preview

Essay On Computerised Accounting Information System

Better Essays

Abstract

The objectives of the report are to investigate the perceived threats of computerized accounting information systems (CAIS) and to discuss how the impact of these threats can be reduced. The report covers the 19 perceived threats of CAIS, preventive controls, detective controls, corrective controls and auditors’ attestation of internal controls. Examples of controls given are authentication, authorization, physical access control, host and application hardening, encryption, training, log analysis, intrusion detection system (IDS), security testing, computer emergency response team (CERT), the role of Chief Security Officer (CSO) and patch management. The types of analysis used in the report are historical and qualitative …show more content…

Authentication is about verification of the identity of the person or device attempting to access the system e.g. passwords, PINs, smart cards, ID badges, fingerprints and voice recognition. Authorization is about restricting access of authenticated users to specific portions of the system and specifying the type of actions they are permitted to perform e.g. access control matrix. Good physical access control should include stationing a receptionist or a security guard at the main entrance while locking the other entrances to the building, visitor sign-in form, monitoring all entry/exit points through CCTV, locking rooms with important servers with card readers, numeric keypads or biometric devices and storing encrypted sensitive data on removable media (Romney & Steinbart 2006).

Firewalls, antivirus software, user account management, sound software design to prevent buffer overflow attack i.e. an attacker sends a program more data than it can handle and disabling of unnecessary programs and features to reduce potential point of attack due to flaws contained in the programs and features are typical examples of host and application hardening. Encryption protects sensitive accounting data by transforming plaintext into ciphertext in which the intruder needs to decrypt to understand the

Get Access