1 / 13100%
1
Information Security and Systems Integrity in Accounting
2
Information Security and Systems Integrity in Accounting
Introduction
Accountants have always shown how to adapt and adopt new technologies. Ensuring that
their processes and systems are correctly documented. Without it, CPA firms are unable to
properly keep ensuring trust, keep up with the real-time auditing, and provide insights to help
their clients. This includes understanding the risk of cybersecurity and the integrity of the
systems in place, such as the accounting information system (AIS). This does not stop the threat
of a cyberattack but helps understand and assess those vulnerabilities to be better prepared.
Taking preventive measures to identify, assess, remediate, and maintenance in a timely manner
are critical to success. There is no shortage of news and resources to help not only accountants
but also the businesses they help. New tools are being created; new techniques are being
developed to reduce errors with AI and adapting to the ever changing industries.
3
Information Security and Systems Integrity in Accounting
Body Section One
Technology and Accounting
Technology has been the driving force for the transformation of so much in our society
from the beginning. Technology as defined in Britannica, “is the application of scientific
knowledge to the practical aims of human life or, as it is sometimes phrased, to the change and
manipulation of the human environment.” This applies to accounting going from mainly a paper-
driven process to a more streamlined workflow. As we develop new technologies, we will need
to adapt. Business as a whole has been changed by technology; algorithms have been made to
keep the figures accurate. These algorithms were made to help companies today make trading
decisions, assurance that user’s financial statements are reported completely, a company’s
prospects are adequately presented, and all are available to stakeholders in a timely manner
(Heller, 2022). If accounting had not advanced to today’s standards, getting anything done in a
timely manner would be next to impossible. To ensure any meaningful audit result with the scale
of today’s companies technology is needed to carry out this critical role (Heller, 2022).
As for the future, technology is a continuous thing and the bar each year is set higher.
People are still at the core of accounting; AI cannot replace human interaction, just make it easier
to keep track of it all. Business as a whole will be raised higher by technology. As has been
stated it cannot replace human interaction, it makes it so attention can be put into other aspects of
the business.
4
Information Security and Systems Integrity in Accounting
Body Section Two
American Institute of Certified Public Accountants (AICPA)
The American Institute of Certified Public Accountants or AICPA is the organization of
Certified Public Accountants. They represent all CPAs in the United States as well as members in
130 countries, providing the services for the CPA profession (Kenton, 2022). AICPA sets the
standards for professional ethics, business valuation, financial statement auditing, attest services
and CPA firm quality control from as far back as 1887 (Kenton, 2022). This also includes
cybersecurity risk management because of the rising cybersecurity threats. With the accounting
profession an ever-changing field with the financial and regulatory environment becoming more
complex while accounting systems are becoming more streamlined (AICPA, 2023).
Information security and systems integrity
Information security is the protection of information and information systems such an
AIS from unauthorized access, use, disclosure, disruption, modification, or destruction to ensure
confidentiality, integrity, and availability (Dempsey et al., 2017). Because information spans
from facts to ideas and knowledge information security does not just span the digital world.
Employees are also counted and are normally considered the weakest link in information security
while simultaneously being their greatest asset (Bulgurcu et al., 2010). Information systems (IS)
are heavily relied upon when managing any risk associated with information systems (Bulgurcu
et al., 2010). IS is more of a management issue than a technical one, because management is
responsible for recognizing the issue not just the IT department. They hold the responsibility for
design, implementation, and maintenance of a company’s internal control system (Hazaa et al.,
2010).
5
Information Security and Systems Integrity in Accounting
Principles
Information security is at its core a set of practices designed to keep data secure. This is
what drives its principles confidentially, integrity, and availability. Confidentiality entails
preserving authorization restrictions on who can access information and disclosure (Dempsey et
al., 2017). This is possibly the most obvious of the principles because keeping data secure needs
to be authorized. This who have access to data need to be able to identify themselves through
passwords. Encryption also plays a key role, hackers or unauthorized people cannot read the
information without the keys (Devopedia, 2020). Integrity means that the data is guarded against
improper internal or external information modification or destruction (Dempsey et al., 2017).
Integrity is also defense against information non-repudiation and authenticity. In short, it
maintains data correctly to prevent untruthful modification. Nonauthorized users are not able to
access data to change if they do not have access. Data is protected from a breach by verification
of data integrity, updated software, and backing up frequently to restore data. Having a backup
file helps to prove the integrity of data if things go south. Data integrity simply put is data that is
unaltered by unauthorized means including in storage, during processing, and in transit
(Dempsey et al., 2017). Integrity also expanse to systems meaning the quality of a system when
it performs as intended free of unauthorized manipulation, intentional or otherwise (Dempsey et
al., 2017). The last of the principles is availability, making sure that information is accessible in a
timely manner and of reliable use (Dempsey et al., 2017). This is the opposite to confidentiality;
availability is the need to ensure that it is accessible to those who have authorization. Systems
must have a redundancy built in the system, backups in place to restore services quickly, updated
security, and proper bandwidth (Devopedia, 2020).
6
Information Security and Systems Integrity in Accounting
Risks and Attacks
Risks and attacks cannot be completely eliminated but they can be managed. There is a
middle ground to this, the objective becomes to find the balance between protecting information
and utilizing the available resources (Dempsey et al., 2017). In terms of information security
management of the organization is ultimately responsible for determining the risk a system poses
for their organization
Examples of both
Just as with everything risk is apart the everyday, people make mistakes both on accident
and on purpose. For businesses the reduction of these risks and to ensure system integrity they
rely on technology-based solutions (Ernst & Young, 2008). System Integrity entails the quality of
a system when it performs as intended without unauthorized manipulation of said system
(Dempsey et al., 2017). Providing system integrity is just one of the basic security services.
Other basic security services include confidentiality, authentication, availability, and non-
repudiation should be guaranteed protection (Abosata et al., 2021). Despite all the new
technologies and streamlining of information systems the power and memory of the device must
be considered. Devices that are used for business are connected to the internet and with each
other, so they are limited to securities they can run. Another variable
7
Information Security and Systems Integrity in Accounting
Body Section Three
Accounting Information Systems (AIS)
Accounting Information Systems (AIS) is a system that keeps records, processes information,
summarizes, as well as reports and communicates the results of business transactions to those with access.
AIS provides both financial and nonfinancial data to help managers make better decisions going forward.
It is considered the most important tool that institutions rely on to conduct business (Hazaa et al., 2010).
Being made up of what is deemed useful by the management, from a simple information system
to the inclusion of nonfinancial information. Organizations that take on AIS are able to provide
accurate information in a timely manner while having it be effective information (Hazaa et al.,
2010). With systems relying more on software today the system still combines the traditional
accounting practices while incorporating modern information technology.
The crucial role it plays.
AIS plays a crucial role for businesses to keep information in one place. As a term of information
system as defined by 4 U.S.C., Sec. 3502 as “a discrete set of information resources organized for the
collection, processing, maintenance, use, sharing, dissemination, or disposition of information”
(Dempsey et al., 2017). On top of this also affects a firm’s overall value. Having a system that keeps
track of the company’s ins and outs is great for its longevity. The more accurate financial performance
makes the company more likely to draw in investors. Managers and investors investigate statement
revenues, costs of goods sold, gross margin, etc, to see the effects of the business financial
dealings. Simply put, the greater the quality equals greater value, creating more success.
Relevant and faithfully represented are key components, free from unauthorized manipulation.
Cybersecurity
8
Cybersecurity has the boarder definition of defending IT assets from attack as an umbrella term
while information security is a specific discipline. While these tend to overlap, they are still separate.
Information Security and Systems Integrity in Accounting
Cybersecurity involves securing data stored within systems, protecting, preventing damage to, and
restoring electronic communications services and systems (Galarita, 2024). This is where the difference
lies in one word electronic, it covers all things electronic systems and communications. It is one of the top
issues for management and boards of just about every company in the world. Says it just covers electronic
is putting it simply. Boardy it is a collection of tools, policies, security concepts, security safeguards,
guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that
can be used to protect the cyber environment and organization user’s assets (Brown & Veale, 2020).
Cybersecurity requires constant maintenance and update to maintain relevance against security
risk.
Relation to AIS and AICPA
AIS data is mainly done electronically, cybersecurity plays an important role in protecting that
data. CPA firms are under threat constantly from cyber based attacks with the increasingly mobile
workforce (Nakamura, 2022). The director of the FBI makes a valid point, “There are only two types of
companies: those that have been hacked, and those that will be” (Cowley, 2012). Managing as well as
reporting cybersecurity risks must be one of the top priorities for every company. Within 2020 was
projected that over one third of the financial and non-financial information was to live in or was passed
through the Cloud (Eaton et al., 2017). That is no small amount of data and properly managing it
saves everyone from later headache. Effective cybersecurity risk management has five steps that
should be done continuously. According to Accounting and Cybersecurity Risk Management,
“the first three stages are foundational to any effective risk management program, where the
organization (1) identifies and prioritizes its risks/exposures, (2) designs and implements relevant
9
controls to mitigate the risks/exposures, and (3) monitors the operating effectiveness of the
controls in mitigating the risks/exposures.” The fourth and fifth steps are represented with the
Information Security and Systems Integrity in Accounting
guidance of the AICPA, which addresses external stakeholders' concerns with the reporting
organization's cybersecurity risk management (Eaton et al., 2017).
Forms of Attacks
Cybersecurity attacks are creative and tricky, most of them easily missed. Because if they failed
at identifying certain risks or prioritizing the wrong risks, management will fail and not be without
consequences (Eaton et al., 2017). Attacks can be from malware being introduced to the system
through an infected email and fraudulent emails for wire transfers, to larger attacks like
ransomware demand for the return of stolen data (Nakamura, 2022).
Preventive Measures
Preventing this attack takes consistency, it’s not something done just once. Firms need to
consistently review and test their own systems for vulnerabilities (Nakamura, 2022). There are
several different strategies to diminish an attack. One of the main things to use is multifactor
authentication, that requires two different factors for someone to access a system. This is
commonly done with a one-time code sent through an app, email, or text. Encrypted devices like
laptops, phones, and tablets are easy targets for people to steal or for their owners to lose
(Nakamura, 2022). Being able to disable and wipe a device remotely is key to keeping sensitive
data out of people’s hands (Nakamura, 2022).
10
Information Security and Systems Integrity in Accounting
Conclusion
As this paper points out, the growth of technology has its pros and cons. The security and
integrity of information should always be one of the top priorities of any company. CPAs are at the center
of it all in an ever-changing environment. One that challenges them to be more aware of the ins and outs,
to have the knowledge and guidance to assist businesses in an ever change environment. The pros and
cons balance each other making it a constant need to be vigilant. AIS makes it easier by keeping both
financial and nonfinancial information in one place to provide accurate information in a timely
manner. The ones involved with the AIS are limited to keep the possibility of error down. If an
error is made, log in information can be traced back to find out who. Errors can be fixed by
companies having a backup file helps to prove the integrity of data if things go south. A well-
designed AIS allows businesses to run smoothly, telling the story of a business’s financial data.
11
References
Bulgurcu, Burcu; Cavusoglu, Hasan; Benbasat, Izak. (September 2010). Information Security
Policy Compliance: An Empirical Study of Rationality-Based Beliefs and Information
Security Awareness. JSTOR. MIS Quarterly. Vol. 34, No. 3. pp. 523-548.
https://www.jstor.org/stable/25750690?
saml_data=eyJzYW1sVG9rZW4iOiI1NGE5YTM4Mi01ZGU3LTQ2ODQtOTBhZC0xZ
GU5NmU5ZDk2NjIiLCJpbnN0aXR1dGlvbklkcyI6WyJjNGZjMjNmMC01MDQzLTRi
OWMtYjgzNS0wZTBkZDBhMDA2MjMiXX0
Cowley, S. 2012. FBI Director: Cybercrime Will Eclipse Terrorism.
https://money.cnn.com/2012/03/02/technology/fbi_cybersecurity/
Dempsey, Kelley., Nieles, Michael., Pillitteri, Victoria Yan., (January 2017). An Introduction to
Information Security. NIST Special Publication 800-12 (DRAFT) Revision 1. CSRC.
https://csrc.nist.gov/csrc/media/publications/sp/800-12/rev-1/draft/documents/
sp800_12_r1_draft.pdf
Devopedia. (July 21, 2020). "Information Security Principles." Version 4,
https://devopedia.org/information-security-principles
Eaton, Tim V., Grenier, Jonathan H., Layman, David. (September 1, 2019). Accounting and
Cybersecurity Risk Management. Current Issues in Auditing; 13 (2): C1–C9.
https://doi.org/10.2308/ciia-52419
Galarita, Brandon. (January 2, 2024). Information Security Vs. Cybersecurity: What’s The
Difference?. Forbes.
https://www.forbes.com/advisor/education/it-and-tech/information-security-vs-cyber-
security/
12
Hazaa, Y. M. H., & Jogdand, D. A. (2020). Availability of General Control Procedures of the
Security of Accounting Information System (AIS): Evidence from Yemen. Journal of
Economic Cooperation & Development, 41(2), 67-90.
https://go.openathens.net/redirector/liberty.edu?url=https://www.proquest.com/scholarly-
journals/availability-general-control-procedures-security/docview/2456178533/se-2
Heller, Isaac. (November 30, 2022). How Technology is transforming Accounting. Forbes.
https://www.forbes.com/sites/forbestechcouncil/2022/11/30/how-technology-is-
transforming-accounting/?sh=51ec4266108e
Kenton, Will. (July 29, 2022). American Institute of Certified Public Accountants (AICPA).
https://www.investopedia.com/terms/a/american-institute-of-certified-public-
accountants.asp
Nakamura, Karen. (September 1, 2022). Cybersecurity risk: Constant vigilance required.
Professional Liabiliy Spotlight. Journal of Accountancy.
https://www.journalofaccountancy.com/issues/2022/sep/cybersecurity-risk-vigilance-
required.html
Nasr Abosata, Saba Al-Rubaye, Gokhan Inalhan, and Christos Emmanouilidis. (May 24, 2021).
Internet of Things for System Integrity: A Comprehensive Survey on Security, Attacks and
Countermeasures for Industrial Applications
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8197321/
n.d. (2023). Accounting and Auditing Publications. AICPA.
https://us.aicpa.org/publications/accountingauditing
n.d. (2018). Cybersecurity risk management reporting fact sheet. AICPA.
13
https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/
downloadabledocuments/cybersecurity-fact-sheet.pdf.
n.d. (Feb 20, 2024). Technology. Britannica.
https://www.britannica.com/technology/technology
Veale, M. & Brown, I. (December 17, 2020). Cybersecurity. Internet Policy Review, 9(4).
https://policyreview.info/concepts/cybersecurity
Students also viewed