1 / 25100%
CONCEPTS OF MANAGEMENT
ARIZONA STATE UNIVERSITY
CIS 235 - INTRODUCTION TO INFORMATION SYSTEMS
WEEK 4
A. INTRODUCTION:
The word management is taken from the word management in English, which is a
derivative of the word "to manage" which means to take care of governance or management.
While the person who organizes it is called a manager. From the above understanding, it can
be concluded that management is a manager's way of directing, fostering and leading people
who are his employees so that the business being run can achieve the goals that have been
set. Quoted from the book Basics of Management (2015) by Dr. Badrudin, M.Ag, the basic
concepts of management can be divided into four, namely as a science, as an art, as a
profession and as a process. According to (Tifani22: 29).
The concept of management is actually as old as human life. This is because
basically humans in their daily lives cannot be separated from the principles of management,
either directly or indirectly, either consciously or unconsciously.Scientific management
science emerged around the beginning of the 20th century in Europe and America when
these countries were being industrial revolution, which is a change in the effective and
efficient management of production. This is because society has increasingly
To want to know the development of the theory must follow where to look forward
and human needs are increasingly numerous and diverse in type. Management in principle is
how each organizes activities so that they run well in achieving goals optimally in
accordance with what is desired. The expected goal will succeed well if limited human
abilities can be developed by dividing work tasks, authority, and responsibility to others so
that synergistically and mutually symbiotic form cooperation and partnerships that are
mutually beneficial and achieve better goals. Without good cooperation, there is no
management. In order to do management well, one must first know the basic concepts of
management. However, until now there are still many individuals who do not know this.
B. HISTORY and BASIC CONCEPTS OF MANAGEMENT
In the development of knowledge of the basic concepts of management, the nature of
management is a process of providing guidance, leadership, organization, control, and
providing other facilities. The definition of management can be called coaching, control,
management, leadership management which is a process of enthusiasm to achieve
predetermined goals (Fathoni, 2019: 17).
Definition of Management:
Early Basic Understanding of Management The term management, then, comes from
the old French management, which means the art of carrying out and organizing.
Management does not yet have an established and universally accepted definition. Mary
Parker Follet (2019: 17), for example, defines management as the art of getting work done
through other people. This definition means that a manager is in charge of organizing and
directing others to achieve organizational goals.
According to Brantas (2023: 37) management is a process or framework that
involves guiding or directing a group of people towards organizational goals or real goals.
As according to Mas'ud Khasan (2022: 39), management is the management of the process
for the effective use of resources in achieving certain goals.
Ricky W. Griffin (2021: 47) defines management as a process of planning,
organizing, coordinating, and controlling resources to achieve goals effectively and
efficiently. Effective means that goals can be achieved in accordance with planning, while
efficient means that tasks are carried out correctly, organized, and according to schedule.
As according to James (2021: 23), it is said that management is a habit that is carried
out consciously and continuously in forming an organization. All organizations have people
who are responsible for the organization in achieving its goals. This person is called a
manager. Managers are more prominent in some organizations than others, but without
effective management, the organization is likely to fail. (Nasrudin, 2021:21)
C. ACTIVITIES IN THE MANAGEMENT FUNCTION:
In Activities in Management Functions, Each Management function is a series of
activities carried out in management based on their respective functions in following a
certain stage in their implementation. Management functions, as explained by Nickels
McHugh (2019), consists of four functions, including planning, organizing, actuating, and
controlling.
1.
Planning Function
Planning is a number of predetermined activities to be carried out in a certain period in
order to achieve a set goal. According to Bintoro Tjokroaminoto (Husaini Usman, 2021:
65), planning is the process of preparing activities in a systematic manner that will be
carried out in achieving certain goals. Therefore, to achieve the desired organizational
goals, careful planning is necessary. Planning activities involve efforts made to
anticipate future trends and the establishment of fixed strategies and techniques to
realize targets or organizations, i.e., how to plan an environmentally friendly business,
how to design a business organization that is able to compete in global competition, and
so on.
2.
Organizing Function
According to Handoko (Husaini Usman, 2021: 146), organizing is: a. determining the
resources and activities needed to achieve organizational goals; b. the process of
designing and developing an organization that will be able to bring these things towards
the goal; c. assigning certain responsibilities; d. delegating the authority needed for
individuals to carry out their duties. Managers will group and determine important
activities to give power to certain people (staff) to carry out these activities. Organizing
activities concern the way strategies and techniques that have been formulated in
planning are designed in a fast and resilient organizational structure, systems and a
conducive organizational environment, and can ensure that all parties in the
organization can work effectively and efficiently to achieve organizational goals.
3.
Implementation Function (Actuating)
Implementation is the stage of realizing the plan that has been prepared previously with
reference to organizing. In the process of implementing the program so that it can be
carried out by all parties in the organization and the process of motivating so that all
parties can carry out their responsibilities with full awareness with high productivity.
4.
Supervisory Function (Controlling)
Supervision is a process carried out to ensure that the entire series of activities that have
been planned, organized, implemented can run in accordance with the expected targets
even though changes occur in the business environment that occurs. Supervision
activities are an assessment of the implementation of the program from the beginning of
its planning to its implementation. Supervision is carried out by a supervisory
coordinator, then the coordinator uses administration, namely men (human resources /
personnel), materials (materials), machines (equipment, facilities and infrastructure),
methods (methods / services), money (sources of funds) and markets (users).
D. TYPES OF MANAGEMENT ACTIVITIES:
Management needs information as a basis for decision making. Information systems
play an important role in providing information to management at all levels. Each-Different
management activities and decisions require different information. Therefore, in order to
provide relevant and useful information to management, information system developers
must understand the activities performed by management and the types of decisions.
Management Activity Type:
Management activities related to their level in the organization are divided into
several parts, namely as follows
1.
Strategic planning: is a top-level management activity, as a process of evaluating the
organization's external environment, implementing organizational goals, and determining
strategies.
a.
The process of evaluating the organization's external environment: The external
environment can affect the running of the organization. Therefore, upper management
must be good at evaluating it, must be able to react to the opportunities provided by the
external environment, for example, new products, new markets. In addition, upper
management must be responsive to pressures from the external environment that are
detrimental to the organization and turn pressures into opportunities as much as
possible.
b.
Goal setting is what the organization wants to achieve based on the vision that
management has. For example, the company's goal is to become the largest seller in the
industry within five years by controlling 60% of the market.
c.
Strategy setting: upper management determines the actions to be taken by the
organization with a view to achieving goals. With strategy all capabilities in the form of
resources are mobilized so that organizational goals can be achieved.
2.
Management control: a system to ensure that the organization is executing its strategy
effectively and efficiently. This is the tactical level, which is the way middle management
carries out tactics so that strategic planning can be carried out successfully. The tactics
implemented are usually short-term, about one year.
3.
The management control process consists of: work programming, budgeting,
implementation and measurement, and reporting and analysis.
4.
Operations control: a system to ensure that each specific task is carried out effectively and
efficiently. It is the application of the program established in management control.
Operations control is carried out under the guidelines of the management control process
and is focused on lower-level tasks.
E. SUPERVISION IN MANAGEMENT:
1.
Definition of Supervision:
Robert J. Mockler (T. Hani Handoko, 2019: 360) suggests that management
supervision is a systematic effort to set implementation standards with planning objectives,
design feedback systems, compare real activities with predetermined standards, determine
and measure deviations and take the necessary corrective actions to ensure that all resources
are needed in the most effective and efficient way in achieving goals. Supervision is
basically directed entirely at avoiding the possibility of misappropriation or deviation from
the objectives to be achieved.
Through supervision, it is hoped that it can help implement policies that have been
determined to achieve planned goals effectively and efficiently. In fact, through supervision
an activity is created that is closely related to determining or evaluating the extent to which
work implementation has been carried out. Supervision can also detect the extent to which
leadership policies are carried out and to what extent deviations occur in the implementation
of the work. Supervision can be defined as a systematic effort by business management to
compare performance against established standards, plans, or objectives to determine
whether performance is in line with these standards and to take action healing that is
necessary to see that human resources are used as effectively and efficiently as possible in
achieving goals.
George R. Tery (2020: 395) defines supervision as determining what has been done,
which means evaluating work performance and if necessary, implementing
corrective actions so that the work results are in accordance with the predetermined
plan.
Robbin (Sugandha, 2019: 150) states that supervision is a very basic activity process
that requires a manager to carry out organizational tasks and work.
Kertonegoro (2018: 163) states that supervision is a process through which managers
try to gain confidence that the activities carried out are in accordance with their
planning.
Terry (Sujamto, 2018: 17) states that supervision is to determine what has been
achieved, conduct a superior evaluation, and take corrective actions if necessary to
ensure that the results are in accordance with the plan.
According to Dale (Winardi, 2021: 224), supervision is not only looking at
something carefully and reporting the results of supervisory activities, but also
contains the meaning of repairing and monitoring straighten it out so that it achieves
the goals that are in line with what was planned.
In essence, supervision is a systematic effort to set standards for the implementation
of goals with planning objectives, design feedback information systems, compare real
activities with predetermined standards, determine and measure deviations, and take the
necessary corrective actions.
THE RELATIONSHIP BETWEEN INFORMATION SYSTEMS AND
MANAGEMENT
The relationship between information systems and management, especially in its
function, is an interrelated and interrelated relationship. An information system is a
mechanism that integrates information collected by from various sources which is converted
into useful information in the decision-making process. An information system provides the
information needed to develop strategies, make decisions, evaluate performance, identify
opportunities and threats, and implement the actions needed to achieve goals.
The management function is a process used to achieve organizational goals, both in a
broader and more specific scope where management functions include planning,
organization, direction, coordination, and control.
How this information system can play a strong role and have a close relationship in
each stage of management can be explained as follows.
A. INFORMATION SYSTEMS IN PLANNING:
Planning is a process that is the first to be carried out, which is a formulation stage
that is compiled in detail to achieve the ultimate goal and is included in management
activities. This stage of planning has a requirement to set goals and identify methods to
achieve an objective. Planning is a process that allows managers to determine organizational
goals as well as the strategies needed to achieve these goals.
Information systems MISplify the management process by providing information
that can be used to improve company performance, integrating information from various
sources such as historical data, market data, consumer data, and technical data to provide a
clear picture of market conditions, internal conditions, and dynamics that apply within the
organization.
With the information available, managers can make more informed decisions,
identify new business opportunities, and develop strategies to achieve organizational goals
that will be used in planning.
Information systems also help managers evaluate the efficiency and effectiveness of
operations, identify opportunities and threats, and implement effective strategies. By using
information systems, managers can make informed decisions, achieve organizational goals,
and improve organizational performance in the planning process. MIS enables managers to
identify obstacles and constraints that may arise during the planning process. This enables
managers to make informed decisions and implement effective strategies. With accurate and
up-to-date information, management can make the right plans and organize resources
efficiently.
From this description, it can be seen that the relationship between information
systems and management functions is very interrelated in preparing a plan, information
systems help managers identify the information needed, integrate information from various
sources, to be processed as planning documents as guidelines for carrying out activities to
achieve goals.
B. INFORMATION SYSTEMS IN ORGANIZING:
Information Systems can also help managers in the organizing process. Organizing is
a process that allows managers to manage company resources efficiently. Information
systems allow managers to analyze information about company resources and develop
effective strategies for managing resources. This allows managers to achieve company goals
in an effective and efficient manner.
Information systems can also assist management in organizing and managing
organizational resources, such as human resources, capital, and raw materials, because
through information systems, accurate reports will be obtained about the condition of
organizational resources, so that management can take appropriate action to improve
efficiency and effectiveness.
Information Systems can also assist management in managing organizational data, so
that management can make the right decisions based on accurate and up-to-date data in
organizing existing resources to be more efficient.
Information systems can also assist management in improving communication and
coordination between departments within an organization. Information systems can assist
management in improving employee performance by providing the information needed to
perform the tasks of each employee so that they will be more efficient and effective.
Along with the development of technology, information systems are needed to help
business activities keep running well. Almost every field needs a system that can control and
manage information properly and neatly. The main purpose of an information system is to
help business activities and human work to be more structured, which is certainly related to
digital transformation in various fields of the startup industry.
Sometimes, in some organizations/business companies have several departments that
carry out their respective tasks so that if good and harmonious coordination is desired, it is
necessary to have a system that can coordinate each department properly. Information
systems are the right system because they have the ability to help coordinate each
department.
Information exchange becomes better and faster with structured and systematic
management. Healthy relationships will be formed between people in one department and
another through information exchange. This relates to the importance of an integrated
system in an organization.
Through the information system, coordination with stakeholders will be more effective so
that it can assist management in improving relationships with external stakeholders, such as
customers, suppliers, and the government.
From this description it can be concluded that Information Systems and management
functions in organizing are interrelated and interrelated. This system assists management in
carrying out management functions more efficiently and effectively, assisting management
in evaluating and selecting appropriate strategies in managing resources, managing data, and
improving communication and coordination between departments. It also assists
management in improving employee performance and relationships with external
stakeholders.
C. INFORMATION SYSTEM IN IMPLEMENTATION:
The next stage is implementation, actuating or directing is a function of management
that aims to divide tasks according to their abilities. This management function is needed to
manage a group or organization, where in the organization or company there are tasks that
are distributed based on their respective positions. The duties and authorities of directors,
managers, staff, and members must be different according to the field and scope of
responsibility.
Direction will be needed after the tasks are divided into individuals or groups
according to their respective fields. This direction is needed so that goals can be achieved
properly and minimize the risk of obstructing the implementation of the plan. Actuating can
be done by guiding, consulting related tasks, and providing motivation to those concerned.
Information Systems will help managers identify the efficiency, productivity, and
performance achieved by the organization in execution. With the information available,
managers can identify problems and develop solutions to improve operating efficiency,
increase productivity, rate and improve performance in the execution stage.
Information systems provide managers with access to relevant and up-to-date
information so that it can help identify obstacles and opportunities in the management
process, help managers take the right decisions, and help managers implement effective
strategies for smooth execution of plans.
D. INFORMATION SYSTEMS IN CONTROL:
The next stage enters into the control process, where after the plan is successfully
made and then enters the process of implementing the plan. The role of managers and
employees is to supervise the implementation and evaluate so that it runs smoothly and
properly.
Evaluation is a management function to assess the results of the work that has been
done. Evaluation is needed to monitor the progress of the plan that has been set, it is also
used to assess whether a change in strategy is needed or not. In this regard, a company
certainly needs Quality Control in an effort to test and regulate the quality of the products
that the company has created.
Information systems can also assist management in leading and controlling the
organization. With accurate and up-to-date information, management can understand the
current situation and make the right decisions to achieve organizational goals...
Information systems provide the information needed to evaluate performance. The
information provided can be useful for controllers to find out things that are implemented in
accordance with what was planned Where the results of the evaluation will be used to make
recommendations on long-term strategies that will promote organizational growth.
Information provided by information systems is important for managers to evaluate
performance. Information systems will provide managers with how the organization can
achieve its goals and how the strategies that have been implemented have affected the
performance of the organization so that it will help managers find the right data to make the
right evaluation reports.
In conclusion, the relationship between information systems and management
functions is interdependent as it will provide the information required by managers to
develop strategies, make decisions and evaluate performance. With the information system,
the implementation to achieve organizational goals will be more efficient. Thus,
management information systems have become an important part of management.
E. INFORMATION SYSTEMS IN DECISION MAKING:
Information systems assist management in making the right decisions by providing
accurate and up-to-date information. With Information Systems, it will help management to
identify potential problems and provide various solutions for decision making to overcome
these problems.
A system must certainly be based on relevant information and from valid sources and
contain a fact so that the decision-making process runs well. With the management
information system in the organization, decision making will be easier and well structured.
One type of information system is a Decision Support System that can be used in
making business decisions.
F. APPLICATION OF INFORMATION SYSTEMS IN MANAGEMENT:
To clarify the relationship between information systems in management, here are
some examples of management information systems implemented in organizations or
businesses:
1.
Enterprise Resource Planning (ERP)
This Enterprise Resource Planning (ERP) module is indeed widely used by large
companies, but small-scale companies can still implement ERP systems. This ERP
system usually functions to manage management and conduct integrated supervision
between units within the company.
2.
Supply Chain Management (SCM)
This SCM system is very useful for management because SCM integrates data such as
raw material supply management, starting from suppliers, manufacturers, retailers to
end consumers.
3.
Transaction Processing System (TPS)
TPS is a management information system that is useful for processing large amounts
of data or transactions that are routine in nature. The application of this program is
usually applied in salary and inventory management.
4.
Office Automation System (OAS)
This application is useful to facilitate coordination and communication between
departments in a company by integrating computer servers for each user in the
company. An example of its application is in the use of email for office activities
every day.
5.
Knowledge Work System (KWS)
A KWS information system is a system that integrates new knowledge into an
organization/entity.
6.
Informatic Management System (IMS)
IMS serves to support a spectrum of tasks within an organization. Apart from that,
IMS can also be used to assist in analyzing decision making. This system can also
unify several information functions with computerized programs such as e-
procurement.
7.
Decision Support System (DSS)
Is a system that helps managers make decisions by observing the environment within
the organization / company. An example of a management information system on this
one is like an electronic link.
8.
Expert System (ES) and Artificial Intelligence (AI)
Recently, there has been a rise in ES and AI. These two systems basically use artificial
intelligence that is useful for analyzing the solution of a problem by using expert
knowledge that has been programmed into it. An example of its application is in the
mechanical schedule system.
9.
Group Decision Support System (GDSS) and Computer-Support System (CSS)
Collaborative Work System (CSCWS) GDSS is almost the same as DSS, the difference
is that GDSS seeks problem solutions through gathering knowledge in a group, not
individually, in the form of questionnaires, consultations and scenarios. An example of
its application is in e-government.
10.
Executive Support System (ESS)
This ESS system helps managers to interact with the company's environment using
graphics and other communication supports so that it is easier and more
communicative.
INTRODUCTION TO DATABASES
A. DEFINITION OF DATABASE:
What is a database? If we want to know and understand what a database is, then we
will find part of the database in a database system. Let's pretend for a moment, thinking
MISply that we are going to make a bicycle that can drive.
You know that a bicycle has several basic components including two wheels, front
and rear. The wheels each have one spoke, right and left pedaling levers, a chain to drive the
rear wheel, and the bike has a handlebar.
To make the bicycle run, it requires a series of systems from the bicycle frame, so
that when the right and left bicycle pedaling levers are moved forward alternately, the
bicycle wheels turn and the bicycle can walk forward.
If you have understood the components that make a bicycle move forward, then you
have found where the database is. The basic components that make up a bicycle such as the
handlebar, two wheels, right pedal lever and left, the bicycle chain, and the bicycle spokes
can be thought of as representations of a database.
Database is one of the basic components in an information system, where the
database can be interpreted as a collection of facts (data) in a series of relationships, between
these facts have a relationship between one fact and another where the series of facts can be
stored, manipulated, and called by its users (organization) for certain purposes.
B. DATABASE SYSTEM:
We already have an example of making a bicycle component so that it can drive, and
now we will talk about the database system.
Note the database system design table above, starting from the goes_right table,
goes_left table, pull_chain table, to the rate_sepedah table, until the bike moves forward.
Then the database system can be categorized as a series of data or objects that are
interconnected and connected into a system so that the bicycle can move forward.
C. PURPOSE AND BENEFITS OF DATABASES:
In its application, databases have many purposes and benefits in different types of
organizations that use them, let's take a look at an example:
1.
The benefits of database implementation in educational institutions: being able to
provide efficiency for users, to search for student data or school data MISultaneously
because of the database. Data has the advantage of being multi-user which can be used
safely with the security of passwords and user logins that are collected centrally so that
it does not take up much space.
2.
Benefits of database implementation in the organization: database systems are able to
manage production data processing in a structured manner, improve the security and
performance of a data processing system, and are able to influence the quality and
quantity of final results in the organization.
From the two examples of database benefits above, we can conclude the purpose of
the database in each application, namely, changing the data processing system from a non-
centralized to a centralized system, so that users get convenience in computerized data
processing, which can be accessed safely and MISultaneously (multi user).
D. DATABASE SYSTEM COMPONENTS:
The database system is formed from several main and supporting components, in building a
database-based application system, namely:
1.
Hardware
The main physical component of the computer used to process the database system.
Example: Computers, Hard Drives, Networks and more.
2.
Operating System
A set of programming languages that runs on top of the BIOS (Basic Input Output), the
operating system is a container for running applications used to design and build database
systems.
Example: Microsoft Windows, Linux, Android and others.
3.
User
Are users who use and process applications, namely, database system applications that
are built.
Example: Programmer, Operator, Database Administrator etc.
4.
Database
Database is the source of a collection of data that is integrated in the database system.
5.
Database Management System (DBMS)
It is software or application, which runs in the operating system, functions to process, run
and design the system from the database.
Example: MySQL, Ms.Acces, Oracle, and others.
6.
Other Application
Is a link between the database system and the external system and centralized into a
system, which is used to facilitate users (users) in interacting with the system created
(user friendly).
Example: Website-based applications, Mobile-based applications and others. From the
real implementation, here are examples of the most commonly used Database System
(DBMS) applications:
1.
MySQL
MySQL is a relational database management system based on SQL and client-server
architecture.
2.
PostgreSQL
PostgreSQL is an enterprise-level open-source database management system. It
supports SQL for relational queries, and JSON for non-relational queries.
3.
MongoDB
MongoDB is a not only SQL (NoSQL) document database system that compiles
information in collections and documents. Some of MongoDB's best features are
unstructured data storage, full indexing support, and replication using APIs.
4.
Cassandra Database
Cassandra is another DBMS that is also NoSQL. It is known for its scalability that
allows users to add more nodes and machines to increase its computing power.
5.
Oracle Database
Oracle is an RDBMS with an architecture that is divided between logical and
physical structures. One of the best features of the Oracle database is the enterprise
grid computing that uses modular physical storage and servers that can be sized by
the user.
E. DATABASE APPLICATION TIERS:
For those of you beginners, before designing a database application, we must first
understand the levels of database applications which are divided into two levels, namely:
1.
Stand Alone Database Application
Is an application that only runs on a computer and can only be accessed by one person
at a time, with the Database (Back End) and the application program (Front End) being
on one computer. An example is Microsoft Access.
2.
Multi User based Database Application
It is a program that can be used by many users at one time and in different places. An
example of a MISple application, is to create a Stand Alone application, then share its
database (share) with other computers that will access the database.
3.
Client-Server based Database Application
It is a database application that requires two database application systems, one as a
database server (center), and a computer interface that is used as a client (accessor). So
in this application, we must use a database server as a data storage medium.
F. DATABASE BASICS:
In a database system design, it is necessary to know in advance. There are several
types and functions of database systems, whose application is also different and depends on
the needs of the user (organization). But in its application, each database system application
still has the same rules in its application.
Such as the use of Database, Table, Column and Record hierarchy provisions in the
database. Here's an example of the database hierarchy usage:
The table above is an example of the application of hierarchy in database systems
(DBMS) in everyday life, such as making a bicycle move forward. Here are some examples
of the use and application of database systems in organizations:
1.
The database is used to collect data on company employees.
2.
Use the database for teacher and student attendance at school.
3.
Use of a database in registration and admission to a ride.
4.
The use of databases in ordering menus at restaurants or cafes.
5.
The use of databases to process office work such as managing financial reports and so
on in the company.
In the existing implementation of database utilization, the following are some examples of
database applications has been widely applied in companies or the surrounding environment:
1.
Attendance Application for companies or organizations
2.
Ticket Purchase App
3.
Hotel Reservation App
4.
Member Loundry Application
5.
Goods Inventory Application
6.
Savings and Loan Cooperative App
7.
Restaurant Reservation and Order App
8.
Employee Salary App
9.
Minimarket Cashier Shopping App
10.
Car Rental App
11.
Insurance Data Application
12.
Goods Delivery Package Application, etc.
INFORMATION SYSTEMS AND INFORMATION TECHNOLOGY AUDIT
A. DEFINITION:
Information Systems (IS) and Information Technology (IT) Audit is an independent
assessment of information systems and information technology in an organization.
Information System Audit. Information System Audit is the process of examining and
assessing an organization's information system. An information system audit is an effort to
collect and assess various evidence in order to determine whether a computer system is able
to secure company data, maintain data integrity, and encourage companies to achieve their
goals effectively and efficiently (Weber, 1999). The main focus in an IS/TI audit is on
aspects of information security, data integrity, service availability, and compliance with
applicable regulations and policies.
Information Technology Audit. An Information Technology Audit includes an
examination of all aspects of the technology used in the organization, including hardware,
software, networks, and the overall IT infrastructure. The goal is to assess the effectiveness
and efficiency of information technology management in achieving organizational goals.
The examination may include an evaluation of IT policies, IT project management, IT
development strategies, and compliance with applicable standards and regulations.
Audits of information systems and information technology are usually conducted by
independent external or internal parties to ensure that the controls and procedures
implemented in the organization meet the desired standards of security, quality, and
compliance. An effective internal audit department considers audits as a partnership with
fellow employees, not as a supervisory function and is carried out on an ongoing scheduled
basis (Kegerreis, Schiller and Davis, 2020).
The results of these audits provide stakeholders with valuable information to take
corrective action and ensure that their IT environment is operating efficiently and securely.
B. SI/TI AUDIT OBJECTIVES:
Information system audits aim to determine whether the software used by the
company can secure assets, maintain data integrity, and encourage the achievement of
organizational goals effectively and efficiently (Fernando et al., 2021). IS/IT audits have
certain objectives and benefits that involve examining, evaluating, and managing
information systems and information technology in an organization. Here are some of the
objectives of SI and IT audits:
1.
Securing Assets
Assets related to the installation of information systems include: hardware, software,
people, data files, system documentation, and other supporting equipment. Information
system security audits based on SNI-ISO 27001 aim to assess the performance of
information systems in protecting information assets from threats and risks (Putra, Wati
and P, 2020).
2.
Maintain Data Integrity
Data integrity means that data has attributes: completeness, good and trustworthy,
purity, accuracy and consistency (Darudiato et al., 2006). Without maintaining data
integrity, organizations/companies cannot portray themselves correctly and existing
events are not revealed as they are so that important decisions and steps in the
organization are misdirected. This decision-making error has an impact on various
things including time and costs incurred.
Data integrity refers to the state in which data remains accurate, consistent, and does not
undergo unauthorized or unwanted changes. Organizations/companies can rely on
correct data to continue their operations, regardless of changes in the business
environment or unexpected events. By maintaining data integrity,
organizations/enterprises can optimize the performance of their information systems,
increase stakeholder trust, and reap long-term benefits significant lengths in information
and technology management.
3.
Maintain system effectiveness
The effectiveness of information systems is a science of processing data into something
of value so that it can be used as a reference in decision making (Abdul Muttalib, 2017).
Variables that determine the effectiveness of information systems include; system
quality, information quality, usefulness, functionality, ease of use, usage capacity, user
satisfaction, impact on individuals and impact on organizations / companies (Weber,
1999).
It is necessary to find out the needs of system users, whether the system produces
information that is useful for users (for example decision makers). The system
effectiveness audit is carried out after a system has been running for some time,
conducting a post audit to determine the extent to which the system has achieved its
objectives, because the information system is said to be effective only if the system can
achieve its objectives. This evaluation will provide recommendations for decision
makers whether system performance is worth maintaining, improving or needing to be
modified, or even the system must be replaced.
4.
Achieving System Efficiency
Information system efficiency refers to the ability of an information system to achieve
organizational/company goals by using available resources optimally. With By ensuring
information system efficiency, organizations can optimize their use of information
technology, increase productivity and better achieve business goals. Information system
efficiency can also help organizations to remain competitive and responsive to changes
in the business environment. In this context, "efficiency" means that the information
system can perform the functions it provides in the most effective and efficient way
possible. Efficiency can be measured from several factors such as time, resource
utilization and suitability (Desiana and Ayu, 2017). Some aspects and characteristics of
information system efficiency include:
Use of Resources. An efficient information system makes optimal use of resources
such as hardware, software and manpower. This includes managing memory, storage
capacity, and computing power.
Response Time. Information system efficiency can be measured by how quickly the
system responds to user requests. A responsive system can increase productivity and user
satisfaction.
Data Availability. An efficient information system provides quick and easy access to
the data required, This involves good database design, accurate data indexing, and effective
data management strategies.
Maintenance and Support. The efficiency of information systems is also seen in the
ability to be well managed and easily maintained. Good design and proper technology
selection can reduce maintenance costs.
Scalability. An efficient information system can handle a large volume of
transactions without experiencing significant performance degradation. Efficient
information systems can also grow over time and increase their capacity without
experiencing significant performance degradation.
Safety and Reliability. Efficiency also includes aspects of security and reliability. An
efficient information system must be able to protect data from security threats and provide
high availability.
5.
Provide Recommendations:
The audit report contains recommendations from the auditor on what should be done
to improve the audit findings, the recommendations are solutive and constructive.
Recommendations from audit results can streamline the time to see risk management
solutions for each step and decision taken by providing a realistic view. Each
recommendation should be tailored to the context organization/company, audit objectives,
and specific findings identified during the audit process.
Follow-up is not only about implementing the recommendations, but also ensuring
that the changes are sustainable and in line with the growing needs of the
organization/company. Organizations/companies should prioritize the implementation of
recommendations based on their urgency and impact on security, performance or operational
sustainability. Stakeholders should and are strongly encouraged to be involved in the
planning and implementation of recommendations in order to achieve optimal results.
Follow-up is the activity of identifying and documenting the auditee's progress in
implementing audit recommendations (Rai, 2008).
C. BENEFITS OF SI/TI AUDITS:
Information system audits provide a number of significant benefits to an
organization/company. There are several benefits of IT audits that can be a consideration for
organizations or companies to conduct. Here are the benefits of an information technology
audit:
1.
Security Enhancement
Information system audits help identify potential security risks and provide
recommendations for strengthening security controls. In an era where cyberattacks are
increasingly complex, information systems audits help organizations/enterprises to ensure
that they have effective defenses against cyber threats. This includes the review of security
policies and the implementation of appropriate security controls.
In addition, information system audits can help detect and prevent potential fraud and fraud.
A careful examination of records and transactions can identify discrepancies or suspicious
behavior. This can prevent unauthorized access, hacking, or data leaks.
2.
Better Risk Management:
The implementation of risk management in an organization does not always succeed
in achieving its goals. This problem can be caused by a lack of consistency in
implementation or the organization cannot adapt to environmental changes that occur
(MISanjuntak, Priyarsono and Sumarti, 2021).
Identifying and evaluating risks associated with information technology can help
organizations/companies better manage risks. Better risk management is a systematic and
proactive approach to identifying, assessing, managing and mitigating risks that an
organization/company may face. Using technology to support risk management, such as
computerized risk management systems and data analytics that can help identify and
measure risks more accurately.
Information systems audits help ensure that information systems and information
technology are reliable and always available. Therefore, processes and infrastructure that are
able to withstand disruptions and crises are one of the characteristics of
organizational/company resilience, including disaster recovery planning and development.
System reliability monitoring and improvement can be implemented based on audit findings.
3.
Improved Information Quality:
The quality of information owned by an organization/company is one of the things
that greatly affects user satisfaction (Rukmiyati and Budiartha, 2020). Improving
information quality refers to efforts to ensure that the data and information owned by an
organization/company or information system are accurate, consistent, relevant, complete,
and reliable. Accurate and reliable data is essential for good decision making.
4.
Operational Efficiency
Operational efficiency refers to the ability of an organization to use resources in an
optimal way to achieve its business objectives. Efficiency improvement Operational
efficiency can bring a variety of benefits, including reduced costs, increased productivity,
and better service to customers. Through the evaluation of business processes and
information technology, audits can identify areas where operational efficiency can be
improved. These improvements can help organizations save time, resources, and costs.
5.
Stakeholder Trust
Increasing stakeholder trust is an important aspect of building a positive reputation
and supporting organizational sustainability. By conducting regular information system
audits, organizations/companies can build stakeholder trust and maintain a positive
reputation.
6.
Improved SI/TI Governance
Improving the governance of information systems (IS) and information technology
(IT) is an important step to ensure that organizations/companies can manage and utilize
information technology effectively, safely, and in accordance with business objectives. An
audit helps ensure that an organization's information technology governance is in line with
best standards and current practices. This includes reviewing policies, procedures, and
organizational structures.
Clear policies and procedures related to SI/TI management include aspects of
security, regulatory compliance, management and security risk, and resource management.
In addition, the support and commitment of the organization's top leadership to IT
governance is also very influential on the success of IT governance. Leadership commitment
is one of the critical factors that influence the success or failure of the implementation of
SI/TI governance, because leaders have a role in determining the vision, mission, strategy,
and policies related to SI/TI, as well as allocating resources and overseeing their
implementation (Rukmiyati and Budiartha, 2020).
D. SCOPE OF SI/TI AUDIT:
There are several subject areas that are potentially reviewed in the IS/TI Audit
process, namely; data center facilities, networks, system platforms, databases, and user
applications (Kegerreis, Schiller and Davis, 2020).
Data Center Facility. A data center facility audit is a process of thoroughly
examining the information technology infrastructure used in data centers and data center
operations to ensure the effectiveness, security, and availability of services.
Network. Network infrastructure includes all server hardware, routers, switches,
firewalls, network topology, connectivity between devices, network segmentation and other
hardware. A computer network infrastructure audit involves a thorough evaluation of the
hardware, software connected to the network, as well as the network configuration to ensure
optimal security, availability, and performance.
System Platform. Evaluate operating system security on all devices to ensure that
they are updated, properly configured, and protected with antivirus and antispyware. An
audit of the operating system platform does not evaluate security but also the availability,
integrity, and performance of the operating systems used in an environment. Potential
vulnerabilities can also be avoided by keeping the versions of the platforms in use up to
date.
Databases. Database audits cover several aspects including access management, data
security policies (including data deletion and alteration), security monitoring, data backup
and recovery, data integrity and data processing. User Application or Software. Evaluate the
integration of the software with other systems and ensure that the software can operate
effectively with other applications and platforms in use. Application audits also include
software licenses, renewal procedures, configuration changes, access control, logging
monitoring, and conformance to business processes.
E. SI/TI AUDIT FRAMEWORK:
Here are some frameworks that are commonly used in information technology (IT) audits:
1.
Control Objective for Information and Related Technology (COBIT):
COBIT is a framework published by ISACA and the IT Governance Institute. COBIT helps
align business goals with IT goals by building relationships between the two and creating
processes that can help bridge the gap between IT and outside departments (White, 2019).
COBIT 5 has five main principles, namely (ISACA, 2012):
Meeting Stakeholder Needs
Covering the Enterprise End to End
Applying a Single Integrated Framework
Enabling a Holistic Approach
Separating Governance from Management
2.
Information Technology Audit Framework (ITAF):
ITAF is a framework that is also published by ISACA. The framework is focused on ISACA
materials and provides a single source where audit and assurance professionals can seek
guidance, research on policies and procedures, obtain audit and assurance programs, and
develop effective reports (ISACA, 2014). ITAF is divided into three main parts, namely;
audit standards, audit guidelines, audit techniques and tools.
3.
ISO/IEC 27001:
ISO/IEC 27001 is an information security management system standard that provides a
framework for managing information security in an organization/company (Junaid, 2023).
This Farmework standard covers risk identification, implementation of security controls, and
maintenance of compliance to help organizations/companies build, implement, maintain,
evaluate and improve the Information Security Management System (ISMS).
4.
Information Technology Infrastructure Library (ITIL):
ITIL (Information Technology Infrastructure Library) was developed by CCTA (Central
Computer and Telecommunications Agency), now known as OGC (Office of Governance
Commerce) in the UK. ITIL is a consistent and comprehensive framework from the results
of proven applications in information technology service management so that a company
can achieve the desired quality of service support (Febianto et al., 2011).
The ITIL framework has several stages in managing IT service management (ITSM)
called the Service Lifecycle. There are 5 service lifecycle processes in ITIL, namely
(Buehring, 2018):
Service Strategy
Service Strategy provides guidance for organizations/companies to implement ITSM
from providing, delivering, managing and operating IT services.
Service Design
The scope of Service Design includes the design of new IT services, changes and
improvements in service quality, service continuity and performance of services.
Service Transition
Service Transition provides guidance to IT organizations to be able to develop or
change the results of IT service design. The processes covered in Service Transition are:
Transition Planning and Support, Change Management, Service Asset & Configuration
Management, Release & Deployment Management, Service Validation, Evaluation, and
Knowledge Management (Buehring, 2018).
Service Operation
Service Operation is a stage that includes all daily operational activities of IT service
management.
Continual Service Improvement (CSI)
CSI is a guide for structuring and maintaining service quality from the design process,
transition and operation. CSI combines various principles and methods from quality
management, one of which is Plan-Do-Check-Act (PDCA) or known as the Deming
Quality Cycle (Febianto et al., 2011).
Each organization/company can choose the framework that best suits its needs and audit
objectives.
Students also viewed