A strong set of internal controls can assist in discouraging unethical behavior such as fraud and abuse. Management has a duty to maintain internal controls over IT systems for several reasons. Mainly, managers have a stewardship responsibility to safeguard assets and funds entrusted to them by the owners of the organization, and meeting this responsibility requires that controls be in place to safeguard assets. IT systems themselves, such as computer hardware and software, are assets that must be protected from theft, abuse, or misuse. Without proper controls on IT systems, the computer systems can be easily misused by outsiders or employees.


An unusual case of computer abuse occurred at a federal agency that regulates financial aspects of companies. The Securities and Exchange Commission (SEC) detected senior managers spending excessive hours viewing pornography during regular working hours. One SEC attorney spent as much as eight hours a day viewing pornography on his office computer. A congressional investigation revealed that 33 high-level SEC staffers in Washington, D.C., were involved in such abuse of computers. Ironically, this misconduct was occurring during the same time that this agency should have been monitoring and reviewing banking institutions and other companies involved in the country's financial meltdown.

While such cases are interesting, they expose a serious misuse of government funds. The U.S. ...

Get Accounting Information Systems: The Processes and Controls, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.