or stop IT systems, and to implement
internal controls that can help prevent or reduce these threats. The AICPA Trust
General Controls For IT Systems
o Authentication Of Users And Limiting Unauthorized Users. Authentication is
intended to ensure that users trying to access the IT system are valid, authorized
users. There are many ways to authenticate users, including log-in procedures
using a user ID and password, smart cards, security tokens, and biometric
o Hacking And Other Network Break-Ins. The more extensive the network
system, the more openings there are for hackers and unauthorized users. A
firewall is hardware, software, or a combination of both that blocks instances of
unauthorized network traffic. The firewall examines network packets of data and
tries to allow authorized data to flow through, yet block unauthorized packets of
o Organizational Structure. The manner in which a company establishes,
delegates, and monitors IT system functions is part of the general controls. For
companies with extensive IT systems, this includes an IT governance committee
of top executives. The IT governance committee should: (1) align IT strategy
2
be segregated. As major changes are made to an IT system, the changes
should follow a process that controls the initiation, approval, development, and
maintenance of IT systems. Often, the process followed is a System
Development Life Cycle (SDLC).
o Physical Environment And Security. An IT system should have controls over
the physical environment and physical access controls to the IT system.
storage of data storage.
o Business Continuity. Business continuity planning is a proactive program to
consider risks to business continuation and to develop plans to limit those risks.
The business continuity plan should include a strategy for backup and restoration
of IT systems, and a disaster recovery plan. The system can use redundant
General Controls From An AICPA Trust Services Principles Perspective. The
AICPA Trust Services Principles are a framework that categorizes risks and controls
into five categories: (1) security, (2) availability, (3) processing integrity, (4) online
privacy, and (5) confidentiality.
o Risks In Not Limiting Unauthorized Users. There are eight IT controls that
can lessen the risk of unauthorized users gaining access to the IT system.
Those eight are: user ID, password, security token, biometric devices, log-in
procedures, access levels, computer logs, and authority tables. Without such
controls, there are security risks, availability risks, processing integrity risks, and
confidentiality risks. Security risks are from external persons, as well as
employees of the organization who may try to access data for which they do not
need access. Unauthorized access to the IT system can allow persons to
data being available to unauthorized users, can occur if authentication controls
3
are weak. An unauthorized user who gains access can browse, steal, or destroy
confidential data.
o Risks From Hacking Or Other Network Break-Ins. Whether the threat is from
confidentiality risk since the person breaking in may access, browse, steal or
change confidential data.
o Risks From Environmental Factors. Any environmental changes that affect
the IT system can cause availability risks and processing integrity risks. These
risks are that systems can be shut down or errors and glitches in processing can
occur that cause lost or corrupted data. Backup power supply systems allow IT
systems to be gradually shut down without the loss or corruption of data
o Physical Access Risks. The security risk is that an intruder who gains physical
access may change user access levels so that he or she can later access data or
systems through any network attached system. The availability risks are that
o Business Continuity Risks. The security risk is that an unauthorized person
may gain access to the backup data. The availability risk is that, as disasters or
events interrupt operations, the system becomes unavailable for regular
data.
Hardware And Software Exposures In IT Systems. There are many possible
configurations of hardware and software that could be used in organizations. This
section describes some typical systems and their corresponding risks and controls.
o The Operating System. The operating system is the software that controls the
basic input and output activities of the computer. The operating system can be
database. In addition, all read/write data functions are controlled by the
operating system and any person who has access to the operating system can
have access to data. Essentially, access to the operating system opens access
to any data or program in the IT system. If a knowledgeable person is able to
access and manipulate the operating system, that person potentially has access
to all data passing through the operating system, and all processes or programs.
Thus the operating system poses security risks, availability risks, processing
integrity risks, and confidentiality risks.
o The Database. The database is an exposure area because any unauthorized
access to the data can compromise the security and confidentiality of the data,
o The Database Management System. As is true of the data, the DBMS poses
security, confidentiality, availability, and processing integrity risk exposures.
Since the database management system reads and writes data to the database,
unauthorized access to the DBMS is another exposure area. An unauthorized
user who is able to access the DBMS may be able to browse, alter, or steal data.
o LANS And WANS. Since LANs and WANs are connected into the larger
network of servers and computers within a company, the LANs represent risk
o Wireless Networks. The wireless network represents another potential “entry
point” of unauthorized access and therefore poses the same four risk exposures
of security, confidentiality, availability, and processing integrity. The wireless
receive those radio signals may gain access to the network.
o The Internet And World Wide Web. The Internet connection required to
conduct Internet based business can open the company network to unauthorized
users, hackers and other network break-ins. An unauthorized user can
compromise security and confidentiality, and affect availability and processing
integrity by altering data or programs or inserting virus or worm programs.
o Telecommuting Workers And Mobile Workers. Telecommuting workers
cause two sources of risk exposures to their organizations. First, the network
5
under the control of the organization since it is located in the teleworker’s home
or on another mobile device. Therefore, the organization must rely on the
teleworker to maintain appropriate security over that computer/mobile device and
to appropriately use firewalls and virus software updates to keep security up to
date. These two “entry points” pose security, confidentiality, availability, and
processing integrity risks.
o Electronic Data Interchange. To conduct EDI with business partners, a
business must use a dedicated network, a value added network, or the Internet.
o Cloud Computing. A public cloud computing model may be used for software
and/or data storage. Although the advantages of cloud computing are
noteworthy, control of the organization’s software and data are transferred to a
third party provider, thus introducing additional security, availability, processing
integrity, and confidentiality risks.
Application Software And Application Controls. Applications software
accomplishes end user tasks such as word processing, spreadsheets, database
maintenance, and accounting functions. Application software represents another
o Input Controls. No matter the manner of input, controls should be in place to
insure that the data entered are accurate and complete. Input controls should be
in place to insure the authorization, accuracy, and completeness of that data
input. These input controls are of four types.
Source document controls. Where source documents are used, several
source document controls should be in place to minimize the potential for
Standard procedures for data input. Without well-defined source data
preparation procedures, employees would be unsure as which forms to use,
when to use them, how to use them, and where to route them. An
6
organization should have error handling procedures. As errors are
discovered, they should be logged, investigated, corrected, and resubmitted
for processing. The error log should be regularly reviewed by an appropriate
manager so that corrective action can be taken on a timely basis.
Programmed input validation checks. Application software can include
input validation checks to prevent or detect input errors. These validation
o Processing Controls. Processing controls are intended to prevent, detect, or
correct errors that occur during the processing in an application. The
reconciliation of control totals at various stages of the processing is called runto
run control totals. During processing, some calculations such as addition or
o Output Controls. The two primary objectives of output controls are to assure
the accuracy and completeness of the output, and to properly manage the
safekeeping of output reports to insure the security and confidentiality of the
information. To insure accuracy and completeness, the output can be reconciled
Ethical Issues In IT Systems. Without proper controls on IT systems, computers
can be easily misused by outsiders or employees. In addition to computer assets
being misused, access to IT systems may give unauthorized users access to other
assets. Management must try to prevent theft conducted using the IT system such
as theft by entering fraudulent transactions. Both misuse of computers and theft