Performance Management · Uses and control of information
Data Security, Governance and Information Control in ACCA PM
Updated 11 October 2026 · Fact-checked
Data security is protecting information from loss, theft, misuse and error. In PM you identify the risk (hacking, privacy breach, errors, unauthorised access), then match it to a control. General controls cover the whole IT environment. Application controls cover input, processing and output of one system. Governance sets who owns and is accountable for data.
Understand Data Security, Governance and Information Control
Information is only useful if it is reliable, complete, timely and secure. If managers cannot trust it, they make poor decisions. If outsiders get it, the business can lose money, customers and reputation.
The risks fall into groups. Security risks include hacking, malware, ransomware, theft of devices and staff misuse. Privacy and data protection risks arise when personal data is collected, stored or shared without consent or proper safeguards. Accuracy risks include input errors, faulty processing and out-of-date data. Availability risks include system failure and loss of data with no backup.
Big data and cloud use raise these risks. Large volumes of personal data attract attackers. Data held by a third-party cloud provider is outside your direct control. Combining data sets can reveal facts about individuals that they never agreed to share. Rules on personal data differ by country, so a global business must comply with several regimes.
Controls reduce these risks. General controls apply across the whole IT environment: access passwords, physical security, firewalls, encryption, backups, disaster recovery, software change controls and staff training. Application controls sit inside a particular system: input checks, processing checks and output checks.
Governance is the framework that sets who owns data, who may use it, how long it is kept and who is accountable. Good governance means clear policies, defined responsibilities, regular review and monitoring. Controls must also be cost-effective: spend should be in proportion to the value of the data and the size of the risk.
Key rules to remember
- Qualities of good information
- Accurate, Complete, Cost-beneficial, User-targeted, Relevant, Authoritative, Timely, Easy to use (ACCURATE)
- Use as a checklist when asked whether information is reliable. Any sensible equivalent list is accepted.
- General vs application controls
- General controls = whole IT environment; Application controls = one specific system
- The most common PM distinction. Give an example of each.
- Application control types
- Input controls + Processing controls + Output controls
- Examples: validation checks, control totals, reconciliation, restricted distribution of reports.
- Control cost test
- Cost of control < Expected loss avoided (benefit)
- A control is worthwhile only if its cost is justified by the risk reduced.
How to solve Data Security, Governance and Information Control questions
Use this method for any scenario or written question on information risk and control.
- 1Read the scenario and note the type of data held (customer, financial, staff, commercial) and where it is held (own servers, cloud, mobile devices).
- 2Identify the specific risks: security, privacy, accuracy, availability. Link each to a fact in the scenario.
- 3Decide what the question asks: risks, controls, the general/application distinction, or governance.
- 4Match each risk to a control. Say how the control works, not just its name.
- 5Classify controls as general or application, or as preventive, detective or corrective, if asked.
- 6Consider cost and practicality, and any legal duty on personal data.
- 7Write in short points, one risk and one control per point, using the scenario's business.
Quickest way: Risk-control pairing
When to use it: For Section B objective cases and short written parts when time is tight.
- Underline the data type and the location in the scenario.
- Name the one risk the question targets.
- Pick the control that directly stops that risk: access controls for unauthorised use, encryption for interception, backups for loss, validation for input error.
- For general versus application, ask: does it protect the whole IT setup or one system's input, processing or output?
- Check that your answer matches the question verb: identify, explain or recommend.
Common mistakes in Data Security, Governance and Information Control
Giving generic answers such as 'use passwords' without linking to the scenario.
Students memorise lists of controls and skip the case facts.
Fix: Tie every control to a named risk and a fact from the scenario, and explain how it works.
Confusing general and application controls.
Both include things like access restrictions, so the labels blur.
Fix: Ask whether the control covers the whole IT environment or one system's input, processing or output.
Treating privacy and security as the same thing.
Both involve protecting data.
Fix: Security is protection from unauthorised access or loss. Privacy is about proper, lawful use of personal data, including consent and purpose.
Ignoring cost and proportion of controls.
Students assume more controls are always better.
Fix: State that controls should be cost-effective and matched to the value of the data and the likelihood of loss.
Listing only external threats such as hackers.
Media coverage focuses on cyber attacks.
Fix: Also cover internal risks: staff error, misuse, weak access rights and lost devices.
Naming a control with no explanation in Section C.
Time pressure leads to one-word answers.
Fix: Write a short sentence per point: the control, what it does, and the risk it reduces.
Worked examples
Example 1
A retailer holds customer names, addresses and purchase histories on cloud servers and analyses them with big data tools. Identify two risks and recommend a control for each.
Show the solution
- Risk 1: unauthorised access. Customer data held in the cloud could be hacked or seen by staff who do not need it.
- Control 1: access controls and encryption. Staff get role-based passwords so they see only data they need, and stored and transmitted data is encrypted.
- Risk 2: privacy breach. Analysing purchase histories may use personal data without consent or for a purpose customers did not agree to.
- Control 2: a data governance policy. It sets what data is collected, the consent obtained, how long it is kept and who is accountable, and data can be anonymised before analysis.
- Add a note on cost: the controls should be proportionate to the sensitivity of the data.
Answer: Risk of unauthorised access is controlled by role-based access and encryption. Risk of privacy breach is controlled by a governance policy covering consent, purpose, retention and accountability, with anonymised data for analysis.
Example 2
A company's payroll system lets clerks enter hours worked. Errors have caused wrong payments. Suggest two application controls and one general control that would improve reliability.
Show the solution
- Application control 1 (input): a validation check that rejects hours above a sensible maximum, or non-numeric entries.
- Application control 2 (processing or output): a control total of hours entered compared with hours processed, and review of an exception report before payment is released.
- General control: access controls so only authorised clerks can enter or change payroll data, with regular backups so data can be restored.
- Explain the distinction: the first two operate inside the payroll system, the third protects the wider IT environment.
Answer: Application controls: input validation on hours and a control total with exception report review. General control: restricted user access with backups. The first two work within payroll; the third covers the whole IT environment.
Exam tips
- Always tie each risk and control to the scenario. Generic lists earn few marks in Section C.
- Learn one clear example each for general and application controls. Objective test questions often ask you to classify a control.
- In objective questions, read for the exact risk named, then choose the control that directly addresses it.
- Mention cost-effectiveness and legal duties on personal data when you are asked to recommend or evaluate.
- Cover internal risks such as staff error and misuse as well as external attacks.
Practice questions from Uses and control of information
- A manufacturing company moves its payroll software from servers it owns to a provider that supplies the software over the internet on a subs…
- A finance director is concerned about the risks of storing the company's management information with a public cloud provider. Which of the f…
- Dunmore Co's software development team currently buys servers and operating systems and builds its own test environments. It is considering …
- Wend Co's finance director receives a monthly report containing forty pages of detailed ledger listings, from which she must find the few it…
- Which of the following is a characteristic of good information as commonly set out for management use?
Data Security, Governance and Information Control in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Data Security, Governance and Information Control: frequently asked questions
What is the difference between general controls and application controls?
General controls apply across the whole IT environment, such as access security, backups and change management. Application controls are built into one system and cover its input, processing and output, such as validation checks and control totals.
What are the main data protection risks of big data?
Large volumes of personal data attract attackers and are costly to lose. Data may be used without consent, or combined so that individuals can be identified. Holding data with third parties, such as cloud providers, also reduces your direct control.
How do I protect data in a management information system?
Combine access controls, encryption, firewalls, backups and staff training with application controls such as validation and reconciliations. Add a governance policy that defines ownership and accountability. Match the level of control to the value and risk of the data.
Is data governance the same as data security?
No. Security protects data from loss and unauthorised access. Governance is the wider framework of policies and responsibilities that decide how data is collected, used, kept and controlled, and security is one part of it.