capt webb
Capt. Horatio T.P. Webb
DISC 4397/7375 Transaction Processing III
Parks -- Spring 2008

Version 5 -- Last Updated 7:30 AM 2/11/2008
NOTICES:
.Applications developed for this site assume Microsoft's Internet Explorer browser Version 6 or higher
COURSE SUMMARY: This course is the final course in a the transaction processing sequence. The focus of this course is on information technology controls. The first part of the course introduces the technology of transaction processing systems and their relationship to IT controls in design, operation and sudit. Standards such as COBIT, COSO, ITIL and SOX are discussed in relation to the technology.
TEXT: Textbook will NOT be used until the fourth week

Information Technology Control and Audit (2nd Edition)
by Sandra Allen-Senft , Daniel P. Manson, Frederick Gallegos
ISBN: 0849320321

COBIT(2.6 meg pdf here)

OFFICE HOURS: MW 1-2:30 280E Melcher Hall
or
by appointment 713-743-4729
GRADING: All grading issues are handled in-person during office hours. Do not send e-mail to the instructor regarding any grading issue. Grades assigned for drops after MON JAN 28 (last day to drop without receiving a grade) will be based on your current class grade. If you have a failing grade at the time of the drop, you will receive an F otherwise a W.
DATE TOPIC ASSIGNMENT
TUE JAN 15  . Transaction Processing History
 . Early Batch Systems
TUE JAN 22  . Enterprise Systems
 . Client-Server Overview
 . Mapping to COBIT & COSO & SOX
     See the ITAudit website
          or
     ITGI's version IT Control Objectives for Sarbanes-Oxley (a 890K pdf)
TUE JAN 29  . Client-side Transaction Systems Issues
TUE FEB 5  . Server-Side Transaction Systems Design and Operation
TUE FEB 12  . SQL and Back-end Considerations
TUE FEB 19  . Security
 . Backup & Recovery
 . IT Controls (a short list)
TUE FEB 26 OSI 7 Layer Model
TCP/IP
Ethernet
Firewall ABC's
TUE MAR 4 COBIT Controls Questionnaires
By Protiviti (password required)
COBIT Sections:
  1. Plan and Organize (PO)
  2. Acquire and Implement (AI)
  3. Delivery and Support(DS)
  4. Monitor and Evaluate (ME)

General Controls and Application Controls
See the readable version at: IT Assurance Guide (COBIT)
This covers COBIT:
  1. Generic Contols PC.n;
  2. (b) Application Controls AC.n;
  3. and specific COBIT controls in the PO; AI; DS and ME sections
TUE MAR 11  . COSO ERM (IIA slides) COSO Summary
(from www.erm.coso.org)
ERM - Control Environment Questionnaire
ERM - Info and Communication Questionnaire
ERM - Monitoring - Control Questionnaire
ERM - Risk Assessment - Control Questionnaire
TUE MAR 18 Spring Holiday
TUE MAR 25  . XBRL
An XBRL summary
XBRL.ORG http://www.xbrl.org/Home/
XBRL 2.1
Presentation Taxonomy US GAAP - Commercial and Industrial
Short Example
Microsoft Example
SGML overview
Gentle Intro to SGML
Parks' XML Coding Pages: XML in traditional ASP:
The XML DTD
Receiving and Displaying XML on the Client
Creating XML on the Client (this is AJAX see here)
 . IE Example AJAX for GL Account Query
 . Cross Browser Example AJAX for GL Account Query
Receiving and Creating XML on the Server
Sending XML from the Server to the Client
Boatwright & Higdon's Complete XML example
Walking the XML tree
Example AJAX for GL Account Query
TUE APR 1  . ITIL ITIL V3 Overview
Sue Conger's ITIL Overview
TUE APR 8
    Speaker: Vicky Sessions
 Director, IT Security and Compliance
 Information Technology
 Dynegy Inc.
TUE APR 15 * (from Protivit Knowledge Leader, password reqd.)
TUE APR 22
   Guest Speaker: Russ Hoskens
Assistant Director
Internal Audit
University of Houston
Cases:
  • UH's Protection of Confidential Information and Critical Sytems Audit 2004
    (http://www.sao.state.tx.us/Reports/report.cfm/report/05-010)
  • UH's Financial System Controls Audit 2005
    (http://www.sao.state.tx.us/Reports/report.cfm/report/06-012)
  • IMPORTANT DATES
    MON JAN 21 Martin Luther King Holiday
    MON JAN 28 Last Day to Drop without receiving a grade.
    MON-WED MAR 17-22 Spring Holiday
    TUE APR 1 Last Day to Drop or Withdraw