Companies outsource various information system functions like payroll, and
AP among others to lower their expense cost. By using outsourcing these
companies need to take extra steps to protect the data being sent. One risk of
using outsourcing is that the company doesn’t have control of the data
anymore. As it is traveling to the outsource location it is vulnerable to hackers.
The company may encrypt the information, that is they may transform plain
text into something unreadable (Romney, 2020, p.376), but it doesn’t make it
secure enough. There is also the chance that as the data is being decrypted (the
data is being transformed back into readable text (Romney, 2022, p. 376))
someone could steal the data during the processing step because it’s not secure
anymore (Romney a 2022, p. 370).
Another risk they face is that the outsource location may have different
standards as to which employees have authorization to access the classified
and encrypted data. It may be that certain employees can decrypt the data but
all employees are allowed to enter the data room at anytime. Until it’s time for
the company to perform an audit, they won’t know if a breach has occurred
until well after it has occurred. They have to rely on the outsource location to
train the employees correctly.
I believe that a company needs to do everything it can to protect every bit of
classified data. It is their responsibility to make sure that only those employees
that need to look at the classified data have the clearance to do so and that those
employees are also trained on how to handle the sensitive information. How to
encrypt and decrypt it. They need to make sire that if they outsource any of the
information. That the outsource location is taking the proper steps and putting
in the right security measures to keep everything safe.
Reference
Romney, M. B., Steinbart, P. J., Summers, S. L., & Wood, D. A. (2020).
Accounting Information Systems (15th ed.). Pearson Education (US).
https://mbsdirect.vitalsource.com/books/9780135573082