0% found this document useful (0 votes)
2 views13 pages

AudCis Module Chapter 2

The document discusses IT governance controls, focusing on the management and assessment of strategic IT resources to reduce risks and ensure value addition to corporations. It outlines the structure of IT functions, emphasizing the importance of segregation of duties and the distinction between centralized and distributed data processing models. Additionally, it highlights audit objectives and procedures to verify the effectiveness of IT governance and physical security controls in safeguarding IT resources.

Uploaded by

geniedigneneng19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views13 pages

AudCis Module Chapter 2

The document discusses IT governance controls, focusing on the management and assessment of strategic IT resources to reduce risks and ensure value addition to corporations. It outlines the structure of IT functions, emphasizing the importance of segregation of duties and the distinction between centralized and distributed data processing models. Additionally, it highlights audit objectives and procedures to verify the effectiveness of IT governance and physical security controls in safeguarding IT resources.

Uploaded by

geniedigneneng19
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

charged back or basically

Chapter 2: Auditing IT
distributed among end users.
Governance Controls ➢ Figure below shows an example
of a usual IT services
Information Technology (IT) Governance structure where the primary
- relatively a new subset of service areas are the database
corporate governance that focuses administration, data
on the management and assessment processing, and systems
of strategic IT resources. development maintenance.
- Key objectives: reduce risk and
ensure investments in IT
resources add value to the
corporation.
- All stakeholders, including BODS,
top management, and departmental
users be active participants in
key IT decisions.

IT Governance Controls – only those o Database


that has an impact with financial Administration –
reporting matters. Three IT responsible for the
governance issues addressed by SOX security and
and COSO framework: integrity of the
database
1. Organizational structure of the o Data processing –
IT function manages computer
2. Computer Center Operations resources for the
3. Disaster Recovery Planning day-to-day operations
and processing of
Structure of the Information
transactions. It
Technology Function consists of:
- Has implications for the nature of a. Data Conversion
internal controls, and thus for – transcribes
the audit. transaction
- There two main organizational data from hard
models: CENTRALIZED and copy source to
DISTRIBUTED approach. a computer
1. Centralized Approach input (e.g.
➢ under this model, data keystroking
processing is performed by one sales orders)
or more large computers housed b. Computer
at a central site that serves Operations –
users throughout the the output of
organization. data conversion
is processed
➢ End users compete for these
here by the
resources based on need.
central
➢ IT function is treated as cost
computer.
center. Operating costs are
Accounting
applications to those needs. Participants in
are executed on systems development are:
a strict • Systems professionals
schedule – gathers, and
controlled by analyzes facts about
central problems, and
computer’s formulates solutions
operating – making new
system. information system.
c. Data Library – • End users – managers
room adjacent or personnel actually
to the computer utilizing the system.
center
• Stakeholders – has
providing safe
interest over such
storage for the
systems but not end
off-line data
users. (e.g.
files. Such
accountants, auditors
files could be
etc.)
current data or
backup data. It Systems Maintenance – where 80-
also stores 90% of the costs are incurred. In
original copies its word itself, maintains design
of commercial of the system, and customizing it
software and based on user needs.
their licenses
Segregation of incompatible
for
Duties – operational tasks should
safekeeping.
be segregated to:
Data Librarian
has the a. Separate transaction
responsibility authorization from transaction
for receipt, processing.
storage, b. Separate record keeping from
retrieval, and asset custody.
custody c. Divide transaction-processing
controls the tasks among individuals such
access to the that short of collusion
library. This between two or more
role, however, individuals’ fraud would not
was reduced or be possible.
completely - Segregation of duties are usually
omitted already done on an operational level,
as the rise of however given that those roles are
real-time now filled mostly by the computer
processing services functions, this concept
progresses. is shifted on a higher-level
o Systems Development and organizational function, such as
Maintenance – systems the following:
development, analyzes user needs ❖ Separating Systems
and designs new systems anchored Development from Computer
Operations – these roles changes to program
are inherently modules for the purposes
incompatible, as systems of committing an illegal
development ultimately at.
creates the system, while ❖ A Superior Structure for
those who operates it Systems Development – where
enters the data being systems development and
processed. Thus, comingling maintenance are separated
them invites fraudulent addressing two control
acts. problems:
❖ Separating Database i. Documentation standards
Administration from Other improved – without
Functions – DBA function is complete and adequate
responsible for critical documentation, formal
tasks pertaining to transfer of system
database security, responsibility to
including creating the systems maintenance
database schema and user cannot occur.
views, assigning database ii. Denying the original
access authority to users, programmer future access
monitoring database usage, to the program deters
and planning for future program fraud.
expansion – delegating this 2. The Distributed Model
to others other than the DBA ➢ An alternative to the
threatens integrity, which centralized approach is the
is the main aim of a DBA. DDP or Distributed Data
❖ Separating New Systems Processing.
Development from ➢ DDP in a nutshell
Maintenance – systems distributes small IT units
analysts basically produce dissected from the central
detailed design of the new IT units among end users,
systems tailored on the depending on their
user needs, while functions, location, or
programmers (who is also both.
responsible for maintenance
during the systems
development life cycle)
codes programs according to
the design specifications.
Two control problems exist
however on the end of a
programmer:
i. Inadequate documentation
– because doing such is
not interesting, or it
increases the risk on
job security.
ii. Program Fraud –
making unauthorized
➢ Risks – which carry control acquisition of
implications for auditor’s hardware and software
perusal. are distributed, as
i. Inefficient use of such, the risks are
resources – includes only tolerable if
risk of mismanagement standards over such
of general IT responsibilities are
resources by end consistently applied.
users, increase in ➢ Advantages:
the risk of i. Cost Reductions – the
operational move to DDP has
inefficiencies due to reduced costs in two
redundancies areas other than
(affecting accuracy those generally
and consistency), and considered: (1) data
the risk of can be entered and
incompatibility edited by the end
between hardware and users, eliminating
software among end- the task for data
user functions (which preparation; (2)
disrupts connectivity application
between units). complexity can be
ii. Destruction of Audit reduced, reducing the
Trails – inadvertent systems dev’t and
deletion or omission maintenance.
of files could serve ii. Improved Cost Control
audit unrecoverable Responsibility –
upon destruction. providing the
iii. Inadequate management control
Segregation of Duties over the IT resources
– distribution of contribute to
small units of IT achieving the goals
function could create of business
incompatible operations, as
functions among end management are the
users. ones making the
iv. Hiring Qualified decisions for
Professionals – risk financial success.
of programming errors iii. Improved User
and system failures Satisfaction – DDP
increases directly improves three areas
with the level of often unsatisfied
employee under centralized
incompetence. approach: (1) users
v. Lack of Standards – desire to control
DDP environment, resources to achieve
developing and their goal – profit
documenting systems, related; (2) users
program languages, want systems
professionals industry and organizational
(analysts, standards. This allows the
programmers, and organization to effectively
operators) to be centralize the acquisition,
responsive to their testing, and implementation of
specific situation; software and hardware and
(3) users want to avoid many problems discussed
become more actively earlier.
involved in 3. User Services – provides
developing and technical help to users during
implementing their the installation of new
own systems software and in
iv. Backup Flexibility troubleshooting hardware and
software problems. There are
Controlling the DDP Environment
various ways to have the end
- Discusses implementation controls users informed like e-
that can mitigate risks in bulletin, group chats, etc.
associated with DDP model: 4. Standard-setting body – poor
1. Implementation of a Corporate control environment can be
IT Function – which is greatly addressed through this. From
reduced from that of the systems development,
centralized approach. The programmng, maintenance, and
corporate IT group provides documentation.
systems development and 5. Personnel Review –
database management for meticulously hiring systems
entity-wide systems in professionals, and even end
addition to technical advice users.
and expertise to the
AUDIT OBJECTIVE
distributed IT community.
The auditor’s objective is to verify
that the structure of the IT function is
such that individuals in incompatible
areas are segregated in accordance with
the level of potential risk and in a
manner that promotes a working
environment. This is an environment in
which formal, rather than casual,
relationships need to exist between
incompatible tasks.

AUDIT PROCEDURES

1. For Centralized IT Function:


2. Central Testing of Commercial ➢ Review relevant
Software and Hardware - A documentation, including
central, technically astute the current organizational
group such as this can evaluate chart, mission statement,
systems features, controls, and job descriptions for
and compatibility with key functions, to determine
if individuals or groups ➢ Verify that compensating
are performing incompatible controls, such as
functions. supervision and management
➢ Review systems monitoring, are employed
documentation and when segregation of
maintenance records for a incompatible duties is
sample of applications. economically infeasible.
Verify that maintenance ➢ Review systems
programmers assigned to documentation to verify
specific projects are not that applications,
also the original design procedures, and databases
programmers. are designed and
➢ Verify that computer functioning in accordance
operators do not have with corporate standards.
access to the operational
details of a system’s
internal logic. Systems
The Computer Center
documentation, such as
systems flowcharts, logic Physical environment of the computers
flowcharts, and program are one of the things being examined by
code listings, should not auditors on their annual audit. The
be part of the operation’s following are areas of potential
documentation set. exposure that can ipact the quality of
➢ Through observation, information, accounting records,
determine that segregation transaction processing, and the
policy is being followed in effectiveness of other more
practice. Review operations conventional internal controls.
room access logs to
determine whether Physical Location
programmers enter the ➢ Directly affected by risk
facility for reasons other of destruction to a natural
than system failures. or man-made disasters. The
2. For Distributed Data Processing computer center should be
(DDP) Approach IT Function: away from such, and from
➢ Review the current normal traffic, and from
organizational chart, the basement (as tere is a
mission statement, and job risk to flood).
descriptions for key
functions to determine if Construction
individuals or groups are
➢ Ideally, a computer center
performing incompatible
should be located in a
duties.
single-story building of
➢ Verify that corporate
solid construction with
policies and standards for
controlled access
systems design,
(discussed next). Utility
documentation, and hardware
(power and telephone) lines
and software acquisition
should be underground. The
are published and provided
building windows should not
to distributed IT units.
be open and an air error. Implementing fault
filtration systemshould be tolerance control ensures
in place that is capable of that no single point of
extracting pollens, dust, potential system failure
and dust mites. exists. Total failure can
occur only if multiple
Access
components fail. Two
➢ Access to the computer examples of fault tolerance
center should be limited to are:
the operators and other 1. Redundant arrays of
employees who work there. independent disks (RAID)
➢ Physical Controls are – uses parallel disks
musts. that contain redundant
➢ Closed-circuit cameras elements of data
should be monitored. applications.
2. Uninterruptible power
➢ It should maintain accurate
supplies – this is the
records of all such
use of an equipment that
traffic.
provides an alternative
Air Conditioning source of electrical
power supply, and also
➢ Computers function best in the control of shutting
an air-conditioned down the devices to
environment, and providing prevent data loss and
adequate air conditioning corruption.
is often a requirement of
the vendor’s warranty. AUDIT OBJECTIVES:
Computers operate best in a
temperature range of 70 to Auditor must verify that:
75 degrees Fahrenheit and a
- Physical security controls are
relative humidity of 50
adequate to reasonably protect
percent.
the organization from physical
Fire Suppression exposures.
- Insurance coverage on
➢ Fire is the most serious
threat to an entity’s equipment is adequate to
computer equipment. Many compensate the organization
businessses go out of for the destruction of, or
business because of loss of damage to, its computer
critical records, such as center.
AR.
AUDIT PROCEDURES:
Fault Tolerance
The following are tests of physical
➢ is the ability of the system security controls.
to continue operation when
part of the system fails Tests of Physical Construction. The
because of hardware auditor should obtain architectural
failure, application plans to determine that the computer
program error, or operator
center is solidly built of fireproof level of RAID in place is adequate
material. There should be adequate for the organization, given the
drainage under the raised floor to level of business risk associated
allow water to flow away in the event with disk failure. If the
of water damage from a fire in an organization is not employing RAID,
upper floor or from some other the potential for a single point of
source. In addition, the auditor system failure exists. The auditor
should assess the physical location should review with the system
of the computer center. The facility administrator alternative
should be located in an area that procedures for recovering from a
minimizes its exposure to fire, disk failure.
civil unrest, and otherhazards.
Tests of the Uninterruptible Power
Tests of the Fire Detection System. Supply. The computer center should
The auditor should establish that perform periodic tests of the backup
fire detection and suppression power supply to ensure that it has
equipment, both manual and sufficient capacity to run the
automatic, are in place and tested computer and air conditioning. These
regularly. The fire-detection system are extremely important tests, and
should detect smoke, heat, and their results should be formally
combustible fumes. The evidence may recorded. As a firm’s computer
be obtained by reviewing official systems develop, and its dependency
fire marshal records of tests, which increases, backup power needs are
are stored at the computer center. likely to grow proportionally.
Indeed, without such tests, an
Tests of Access Control. The auditor
organization may be unaware that it
must establish that routine access
has outgrown its backup capacity
to the computer center is restricted
until it is too late.
to authorized employees. Details
about visitor access (by programmers Tests for Insurance Coverage. The
and others), such as arrival and auditor should annually review the
departure times, purpose, and organization’s insurance coverage on
frequency of access, can be obtained its computer hardware, software, and
by reviewing the access log. To physical facility. The auditor
establish the veracity of this should verify that all new
document, the auditor may covertly acquisitions are listed on the
observe the process by which access policy and that obsolete equipment
is permitted, or review videotapes and software have been deleted. The
from cameras at the access point, if insurance policy should reflect
they are being used. management’s needs in terms of
extent of coverage. For example, the
Tests of Raid. Most systems that
firm may wish to be partially self-
employ RAID provide a graphical
insured and require minimum
mapping of their redundant disk
coverage. On the other hand, the
storage. From this mapping, the
auditor should determine if the
firm may seek complete replacement- restoration of those
cost coverage. functions that generate
cash flows sufficient to
satisfy short-term
obligations. Too often,
Disaster Recovery Planning this task is incorrectly
viewed as a technical
computer issue and
therefore delegated to IT
professionals. Although the
technical assistance of IT
professionals will be
required, this task is a
business decision and
should be made by those best
equipped to understand the
business problem.

Creating a Disaster Recovery Team

Natural Disaster is the most ➢ To avoid serious omissions


devastating, Human-made on the other or duplication of effort
hand can be as devastating but limited during implementation of
in scope, while System failures are less the contingency plan, task
severe but has the most frequent responsibility must be
occurrence. clearly defined and
communicated to the
Disasters of the sort outlined above personnel involved.
usually cannot be prevented or evaded. ➢ The environment created by
Once stricken, the victim firm’s the disaster may make it
survival will be determined by how well necessary to violate
and how quickly it reacts. control principles such as
Four main and common features of DRPs: segregation of duties,
access controls, and
1. Identify critical applications supervision.
2. Create disaster recovery team
3. Provide site backup
4. Specify backup and off-site
storage procedures

Identify Critical Applications

➢ Recovery efforts must


concentrate on restoring
those applications that are
critical yo the short-term
survival of the
organization. For most
organizations, short-term
survival requires the
Providing a second-site backup current version of the
operating system need to be
1. Mutual Aid Pact – an agreement
clearly specified.
between organizations (with
➢ Application Backup - DRP
compatible computer facilities)
should include procedures
to aid each other with their data
to create copies of current
processing needs in the event of
versions of critical
a disaster.
applications. In the case
2. Empty Shell or Cold Site – an
of commercial software,
arrangement where an organization
this involves purchasing
purchases or leases a building
backup copies of the latest
that will serve as a data center
software upgrades used by
in the event of a disaster.
the organization. For in-
Recover however depends on the
house developed
timely availability of the
applications, backup
necessary computer hardware to
procedures should be an
restore the data processing
integral step in the
function. An unanticipated
systems development and
hardware supply problem at this
program change process.
critical juncture could be a fatal
➢ Backup Data Files - The
blow.
state-of-the-art in
3. Recovery Operations Center (ROC)
database backup is the
or Hot Site – a fully equipped
remote mirrored site, which
backup data center that many
provides complete data
companies share. They usually pay
currency.
an annual fee for an access
➢ Backup Documentation -
rights.
System documentation can
4. Internally Provided Backup – This
constitute a significant
permits the organzations to
amount of material and the
develop standardized hardware and
backup process is
software configurations, which
complicated further by
ensure functional compatibility
frequent application
among their data processing
changes. Computer Aided
centers and minimize cutover
Software Engineering (CASE)
problems in the event of a
documentation tools may
disaster.
however be used. Backup for
Backup and Off-site Storage Procedures manuals must also be done.
➢ Backup Supplies and Source
Data processing personnel should Documents - The
routinely perform backup and storage organization should create
procedures to obtain and secure these backup inventories of
critical resources. supplies and source
➢ Operating System Backup - documents used in
If the company uses a cold processing critical
site or other method of site transactions. At this
backup that does not point, it is worth noting
include a compatible that a copy of the current
operating system (O/S), DRP document should also be
procedures for obtaining a
stored off-site at a secure effectiveness of the mutual aid
location. pact. Auditors should be skeptical
➢ Testing the DRP – must be of such arrangements for two
performed periodically, reasons. First, the sophistication
this will identify
of the computer system may make it
preparedness of personnel
difficult to find a potential
and identify omissions or
bottlenecks. Most
partner with a compatible
successful when done in a configuration. Second, most firms do
surprise. not have the necessary excess
The organization’s capacity to support a disaster-
management should seek stricken partner while also
measures of performance in processing their own work. When it
each of the following comes to the crunch, the management
areas: (1) the of the firm untouched by disaster
effectiveness of DRP team
will likely have little appetite for
personnel and their
the sacrifices that must be made to
knowledge levels; (2) the
degree of conversion
honor the agreement.
success (i.e., the number More viable but expensive options
of lost records); (3) an
are the empty shell and recovery
estimate of financial loss
operation center. These too must be
due to lost records or
facilities; and (4) the
examined carefully.
effectiveness of program, - If the client organization is
data, and documentation
using the empty shell method,
backup and recovery
then the auditor needs to
procedures.
verify the existence of valid
AUDIT OBJECTIVE: contracts with hardware
vendors that guarantee
The auditor should verify that
delivery of needed computer
management’s disaster recovery plan
hardware with minimum delay
is adequate and feasible for dealing
after the disaster.
with a catastrophe that could
- If the client is a member of a
deprive the organization of its
ROC, the auditor should be
computing resources.
concerned about the number of
AUDIT PROCEDURES: ROC members and their
geographic dispersion. A
In achieving the above objective,
widespread disaster may create
the following tests may be
a demand that cannot be
performed:
satisfied by the ROC facility.
Site Backup. The auditor should
Critical Application List. The
evaluate the adequacy of the backup
auditor should review the list of
site arrangement. System
critical applications to ensure that
incompatibility and human nature
it is complete. Missing applications
both greatly reduce the
can result in failure to recover.
The same is true, however, for that a team leader listed in the plan
restoring unnecessary applications. had been deceased for nine months.
To include applications on the
critical list that are not needed to
achieve short-term survival can OUTSOURCING THE IT FUNCTION
misdirect resources and distract
attention from the primary objective Often cited benefits of IT
during the recovery period. outsourcing include improved core
business performance, improved IT
Software Backup. The auditor should performance (because of the vendor’s
verify that copies of critical expertise), and reduced IT costs. By
applications and operating systems moving IT facilities offshore to low
are stored off-site. The auditor labor-cost areas and/or through
should also verify that the economies of scale (by combining the
applications stored off-site are work of several clients), the vendor
current by comparing their version can perform the outsourced function
numbers with those of the actual more cheaply than the client firm
applications in use. could have otherwise.
Data Backup. The auditor should The logic underlying IT outsourcing
verify that critical data files are follows from core competency theory,
backed up in accordance with the which argues that an organization
DRP. should focus exclusively on its core
business competencies, while
Backup Supplies, Documents, and
allowing outsourcing vendors to
Documentation. The system
efficiently manage the non–core
documentation, supplies, and source
areas such as the IT functions.
documents needed to process critical
transactions should be backed up and Commodity IT assets are not unique
stored off-site. The auditor should to a particular organization and are
verify that the types and quantities thus easily acquired in the
of items specified in the DRP such marketplace. These include such
as check stock, invoices, purchase things as network management,
orders, and any special purpose systems operations, server
forms exist in a secure location. maintenance, and help-desk
functions. Specific IT assets, in
Disaster Recovery Team. The DRP
contrast, are unique to the
should clearly list the names,
organization and support its
addresses, and emergency telephone
strategic objectives. Because of
numbers of the disaster recovery
their idiosyncratic nature, specific
team members. The auditor should
assets have little value outside
verify that members of the team are
their current use. Such assets may
current employees and are aware of
be tangible (computer equipment),
their assigned responsibilities. On
intellectual (computer programs), or
one occasion, while reviewing a
human.
firm’s DRP, the author discovered
Transaction Cost Economics (TCE)
theory is in conflict with the core
competency school by suggesting that
firms should retain certain specific
non–core IT assets inhouse.

Risks Inherent to IT Outsourcing

1. Failure to perform
2. Vendor exploitation – because
of the inclusion of specific
assets. The dependency created
in outsourcing even the
specific assets may threaten
the client’s long-term
flexibility, agility, and
competitiveness and result in
even greater vendor dependency
3. Outsourcing Costs exceed
Benefits
4. Reduced Security
5. Loss of Strategic Advantage -
IT outsourcing may affect
incongruence between a firm’s
IT strategic planning and its
business planning functions.

Audit Implications of IT Outsourcing

The use of a service organization


does not reduce management’s
responsibility to maintain effective
internal control over financial
reporting. Rather, user management
should evaluate controls at the
service organization, as well as
related controls at the user
company, when making its assessment
about internal control over
financial reporting.

You might also like