capt webb
Capt. Horatio T.P. Webb
MIS 4397/7375 Transaction Processing III
Parks -- Spring 2010

Version 1 -- Last Updated 7:30 AM 1/19/2010
NOTICES:
.Applications developed for this site assume Microsoft's Internet Explorer browser Version 6 or higher
COURSE SUMMARY: This course is the final course in a the transaction processing sequence. The focus of this course is on information technology controls. The first part of the course introduces the technology of transaction processing systems and their relationship to IT controls in design, operation and sudit. Standards such as COBIT, COSO, ITIL and SOX are discussed in relation to the technology.
TEXT: Textbook will NOT be used until the third week

Information Technology Control and Audit (3nd Edition)
by Sandra Allen-Senft and Frederick Gallegos
ISBN: 978-1-4200-6550-3, CRC Press (Auerbach), 2009

COBIT 4.1 (by IT Governance Institute, 2007, 5.2 meg pdf here)
COBIT 4.0 (by IT Governance Institute, 2005, 2.6 meg pdf here)

We will using the Protiviti Knowledge Base as a library reference. Click here to activate your account. The required confirmation number will be provided in class.

OFFICE HOURS: MW 1-2:30 280E Melcher Hall
or
by appointment 713-743-4729
GRADING: All grading issues are handled in-person during office hours. Do not send e-mail to the instructor regarding any grading issue. Grades assigned for drops after MON FEB 1 (last day to drop without receiving a grade) will be based on your current class grade. If you have a failing grade at the time of the drop, you will receive an F otherwise a W.
DATE TOPIC ASSIGNMENT
TUE JAN 19  . Transaction Processing History
 . Early Batch Systems
Allen-Senft,Gallegos Text Chapters 1-7
light reading
TUE JAN 26  . Enterprise Systems
 . Client-Server Overview
TUE FEB 2  .COBIT 4.1 Overview see COBIT 4.1 above
IT General Controls (here)
TUE FEB 9  .COBIT 4.1 Plan and Organize (pg. 29-72)
Allen-Senft,Gallegos Text Chapters 8-12
COBIT 4.1 Plan and Organize
  • PO1 Define a Strategic IT Plan
  • PO2 Define the Information Architecture
  • PO3 Determine Technological Direction
  • PO4 Define the IT Processes, Organization and Relationships
  • PO5 Manage the IT Investment
  • PO6 Communicate Management Aims and Direction
  • PO7 Manage IT Human Resources
  • PO8 Manage Quality
  • PO9 Assess and Manage IT Risks
  • P10 Manage Projects
TUE FEB 16  .COBIT 4.1 Aquire and Implement (pg. 73-100)
Allen-Senft,Gallegos Text Chapters 13-17
COBIT 4.1 Acquire and Implement
  • AI1 Identify Automated Solutions
  • AI2 Acquire and Maintain Application Software
  • AI3 Acquire and Maintain Application Software
  • AI4 Enable Operation and Use
  • AI5 Procure IT Resources
  • AI6 Manage Changes
  • AI7 Install and Accredit Solutions and Changes
TUE FEB 23  .COBIT 4.1 Deliver and Support (pg. 101-152)
Allen-Senft,Gallegos Text Chapters 18-22
COBIT 4.1 Deliver and Support
  • DS1 Define and Manage Service Levels
  • DS2 Manage Third-party Services
  • DS3 Manage Performance and Capacity
  • DS4 Ensure Continuous Service
  • DS5 Ensure Systems Security
  • DS6 Identify and Allocate Costs
  • DS7 Educate and Train Users
  • DS8 Manage Service Desk and Incidents
  • DS9 Manage the Configuration
  • DS10 Manage Problems
  • DS11 Manage Data
  • DS12 Manage the Physical Environment
  • DS13 Manage Operations
TUE MAR 2  .COBIT 4.1 Monitor and Evaluate (pg. 153-168)
COBIT 4.1 Monitor and Evaluate
  • ME1 Monitor and Evaluate IT Performance
  • ME2 Monitor and Evaluate Internal Control
  • ME3 Ensure Compliance With External Requirements
  • ME4 Provide IT Governance
TUE MAR 9 COBIT Controls Questionnaires
By Protiviti (password required)
COBIT Sections:
  1. Plan and Organize (PO)
  2. Acquire and Implement (AI)
  3. Delivery and Support(DS)
  4. Monitor and Evaluate (ME)

General Controls and Application Controls
See the readable version at: IT Assurance Guide (COBIT)
This covers COBIT:
  1. Generic Contols PC.n;
  2. (b) Application Controls AC.n;
  3. and specific COBIT controls in the PO; AI; DS and ME sections
TUE MAR 16 Spring Holiday
TUE MAR 23  . COSO ERM (IIA slides) COSO Summary
(from www.erm.coso.org)
ERM - Control Environment Questionnaire
ERM - Info and Communication Questionnaire
ERM - Monitoring - Control Questionnaire
ERM - Risk Assessment - Control Questionnaire
TUE MAR 30 Tech Topics

 SQL and Back-end Considerations
 . Security
 . Backup & Recovery
OSI 7 Layer Model
TCP/IP
Ethernet
Firewall ABC's
 . XBRL
An XBRL summary
XBRL.ORG http://www.xbrl.org/Home/
XBRL 2.1
Presentation Taxonomy US GAAP - Commercial and Industrial
Short Example
Microsoft Example

SGML overview
Gentle Intro to SGML
Parks' XML Coding Pages: XML in traditional ASP:
The XML DTD
Receiving and Displaying XML on the Client
Creating XML on the Client (this is AJAX see here)
 . IE Example AJAX for GL Account Query
 . Cross Browser Example AJAX for GL Account Query
Receiving and Creating XML on the Server
Sending XML from the Server to the Client
Boatwright & Higdon's Complete XML example
Walking the XML tree
Example AJAX for GL Account Query
Example XBRL demo
TUE APR 6  . ITIL ITIL V3 Overview
Sue Conger's ITIL Overview
TUE APR 13 * (from Protivit Knowledge Leader, password reqd.)
TUE APR 20 Guest Speaker: Ishmael Cooper
IT Director -- Governance & Information Risk
Tesoro Companies, Inc. San Antonio

and

Tracy D. Jackson, CPA, CIA, CISA
VP, Internal Audit
Tesoro Companies, Inc.

TUE APR 27
   Review
Cases:
  • UH's Protection of Confidential Information and Critical Sytems Audit 2004
    (http://www.sao.state.tx.us/Reports/report.cfm/report/05-010)
  • UH's Financial System Controls Audit 2005
    (http://www.sao.state.tx.us/Reports/report.cfm/report/06-012)
  • IMPORTANT DATES
    MON FEB 1 Last Day to Drop without receiving a grade.
    MON-WED MAR 15-20 Spring Holiday
    TUE APR 6 Last Day to Drop or Withdraw