ACCA Strategic Professional · Strategic Business Leader
IT Systems Security and Control for ACCA SBL
IT systems security and control is about protecting information and systems from threats, and proving that protection works. In SBL, you identify the risks in the scenario, recommend fitting controls (general, application, access, recovery, governance), and explain the business impact. Link each control to a specific risk and a cost-benefit view.
What this chapter covers
This chapter covers how an organisation protects its information systems and the data they hold. You start with the threats: malware, phishing, insider misuse, system failure and weak third-party links. You then move to the controls that reduce those threats: general and application controls, access controls, authentication and encryption, data protection and policy, recovery planning, and finally the governance of cyber risk at board level.
SBL does not test you as an IT specialist. You are an adviser to the board or senior management. The exam gives you a business with a digital weakness, such as a data breach, a legacy system, a cloud move or a rushed digital launch. You must say what is wrong, what it could cost and what to do about it. Technical terms matter, but only when you tie them to the case.
The chapter connects to much of the rest of SBL. Cyber risk sits inside enterprise risk management and governance. Controls link to internal control and the role of the audit committee. Data and systems link to digital strategy, change management and organisational resilience. Data privacy links to ethics and stakeholder trust. A good answer here often draws on these other areas at the same time.
SBL is a case-based exam where 20 of the 100 marks reward professional skills, and technology risk appears in many scenarios because almost every modern business depends on data and systems. If you know this chapter well, you can spot risks quickly, give practical and specific recommendations, and show commercial judgement rather than listing generic controls. Weak answers name controls without linking them to the case. Strong answers explain why a control fits this business, what it costs and what risk remains. That difference is where marks are won, and the same reasoning also helps in risk, governance and strategy tasks.
IT systems security and control: topics in the order to study them
- 1IT Systems Security Risks and ThreatsStart here because every control in the chapter exists to answer a risk, so you need the threat picture first.
- 2IT General and Application ControlsNext learn the main control framework, which gives you the structure for most control recommendations.
- 3Access Controls, Authentication and EncryptionThis is the most common practical control area, and it builds directly on the general controls idea.
- 4Data Protection, Privacy and Information Security PolicyOnce you know the technical controls, you add the legal, ethical and policy layer that governs how data is handled.
- 5Business Continuity, Disaster Recovery and BackupThis covers what happens when prevention fails, so it comes after prevention-focused topics.
- 6Cyber Security Governance and Risk ManagementFinish with board-level oversight, which pulls all the earlier topics into one risk and governance view.
How to prepare IT systems security and control
Prepare this chapter as an adviser, not as a technician. Your aim is to link a risk to a control and to a business outcome, in the language of the case.
- Read the chapter once for the big picture. Build a one-page map: threats on the left, controls in the middle, governance on the right.
- For each threat, write one control that prevents it, one that detects it and one that helps you recover. This stops you giving only preventive answers.
- Learn short definitions of key terms such as general controls, application controls, authentication, encryption and recovery objectives. Be able to explain each in one plain sentence.
- Practise with case extracts. Underline every sign of weakness in the scenario, such as shared passwords, no backups, rapid growth or remote working, and match each to a control.
- Write full answers under time pressure. State the point, apply it to the case, and explain the consequence. Add a cost, practicality or people comment to show commercial acumen.
- Add the wider view. Ask who is responsible at board level, how the risk fits into risk management, and what the ethical or stakeholder impact is.
- Review your answers against a marking-style checklist: did you answer the requirement, use case facts, and give a clear recommendation?
Common mistakes in IT systems security and control
Listing generic controls without using the case
Fix: Quote or paraphrase case facts first, then choose the control that fixes that exact weakness.
Treating IT security as only a technical issue
Fix: Add board responsibility, risk appetite, staff behaviour and stakeholder impact to each answer.
Recommending only preventive controls
Fix: Cover prevention, detection and recovery, and say what risk will remain.
Ignoring cost and practicality
Fix: Comment on cost, disruption and implementation, and prioritise the most important actions.
Confusing general controls with application controls
Fix: Remember that general controls support the whole IT environment, while application controls work inside a specific system or process.
Writing long technical explanations that earn few marks
Fix: Keep technical detail short. Spend your time on application, consequences and clear advice to the reader.
Last-day revision: IT systems security and control
- Every control must answer a specific risk in the scenario.
- Threats come from outside (hackers, malware, phishing) and inside (errors, misuse, disgruntled staff).
- General controls cover the overall IT environment; application controls cover individual systems and transactions.
- Application controls typically cover input, processing and output accuracy and completeness.
- Access controls decide who can see or change what; apply the principle of least privilege.
- Authentication proves identity; multi-factor authentication is stronger than a password alone.
- Encryption protects data if it is intercepted or stolen, but key management must be sound.
- Data protection means handling personal data lawfully, fairly and securely, with clear accountability.
- An information security policy sets rules, and staff training makes it work in practice.
- Backups, disaster recovery and continuity plans must be tested, not just written.
- Cyber risk is a board issue, not only an IT issue.
- Always weigh control cost against the risk reduced, and state the residual risk.
IT systems security and control practice questions
- Altamira Bank's board states that, after a system failure, payment processing must be restored within 2 hours, and that no more than 15 minu…
- Zenith Insurance allows staff to work remotely. The risk committee proposes that access to claims data be granted only after checking user i…
- Delta Foods stores customer records on laptops used by sales staff who travel. The IT director is concerned about the consequences if a lapt…
- Zephyr Insurance needs an alternative site for its claims system. Its tolerable downtime is 4 hours and budget is limited. It rejects a hot …
- Dunmore Health stores patient records that clinicians access from tablets on hospital wards. The board wants a control so that a stolen tabl…
- Meridian Bank allows staff to use personal smartphones to access email and client files. Which risk is most directly increased by this bring…
- Karvale Logistics lets warehouse supervisors approve purchase orders and also create new suppliers in its ERP system. An internal review fin…
- Nordvik Retail takes a full backup every Sunday and a differential backup every other night. Data is lost on Thursday morning, before that d…
IT systems security and control in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
IT systems security and control: frequently asked questions
How is IT systems security tested in SBL?
It appears inside the integrated case study, usually as a risk or weakness the business must deal with. You may be asked to assess risks, recommend controls or advise on governance. All answers are written, and you must apply them to the scenario.
Do I need deep technical IT knowledge for SBL?
No. You need to understand the main threats and controls well enough to explain them to a board in plain terms. Business impact and judgement matter more than technical depth.
How do I score professional skills marks in this chapter?
Show analysis of the case facts, scepticism about weak assumptions, commercial awareness of cost and benefit, and clear communication to the reader. A structured, practical recommendation scores better than a long list.
How should I link this chapter to other SBL topics?
Connect cyber risk to risk management, governance and internal control, and connect data handling to ethics and stakeholder trust. Also consider how technology change affects strategy and people.