SlideShare a Scribd company logo
1 of 16
The Management Control Framework
How can an auditor evaluate top mgt and EDP
mgt involvement in a computer installation?
The Management Control Framework
Evaluating the Planning Function
The major plans formulated for a computer
installation include:
• feasibility study
• changeover plan
• master plan
• project plan
• disaster recovery plan.
The Management Control Framework
Evaluating the Organizing Function
• The planning process establishes goals and objectives for a
computer installation and the organizing process structures
personnel, facilities, and information flows to enable these
goals and objectives to be achieved.
Centralization Vs Decentralization
• A major organization design issue often facing top and EDP
mgt is whether to centralize or decentralize computer
facilities.
• Some computer operations can be centralized or
decentralized
The Management Control Framework
Organizational
Strategy
Advantages Disadvantages
Decentralize
Systems analysis
Better systems
designed through
greater awareness
of user needs
Greater difficulties
in standardizing and
integrating systems
Centralize
Programming
Decentralize H/W
Centralize S/W
The Management Control Framework
Selecting hardware/software facilities
• Another aspect of organizing is choosing
suitable hardware/software facilities.
• This involves preparing a manual of
specifications for distribution to vendors and
evaluating vendor proposals and selecting a
final hardware/software configuration.
The Management Control Framework
Methods/Performance Standards
• To guide and control its activities, a computer
installation must have: a methods standards
and performance standards.
• Methods standards have four major purposes
(a) Facilitate communication between
interdependent parties, e.g, between systems
analysts and programmers.
The Management Control Framework
(b) Reduce the effects of personnel turnover;
new staff are not affected by the
idiosyncrasies of their predecessors.
(c) Reduce the effects of technological change,
for e.g, by facilitating hardware/software
changeover.
(d) Form the basis for perfomance standards by
providing a common measurement base
The Management Control Framework
Evaluating the Staffing Function
• Staff planning involves taking an inventory of
the current staff capabilities, determining
future staff requirements, assessing the likely
turnover of staff, and determining how
positions will befilled.
Personnel acquisition
• For each position in the computer installation,
a formal documented job specification must
exist defining the nature of the job, its duties,
and opportunities for advancement.
The Management Control Framework
Personnel Termination
• Personnel termination may be voluntary or
involuntary, in either case, some control
procedures must be exercised
(a) Upon an employees giving notice, if the
employee is a key person, mgt must be
immediatelyinformed.
(b) Upon termination, a checklist must be
prepared.
(c) The terminating employee should provide
training for the replacement employee.
The Management Control Framework
(d) If the employee is disgruntled, the employee
should be assigned to non critical areas.
(e) Exit interviews should be given
• Any areas of discontent are determined
• Reminders are given on secrecy oaths etc
• Potential problems are identified
The Management Control Framework
Evaluating the Directing Function
• The process of directing is based upon three
major principles:
1. unity of command whereby individuals should
report to a single supervisor to avoid conflict
in instructions and promote a greeter feeling
of responsibility for results achieved
2. direct supervision whereby mgt should
supplement objective methods of supervision
with direct personal conduct
The Management Control Framework
3. Appropriate variation of supervisory
techniques to suit different people, tasks and
organisational environments.
• To evaluate how well top mgt and EDP mgt
perform the directing function, it requires the
auditor to understand areas fundamental to
effective directing.
(a)Human motivation
• An auditor can evaluate human motivation, by
examining variables that indicate when
motivation problems exist e.g. staff turnover
The Management Control Framework
Leadership
• As with motivation, the auditor must be aware
of indicators that suggest poor leadership:
staffturnover, projects failing to meet budgets
etc.
Communications
• The auditor has both formal and informal
sources of evidence for evaluating how well
top and EDP mgt communicate with their
subordinate staff.
The Management Control Framework
• Formal evidence include minutes of meetings
and informal evidence include interviews with
installation staff. General awareness of the
staff of other developments within the
installation even though they may not be
directly involved with the developments.
The Management Control Framework
Evaluating the Controlling Function
• The controlling function involves determining
when the actual activities of the computer
installation deviate from the planned
activities.
The means of control
• Mgt exercises control over computer
installations activities through normal means:
plans andbudgets, measuring actual
performance, and determining variances from
budgets.
The Management Control Framework
• Some essential control elements in a
computer installation include; performance
standards, documentation standards,
checkpoint reviews, project control aids and
postaudits

More Related Content

Similar to Information Systems Management Control Framework(1).ppt

Presentation1.pptx
Presentation1.pptxPresentation1.pptx
Presentation1.pptx
abdo badr
 
Project management
Project managementProject management
Project management
Rohit Mishra
 

Similar to Information Systems Management Control Framework(1).ppt (20)

CV D. Maimbolwa
CV D. MaimbolwaCV D. Maimbolwa
CV D. Maimbolwa
 
Project control and process instrumentation
Project control and process instrumentationProject control and process instrumentation
Project control and process instrumentation
 
Presentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCMPresentation on iso 27001-2013, Internal Auditing and BCM
Presentation on iso 27001-2013, Internal Auditing and BCM
 
Proj Mgmt.ppt
Proj Mgmt.pptProj Mgmt.ppt
Proj Mgmt.ppt
 
Presentation1.pptx
Presentation1.pptxPresentation1.pptx
Presentation1.pptx
 
Business Process Reengineering | Case studies
Business Process Reengineering | Case studiesBusiness Process Reengineering | Case studies
Business Process Reengineering | Case studies
 
Project management
Project managementProject management
Project management
 
Project management
Project managementProject management
Project management
 
The Importance of Security within the Computer Environment
The Importance of Security within the Computer EnvironmentThe Importance of Security within the Computer Environment
The Importance of Security within the Computer Environment
 
Lecture 7. CONTROL.pptx
Lecture 7. CONTROL.pptxLecture 7. CONTROL.pptx
Lecture 7. CONTROL.pptx
 
UNIT V CONTROLLING.pptx
UNIT V CONTROLLING.pptxUNIT V CONTROLLING.pptx
UNIT V CONTROLLING.pptx
 
Prativa biswas
Prativa biswasPrativa biswas
Prativa biswas
 
Prativa biswas
Prativa biswasPrativa biswas
Prativa biswas
 
Controlling
ControllingControlling
Controlling
 
PLANNING PRODUCTION AND CONTROL
PLANNING PRODUCTION AND CONTROLPLANNING PRODUCTION AND CONTROL
PLANNING PRODUCTION AND CONTROL
 
Introduction to Production Planning & Control & Manufacturing.pptx
Introduction to Production Planning & Control & Manufacturing.pptxIntroduction to Production Planning & Control & Manufacturing.pptx
Introduction to Production Planning & Control & Manufacturing.pptx
 
Construction Commissioning Best Practices during Turnover
Construction Commissioning Best Practices during TurnoverConstruction Commissioning Best Practices during Turnover
Construction Commissioning Best Practices during Turnover
 
Auditing in computerized environment.pptx
Auditing in computerized environment.pptxAuditing in computerized environment.pptx
Auditing in computerized environment.pptx
 
Chapterhjhlzuoollkkklhkoksfghjyrec-7.pptx
Chapterhjhlzuoollkkklhkoksfghjyrec-7.pptxChapterhjhlzuoollkkklhkoksfghjyrec-7.pptx
Chapterhjhlzuoollkkklhkoksfghjyrec-7.pptx
 
UNIT4.ppt
UNIT4.pptUNIT4.ppt
UNIT4.ppt
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Information Systems Management Control Framework(1).ppt

  • 1. The Management Control Framework How can an auditor evaluate top mgt and EDP mgt involvement in a computer installation?
  • 2. The Management Control Framework Evaluating the Planning Function The major plans formulated for a computer installation include: • feasibility study • changeover plan • master plan • project plan • disaster recovery plan.
  • 3. The Management Control Framework Evaluating the Organizing Function • The planning process establishes goals and objectives for a computer installation and the organizing process structures personnel, facilities, and information flows to enable these goals and objectives to be achieved. Centralization Vs Decentralization • A major organization design issue often facing top and EDP mgt is whether to centralize or decentralize computer facilities. • Some computer operations can be centralized or decentralized
  • 4. The Management Control Framework Organizational Strategy Advantages Disadvantages Decentralize Systems analysis Better systems designed through greater awareness of user needs Greater difficulties in standardizing and integrating systems Centralize Programming Decentralize H/W Centralize S/W
  • 5. The Management Control Framework Selecting hardware/software facilities • Another aspect of organizing is choosing suitable hardware/software facilities. • This involves preparing a manual of specifications for distribution to vendors and evaluating vendor proposals and selecting a final hardware/software configuration.
  • 6. The Management Control Framework Methods/Performance Standards • To guide and control its activities, a computer installation must have: a methods standards and performance standards. • Methods standards have four major purposes (a) Facilitate communication between interdependent parties, e.g, between systems analysts and programmers.
  • 7. The Management Control Framework (b) Reduce the effects of personnel turnover; new staff are not affected by the idiosyncrasies of their predecessors. (c) Reduce the effects of technological change, for e.g, by facilitating hardware/software changeover. (d) Form the basis for perfomance standards by providing a common measurement base
  • 8. The Management Control Framework Evaluating the Staffing Function • Staff planning involves taking an inventory of the current staff capabilities, determining future staff requirements, assessing the likely turnover of staff, and determining how positions will befilled. Personnel acquisition • For each position in the computer installation, a formal documented job specification must exist defining the nature of the job, its duties, and opportunities for advancement.
  • 9. The Management Control Framework Personnel Termination • Personnel termination may be voluntary or involuntary, in either case, some control procedures must be exercised (a) Upon an employees giving notice, if the employee is a key person, mgt must be immediatelyinformed. (b) Upon termination, a checklist must be prepared. (c) The terminating employee should provide training for the replacement employee.
  • 10. The Management Control Framework (d) If the employee is disgruntled, the employee should be assigned to non critical areas. (e) Exit interviews should be given • Any areas of discontent are determined • Reminders are given on secrecy oaths etc • Potential problems are identified
  • 11. The Management Control Framework Evaluating the Directing Function • The process of directing is based upon three major principles: 1. unity of command whereby individuals should report to a single supervisor to avoid conflict in instructions and promote a greeter feeling of responsibility for results achieved 2. direct supervision whereby mgt should supplement objective methods of supervision with direct personal conduct
  • 12. The Management Control Framework 3. Appropriate variation of supervisory techniques to suit different people, tasks and organisational environments. • To evaluate how well top mgt and EDP mgt perform the directing function, it requires the auditor to understand areas fundamental to effective directing. (a)Human motivation • An auditor can evaluate human motivation, by examining variables that indicate when motivation problems exist e.g. staff turnover
  • 13. The Management Control Framework Leadership • As with motivation, the auditor must be aware of indicators that suggest poor leadership: staffturnover, projects failing to meet budgets etc. Communications • The auditor has both formal and informal sources of evidence for evaluating how well top and EDP mgt communicate with their subordinate staff.
  • 14. The Management Control Framework • Formal evidence include minutes of meetings and informal evidence include interviews with installation staff. General awareness of the staff of other developments within the installation even though they may not be directly involved with the developments.
  • 15. The Management Control Framework Evaluating the Controlling Function • The controlling function involves determining when the actual activities of the computer installation deviate from the planned activities. The means of control • Mgt exercises control over computer installations activities through normal means: plans andbudgets, measuring actual performance, and determining variances from budgets.
  • 16. The Management Control Framework • Some essential control elements in a computer installation include; performance standards, documentation standards, checkpoint reviews, project control aids and postaudits

Editor's Notes

  1. The employee supervisor should be contacted to determine reasons for leaving Check list Keys and id badges are recovered – employee passwords are cancelled – distribution lists are changed – reports, boooks etc are returned – equipment issued are returned
  2. The employee supervisor should be contacted to determine reasons for leaving Check list Keys and id badges are recovered – employee passwords are cancelled – distribution lists are changed – reports, boooks etc are returned – equipment issued are returned