Control Activities
The sixth component of COSO's ERM model is control activities, which are policies, procedures, and rules that provide reasonable assurance that management's control objectives are met and the risk responses are carried out. It is management's responsibility to develop a secure and adequately controlled system. Controls are much more effective when placed in the system as it is built, rather than as an afterthought. As a result, managers need to involve systems analysts, and designers, and end users when designing computer-based control systems.