Publication | Closed Access
Combining Decision Making Trial and Evaluation Laboratory with Analytic Network Process to Perform an Investigation of Information Technology Auditing and Risk Control in an Enterprise Resource Planning Environment
20
Citations
49
References
2012
Year
EngineeringInformation Technology AuditingBusiness IntelligenceInformation SecurityIt Disaster RecoveryDifferent TypesCyber-risk ManagementAuditingSafety-critical SystemInformation Technology ManagementRisk ManagementManagementSystems EngineeringEnterprise Information SystemData Access ControlData ManagementInformation System PlanningAnalytic Network ProcessReliabilityAccountingInformation ManagementDecision Making TrialEnterprise Resource PlanningData AccessInformation AssuranceBusinessData Risk
The research examined different types of risk through interviews with experts. The risks studied include business interruption risk, process interdependency risk and system security risk. The decision making trial and evaluation laboratory is used to find the relationship among risks and combined with the analytic network process to select the optimal measures for reducing risks. The results indicate that information technology (IT) consultants prefer the Disaster Recovery Plan (DRP). They usually use the remote replication or High Availability (HA) to protect data. IT personnel believe that all of the IT risk controls are important. Auditors indicate that data access control is very important because users have to execute data access every day. Users of IT express a preference towards data input/output control as the most important control. The results achieved from all experts indicate that the most important controls overall are data input/output control, data access control and so on. Managers need to consider these risks to avoid any potential problems. Copyright © 2012 John Wiley & Sons, Ltd.
| Year | Citations | |
|---|---|---|
Page 1
Page 1