Preview

State Of Controls In Afri-Wire

Powerful Essays
Open Document
Open Document
1283 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
State Of Controls In Afri-Wire
1.1 Outline how you intend to respond to the managing director’s comments in your report to the board of directors on the state of controls in Afri-Wire computer operations.

We have recently completed an audit for Afri-Wire company and found that the long tems disater recovery management controls have not been put in place, which cause the company to be at risk.A control structure, which provides assurances of integrity, reliability, and validity, must be designed, developed, and implemented in order to provide perfect service which is intergrated through the network. The following activities need to be implementing in the company and also in the disaster recovery plan regularly : conduct IT service analysis, provide employee training,
…show more content…
Managing director argues that for three reasons it is not cost- effective to prepare a long-term disaster recovery plan and to practice recovery protocols on a regular basis:

• First, she believes a plan is useless because, in the event of a major disaster, timely recovery is impossible anyway. She points out that it would take several days for the telephone company to reconfigure all the data communication lines to another site. Even if Afri-Wire had another switch available immediately, it would not operate during this period.

Response:
The most salient indicator of a well-prepared company is the extent of its backup activities because natural disasters can destroy physical computers and supporting infrastructure. The company can use offsite locations for data storage and backup by mease of creating a hot sites that can be created in a different geographical location, with the replication of data so that when a disaster occurs,the backup can be used immediately without delay.(JIBC April 2010, Vol. 15,
…show more content…
The COSO framework
It has been identified by the SEC as a good starting ground for Sarbanes compliance. It addresses accounting controls over business operations and the financial reporting process; however, it does not make specific reference to IT controls.
b. COBIT
Which is published by ISACA (the InformationSystems Audit and Control Association), was created to address IT controls not specifically mentioned in the COSO framework. It is going to be a guideline for the entity-level assessment focusing on IT security controls. Primary emphasis of CoBiT is to ensure that information needed by businesses is provided by technology and the required assurance qualities of information are both met. (Sandra Senft &Frederick Gallegos 2012)
c. The Information Technology Infrastructure Library (ITIL)
Is a set of concepts and techniques for managing information technology (IT) infrastructure, development, and operations.It will assist in improving decision making and optimized risk.
d. Sarbanes-Oxley Act is arranged into 11 “Titles”. With regards to compliance, the most important sections within the 11 titles that could be used to support the audit is listed below: (Janet

You May Also Find These Documents Helpful

  • Satisfactory Essays

    acct 504 case study 2

    • 600 Words
    • 3 Pages

    The Sarbanes-Oxley Act of 2002 (SOX) has established the following guidelines for publicly traded corporations and require adherence for internal controls and procedures for financial reporting. Senior management and executives will be responsible for ensuring that controls are effective and reliable. Outside auditors must periodically verify the accuracy of and adherence to the internal controls. As part of the annual Exchange Act report, an internal control report will generated along with the information recorded during each fiscal year.…

    • 600 Words
    • 3 Pages
    Satisfactory Essays
  • Satisfactory Essays

    This paperwork of IT 244 Week 3 Checkpoint Toolwire Smart Scenario Business Continuity Disaster Recovery consists of:…

    • 367 Words
    • 3 Pages
    Satisfactory Essays
  • Powerful Essays

    Sox Act

    • 2419 Words
    • 10 Pages

    References: United States Securities and Exchange Commission (September 2009). Study of the Sarbanes-Oxley Act of 2002 Section 404; Internal Control over Financial Reporting Requirements. Retrieved from http://www.sec.gov/news/studies/2009/sox-404_study.pdf…

    • 2419 Words
    • 10 Pages
    Powerful Essays
  • Satisfactory Essays

    ACC 230 Entire Course

    • 1473 Words
    • 6 Pages

    Do you think this law will make financial statements more reliable? Also, discuss how SarbanesOxley establishes…

    • 1473 Words
    • 6 Pages
    Satisfactory Essays
  • Better Essays

    Supply Disruption  Customer Disruption  Employee Disruption Communication Utilities Contingency Planning Process High Level Contingency and Disaster Recovery Planning Strategy • Develop the Business Contingency Planning • • • • • • • Policy and Business Process Priorities Conduct a Risk Assessment Conduct the Business Impact Analysis (BIA) Develop Business Continuity and Recovery Strategies Develop Business Continuity Plans Conduct awareness, testing, and training of the DRP Conduct Disaster Recovery Plan maintenance and exercise Identify business processes Industry Standards ISO 27001 : Requirements for Information Security Management Systems. Section 14 addresses business continuity management.…

    • 1114 Words
    • 10 Pages
    Better Essays
  • Powerful Essays

    Caregroup Executive Summary

    • 3822 Words
    • 16 Pages

    Support model can help CareGroup avoid another incident like the network collapse of November, 2002. Because implementing the entire service management framework will take years and is an expensive proposition, the author recommends starting with the five aspects most relevant to CareGroup 's situation just after the incident. Establishing a service desk is the best first step; all of the other service support processes take advantage of this single point of interface between IT providers…

    • 3822 Words
    • 16 Pages
    Powerful Essays
  • Good Essays

    Acc 291

    • 469 Words
    • 2 Pages

    There are five pertinent compliance sections of the eleven sections within the Sarbanes-Oxley Act. The five compliance sections, according to “A Guide To The Sarbanes-Oxley Act” (2006), “Sarbanes Oxley Section 302, Sarbanes Oxley Section 401, Sarbanes Oxley Section 404, Sarbanes Oxley Section 409, and Sarbanes Oxley Section 802”.…

    • 469 Words
    • 2 Pages
    Good Essays
  • Powerful Essays

    From a planning and implementation perspective people are a major factor in business continuity efforts. When a natural disaster strikes, some or all of your employees will be impacted. Loss of life or serious injury is a real possibility. As you evaluate business functions and processes, you will also need to identify key positions, knowledge, and skills needed for business continuity. "The BC/DR plan needs to look at key positions within the company and understand the role of each in the business continuity realm." (Business Impact…

    • 1932 Words
    • 8 Pages
    Powerful Essays
  • Best Essays

    Sarbane-Oxley Act of 2002

    • 3019 Words
    • 11 Pages

    The Sarbanes-Oxley Act of 2002 – its official name being “Public Company Accounting Reform and Investor Protection Act of 2002” – is recognized to be the most significant U.S. federal disclosure and corporate governance legislation since the Securities Act of 1933 (the Securities Act) and the Securities Exchange Act of 1934 (the Exchange Act), and, the provisions of the Act are significant enough that it is considered by many to be the most significant change to federal securities laws in the U.S. since the New Deal.…

    • 3019 Words
    • 11 Pages
    Best Essays
  • Good Essays

    Baf 110 Notes Ch 1

    • 433 Words
    • 2 Pages

    Sarbanes- Oxley Act (2002)- federal law intended to improve governance of public corporations by holding boards of directors, management, and auditors to high standards of conduct and accountability. (p.3)…

    • 433 Words
    • 2 Pages
    Good Essays
  • Better Essays

    Sarbanes Oxley

    • 6282 Words
    • 26 Pages

    The act contains 11 titles, or sections, ranging from additional corporate board responsibilities to criminal penalties, and requires the Securities and Exchange Commission (SEC) to implement rulings on requirements to comply with the law. Harvey Pitt, the 26th chairman of the SEC, led the SEC in the adoption of dozens of rules to implement the Sarbanes–Oxley Act. It created a new, quasi-public agency, the Public Company Accounting Oversight Board, or PCAOB, charged with overseeing, regulating, inspecting and disciplining accounting firms in their roles as auditors of public companies. The act also covers issues such as auditor independence, corporate governance, internal control assessment, and…

    • 6282 Words
    • 26 Pages
    Better Essays
  • Satisfactory Essays

    Sarbanes Oxley Act

    • 380 Words
    • 2 Pages

    Sarbanes–Oxley Act of 2002 is a United States federal law that mandated a number of reforms to increase corporate responsibility, enhance financial disclosures and prevent corporate and accounting fraud (Shakespeare, 2008). The laws are a set of rules that guides the conduct in society. Legal rules and ethical decisions are similar but differ on certain points. Sarbanes Oxley was created with new standards for corporate accountability as well as new penalties for acts of wrongdoing.…

    • 380 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Ipremier Case

    • 545 Words
    • 3 Pages

    2. I believe the company’s operating procedures were not completely deficient but do need an improvement. The reason for this is because they lack of knowledge of the binder placing and outdated procedure. In addition, it was unclear how the CEO was going to be contacted and what information would be distributed. We could improve the operating procedures by having an updated and prepared emergency procedure binder, which would instruct workers what to do in case of any emergency. In addition, having a structure communication system to identify whom to contact in case of an emergency. Finally, making sure the contract with Qdata and who can access the data center since they had trouble accessing it.…

    • 545 Words
    • 3 Pages
    Good Essays
  • Better Essays

    Contingency planning are steps, procedures, and policies for management that are created to keep business operations on track running and/or to restore them as well possibly during disaster or system failure. Disaster recovery is a number of processes that only pays attention to the processes of recovery. As defined by the Department of Health and Human Services, a contingency /disaster recovery plan is a strategic measure taken if there is a malfunction in a business product or if there is disaster such as flood, or fire or if things don’t go according to plan, (DHHS,…

    • 805 Words
    • 4 Pages
    Better Essays
  • Satisfactory Essays

    Itil Exam

    • 2419 Words
    • 10 Pages

    QUESTION NO: 1 Which activity is not the responsibility of IT service continuity management? A. Drawing up back-out scenarios B. Analyzing risks C. Testing back-out arrangements D. Executing impact analyses of incidents related to the back-out facilities Answer: D QUESTION NO: 2 Which ITIL process has responsibility in preventing unauthorized access to data? A. IT service continuity management B. Availability management C. Release management D. Security management Answer: D QUESTION NO: 3 Which ITIL process or which ITIL department has responsibilities that include distributing information to users? A. Change management B. Service desk C. Customer relationship management D. Incident Management Answer: B QUESTION NO: 4 Where are activities documented with the aim of improving an IT service? A. Service Quality Plan (SQP) B. Service improvement program (SIP) C. Service catalogue D. Service Level Agreement (SLA) Answer: B QUESTION NO: 5 In the change management process, which role is ultimately responsible for the entire process? A. Change Advisory Board B. IT Manager C. Change Manager D. Change Coordinator Answer: C QUESTION NO: 6 In TestKing.com, the purchasing department has relocated internally, not just the people, but also their IT resources. A service Desk employee has been commissioned to relocate…

    • 2419 Words
    • 10 Pages
    Satisfactory Essays