Question

In: Computer Science

How would you define the differences between preventative, detective, and responsive controls? What are some examples...

How would you define the differences between preventative, detective, and responsive controls? What are some examples of each? Can these different controls overlap or are they independent of each other working as security layers and risk control?

Solutions

Expert Solution

Detective controls are internal controls designed to identify problems that already exist. Audits are an example of a detective control. Monthly reconciliation of bank accounts, review and verification of refunds, reconciliation of petty cash accounts, audits of payroll disbursements or conducting physical inventory are all examples of detective controls. Preventive and detective controls are often required in combination to provide sufficient protection. Computer systems require preventive controls through acceptable use and access control. Computer usage logs must be kept. Logs are a form of detective control to be reviewed and audited at regular intervals.

Examples of this type are:

  • Intrusion Detection Systems IDS.
  • Alarms.
  • Lights.
  • Motion Detectors.
  • Security Guards.
  • Video Surveillance.
  • Logs and Audit Trails.
  • Enforcing Staff Vacations.

Many prevent controls are based on the concept of separating duties. Examples include prohibiting the same person from conducting related transactions such as initiating and recording transactions; making purchases and approving payments; ordering and accepting inventory; approving vendors and making payments; receiving bills and approving payments; and authorizing returns and issuing refunds. Payroll preparation and distribution duties and approving, writing and signing checks should also be done by different people. Examples of internal controls built around the concept of authorization, approval and verification include requiring supervisory review and approval of payroll information before disbursement, requiring interdepartmental dual authorization of payroll data by accounting and human resources departments and requiring prior approval of credit customers, vendors and purchases.

Examples for such type of controls are:

  • Firewalls.
  • Intrusion Prevention Systems IPS.
  • Security Guards.
  • Biometric Access Control.
  • Using Encryption.
  • Video Surveillance.
  • Fences.
  • Strong Authentication.
  • Locks.
  • Mantraps.
  • Antivirus Software.

Related Solutions

Describe the difference between preventative and detective controls and discuss the strengths and weaknesses of each.
Describe the difference between preventative and detective controls and discuss the strengths and weaknesses of each.
What preventative and detective controls can be put in place to prevent scandals like the Wells...
What preventative and detective controls can be put in place to prevent scandals like the Wells Fargo scandal from happening again?
discuss about further into COBIT and the 3 types on controls: preventative, detective and corrective.
discuss about further into COBIT and the 3 types on controls: preventative, detective and corrective.
For your first post, define financial management. What are some other examples of the differences between...
For your first post, define financial management. What are some other examples of the differences between financial management and financial accounting? Give examples.
Define financial management. What are some other examples of the differences between financial management and financial...
Define financial management. What are some other examples of the differences between financial management and financial accounting? Give examples.
In Chapter 7, we discussed the differences between preventive, detective, and corrective controls. Chapters 8-10 offer...
In Chapter 7, we discussed the differences between preventive, detective, and corrective controls. Chapters 8-10 offer specific types of controls within those categories over information security, confidentiality, privacy, processing integrity, and availability. Think about controls that you have encountered in your own life (personal, professional, within organizational memberships, etc.). Note that at the time, you may or may not have realized that the answer to “why is this done?” was that a control was being implemented: a control over operations,...
What are some internal controls for inventory? How do these controls change between industries?
What are some internal controls for inventory? How do these controls change between industries?
What are the differences between individual and group behavior? Provide some examples.
What are the differences between individual and group behavior? Provide some examples.
How would you distinguish between the two members of the pair. Tell what differences you would...
How would you distinguish between the two members of the pair. Tell what differences you would expect to see in both the IR and the NMR. Be specific and detailed, with numbers. 5. Identify specific signals in the; IR NMR for methyl 2-phenylacetate and ethyl benzoate
Would need some guidance on answering the following What are the similarities and differences between the...
Would need some guidance on answering the following What are the similarities and differences between the two t tests for the difference between two population means? Under what condition should we use the t test for the matched samples? Thanks
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT