Think about what a computerised accounting system actually holds. Not just numbers — the financial bloodstream of a business. Who owes money, who is owed, what the margins are, what salaries are paid, which customers are slow payers. If that data is wrong, or if the wrong person sees it, or if it simply vanishes one morning, the business is in serious trouble. So a CAS is not just a calculator that happens to be on a computer. It is a system that must actively defend its data. That defence is what "security and control" means.
The intuition is simple: you are protecting against three distinct kinds of harm. Someone getting in who shouldn't (unauthorised access). Someone changing data they had no business changing (tampering). And data being destroyed or lost, whether by accident, malice, or a crashed hard disk (loss). Every control you will study exists to block one of these three.
Now the precise picture. Security and control in a CAS is the set of procedures and safeguards that ensure the confidentiality, integrity, and availability of accounting data and the continuity of its processing. Confidentiality maps to access control, integrity maps to tamper protection, availability maps to backup and physical protection. Hold those three words — they organise everything.
Passwords are the first gate. A password authenticates a user — it establishes who is at the keyboard. The strength of this control depends on the password being secret, changed periodically, and not shared. A shared password destroys the entire audit trail, because you can no longer tell who did what.
User rights (also called access privileges) are the second gate, and they are the more interesting one. Authentication tells you who someone is; authorisation tells you what they may do. A data-entry clerk should be able to record transactions but not alter the chart of accounts or delete a posted entry. A manager might view reports but not change master data. This is the principle of least privilege — give each user only the access their job genuinely requires. It is what stops an insider from quietly rewriting the books.
Audit trails are the memory of the system. Every entry, edit, and deletion is logged with a timestamp and the user who made it. This does two things: it deters tampering (you know you'll be caught), and it lets you reconstruct what happened after the fact. A good audit trail is itself protected — if a user could edit the log, it would be worthless.
Backups protect against loss. Regular copies of the data, stored separately from the live system, mean that a crash, a fire, or a ransomware attack does not end the business. The key word is regular — a backup from six months ago is nearly useless. And a backup stored on the same machine it is backing up is not a backup at all. …