An information system (IS) auditor was asked to review the alignment between information technology (IT) and business goals for Cachero, a small but rapidly growing financial institution. The IS auditor requested information including business and IT goals and objectives; however, these were limited to a short, bulleted list for business goals and PowerPoint slides used in reporting meetings for IT goals. It was also found in the documentation provided that over the past two (2) years, the risk management committee (composed of senior management) met on only three (3) occasions, and no minutes of what was discussed were kept for these meetings. When the IT budget for the upcoming year was compared to the strategic plans for IT, it was noted that several of the initiatives mentioned in the plans for the upcoming year were not included in the budget for that year. The IS auditor also discovered that Cachero does not have a full-time chief information officer (CIO). The organizational chart of the entity denotes an IS manager reporting to the chief financial officer (CFO), who, in turn, reports to the board of directors. The board plays a major role in monitoring IT initiatives in the entity, and the CFO frequently communicates the progress of IT initiatives. When the IS auditor reviewed the segregation of duties (SoD) matrix, it was apparent that application programmers are only required to obtain approval from the database administrator (DBA) to directly access the production data. It was also noted that the application programmers must provide the developed program code to the librarian, who then migrates it to production. IS audits are carried out by the internal audit department, which reports to the CFO at the end of every month, as part of the business performance review process; the financial results of the entity are reviewed in detail and signed off by the business managers for the correctness of data contained therein. Questions: 1. In no more than five (5) sentences, discuss what should an IS auditor suggest regarding the governance structure of Cachero. 2. The IS budgeting process should be integrated with business processes and aligned with organizational budget cycles. What advice would the IS auditor give to the organization to ensure the budget covers all aspects and can be accepted by the board? Discuss your answer in no more than five (5) sentences.

Understanding Business
12th Edition
ISBN:9781259929434
Author:William Nickels
Publisher:William Nickels
Chapter1: Taking Risks And Making Profits Within The Dynamic Business Environment
Section: Chapter Questions
Problem 1CE
icon
Related questions
Question

An information system (IS) auditor was asked to review the alignment between information technology (IT) and business goals for Cachero, a small but rapidly growing financial institution. The IS auditor requested information including business and IT goals and objectives; however, these were limited to a short, bulleted list for business goals and PowerPoint slides used in reporting meetings for IT goals. It was also found in the documentation provided that over the past two (2) years, the risk management committee (composed of senior management) met on only three (3) occasions, and no minutes of what was discussed were kept for these meetings. When the IT budget for the upcoming year was compared to the strategic plans for IT, it was noted that several of the initiatives mentioned in the plans for the upcoming year were not included in the budget for that year.

The IS auditor also discovered that Cachero does not have a full-time chief information officer (CIO). The

organizational chart of the entity denotes an IS manager reporting to the chief financial officer (CFO), who,

in turn, reports to the board of directors. The board plays a major role in monitoring IT initiatives in the entity,

and the CFO frequently communicates the progress of IT initiatives.

When the IS auditor reviewed the segregation of duties (SoD) matrix, it was apparent that application

programmers are only required to obtain approval from the database administrator (DBA) to directly access

the production data. It was also noted that the application programmers must provide the developed program code to the librarian, who then migrates it to production. IS audits are carried out by the internal audit department, which reports to the CFO at the end of every month, as part of the business performance review process; the financial results of the entity are reviewed in detail and signed off by the business managers for the correctness of data contained therein.

 

 

 

Questions:

 

1. In no more than five (5) sentences, discuss what should an IS auditor suggest regarding the governance structure of Cachero.

 

2. The IS budgeting process should be integrated with business processes and aligned with organizational budget cycles. What advice would the IS auditor give to the organization to ensure the budget covers all aspects and can be accepted by the board? Discuss your answer in no more than five (5) sentences.

Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 2 steps

Blurred answer
Knowledge Booster
Introduction to Forecasting
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, management and related others by exploring similar questions and additional content below.
Similar questions
  • SEE MORE QUESTIONS
Recommended textbooks for you
Understanding Business
Understanding Business
Management
ISBN:
9781259929434
Author:
William Nickels
Publisher:
McGraw-Hill Education
Management (14th Edition)
Management (14th Edition)
Management
ISBN:
9780134527604
Author:
Stephen P. Robbins, Mary A. Coulter
Publisher:
PEARSON
Spreadsheet Modeling & Decision Analysis: A Pract…
Spreadsheet Modeling & Decision Analysis: A Pract…
Management
ISBN:
9781305947412
Author:
Cliff Ragsdale
Publisher:
Cengage Learning
Management Information Systems: Managing The Digi…
Management Information Systems: Managing The Digi…
Management
ISBN:
9780135191798
Author:
Kenneth C. Laudon, Jane P. Laudon
Publisher:
PEARSON
Business Essentials (12th Edition) (What's New in…
Business Essentials (12th Edition) (What's New in…
Management
ISBN:
9780134728391
Author:
Ronald J. Ebert, Ricky W. Griffin
Publisher:
PEARSON
Fundamentals of Management (10th Edition)
Fundamentals of Management (10th Edition)
Management
ISBN:
9780134237473
Author:
Stephen P. Robbins, Mary A. Coulter, David A. De Cenzo
Publisher:
PEARSON