Combining Decision Making Trial and Evaluation Laboratory with Analytic Network Process to Perform an Investigation of Information Technology Auditing and Risk Control in an Enterprise Resource Planning Environment

被引:14
|
作者
Tsai, Wen-Hsien [1 ]
Chou, Yu-Wei [1 ]
Lee, Kuen-Chang [2 ]
Lin, Wan-Rung [3 ]
Hwang, Elliott T. Y. [4 ]
机构
[1] Natl Cent Univ, Dept Business Adm, Tao Yuan, Taiwan
[2] Soochow Univ, Dept Accounting, Taipei, Taiwan
[3] Chinese Culture Univ, Dept Banking & Finance, Taipei, Taiwan
[4] Chung Yuan Christian Univ, Dept Informat Management, Tao Yuan, Taiwan
关键词
information technology auditing; risk control; internal control; enterprise resource planning (ERP); decision making trial and evaluation laboratory (DEMATEL); analytic network process (ANP); EVALUATION MODEL; SYSTEMS; MANAGEMENT; SELECTION; SOFTWARE; IMPACT; AHP;
D O I
10.1002/sres.2129
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The research examined different types of risk through interviews with experts. The risks studied include business interruption risk, process interdependency risk and system security risk. The decision making trial and evaluation laboratory is used to find the relationship among risks and combined with the analytic network process to select the optimal measures for reducing risks. The results indicate that information technology (IT) consultants prefer the Disaster Recovery Plan (DRP). They usually use the remote replication or High Availability (HA) to protect data. IT personnel believe that all of the IT risk controls are important. Auditors indicate that data access control is very important because users have to execute data access every day. Users of IT express a preference towards data input/output control as the most important control. The results achieved from all experts indicate that the most important controls overall are data input/output control, data access control and so on. Managers need to consider these risks to avoid any potential problems. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:176 / 193
页数:18
相关论文
共 9 条