Question

You have been hired by the CFO of Strayer University to develop a plan to protect...

  • You have been hired by the CFO of Strayer University to develop a plan to protect its accounting and financial systems at a reasonable cost. Suggest a high-level plan for the CFO. Provide support for your suggestion.
  • Based on your security plan recommendation, determine the system aspect that is most likely to be violated.
0 0
Add a comment Improve this question Transcribed image text
Answer #1

igh Level Plan will be:

  1. Preventive Controls: Designed to prevent the occurrence of errors and misappropriation of resources. For example – security checks, access control, reference check for new employees, credit check for potential clients etc. Such controls include control on transactions, people and functions through:
    1. Separation of responsibilities for different functions of an activity. Authorization, Recording, Access to asset and Reconciliation for a transaction should be handled by 4 employees.
    2. Twofold controls for key functions or transactions above certain amount
    3. Cross-checking at every step (for example – reconciliations between sales ledger and debtors)
    4. Reasonableness checks (for example – amount of insurance premium should be reasonable with respect to the sum insured and / or cost of asset insured)
    5. Completeness checks (say for example – forms cannot be processed until all mandatory details are filled in)
  2. Detective Controls: Preventive controls are complemented by detective controls that are designed to detect the errors which preventive controls fail to prevent. For example:
    1. Physical inventory check,
    2. Reconciliation of Bank statement, petty cash accounts etc.
    3. Such controls rely on sample checking and are often combined with preventive controls to provide extra layer of protection against potential risks. They are usually lesser expensive in comparison to preventive controls.
  3. Corrective Controls: Such controls aim to rectify the issues highlighted by detective controls. For example: In case a discrepancy has been noted in the list of inventory booked in the inventory register and that physically checked, a corrective control will look into the issues of difference and rectify the register.

Support for my suggestion:

My suggestions primarily aim to design controls that:

  • Should have adequate checks to ensure financial, accounting and operational information generated by the system is accurate and reliable
  • Should generally complement each other towards safeguarding of assets, compliance with law, reliable financials, efficient operations and achieving firm’s objectives.

So my design controls are such that they

  1. First attempt to prevent threat from occurring in the first place
  2. Put in place adequate controls to detect the threat once it has occured and then
  3. Attempt to reduce the possible losses

System aspect that will be most likely violated:

  1. Effective internal control can prevent human errors (unintentional, due to carelessness or ignorance) but may not be efficient to prevent fraud.
  2. Thus internal controls can give reasonable but not 100% assurance about prevention of errors and frauds.
  3. Stealing of the data by authorized personnel
  4. Passing on the stolen data to unauthorized personnel
  5. Obsolescence in system technology
  6. Hacks
Add a comment
Know the answer?
Add Answer to:
You have been hired by the CFO of Strayer University to develop a plan to protect...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • You have been hired by the CFO of Strayer University to develop a plan to protect...

    You have been hired by the CFO of Strayer University to develop a plan to protect its accounting and financial systems at a reasonable cost. Suggest a high-level plan for the CFO. Provide support for your suggestion. Based on your security plan recommendation, determine the system aspect that is most likely to be violated.

  • ***I only need the High Level Project Plan (Time to Implement)****** You have recently been hired...

    ***I only need the High Level Project Plan (Time to Implement)****** You have recently been hired by a new Japanese accounting firm, headquarter in Tokyo, as the director ofInformation Systems and Telecommunications. Your assignment is to assist security posture of the firm anddevelop a security structure for this new company. Write your recommendations and reasons to the firm’s CEO. The firm has 600 employees in Tokyo, 50 in Houston, and is planning to open two branch offices in India andCalifornia....

  • Assume that you have been hired by a bank to harden their defenses. The step are:

    Assume that you have been hired by a bank to harden their defenses. The step are: Determine the types of information a bank has that needs to be protected. Rank the types of information that you have identified from most to least critical and briefly state why they received that ranking. What would you suggest to the bank as ways to protect the online information or mitigate the damage if the information is compromised? What would you suggest to the bank as ways to...

  • Assume that you have been hired by a bank to harden their defenses. The step are:...

    Assume that you have been hired by a bank to harden their defenses. The step are: Determine the types of information a bank has that needs to be protected. Rank the types of information that you have identified from most to least critical and briefly state why they received that ranking. What would you suggest to the bank as ways to protect the online information or mitigate the damage if the information is compromised? What would you suggest to the...

  • Assume that you have been hired by a bank to harden their defenses. The step are:...

    Assume that you have been hired by a bank to harden their defenses. The step are: Determine the types of information a bank has that needs to be protected. Rank the types of information that you have identified from most to least critical and briefly state why they received that ranking. What would you suggest to the bank as ways to protect the online information or mitigate the damage if the information is compromised? What would you suggest to the...

  • 9. Assume that you have been hired by a bank to harden their defenses. The step...

    9. Assume that you have been hired by a bank to harden their defenses. The step are: Determine the types of information a bank has that needs to be protected. Rank the types of information that you have identified from most to least critical and briefly state why they received that ranking. What would you suggest to the bank as ways to protect the online information or mitigate the damage if the information is compromised? What would you suggest to...

  • You have been selected as the consultant to develop a business plan for Durango Manufacturing Company,...

    You have been selected as the consultant to develop a business plan for Durango Manufacturing Company, which is a start-up, medium-sized public manufacturing company. The CEO has a background in manufacturing and is well versed in supply chain management. However, the CEO has limited experience in financial management and creating value for the various stakeholder groups. Your business plan must include a five (5) year strategy to increase revenues by 10% and a recommendation for creating an organizational structure to...

  • Please don't copy and paste from internet or from past post You have been hired as...

    Please don't copy and paste from internet or from past post You have been hired as the new Risk Manager at WeCare General Hospital. You were hired mainly due to your experience in creating a High Reliability Organization. As CEO of WeCare General, I have received an executive brief on the top 10 patient safety concerns in healthcare. The number 1 concern is Diagnostic Errors. You are being asked to write a recommendation for me outlining the steps you will...

  • Please don't copy and paste from internet You have been hired as the new Risk Manager at WeCare General Hospital. You we...

    Please don't copy and paste from internet You have been hired as the new Risk Manager at WeCare General Hospital. You were hired mainly due to your experience in creating a High Reliability Organization. As CEO of WeCare General, I have received an executive brief on the top 10 patient safety concerns in healthcare. The number 1 concern is Diagnostic Errors. You are being asked to write a recommendation for me outlining the steps you will take to determine if...

  • You are a consultant for a small to mid-range business and have been hired to evaluate...

    You are a consultant for a small to mid-range business and have been hired to evaluate your customer’s server hardware. You notice that all of their hardware currently uses the PCI bus, and you recommend that they upgrade to PCI Express (PCIe) equipment. What is the reason for your recommendation? A. PCI-standard hardware has a number of flaws that can be used by hackers on the Internet to compromise the security of server data. B. PCI standard hardware is old...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT