Hello: Ineed help with this questions. Change management controls are a type of
ID: 3804407 • Letter: H
Question
Hello: Ineed help with this questions.
Change management controls are a type of IT organization and management controls, which are a subset of IT management-level (general) controls.
a) What are change management controls?
b) Assume that an organization’s change management controls pertaining to application software are ineffective. What impact would this have on the reliance that management can place on application-based control?
c) Assume instead that the organization’s change management controls pertaining to application software are effective. Assume further that the internal audit function determined that the controls imbedded in the purchasing process application software were designed adequately and operating effectively last year. What impact would this have on this year’s internal auditing testing of the controls imbedded in the purchasing process application software?
d) Based on the answers B and C above, what general conclusion can be reached about the relationship between IT management-level (general controls and application-based controls?
Explanation / Answer
a) Change Management control is a policy which is used to manage all the changes made in a system. The purpose change management control is to control unnecessary chages in a system and to document all the changes efficiently under information technology.
b) The ineffective change management controls to application software can lead to increased compliance , increased operational costs, internal and external security risks Legal exposure, Misuse of resources.
c) The report of the Internal auditing testing is directly sent to the management, the performance is improved, avoidance of additional and excessive costs, The additional and excessive risks are mitigated, control environment is improved.
d) The application based control relates to the transactions of computer based systems , The relaince depends upon the designing and operation of General controls , the management relies on the application controls for risks management, Thus if General controls are not effective then unauthorized , unaaproved and untested programs are used in production which compromise integrity of application controls.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.