Transcript Audcise g2 Finalist
Transcript Audcise g2 Finalist
AUDITING IN COMPUTER
INFORMATION SYSTEM
ENVIRONMENT
GROUP 2
Leader
Silong, Zarah Jake C.
Members
Abas, Kem A.
Bulabon, Dayn Allison M.
Cuazon, John Rhod B.
Gatela, Jhaika
Limbo, Honeyleigh M.
Lubiano, Analiza D.
Pacheco, Jethca Jill
Serato, Clarizze Ann R.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
3.1 SALIENT PROVISIONS OF GLOBAL AND LOCAL RELEVANT REGULATIONS (US SOX AND
DATA PRIVACY)
US SOX
Sarbanes-Oxley Act of 2002
Also known as the SOX act of 2002, a law the US Congress passed on July 30 of that year
to help protect investors from fraudulent financial reporting by corporations, such as the case
of Enron & WorldCom.
It mandated strict reforms to existing securities regulations and imposed through new
penalties on lawbreakers.
SOX REPRESENT THE FF. GUIDELINES FOR BEST PRACTICES 1. SEPARATE CEO AND CHAIRMAN
1. CEO – they have the opportunity to discuss issues without management present
2. CHAIRMAN – important in facilitating such discussions.
4. COMPENSATE COMMITTEES
The compensation should not be a rubber stamp for management.
5. NOMINATING COMMITTEES
The board nominations committee should have a plan to maintain a fully staffed BOD
with capable people as it moves forward for the next several years.
The Data Privacy Act of 2012 establishes a legal framework to protect personal data
processed in both public and private information systems. This law reflects a shift in Philippine
data governance toward privacy protection in digital environments.
This law also created an independent National Privacy Commission (NPC) to enforce
compliance and align the Philippines with international data protection standards. Because
many CIS audits involve examination of data handling and privacy controls, RA 10173 provides
legal criteria for auditors tasked with evaluating how systems protect personal information.
ISO 27001/27002 series - used to implement and audit information security and privacy
control sets.
These frameworks help auditors classify, assess, and benchmark IT controls within the
larger audit engagement, bridging the gap between regulatory requirements (like SOX and the
Data Privacy Act) and actual audit procedures in computerized environments.
The framework for ISACA IT audit and assurance standards have the following levels:
1.) Standards: Which are mandatory requirements for IT audit and assurance reporting.
2.) Guidelines: Provides guidance in applying IT audit and assurance standards.
3.) Procedures: Are examples of the processes that an auditor might follow.
is used to organize internal controls that prevent the fraudulent reporting of financial
activities. It provides guiding principles for internal controls across the entire enterprise. COSO
has also published a popular framework for enterprise risk management (ERM).
4. DATA MANAGEMENT
Types of Data
Quantitative Data: Numerical and measurable, analyzed statistically. Examples include test
scores, income levels, population counts, and temperature readings.
Observations: Recording behaviors or events in their natural settings. Provides contextual and
real-time data. Example: Observing classroom interactions.
3. Cloud Storage
Cloud-based storage uses the internet like one extensive network instead of relying on a
local area network. Data is stored in an off-site location, and authorized users can access their
data through the internet, regardless of location. Cloud storage offers easy expansion as
business grows and can have lower setup and operating costs than on-premise storage options
when dealing with vast amounts of data.
Cloud storage
Advances in technology have made cloud storage much more cost-effective for many
organizations. With this device, your data is stored in offsite locations instead of on-premise
and hosted on a public cloud network or service provider. Your provider maintains the
infrastructure and keeps your data secure. Cloud storage is easy to access from any internet-
connected device.
This device combines public and private cloud services to better address your needs.
You can keep compliance-regulated or highly sensitive data on a private cloud, where you have
full control of security. Then store less sensitive information on a public cloud, which is less
expensive. Some hybrid solutions also combine cloud storage with on-premise devices for
further customization.
Conceptual schema
A conceptual database schema is a high-level schema in a database that provides an
overall view of the entire system of databases without showing implementation details, such as
data types or constraints. They help users understand data flow within an organization and
make it easier for both technical and non-technical users.
Logical schema
The logical schema outlines the logical structure of the data in the database. It defines
how the data is organized and the relationships among the data entities without showing how it
is physically stored. This schema type maintains data consistency and integrity by specifying
data types and constraints to validate entries during the database's design phase.
Physical schema
A physical database schema describes where the data is located in a system. This can
cover file locations, indexing strategies, and storage formats for each table to ensure maximum
performance when you deal with a large amount of data.
By effectively navigating these eight stages, organizations can transform raw data into
information they can truly use to drive innovation.
1. Data generation
Data generation marks the birth of the data lifecycle. This first stage involves the
creation of data from a variety of sources, including:
Customer interactions
Business and financial transactions
Social media activities
Internet of Things (IT) devices
For example, a retail company might generate customer data from point-of-sale (POS) systems,
e-commerce shopping carts, and feedback forms.
2. Data collection
The second stage in the data lifecycle, data collection, involves the structured gathering
of relevant data from a variety of sources like:
This stage is critical to the process, as it ensures that the data needed for analysis is
accurately aggregated and that data loss is reduced.
3. Data processing
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
Data processing is the third stage in the data lifecycle. It involves the following steps
that prepare data for analysis:
1. Data cleaning: Removing duplicate content, correcting errors, and filling in missing
values.
2. Data transformation: Converting raw or unstructured data into a suitable format or
structure.
3. Data integration: Combining data from disparate sources into a cohesive dataset.
4. Data reduction: Simplifying datasets by eliminating redundant or irrelevant data.
5. Data validation: Ensuring processed data meets organizational standards and accurately
reflects its original sources.
These steps prepare collected data for meaningful analysis, ensuring accuracy and consistency.
4. Data storage
The fourth stage of the data lifecycle, data storage, is essential for ensuring data is
accessible, safeguarded, and backed up for future use. This stage focuses on data privacy —
configuring your storage solution for privacy — by securely storing processed data in:
Databases
Data warehouses
Cloud storage solutions
Data lakes
On-location storage (e.g., physical servers)
This stage in the data lifecycle involves choosing the right storage solution for your data
protection needs and organizing data for efficient retrieval and use.
5. Data management
Data management is the fifth stage in the data lifecycle. It encompasses the ongoing
organization and maintenance of data through:
Data governance: Establishing standards, defining user roles, and ensuring compliance.
Setting policies for data sharing across departments.
Data quality management: Monitoring, cleaning, and validating data.
Data security: Implementing encryption and access controls and conducting security
audits.
Data access and retrieval: Setting up and using indexing and cataloging techniques.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
These processes ensure data remains accurate, accessible, and meets regulatory
requirements. And, most importantly, ensures privacy while data is being used.
6. Data analysis
Data analysis, the sixth stage in the data lifecycle, is where real value is discovered by
using analytical tools and techniques to identify patterns, trends, and correlations in data. The
key components involved are:
Descriptive analytics: Summarizes past data to help organizations understand what has
happened.
Diagnostic analytics: Examines data to determine why certain events or issues occurred.
Predictive analytics: Uses historical data and machine learning (ML) to forecast trends
and future outcomes.
Prescriptive analytics: Guides future actions by predicting optimal steps to reach a
specific goal.
This stage makes it possible to extract meaningful insights from data so businesses can
make more informed decisions.
7. Data Visualization
The seventh stage of the data lifecycle is data visualization. It involves representing data
graphically to communicate data insights effectively. This is the stage in which complex data
becomes more understandable through visualizations like:
Note: Although data visualization is the 7th step in the data lifecycle, a data analyst, data
scientist, or data engineer, will likely refer to multiple types of visualizations in the exploratory
stage of their analysis and perhaps even earlier in the process.
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
8. Data interpretation
Data interpretation is the final stage in the data lifecycle. This is the stage in which the
analyzed and visualized data is used to make informed business decisions. The key activities
involved in this stage include:
4.4 RELATIONAL DATABASE STRUCTURE FOR DATA RELEVANCE INTEGRITY, USE OF DATA
DICTIONARIES, AND NORMALIZATION
RELATIONAL DATABASE
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
Relational database structures store data in tables composed of rows and columns,
where each table represents a specific type of information such as customers, products, or
transactions. These tables are linked to one another through keys, allowing related data to be
connected without unnecessary duplication. This structure helps organize data clearly and
makes it easier to store, retrieve, and manage information efficiently.
c. Entity Integrity- this rule ensures that the primary key is never empty (null). Every record
must have a valid identity.
d. Referential Integrity- this makes sure relationships between tables stay valid.
For example, you cannot delete a customer if there are still orders connected to that customer.
e. Domain Integrity- this controls the type of data allowed in a column. For example, an Age
field should only accept numbers within a reasonable range. These structures help prevent
errors, missing data, and inconsistencies.
Names of tables
Names of columns
Data types (text, number, date, etc.)
Size limits
Descriptions of each field
Rules or restrictions
3. NORMALIZATION
Is the process of organizing data to reduce duplication and avoid inconsistencies. It
involves dividing large tables into smaller, related tables so that each table focuses on a single
type of information. Through normalization, data is stored efficiently, updates become easier,
and the overall accuracy and reliability of the database are improved.
1. First Normal Form (1NF)- each column should contain only one value, not multiple values.
Example: Instead of listing many phone numbers in one field, create separate records.
2. Second Normal Form (2NF)- data should depend on the whole primary key, not just part of
it. This usually means separating data into new tables.
3. Third Normal Form (3NF)- remove columns that do not directly depend on the primary key.
This prevents storing unrelated information in the same table.
SQL queries enables auditors to assess both factors effectively, ensuring accurate and reliable
audit outcomes.
Purpose: Detects missing or incomplete data that may indicate recording errors.
4.6 DATA INTEGRATION FROM VARIOUS SOURCES FOR ANALYSIS AND DECISION-MAKING
Classify the data integration from various sources for analysis and decision-making
Data integration combines heterogeneous data into a consistent, usable form for analytics and
operations.
DEFINITIONS:
Computer – Assisted Audit Techniques (CAATs)
Refers to the use of specialized software and tools by auditors to perform auditing tasks
more efficiently and effectively.
1. Audit Software
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
The main advantage of these programs is that they can be used to process large
volumes of data in a relatively short period, which it would be inefficient to do manually. The
programs can then present the results so that they can be investigated further.
2. Test Data
BURAUEN COMMUNITY COLLEGE
Burauen Sports Complex, San Diego, District 9
Burauen, Leyte
Phone: 09760510107/09674116167
Email: localcollegebcc@[Link]
used to test specific controls in computer programs, such as online password and data
access controls. Test data involves the auditor submitting ‘dummy’ /fake data into the client’s
system to ensure that the system correctly processes it and that it prevents or detects and
corrects misstatements.
Objective:
is to test the operation of application controls within the system. To be successful, test
data should include both data with errors built into it and data without errors.
EXAMPLES OF ERRORS:
Codes that do not exist;
Transactions above pre-determined limits;
Invoices with arithmetical errors; and
Submitting data with incorrect batch control totals.
PURPOSE OF CAATS
Efficiency: CAATs help auditors quickly process and analyze large datasets, which
improves the efficiency of the audit process.
Accuracy: Automated tools reduce the risk of human error and increase the accuracy of
audit findings.
Comprehensive Coverage: CAATs enable auditors to examine entire data populations,
rather than relying on samples, leading to more comprehensive audit results.
Detection of Irregularities: These tools help identify anomalies, trends, and patterns
that may indicate fraud, errors, or other issues that require further investigation.
Risk Management: By enabling continuous monitoring and real-time analysis, CAATs
help in identifying and mitigating risks promptly.
2. Enhanced Accuracy – CAAT tools can perform complex calculations and data analysis
with a high level of accuracy. They can identify anomalies, patterns, and trends in large
datasets that may be difficult to detect manually.
3. Improved Audit Quality – CAATs provides auditors with access to a wide range of data
analysis techniques and tests. This enables them to perform more comprehensive and
thorough audits, leading to higher audit quality and assurance.
4. Increased Audit Coverage – CAAT allows auditors to analyze large volumes of data
quickly and efficiently. This enables to cover large sample size population audit,
providing a more comprehensive view of the organization’s operations.
5. Standardization and Consistency – CAAT tools provide a standardized approach to data
analysis and audit procedures. This ensures consistency in the audit process and
facilities comparability across different audits or audit periods.
Reporting: Generating automated reports based on the findings of the CAATs, which can
be used to support audit conclusions.