0% found this document useful (0 votes)
6 views26 pages

Chapter 2

its about security

Uploaded by

gss_1987
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
6 views26 pages

Chapter 2

its about security

Uploaded by

gss_1987
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
CHAPTER 2 Conducting an Information Systems Audit 33 Chapter Key Points 1 Usually, auditors cannot examine and evaluate all the data processing carried out within an organization: They need guidelines that will direct them toward those aspects of the information systems function in which material losses or account misstatements are most likely to occur. Because ultimately auditors must evaluate the reliability of controls, they need to understand the nature of controls. A control isa system that prevents, detects, or corrects unlawful ‘events. Itis a system because all components of the control must be in place and working for the control to function reliably. 1 Controls reduce expected losses from unlawful events by (a) decreasing the probability of the event occurring in the first place, or (b) limiting the losses that arise if the event occurs. BH Auditors deal with complexity in an information systems audit by dividing systems to be evaluated into subsystems, evaluating the reliability of controls in each subsystem, and then determining the implications of each subsystem’ level of reliability for the overall reliability of the system. The objective of factoring is to identify a set of subsystems that can be easily understood and evaluated because they are loosely coupled with other subsystems and internally cohesive in the sense that they perform a single function. I Two major sets of systems need to be factored asa basis for ‘conducting an information systems audit: Management systems provide the stable infrastructure in which information systems ccan be built and operated on a day-to-day basis, and application systems undertake basic transaction processing, management reporting, and decision support. 1 Management systems can be factored into subsystems that perform top-level information systems management, systems development management, programming management, data ‘administration, quality assurance, security administration, and operations management. Application systems can be factored {into subsystems that perform boundary, input, communication, nig, database, and output functions. An information systems audit involves evaluating the reliability of controls in Each of these management and application subsystems. 1 Doring an information systems aucit, there is some risk that the audit procedures will fail to detect material losses or account misstatements when they exist. This risk isa function of three factors: (a) inherent risk, which reflects the likelihood that a ‘material loss or account misstatement exists in some segment of the audit before the reliability of internal controls is considered; (6) control risk, which reflcts the likelihood that internal ‘controls in some segment of the audit will not prevent, detect, for correct material losses or account misstatements that arise; ‘and (c) detection risk, which reflects that the audit procedures, tused in some segments of the audit will ail to detect material losses or account misstatements. Because auditors cannot influence inherent risk or control risk, they adjust the nature § 34 PART! Introduction audit procedures they Carry out to ing, INTRODUCTION and extent Of 201 he overall level of audit risk “Se detection tag cae types of audit procedures t0 ofa; . oa eats ae nded, data integrity is main) Yea, on whether 20° ertective and efient: (2) procedures, 8 and system of controls, (b) tests Of controls, (c) sy stat a js of transactions, (4) substantive tests of gq, tive ee fe results, and (e) analytical review rts balance ve major steps in an audit: (a) planning There pudtorafempts t gain an undersiancing of wei trls used within an organization, (b) ests oy sas sawhich the auditor tests significant controls to gy. Cpether Bey are operating effectively: (c) tests of transactign” siete anitor undertakes Substantive tests 10 evaluate Sark fnateral loss or account misstatement has oo, pnt occur (d) fess balances or overall results, in i secks to obtain sufficient evidence to make dgment onthe extent of 1sses OF COUNT MSs have occurred or might occur, and (e) completion of the audit ig wich the auditor gives an opinion on whether material losses fecount misstatements have occurred or might occur. 5 During the tess of controls phase, one ofthe important de that auditors make is whether to test controls by auditin or through the computer. They might audit around the compute, ifthe application system is simple, its inherent risk is low, and the reliability ofthe system's intemal processing can be easily inferred. They must audit through the computer whenever an application's inherent risk is high and itis difficult to infer the internal processing carried out by the system. sions round Itis a sobering experience to be in charge of the information systems aacit an organization that has several hundred programmers and analysts, mx computers, and thousands of files. Obviously, all organizations are not this sz Except for the smallest organizations, however, auditors usually cannot re form a detailed check of all the data processing carried out within the informs tion systems function. Instead, they must rely on a sample of data to determin: pric objectives of information systems auditing are being achieved. then, can re Baa information systems audits so that we ob TesSonable assurance that an organization safeguards its data-processing &S** Iainiais data integrity, and achieves system effectiveness and eticien©! © hares this question, this chapter provides an overview of a general Os that e muchot tna ¢8 {9 conduct an information systems audit, This m3! Temainder of the book. wes discussing some te yen, maki ood ‘encountered wh: n systems. Next We ‘affect the overall PP’ | a_i et CHAPTER 2 Conducting an information Systems Audit 35 . to an audit, and the types of audit procedures used to of these risks. We then consider the basic steps to be undertabern ofan information systems audi. Finally, we examine eae ne ond must make when planning and conducting an information systems audit. namely, how much do they need to know about the internal workings of a com. | puter-based information system before an effective audit can be contacted? ‘assess or control the level THE NATURE OF CONTROLS Information systems auditors ultimately are concerned with i f yster 7 evaluating the reli we understand what is meant by a control. Here, then, is the definition we shall adopt for the purposes of this book (see, also, Wand and Weber 1989): A control is a system that prevents, detects, or corrects unlawful events There are three key aspects to this definition. First, a control is a system. In other words, it comprises a set of interrelated components that function to- gether to achieve some overall purpose. Unfortunately, we tend to name con- trols by focusing on just one feature of the control. For example, probably all of us are familiar with a password control. A password, per se, however, is not a control. Passwords become a control only in the context of a system that allows secure issue of or choice of passwords, correct validation of passwords, secure storage of passwords, follow-up on illicit use of passwords, and so on. If this system breaks down in some way, passwords will be ineffective as a control. In short, the term “password control” is a notation for the constellation of things that work together to ensure only authorized people use computing resources. When we evaluate a control, therefore, we must consider its reliability from a systems perspective. Second, the focus of controls is unlawful events. An unlawful event can arise if unauthorized, inaccurate, incomplete, redundant, ineffective, or ineffi ient input enters the system. For example, a data-entry clerk might key incom- plete data into the system. An unlawful event can also arise if the system trans- forms the input in an unauthorized, inaccurate, incomplete, redundant, ineffective, or inefficient way. For example, a program could contain erroneous instructions that result in incorrect computations being performed. Whatever the reason, the system moves into a state that we deem to be unacceptable. Third, controls are used to prevent, detect, or correct unlawful-events. Con- sider some examples: 1. Preventive control: Instructions are placed on a source document to prevent clerks from filling it out incorrectly. Note that the control works only if the in- ‘structions are sufficiently clear and the clerk is sufficiently well trained to un- derstand the instructions. Thus, both the clerk and the instructions are compo- nents of the system that constitutes the control. The instructions by themselves, are not the control. 2. Detective conirol: An input program identifies incorrect data entered into a system via a terminal. Again, the control is a system because various parts of the program must work together to pinpoint errors. . 3. Corrective control: A program uses special codes that enable it to correct data corrupted because of noise on a communications line. Once more, the control is a system because various parts of the program must work together in con- junction with the error-correcting codes to rectify the error.

You might also like