Better Business Company (BBC) is in the process of planning a more advanced computer-based information system. Slavish, & Moore, LLP, BBC’s consulting firm, has recently been provided with an overview of their proposed plan:
To ensure that the system functions as needed, the BBC Information System (BBCIS) will be created with input from its employees. System construction will begin with prototyping, computer-aided software engineering technology, and Gantt charts. From this point, IT professionals and a systems administrator, who are full-time employees of BBC, will create data models of the business process, define conceptual user views, design database tables, and specify system controls. Users in each department will submit written descriptions of their information needs and business problems to the IT professionals, who will then perform feasibility studies. Each aspect of the system will be documented in accordance with best practices and standards.
The systems administrator will determine access privileges and maintain access control lists and database authorization tables. The administrator will have sole access to the transaction log, which will be used to record all changes made to database tables. A role of the administrator is to detect unauthorized access, reconstruct events, and promote personal accountability. The systems administrator will also be responsible for ensuring that virus protection software is current. Another important task of the administrator is to ensure that adequate backup to databases and applications occur and that disks and tapes are stored in a secure off-site location.
Each employee requiring computer access will be assigned a user ID and password that will be entered when logging onto the system. If a computer terminal is left idle for more than five minutes, the system will close out the session and the user will need to log on again. Furthermore, users will be required to change their passwords once every year.
Hardware will be purchased from Bell Computer Company with the advice of in-house systems developers. With the exception of basic applications, user departments will be allowed to purchase additional software that they need, which will be added to the system.
BBCIS will run on a central server in the computer center located in the company’s administration building. Two security guards will be assigned to the entrance to the computer room. To access the computer center, employees will swipe their ID cards on the lock to the main entrance door. The system will record the times of each entry and departure from the center. The data center will employ an advanced air-conditioning and air filtration system to eliminate dust and pollens. There will also be a sprinkler system to minimize damages in case of a fire.
Required
Based on BBC’s plans for the implementation of a new computer system, describe the potential risks and needed controls. Classify these according to the relevant areas of the COSO framework.
Trending nowThis is a popular solution!
Chapter 15 Solutions
Accounting Information Systems
- Consider the following dialogue between a system professional, Jim Festin, and a manager of adepartment targeted for a new information system, Charles Puno:Festin: The way to go about the analysis is to first examine the old system, such as reviewing keydocuments and observing the workers perform their tasks. Then we can determine which aspects areworking well and which should be preserved.Puno: We have been through these types of projects before and what always ends up happening isthat we do not get the new system we are promised; we get a modified version of the old system.Festin: Well, I can assure you that will not happen this time. We just want a thorough understanding ofwhat is working well and what is not.Puno: I would feel much more comfortable if we first started with a list of our requirements. We shouldspend some time up-front determining exactly what we want the system to do for my department. Thenyou systems people can come in and determine what portions to salvage if you…arrow_forwardScenario: IBM is a software development company and is currently working on an online cloud based Data storage management system. The system analyst collected the following system requirements from the dient. You are supposed to identify the functional and non-functional requirements. a. The system shall be operational 10 hours a day and 5 days a week. b. If the system fails, the system will be recovered back up within 45 seconds or less. c. Admin shall be able to get information about all the registered customers. d. Admin shall be able to update any change in the database.arrow_forwardAvenue Eight Designs hired a consulting firm three months ago to redesign the information system used by the architects. The architects will be able to use state-of-the-art CAD programs to help designing the products. Further, they will able to store these design on a network server where they and other architects may be able to call them back up for future designs with similar components. The consulting firm has been instructed to develop the system without disrupting the architects. In fact, the top management believes that the best route is to develop the system and then to “introduce” it to the architects during training session. Management does not want the architects to spend precious billable hours guessing about the new system of putting work off until the new system is working. Thus, the consultants are operating in a back room under a shroud of secrecy. a) Do you think that management is taking the best course of action for the announcement of the new system? Why? b) Do you…arrow_forward
- Systems Analysis Consider the following dialogue between a systems professional, Joe Pugh, and a manager of a department targeted for a new information system, Lars Meyer: Pugh: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers perform their tasks. Then we can determine which aspects are working well and which should be preserved. Meyer: We have been through these types of projects before and what always ends up happening is that we do not get the new system we are promised; we get a modified version of the old system. Pugh: Well, I can assure you that will not happen this time. We just want a thorough understanding of what is working well and what is not. Meyer: I would feel much more comfortable if we first started with a list of our requirements. We should spend some time up-front determining exactly what we want the system to do for my department. Then you systems people can come in and determine what…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding the development of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead, we get a modified version of the old system. CIO: I can assure you that this will not happen this time. My team just wants a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time determining what exactly we want the system to do upfront. Then your team can come in and…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding the development of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead, we get a modified version of the old system. CIO: I can assure you that this will not happen this time. My team just wants a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time determining what exactly we want the system to do upfront. Then your team can come in and…arrow_forward
- The Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding the development of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead we get a modified version of the old system. CIO: I can assure you that will not happen this time. My team just want a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time in determining what exactly we want the system to do upfront. Then your team can come in and determine…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding the development of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead we get a modified version of the old system. CIO: I can assure you that will not happen this time. My team just want a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time in determining what exactly we want the system to do upfront. Then your team can come in and determine…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently hadthe following conversation regarding the development of a new information system for the company:CIO: The way to go about the analysis is to first examine the old system, such as reviewing keydocuments and observing the workers performing their tasks. Then we can determine which aspectsare working well and which should be preserved.MD: We have been through these types of projects before, and what always ends up happening is thatwe do not get the new system we are promised. Instead we get a modified version of the old system.CIO: I can assure you that will not happen this time. My team just want a thorough understanding ofwhat is working well and what is not.MD: I would feel much more comfortable if we first started with a list of our requirements. We shouldspend more time in determining what exactly we want the system to do upfront. Then your team cancome in and determine what portions…arrow_forward
- Systems Development and Implementation Kruger Designs hired a consulting firm 3 months ago to redesign the information system used by the architects. The architects will be able to use state-of-the-art CAD programs to help in designing the products. Further, they will be able to store these designs on a network server where they and other architects may be able to call them back up for future designs with similar components. The consulting firm has been instructed todevelop the system without disrupting the architects. In fact, top management believes that the best route is to develop the system and then to “introduce” it to the architects during a training session. Management does not want the architects to spend precious billable hours guessing about the new system or putting work off until the new system is working. Thus, the consultants are operating in a back room under a shroud of secrecy. Required: a. Do you think that management is taking the best course of action for the…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding thedevelopment of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead we get a modified version of the old system. CIO: I can assure you that will not happen this time. My team just want a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time in determining what exactly we want the system to do upfront. Then your team can come in and determine…arrow_forwardThe Chief Information Officer (CIO) and the Managing Director (MD) of Illustrious Limited recently had the following conversation regarding thedevelopment of a new information system for the company: CIO: The way to go about the analysis is to first examine the old system, such as reviewing key documents and observing the workers performing their tasks. Then we can determine which aspects are working well and which should be preserved. MD: We have been through these types of projects before, and what always ends up happening is that we do not get the new system we are promised. Instead we get a modified version of the old system. CIO: I can assure you that will not happen this time. My team just want a thorough understanding of what is working well and what is not. MD: I would feel much more comfortable if we first started with a list of our requirements. We should spend more time in determining what exactly we want the system to do upfront. Then your team can come in and determine…arrow_forward
- Accounting Information SystemsAccountingISBN:9781337619202Author:Hall, James A.Publisher:Cengage Learning,