The integrity of information systems

Ian O. Angell, Steve Smithson · Information Systems Management · 1991

Accidents, mismanagement or negligence, design flaws, deliberate theft, fraud, sabotage, labour strikes, abuse of facilities, disaster, disruption are everywhere [1]. The security hazards implicit in information systems have received enormous publicity in recent years, and far too often they are rationalized away as individual (and correctable?) programming bugs or misunderstanding on the part of management and users. The development, implementation and introduction of more sophisticated IT applications has introduced further, even more complex structure into organizations [2], a structure not of their own making. It has culminated in the old checks and balances being no longer valid or disappearing altogether. When stored in a computer, programs and data can be altered quickly and easily, but they lack any permanent physical existence, so there is a tendency to print out frequent hard copy. There ensues an explosion of traditional paper files reflecting more the transitional nature of the programs and data, rather than referring to their current state on the computer. Computer networks have complicated matters even further, by promoting quick and easy communication, which all too often ‘punches a hole’ through layers of defence. Computers themselves have been used as part of that defence, but data-entry and processing has been concentrated in the hands of people who often deny the need for programmed supervision, and who have the technological means at their disposal to circumvent such regulation anyway.

Read the paper · More papers on PaperTik