TutorChase logo
Login
CIE A-Level Accounting Notes

1.2.8 Security of Computerised Accounting Data

CIE Syllabus focus:

'Candidates should understand how the security of data can be ensured within a computerised accounting system.'

Computerized accounting systems store valuable financial information. Effective security protects that information from unauthorized access, accidental loss, deliberate fraud, and technical failure, helping the business produce reliable accounting records.

Why data security matters

A computerized accounting system holds records such as sales, purchases, receivables, payables, payroll, and bank balances. If data is stolen, altered, deleted, or made unavailable, the business may produce unreliable accounting information and make poor decisions. Security is therefore essential for accuracy, fraud prevention, and continuity of operations.

Data security: The protection of accounting data from unauthorized access, alteration, destruction, or loss.

Good security should protect confidentiality so only authorized people can view data, integrity so data remains accurate and complete, and availability so users can access the system when needed.

Pasted image

The computer security (CIA) triad diagram summarises the three core objectives of accounting data security: confidentiality, integrity, and availability. It helps students see that effective controls (e.g., passwords, backups, and audit trails) are designed to protect one or more of these objectives simultaneously. Source

Access controls

User IDs, passwords, and authentication

Each user should have a unique user ID. This makes responsibility clear and reduces the risk of unauthorized activity being hidden. Passwords should be strong, kept secret, and changed when required by policy. Users should log out or lock screens when not using the system. Where available, extra authentication, such as a code sent to a device, gives further protection.

Pasted image

This diagram shows an access-control decision flow where sign-in “signals” (such as user/location, device, and risk) lead to outcomes like allowing access, requiring multi-factor authentication (MFA), or blocking access. It reinforces the idea that authentication is not just a password, but a set of controls that reduce unauthorized access to accounting data. Source

Different users also need different levels of authority within the system.

Access rights: The permissions that determine which parts of the system a user may view, enter, edit, or approve.

Permission levels and segregation

Not every employee should have full access. A cashier may enter receipts, while a manager approves changes to customer balances or supplier details. Limiting access on a need-to-know basis protects confidentiality and reduces the risk of fraud. It also supports segregation of duties, because one person should not control every stage of a transaction.

Permissions should be reviewed regularly. If an employee changes role, their access should be updated. If they leave the business, access should be removed immediately. Shared usernames should be avoided because they weaken accountability and make investigation harder.

Preventing data loss and damage

Backups and recovery

Backups protect the business if hardware fails, files become corrupted, or data is deleted. They should be made regularly, preferably automatically, and copies should be kept separately from the main system. Off-site or cloud storage is valuable because a fire, theft, or flood could destroy both the computer and local files. A business should also test whether backup files can actually be restored.

Backup: A separate copy of accounting data kept so records can be restored if the original data is lost or damaged.

A strong backup plan states how often backups are made, who checks them, where copies are stored, and how quickly the system should be restored after a failure. Businesses with a high volume of daily transactions usually need more frequent backups.

Protection against malware and technical failure

Viruses, ransomware, and other malware can damage records or prevent access to them. Anti-virus software, firewalls, and regular software updates reduce this risk. Staff should not install unauthorized software or open suspicious attachments, as this can introduce malicious programs into the system.

Equipment should also be protected from power problems. Surge protection and an uninterruptible power supply help reduce the chance of lost data caused by sudden shutdowns. Regular maintenance lowers the risk of hardware failure.

Maintaining integrity and confidentiality

Encryption and secure transfer

Accounting data is often sent to external accountants, branches, or cloud services. If it is intercepted, confidential information may be exposed. Encryption protects stored files and transmitted data by making it unreadable without authorization.

Encryption: The conversion of data into coded form so it cannot be read without authorization.

Secure connections and approved file-sharing methods are preferable to sending sensitive reports through insecure channels. Portable storage devices should be controlled carefully because they can be lost, stolen, or copied easily.

Audit trails and monitoring

A computerized system should record who entered, edited, or deleted data and when the action happened. This is known as an audit trail.

Audit trail: A record showing the source of data and the changes made to it, including the user and time of the action.

Audit trails help detect errors and suspicious activity. Managers can review unusual changes, repeated failed login attempts, or transactions entered outside normal procedures. Monitoring strengthens accountability because actions can be traced to individual users.

Authorization and input control

Sensitive actions should require approval. Examples include changing supplier bank details, writing off balances, or amending key standing data. This reduces the risk of unauthorized or fraudulent changes.

Input controls also support security. Validation checks and reasonableness checks help prevent incorrect or manipulated information from entering the system. Security is not only about keeping outsiders out; it is also about ensuring the data inside the system remains trustworthy.

Physical and procedural security

Even the best software controls can fail if physical and human controls are weak. Computers and servers should be kept in secure locations, with access restricted to authorized staff. Printed reports containing payroll or account details should be stored securely and destroyed safely when no longer needed.

Staff training is essential. Employees should know how to recognize suspicious emails, protect passwords, follow security procedures, and report incidents immediately. Refresher training matters because security threats change over time, and careless behavior can bypass strong technical controls.

Review of controls

Security arrangements should not remain unchanged. Management should review user permissions, backup reports, anti-virus status, and incident logs regularly. A control that was suitable before may become inadequate after staff changes, remote access, or business expansion. Regular review helps ensure that accounting data remains confidential, accurate, and available.

Practice Questions

State two ways a business can reduce the risk of unauthorized access to a computerized accounting system. [2]

  • 1 mark for each valid way stated, up to 2 marks.

  • Accept answers such as:

    • unique user IDs

    • strong passwords

    • access rights / permission levels

    • two-factor authentication

    • locking screens or logging out

    • removing access for former employees

Explain three methods a business can use to ensure the security of data within a computerized accounting system. [6]

  • 1 mark for each valid method identified, up to 3 marks.

  • 1 mark for each explanation linked to how that method improves security, up to 3 marks.

  • Accept answers such as:

    • regular backups: data can be restored after loss, damage, or system failure

    • off-site or cloud backup: data is protected if the business premises are affected by fire or theft

    • access rights: users can only view or change data needed for their role

    • encryption: stolen or intercepted data cannot easily be read

    • anti-virus software / firewalls / updates: reduce the risk of malware or cyberattack

    • audit trails: changes can be traced to a specific user

    • physical security: prevents theft or unauthorized use of equipment

    • staff training: reduces mistakes and unsafe behavior

FAQ

Ransomware can lock a business out of its accounting records by encrypting the files. This may stop invoicing, payroll processing, supplier payments, and bank reconciliation work.

It is especially serious because deadlines still exist even when the system cannot be accessed. Paying a ransom does not guarantee recovery, so businesses need clean backups and a clear response plan.

Remote access increases risk because staff may use home networks, mobile devices, or public internet connections.

Useful controls include:

  • a secure VPN connection

  • company-approved devices

  • device encryption

  • screen locks

  • avoiding public Wi-Fi for sensitive work

  • remote wiping if a laptop is lost

Remote workers should also be trained to spot phishing emails and protect printed documents at home.

The first priority is to contain the problem. Access may need to be blocked, affected devices isolated, and passwords reset.

After that, the business should:

  • preserve logs and evidence

  • inform management promptly

  • identify what data may have been affected

  • check whether backups are clean before restoring

  • review whether external reporting is required

A rushed response can destroy evidence, so actions should follow a documented procedure.

Cloud backups are often automatic and easy to access, but they depend on internet connectivity and trust in the provider’s security. Physical off-site backups give the business direct control, but they require transportation, storage, and manual handling.

A business should compare:

  • cost

  • speed of recovery

  • reliability

  • encryption standards

  • storage location

  • ease of testing restores

Many businesses use both methods for added protection.

Biometric login, such as fingerprint or facial recognition, can improve convenience and reduce password sharing. However, it should not always be the only control.

If a biometric device fails or a staff member cannot use it, backup access is still needed. Biometric data also needs strong protection because, unlike a password, it cannot simply be changed if compromised.

For that reason, biometrics are often strongest when used with another method, not as a complete replacement.

Hire a tutor

Please fill out the form and we'll find a tutor for you.

1/2
Your details
Alternatively contact us via
WhatsApp, Phone Call, or Email