Yuvraj Bachhawat’s CA Final - ISCA 6.
1
Academy Ch. 6 – Auditing of Information System
Ch- 6 Auditing of Information Systems
Ch-6 Audit of Information Systems
(Part 1) - Introduction (Part 2) - Controls & Audit (Part 3) –The IS Audit
(Part 4) - Performing IS (Part 5) - IS Audit & Audit (Part 6) – Audit and Evaluation
Audit Evidence Techniques for Physical &
Environmental Controls
(Part 7) - Managerial Controls (Part 8) - Application Controls & (Part 9) - Audit of Application
and their Audit Trails their audit trails Security Controls
Part 1-Introduction:
Information Systems have become an integral part of our day-to-day life.
As the usage of technology and information system is increasing, associated risk with
technology is also imposing several threats to the information systems.
Thus it is imperative for organizations to place proper controls.
Controls can be classified based on:
Nature say, preventive, detective and corrective or
Some other parameters like physical, logical or environmental.
Compliance is an important audit procedure where an auditor evaluates the existence,
effectiveness and continued effectiveness of internal controls.
The chapter highlights the audit procedures used for performing systems audit for an
organization.
Part 2- Controls and Audit:
Control is a system that prevents, detects or corrects unlawful events.
Various controls are adapted as per requirement and accordingly, their audit become
necessary.
(Part 2) - Controls and Audit
2.1) – Need for Audit of 2.2) – Effect of Computers 2.3) – Responsibility for
Information System on Audit Controls
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.2
Academy Ch. 6 – Auditing of Information System
2.1) Need for Audit of Information Systems:
Factors influencing an organization toward controls and audit of computers:
1) Organisational Costs of Data Loss:
Data is a critical resource of an organisation for its present and future process and its ability
to adapt and survive in a changing environment.
2) Cost of Incorrect Decision Making:
High level decisions require accurate data to make quality decision rules.
To ensure accuracy, management and operational controls taken by managers involve
detection, investigations and correction of the processes.
3) Costs of Computer Abuse:
Following can lead to destructions of system assets (hardware, software, data, information):
Unauthorised access to computer systems and facilities
Unauthorised copies of sensitive data, malwares etc.
4) Value of Computer Hardware, Software and Personnel:
These are critical resources of an organisation, which have a credible impact on its
infrastructure and business competitiveness.
5) High Costs of Computer Error:
In a computerised enterprise environment where many critical business processes are
performed, a data error during entry or process would cause great damage.
6) Maintenance of Privacy:
Today, data collected in a business process contains private information about an individual
too & there is a fear that privacy has eroded beyond acceptable levels.
7) Controlled evolution of computer Use:
Use of Technology and reliability of complex computer systems cannot be guaranteed &
the consequences of using unreliable systems can be destructive.
The impact of the information systems audit function on organizations are as follows:
Information Systems Auditing:
It is the process of :
Attesting objectives (external auditor) that focus on asset safeguarding & data integrity &
Management objectives (internal auditor) that include effectiveness and efficiency both.
1) Improved Asset Safeguarding Objectives:
The information system assets (hardware, software, data information etc.) must be
protected by a system of internal controls from unauthorised access.
2) Improved Data Integrity Objectives:
It is a fundamental attribute of IS Auditing.
Data Integrity is important from the business perspective of the decision maker, competition
and the market environment.
3) Improved System Effectiveness Objectives:
Effectiveness of a system is evaluated by auditing the objective of the system to meet
business and user requirements.
4) Improved System Efficiency Objectives:
To optimize the use of various information system resources (machine time).
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.3
Academy Ch. 6 – Auditing of Information System
2.2) Effect of Computers on Audit Process:
To cope up with the new technology usage in an enterprise, the auditor should be
competent to provide independent evaluation as to whether the business process
activities are recorded and reported according to established standards or criteria.
Two basic functions carried out to examine these changes are:
Impact of Computerisation on audit
process can be classified as follows
A) - Changes to Evidence B) - Changes to Evidence
Collection Evaluation
A) Changes to Evidence Collection:
Existence of an audit trail is a key financial audit requirement.
Without an audit trail, the auditor may have extreme difficulty in gathering sufficient,
appropriate audit evidence to validate the figures in the client’s accounts.
The performance of evidence collection and understanding the reliability of controls
involves issues like-
1) Data retention and storage:
A client’s storage capabilities may restrict the amount of historical data that can be
retained “on-line” and readily accessible to the auditor.
If the client has insufficient data retention capacities the auditor may not be able to review
a whole reporting period transactions on the computer system.
For example, the client’s computer system may save data on detachable storage device by
summarising transactions into monthly, weekly or period end balances.
2) Absence of input documents:
Transaction data may be entered into the computer directly without the presence of
supporting documentation e.g. input of telephone orders into a telesales system.
The increasing use of EDI will result in less paperwork being available for audit examination.
3) Non-availability of audit trail:
The audit trails in some computer systems may exist for only a short period of time.
The absence of an audit trail will make the auditor’s job very difficult and may call for an audit
approach which involves auditing around the computer system by seeking other sources of
evidence to provide assurance that the computer input has been correctly processed.
4) Lack of availability of printed output:
The results of transaction processing may not produce a hard copy form of output, i.e. a
printed record.
In the absence of physical output it may be necessary for the auditor to directly access the
electronic data retained on the client’s computer.
This is normally achieved by having the client provide a computer terminal and being
granted “read” access to the required data files.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.4
Academy Ch. 6 – Auditing of Information System
5) Audit evidence:
Certain transactions may be generated automatically by the computer system.
Example: Fixed asset system may automatically calculate depreciation on assets at the end
of each calendar month.
The depreciation charge may be automatically transferred (journalised) from the fixed assets
register to the depreciation account and hence to the client’s income & expenditure account.
6) Legal issues:
The use of computers to carry out trading activities is also increasing.
More organisations in both the public and private sector intend to make use of EDI and
electronic trading over the Internet.
This can create problems with contracts e.g.:
When is the contract made What are the terms of the contract
Where is it made (legal jurisdiction) Who are the parties to the contract
The laws regarding the admissibility of computer evidence varies from one country to
another. Within a country laws may even vary between one state and another.
If the auditor intends to gather evidence for use in a court, s(he) should firstly find out
what the local or national laws stipulate on the subject.
In addition, the admissibility of evidence may vary from one court to another. What is
applicable is a civil court may not be applicable in a criminal court.
B) Changes to Evidence Evaluation:
Evaluation of audit trail and evidence is to trace consequences of control’s strength and
weakness throughout the system.
1) System generated transactions:
Financial systems may have the ability to initiate, approve and record financial transactions.
2) Automated transaction processing
Automated transaction processing systems can cause the auditor problems.
For example when gaining assurance that a transaction was properly authorised or in
accordance with delegated authorities.
Automated transaction generation systems are frequently used in ‘just in time’ (JIT) inventory
and stock control systems: When a stock level falls below a certain number, the system
automatically generates a purchase order and sends it to the supplier (perhaps using EDI
technology)
3) Systemic Error:
Computers are designed to carry out processing on a consistent basis i.e. given the same
inputs and programming; they invariably produce the same output.
This consistency can be viewed in both a positive and a negative manner.
If the computer is doing the right thing, then with all other things being equal, it will
continue to do the right thing every time and vice versa.
Therefore, whenever an auditor finds an error in a computer processed transaction, s(he)
should be thorough in determining the underlying reason for the error.
If the error is due to a systemic problem, the computer may have processed hundreds or
thousands of similar transactions incorrectly.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.5
Academy Ch. 6 – Auditing of Information System
2.3) Responsibility for Controls
Management is responsible for establishing and maintaining control to:
Achieve the objectives of effective and efficient operations &
Provide reliable information systems.
Management should consistently:
Apply the internal control to meet each of the internal control objectives and
To assess internal control effectiveness.
Management levels can be classified at three levels:
Senior management- Responsible for strategic planning and objectives, thus setting the
course in the lines of business that the company will pursue.
Middle management - Develops the tactical plans, activities and functions that accomplish
the strategic objectives,
Supervisory management - Oversees & controls the daily activities and functions of the
tactical plan.
Part 3- The IS Audit:
Part 3 – The IS Audit
3.1) - Objectives of IS 3.2) - Responsibility of 3.3) - Functions of IS
Audit IS Auditor Auditor
3.4) - Categories of IS 3.5) - Steps in IS Audit 3.6) - Audit Standards &
Audit Best Practices
3.1) Objectives of IS Audit:
The IS Audit is done to:
Assess internal controls within the IS environment to assure validity, reliability, and security
of information and information systems.
Assess efficiency and effectiveness of the IS environment.
3.2) Responsibility of IS Auditor:
The audit objective and scope has a significant bearing on the skill and competence
requirements of an IS auditor.
The set of skills that is generally expected to be with an IS auditor include:
1) Sound knowledge of business operations, practices and compliance requirements.
2) Should possess the requisite professional technical qualification and certifications.
3) A good understanding of information Risks and Controls.
4) Knowledge of IT strategies, policy and procedural controls.
5) Ability to understand technical and manual controls relating to business continuity.
6) Good knowledge of Professional Standards & Best Practices of IT controls & security.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.6
Academy Ch. 6 – Auditing of Information System
3.3) Functions of IS Auditor:
IS Auditor as a part of audit function reviews following risks relating to IT systems & processes:
Inadequate information security controls:
Missing or outdated antivirus controls
Open Systems without password or weak passwords
Inefficient use of resources, or poor governance:
Huge spending on unnecessary IT projects like printing resources, storage devices etc.
Ineffective IT strategies, policies and practices:
Including a lack of policy for use of ICT resources,
Lack of Internet usage policies,
Security practices etc.
IT-related frauds including phishing, hacking etc.
3.4) Categories of IS Audits
IS Audits has been categorized into five types:
1) Systems and Application:
An audit to verify that systems & applications are appropriate, are efficient, & are
adequately controlled to ensure valid, reliable, timely, and secure input, processing, and
output at all levels of a system's activity.
2) Information Processing Facilities:
An audit to verify that the processing facility is controlled to ensure timely, accurate, and
efficient processing of applications under normal and potentially disruptive conditions.
3) Systems Development:
An audit to ensure that systems are developed in accordance with generally accepted
standards for systems development and meet the objectives of organisation.
4) Management of IT and Enterprise Architecture:
An audit to verify that IT management has developed an organizational structure and
procedures to ensure a controlled and efficient environment for information processing.
5) Telecommunications, Intranets, and Extranets:
An audit to verify that controls are in place on the client, server, and on the network
connecting the clients and servers.
3.5) Steps in Information System Audit
Steps in Information System Audit can be categorized into six stages as follows:
1) Scoping and pre-audit survey:
Auditors determine the main area/s of focus based on the scope-definitions agreed with
management.
Information sources at this stage include background reading and web browsing, previous
audit reports, pre audit interview, observations etc.
2) Planning and preparation:
In this the scope is broken down into greater levels of detail, usually involving the
generation of an audit work plan or risk-control-matrix.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.7
Academy Ch. 6 – Auditing of Information System
3) Fieldwork:
Gathering evidence by interviewing staff and managers, reviewing documents, and
observing processes etc.
4) Analysis:
This step involves sorting out, reviewing all the evidence gathered earlier.
5) Reporting:
Reporting to the management is done after analysis of evidence gathered and analyzed.
6) Closure:
Closure involves preparing notes for future audits and follow up with management to
complete the actions they promised after previous audits.
3.6) Audit Standards and Best Practices
IS auditors need guidance and a yardstick to measure the 3Es’ (Economy, Efficiency and
Effectiveness) of a system.
The auditor needs guidance on how:
Information System should be assessed to plan their audits effectively and efficiently?
To focus their effort on high-risk areas and;
To assess the severity of any errors or weaknesses found during the IS audit process.
Several well known organizations have given practical and useful information on IS Audit,
which are given as follows:
1) ISACA (Information Systems Audit and Control Association):
ISACA is a global leader in information governance, control, security and audit.
ISACA developed the following to assist IS auditor while carrying out an IS audit.
a) IS auditing standards: ISACA issued 16 auditing standards, which defines the mandatory
requirements for IS auditing and reporting.
b) IS auditing guidelines: ISACA issued 39 auditing guidelines, which provide a guideline
in applying IS auditing standards.
c) IS auditing procedures: ISACA issued 11 IS auditing procedures, which provide
examples of procedure an IS auditor need to follow while conducting IS audit for
complying with IS auditing standards.
d) COBIT (Control objectives for information and related technology): This is a framework
containing good business practices relating to information technology.
2) ISO 27001:
ISO 27001 is the international best practice and certification standard for an Information
Security Management System (ISMS).
An ISMS is a systematic approach to manage Information security in an IS environment.
It encompasses people and, processes.
ISO 27001 defines how to organise information security in any kind of organization, profit
or non-profit, private or state-owned, small or large.
It is safe to say that this standard is the foundation of information security management.
Many Indian IT companies have taken this certification, including INFOSYS, TCS, WIPRO.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.8
Academy Ch. 6 – Auditing of Information System
3) Internal Audit Standards:
IIA (The Institute of Internal Auditors) is an international professional association.
This association provides dynamic leadership for the global profession of internal auditing.
IIA issued Global Technology Audit Guide (GTAG).
GTAG provides management of organisation about information technology management,
control, and security and IS auditors with guidance on various information technology associated
risks and recommended practices.
4) Standards on Internal Audit issued by ICAI:
The standards issued by the ICAI highlight the process to be adopted by internal auditor in
specific situation.
5) Information Technology Infrastructure Library ( ITIL):
The ITIL is a set of practices for IT Service Management (ITSM) that focuses on aligning IT
services with the needs of business.
In its current form (known as ITILv3 and ITIL 2011 edition), ITIL is published in a series of five
core publications, each of which covers an ITSM lifecycle stage.
ITIL describes procedures, tasks and checklists that are not organization-specific, used by an
organization for establishing a minimum level of competency.
It allows the organization to establish a baseline from which it can plan, implement, &
measure.
Part 4- Performing IS Audit:
Part 4 – Performing IS Audit
4.1) - Introduction 4.2) - Audit 4.2) - Basic 4.3) – Preliminary
Testing Plan Investigation
4.1) Introduction:
Auditor uses the concepts of Materiality and significance to plan the nature, timing, and
extent of audit procedures.
Materiality and significance include both quantitative and qualitative factors in relation to
the subject matter of the audit.
Even though a system may process transactions that are quantitatively immaterial or
insignificant, the system may contain sensitive information or provide an access path to
other systems that contain information that is sensitive.
For example, an application that provides public information via a website, if improperly
configured, may expose internal network resources, including sensitive systems, to
unauthorized access.
The underlying principle is that the auditor is not required to spend resources on items of
little importance; i.e. those that would not affect the judgment or conduct of a reasonable
user of the audit report, in light of surrounding circumstances.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.9
Academy Ch. 6 – Auditing of Information System
On the basis of this principle, the auditor may determine that some areas of the IS controls
audit are not material or significant, & therefore warrant little or no audit attention
Planning occurs throughout the audit as an iterative process.
For example, based on findings from the testing phase, the auditor may change the
planned audit approach, including the design of specific tests.
Objectives of planning phase are to:
Obtain an understanding of the entity and its operations,
Identify significant issues,
Assess risk, and
Design the nature, extent, and timing of audit procedures.
4.2) Audit Testing:
Auditor must devise an audit testing plan to determine whether the controls are effective.
The key audit concern is that the testing should reveal any type of exposure to sensitive
data and that the information produced by the application is valid, intact, and correct.
The auditor should conduct test with both valid & invalid data to test the ability of error
detection, correction, and prevention within the application.
The intensity and extent of the testing should be related to the sensitivity & importance of
the application.
The auditor performs the necessary testing by using documentary evidence, corroborating
interviews and personal observation.
Validation of the information obtained is prescribed by auditor’s work programme.
It calls for validation in several ways as follows (how validity of information obtained by
auditor can be checked?):
Asking different personnel the same question and comparing the answers
Asking the same question in different ways at different times
Comparing check list answers to observations and actual system results
Conducting in-depth studies of critical phases of the operation
4.3) Basic Plan:
Planning in an Information System Audit ensures that audit is performed in an effective manner.
The objective of audit planning is to optimize the use of audit resources.
Planning helps to:
Develop budgets of time and costs.
Develop the annual audit schedule to perform the individual audits.
Ensure that appropriate attention is devoted to important areas of the audit.
Properly assign work to assistants.
Important points are given as follows:
The auditor should develop and document an overall audit plan describing the expected
scope and conduct of the audit.
Obtaining knowledge of the business is an important part of planning the work as it assists
auditor in the identification of events, transactions and practices which may have a
material effect on the financial statements.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.10
Academy Ch. 6 – Auditing of Information System
The extent of planning will vary according to the:
Size of the entity
Complexity of the audit
Auditor’s experience with the entity
Knowledge of the business
The auditor may discuss elements of the overall audit plan and certain audit procedures
with the entity’s audit committee, the management and staff to:
Improve the effectiveness and efficiency of the audit and
Coordinate audit procedures with work of the entity’s personnel.
Planning is a continuous activity which goes on throughout the entire audit cycle.
4.4) Preliminary Review:
The preliminary review of audit environment enables the auditor to gain:
Understanding of the business, technology and control environment &
Clarity on the objectives of the audit and scope of audit.
The following are some of the critical factors, which should be considered by an IS auditor
as part of his/her preliminary review:
1) Knowledge of the Business:
Related aspects are given as follows:
Nature of Business, its products & services.
General exposure to business,
Vendors and Strategic business partners/associates,
Set up and organization of IT department.
2) Understanding the Technology:
An important task for the auditor as a part of his preliminary evaluation is to gain good
understanding of the technology environment and related issues.
This could include consideration of the following:
Analysis of business processes and level of automation,
Role of IT in the success and survival of business (i.e. extent of dependence on IT),
Understanding technology architecture which could be distributed architecture or a
centralized architecture or a hybrid architecture,
Studying network diagrams to understand network connectivity,
Understanding extended enterprise architecture wherein the organization systems
connect seamlessly with other stakeholders such as vendors (SCM), customers (CRM),
Employees (ERM) and the government,
Knowledge of various technologies and their advantages and limitations.
Studying Information Technology policies, standards, guidelines and procedures.
3) Understanding Internal Control Systems:
For understanding of Internal Controls emphasis sholud be placed on compliance &
substantive testing.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.11
Academy Ch. 6 – Auditing of Information System
4) Legal Considerations and Audit Standards:
Related points are given as follows:
The auditor should evaluate the legal as well as statutory implications on his/her audit work.
For Information Systems audit work conducted as part of a statutory requirement, auditor
should take into consideration the regulations & guidelines for conduct of his audit.
The statutes or regulatory framework may impose stipulations as regards minimum set of
control objectives to be achieved by the subject organization. Sometimes, this may also
include restrictions on the use of certain types of technologies e.g. freeware, shareware.
The IS Auditor should also consider the Audit Standards applicable to his conduct &
performance of audit work as non-compliance would result in the violation of the code of
professional ethics & will also have an adverse impact on the auditor’s work.
5) Risk Assessment and Materiality:
Risk Assessment is a critical and inherent part of the Information Systems Auditor’s
planning.
Risk Assessment is the process of:
Identifying the risk,
Assessing the risk considering both the probability and the impact of occurrence,
Recommending controls to reduce the risk to an acceptable level.
Risk assessment allows the auditor to:
Determine the scope of the audit &
Assess the level of audit risk.
Risk assessment will aid in planning decisions such as:
The nature, extent, and timing of audit procedures.
The areas or business functions to be audited.
The amount of time and resources to be allocated to an audit
The steps to be followed for a risk-based approach to make an audit plan are given as
follows:
Inventory the information systems in use in the organization and categorize them.
Determine which of the systems impact critical functions or assets.
Assess what risks affect these systems and the severity of the impact on the business.
Accordingly, decide the audit priority, resources, schedule and frequency.
Risks that affect a system can be differentiated as inherent Risk , control risk, detection risk
Categories of Risk:
1) Inherent risks:
Inherent risk is the susceptibility of information resources to material theft, destruction,
disclosure, unauthorized modification, or other impairment, assuming that there are no
related internal controls.
If the auditor concludes that there is a high likelihood of risk exposure, ignoring internal
controls, the auditor would conclude that the inherent risk is high.
For example:
Inherent risk would be high if the audit subject is an off-site.(E.g. ATM)
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.12
Academy Ch. 6 – Auditing of Information System
2) Control risks:
Control risk is the risk that could occur in an audit area, and which could be material, will not be
prevented or detected and corrected on a timely basis by the internal control system.
Control risk is a measure of the auditor's assessment of the likelihood that risk exceeding a
tolerable level, will not be prevented or detected by the client's internal control system.
3) Detection risks:
Detection risk is the risk that the IT auditor’s substantive procedures will not detect an
error which could be material, individually or in combination with other errors.
For example-The detection risk associated with identifying breaches of security in an
application system is ordinarily high because logs for the whole period of the audit are not
available at the time of the audit.
Part 5- IS Audit and Audit Evidence:
According to SA-230, Audit Documentation refers to the record of:
Audit procedures performed,
Relevant audit evidence obtained,
Conclusions the auditor reached.
The objective of auditors’ working papers is to record and demonstrate the audit work
from one year to another.
Evidences are also necessary for the following purposes:
Information about the business being audited, including the recent history
Evidence of audit work performed
Means of controlling current audit work
Schedules supporting or additional item in the accounts
Part 5-IS Audit & Audit Evidence
5.1) – Inherent Limitations 5.2) - Digital Evidences 5.3) - Concurrent 5.4) - Audit Trail
of audit Provisions Audit
5.1) Inherent Limitations of Audit:
To prepare proper report, auditor needs documented evidences.
The problem of documents not available in physical form has been highlighted at many
places.
Following is list of actions that auditor needs to take to address the problems:
Use of special audit techniques, referred to as Computer Assisted Audit Techniques, for
documenting evidences.
Audit timing can be so planned that auditor is able to validate transactions as they
occur in system.
Auditor shall form his/her opinion based on above processes.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.13
Academy Ch. 6 – Auditing of Information System
5.2) Provisions relating to Digital Evidences
As per Indian Evidence Act, 1872, “Evidence” means and include:
All statements, which the Court permits or requires to be made before it by witnesses, in
relation to matters of fact under inquiry; such statements are called oral evidence.
All documents produced for the inspection of the Court (documentary evidence).
Documentary Evidence also includes ‘Electronic Records’.
The Information Technology Act, 2000 provides the legal recognition of electronic records
and electronic signature through its various sections.
5.3) Concurrent or Continuous Audit
Real-time recordings need real-time auditing i.e. continuous auditing to provide continuous
assurance about the quality of the data.
Continuous auditing enables auditors to significantly reduce & perhaps to eliminate the time
between occurrence of the client's events & the auditor's assurance services thereon.
Continuous auditing techniques (CAT) use two bases for collecting audit evidence:
Use of embedded modules in the system to collect, process, and print audit evidence,
Special audit records used to store the audit evidence collected.
Continuous auditing has a number of potential benefits including:
Reducing the amount of time and costs auditors traditionally spent on manual examination
of transactions.
Increasing quality of audits by allowing auditors to focus more on understanding clients
business & internal control structure.
Specifying transaction selection criteria to choose transactions and perform both test of
controls and substantive tests throughout the year on an ongoing basis.
Enabling auditors to test larger sample of client's transactions faster and more efficiently
than the manual testing.
5.3) - Continuous Audit
A) - Advantages & B) - Types of Audit
Disadvantages Tools
A) Advantages and Disadvantages of Continuous Auditing:
I) Some of the advantages of continuous audit techniques are given as under:
1) Timely, Comprehensive and Detailed Auditing:
Evidence would be available more timely and in a comprehensive manner.
The entire processing can be evaluated and analyzed rather than examining the inputs and
the outputs only.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.14
Academy Ch. 6 – Auditing of Information System
2) Surprise test capability:
As evidences are collected from the system itself by using CAT, auditors can gather
evidence without the systems staff and application system users being aware that
evidence is being collected at that particular moment.
This brings in the surprise test advantages.
3) Information to system staff on meeting of objectives:
Continuous Audit Techniques provides information to systems staff regarding whether an
application system meets the objectives of :
Asset safeguarding Effectiveness
Data integrity Efficiency
4) Training for new users:
Using these audit tools, new users can submit data to the application system, and obtain
feedback on any mistakes they make via the system’s error reports.
II) The following are some of the disadvantages & limitations of the use of the Continuous
Audit Techniques:
1) Auditors should be able to obtain resources required from the organization to support
development, implementation, operation, and maintenance of CAT.
2) Continuous Audit Technique is more likely to be used if auditors are involved in the
development work associated with a new application system.
3) Auditors need the knowledge and experience of working with computer systems to be able
to use Continuous Audit Techniques effectively and efficiently.
4) Continuous Audit Techniques are more likely to be used where the audit trail is less visible
and the costs of errors and irregularities are high.
5) Continuous Audit Techniques are unlikely to be effective unless they are implemented in
an application system that is relatively stable.
B) Types of Audit Tools:
Many audit tools are also available; some of them are described below:
I) Snapshots:
Tracing a transaction is a computerized system can be performed with the help of
snapshots.
The snapshot software is built into the system at those points where material processing
occurs which takes images of the flow of any transaction as it moves through the
application.
These images can be utilized to assess the authenticity, accuracy, and completeness of the
processing carried out on the transaction.
Areas to think upon while involving such a system are:
Locating the snapshot points based on materiality of transactions.
When the snapshot will be captured
Reporting system design.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.15
Academy Ch. 6 – Auditing of Information System
II) System Control Audit Review File (SCARF):
Working:
The SCARF technique involves embedding audit software modules within a host
application system to provide continuous monitoring of the system’s transactions.
The information collected is written onto a special audit file- the SCARF master files.
Auditors then examine the information contained on this file to see if some aspect of the
application system needs follow-up.
In many ways, the SCARF technique is like the snapshot technique.
Auditors might use SCARF to collect the following types of information:
1) Application System Errors:
SCARF audit routines provide an independent check on:
Any design and programming errors
Errors which could creep into the system when it is modified & maintained.
2) Policy and Procedural Variances:
Organizations have to adhere to the policies, procedures and standards of the organization
and the industry to which they belong.
SCARF audit routines can be used to check when variations from these policies, procedures
and standards have occurred.
3) System Exception:
SCARF can be used to monitor different types of application system exceptions.
SCARF can be used to see how frequently salespersons override the standard price.
4) Statistical Sample:
SCARF provides a convenient way of collecting all the sample information together on one
file and use analytical review tools thereon.
5) Snapshots and Extended Records:
Snapshots and extended records can be written into the SCARF file and printed when
required.
6) Profiling Data:
Auditors can use embedded audit routines to collect data to build profiles of system users.
Deviations from these profiles indicate that there may be some errors or irregularities.
7) Performance Measurement:
Auditors can use embedded routines to collect data that is useful for measuring or
improving the performance of an application system.
III) Integrated Test Facility (ITF):
The ITF technique involves the creation of a dummy entity in the application system files
and the processing of audit test data against the entity as a means of verifying processing
authenticity, accuracy, and completeness.
This test data would be included with the normal production data used as input to the
application system.
In such cases the auditor has to decide what would be the method to be used to enter test
data and the methodology for removal of the effects of the ITF transactions.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.16
Academy Ch. 6 – Auditing of Information System
Methods of Entering Test Data:
Test data can be posted against an ITF dummy entity using two methods:
a) Method 1:
Tag live transactions submitted as production input to the application system to be tested.
The application system has to be programmed to recognize the tagged transactions and
have them invoke two updates, one to the application system master file record and one
to the ITF dummy entity.
Tagging live transactions as ITF transactions has the advantages of ease of use and
testing with transactions representative of normal system processing.
b) Method 2:
It involves designing new test transactions and entering them with the production input
into the application system.
In this approach auditor has to create the test data and insert the dummy entity’s unique
identifier to denote that it is an ITF transaction.
Methods of Removing the Effects of ITF Transactions:
The application system may be programmed to recognize ITF transactions and to ignore
them in terms of any processing that might affect users. OR
Another method would be the removal of effects of ITF transactions by submitting
additional inputs that reverse the effects of the ITF transactions. OR
Another less used approach is to submit trivial entries so that the effects of the ITF
transactions on the output are minimal. The effects of the transactions are not really
removed.
IV) Continuous and Intermittent Simulation (CIS):
This technique can be used to trap exceptions whenever the application system uses a
Database Management System (DBMS).
During application system processing, CIS executes in the following way:
The DBMS reads an application system transaction. It is passed to CIS which then
determines whether it wants to examine the transaction further. If yes, the next steps are
performed or otherwise it waits to receive further data from the DBMS.
CIS replicates or simulates the application system processing.
Every update to the database that arises from processing the selected transaction will
be checked by CIS to determine whether discrepancies exist between the results it
produces and those the application system produces.
Exceptions identified by CIS are written to a exception log file.
The advantage of CIS is that it does not require modification to the application & yet
provides an online auditing capability.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.17
Academy Ch. 6 – Auditing of Information System
V) Audit Hooks:
There are audit routines that flag suspicious transactions.
For example, internal auditors at Insurance Company determined that their policyholder
system was vulnerable to fraud every time a policyholder changed his or her name or
address and then subsequently withdrew funds from the policy.
Auditors devised a system of audit hooks to tag records with a name or address change.
The internal audit department will investigate these tagged records for detecting fraud
whenever questionable transactions occur.
5.4) Audit Trail:
5.4) - Audit Trail
A) - Introduction B) - Audit Trail Objectives C) – Implementing Audit Trail
A) Introduction:
Audit trails are logs that are designed to record activity at the system, application, & user level.
Properly implemented audit trails provide an important detective control to help
accomplish security policy objectives.
Audit trail controls attempt to ensure that a chronological record of all events that have
occurred in a system is maintained.
This record is needed to answer queries, fullfill statutory requirements, detect the
consequences of error and allow system monitoring.
The accounting audit trail shows the source and nature of data and processes that update
the database.
The operations audit trail maintains a record of attempted or actual resource consumption
within a system.
B) Audit Trail Objectives:
Audit trails can be used to support security objectives in three ways:
1) Detecting Unauthorized Access to the system:
Detecting unauthorized access can occur in:
Real time or
After the fact
Real time:
The primary objective of real-time detection is to protect the system from outsiders who
are attempting to breach system controls.
A real-time audit trail can also be used to report on changes in system performance that
may indicate infestation by a virus or worm.
After-the-fact:
After-the-fact detection logs can be stored electronically and reviewed periodically or as
needed.
When properly designed, they can be used to determine if unauthorized access was
accomplished, or attempted and failed.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.18
Academy Ch. 6 – Auditing of Information System
2) Facilitating the reconstruction of events:
Audit analysis can be used to reconstruct the steps that led to events such as system
failures, security violations by individuals, application processing errors.
Knowledge of the conditions that existed at the time of a system failure can be used to
assign responsibility and to avoid similar situations in the future.
3) Promoting personal accountability:
Audit trails can be used to monitor user activity at the lowest level of detail.
This capability is a preventive control that can be used to influence behaviour.
Individuals are likely to violate an organisation’s security policy if they know that their
actions are not recorded in audit log.
C) Implementing an Audit Trail:
The information contained in audit logs is useful to accountants in measuring the potential
damage and financial loss associated with:
Application errors, Unauthorized access by outside
Abuse of authority intruders.
Logs also provide valuable evidence and help in assessing both the adequacies of controls
in place and the need for additional controls.
Part 6- Audit and Evaluation Techniques for Physical and Environmental
Controls
Part 6 - Audit & Evaluation Techniques for
physical & Environmental Controls
6.1) - Audit of Physical Access Controls 6.2) - Audit of Environmental Controls
6.1) Role of IS Auditor in Physical Access Controls
Auditing physical access requires the auditor to review the physical access risk and controls
to form an opinion on the effectiveness of the physical access controls.
Auditing involves the following:
1) Risk Assessment:
The auditor must satisfy him/herself that the risk assessment procedure adequately covers
periodic and timely assessment of all:
Assets, Vulnerabilities of safeguards &
Physical access threats Exposures there from
2) Controls Assessment:
The auditor based on the risk profile evaluates whether the physical access controls are in
place & adequate to protect the IS assets against the risks.
3) Review of Documents:
It requires examination of relevant documentation such as:
The security policy and procedures Building plans
Premises plans Inventory list
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.19
Academy Ch. 6 – Auditing of Information System
6.2) Audit of Environmental Controls
Role of Auditor in Environmental Controls:
Audit of environmental controls should form a critical part of every IS audit plan.
Some of the critical audit considerations that an IS auditor should take into account while
conducting his/her audit is given below:
1) Audit Planning and Assessment (As part of risk assessment):
The risk profile should consider different kinds of environmental risks.
These should comprise both natural and man-made threats.
The profile should be periodically reviewed to ensure updation with newer risks.
The controls assessment must ascertain that controls safeguard the organization against all
acceptable risks.
The security policy of the organization should be reviewed to assess policies & procedures
that safeguard the organization against environmental risks.
Building plans and wiring plans need to be reviewed.
The IS auditor should interview relevant personnel to satisfy himself about:
Employees’ awareness of environmental threats & controls
Role of the interviewee in environmental control procedures.
Review:
Administrative procedures such as preventive maintenance plans.
Incident Reporting and Handling Procedures
Inspection and testing plan.
2) Audit of Environmental Controls:
The Auditor should verify:
The presence of water & smoke detectors, power supply arrangements to such devices.
The location of fire extinguishers, fire fighting equipment & refilling date of fire extinguishers.
Emergency procedures, evacuation plans and marking of fire exists.
There should be half-yearly Fire drill to test the preparedness.
Documents for compliance with legal and regulatory requirements with regards to fire safety
equipment, external inspection certificate and shortcomings pointed out by other auditors.
Power sources and conduct tests to assure the effectiveness of the power conditioning
equipment, and generators. Also the power supply interruptions must be checked to test
the effectiveness of the back-up power.
Environmental control equipment such as air-conditioning, dehumidifiers, heaters etc.
Identify undesired activities such as smoking, consumption of eatables.
3) Documentation:
As part of the audit procedures, the IS auditor should also document all findings.
The working papers could include audit assessments, audit plans, audit procedures,
questionnaires, interview sheets, inspection charts etc.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.20
Academy Ch. 6 – Auditing of Information System
Part 7-Managerial Controls and their Audit Trails
Types of Managerial Controls:
Controls: Scope:
Discusses the top management’s role in planning,
organizing, leading and controlling the information
Top Management and
systems function.
Information Systems
Also provides advice to top management in relation to
Management Controls
long-run policy decision making and translates long-run
policies into short-run goals and objectives.
Provides a contingency perspective on models of the
System Development
information systems development process that auditors
Management Controls
can use as a basis for evidence collection and evaluation.
Discusses the major phases in the program life cycle and
Programming
the important controls that should be exercised in each
Management Controls
phase.
Data Resource Discusses the role of database administrator and the
Management Controls controls that should be exercises in each phase.
Discusses the major functions that quality assurance
Quality Assurance management should perform to ensure that the
Management Controls development, implementation, operation, & maintenance
of information systems conform to quality standards.
Discusses the major functions performed by security
administrators to identify major threats to the IS functions
Security Management
and to design, implement, operate, and maintain controls
Controls
that reduce expected losses from these threats to an
acceptable level.
Discusses the major functions performed by operations
Operations Management
management to ensure the day-to-day operations of the IS
Controls
function are well controlled.
Some of the key areas that auditors should pay attention to while evaluating
Managerial controls and its types are provided below:
7.1) Top Management and Information Systems Management Controls:
The major activities that senior management must perform are – Planning, Organizing,
Controlling and Leading.
The Role of auditor at each activity is discussed below:
a) Planning:
Auditors need to evaluate whether top management has formulated a high-quality
information system’s plan that is appropriate to the needs of an organization or not.
A poor-quality information system is ineffective and inefficient leading to losing of its
competitive position within the marketplace.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.21
Academy Ch. 6 – Auditing of Information System
b) Organizing:
Auditors should be concerned about how well top management acquires and manages staff
resources for three reasons:
The effectiveness of the IS function depends primarily on the quality of its staff. The IS
staff need to remain up to date and motivated in their jobs.
Intense competition and high turnover have made acquiring and retaining good
information system staff a complex activity.
Research indicates that the employees of an organization are the most likely persons
to perpetrate irregularities.
c) Leading:
Generally, the auditors examine variables that often indicate when motivation problems
exist or suggest poor leadership.
For example - staff turnover statistics, frequent failure of projects to meet their budget and
absenteeism level to evaluate the leading function.
Auditors may use both formal and informal sources of evidence to evaluate how well top
mangers’ communicate with their staff.
The formal sources include IS plans, documents standards and policies whereas the informal
sources of evidence include interviews with IS staff about their level of satisfaction with the
top management.
Auditors must try to assess both the consequences of poor communications within the
information systems function and to assess the implications for asset safeguarding, data
integrity, system effectiveness, and system efficiency.
d) Controlling:
Auditors should focus on subset of the control activities that should be performed by top
management – namely, those aimed at ensuring that the information systems function
accomplishes its objectives at a global level.
7.2) System Development Management Controls:
Three different types of audits may be conducted during system development process as
follows:
Concurrent Auditors are members of the system development team.
Audit They assist the team in improving the quality of systems development
for the specific system they are building and implementing.
Post - Auditors seek to help an organization learn from its experiences in the
implementation development of a specific application system.
Audit In addition, they might be evaluating whether the system needs to be
scrapped, continued, or modified in some way.
General Audit Auditors evaluate systems development controls overall.
They seek to determine whether they can reduce the extent of
substantive testing needed to form an audit opinion about management’s
assertions relating to the financial statements for systems effectiveness
and efficiency.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.22
Academy Ch. 6 – Auditing of Information System
An external auditor is more likely to undertake general audits rather than concurrent or
post-implementation audits of the systems development process.
For internal auditors, management might require that they participate in the development of
material application systems or undertake post-implementation reviews of material application
systems as a matter of course.
7.3) Programming Management Controls:
Some of the major concerns that an auditor should address under different activities
involved in Programming Management Control Phase are:
Phase Audit Trails
They should evaluate whether the extent of planning are appropriate to
Planning the different types of software that are developed or acquired.
They must evaluate how well the planning work is being undertaken.
They must evaluate whether the nature of and extent of control activities
undertaken are appropriate for the different types of software that are
Control developed or acquired.
They must gather evidence on whether the control procedures are
operating reliably.
Auditors should find out whether programmers use some type of
systematic approach to design.
Design
Auditors can obtain evidence of the design practices used by undertaking
interviews, observations, and reviews of documentation.
Auditors should seek evidence on the level of care exercised by
programming management in choosing a module implementation and
integration strategy.
Auditors should seek evidence to determine whether programming
Coding management ensures that programmers follow structured programming
conventions.
Auditors should seek evidence to check whether programmers employ
automated facilities to assist them with their coding work.
Auditors can use interviews, observations, and examination of
documentation to evaluate how well unit testing is conducted.
Auditors are most likely concerned primarily with the quality of integration
testing work carried out by information systems professionals rather than
Testing
end users.
Auditor’s primary concern is to see that whole -of-program tests have
been undertaken for all material programs and that these tests have been
well-designed and executed.
Auditors need to ensure effectively and timely reporting of maintenance
Operation needs occurs and maintenance is carried out in a well-controlled manner.
and Auditors should ensure that management has implemented a review
Maintenance system and assigned responsibility for monitoring the status of
operational programs.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.23
Academy Ch. 6 – Auditing of Information System
7.4) Data Resource Management Controls:
Auditors should determine what controls are exercised to maintain data integrity. They
might also interview database users to determine their level of awareness of these
controls.
Auditors might employ test data to evaluate whether access controls and update controls
are working.
7.5) Quality Assurance Management Controls:
Auditors might use interviews, observations and reviews of documentation to evaluate
how well Quality Assurance (QA) personnel perform their monitoring role.
Auditors might evaluate how well QA personnel make recommendations for improved
standards or processes through interviews, observations, and reviews of documentation.
Auditors can evaluate how well QA personnel undertake the reporting function and
training through interviews, observations, and reviews of documentation.
7.6) Security Management Controls
Auditors must evaluate whether security administrators are conducting ongoing, high-
quality security reviews or not.
Auditors check whether the organizations audited have appropriate, high -quality disaster
recovery plan in place.
Auditors check whether the organizations have opted for an appropriate insurance plan or
not.
7.7) Operations Management Controls
Auditors should pay concern to see whether the documentation is maintained securely and
that it is issued only to authorized personnel.
Auditors can use interviews, observations, and review of documentation to evaluate -
the activities of documentation librarians;
how well operations management undertakes the capacity planning and
performance monitoring function;
the reliability of outsourcing vendor controls;
whether operations management is monitoring compliance with the outsourcing
contract; and
whether operations management regularly assesses the financial viability of any
outsourcing vendors that an organization uses.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.24
Academy Ch. 6 – Auditing of Information System
Part 8- Application Controls
An overview of application controls:
Controls Scope
Boundary Establishes interface between the user of the system & the system itself.
Controls The system must ensure that it has an authentic user.
Input Controls Responsible for bringing both the data and instructions in to the
information system.
Input Controls are validation & error detection of data input.
Communication Responsible for controls over physical components, communication line
Controls errors, flows, and links, topological controls, channel access controls,
controls over subversive attacks, audit trail controls.
Processing Responsible for computing, sorting, classifying and summarizing data.
Controls It maintains the chronology of events from the time data is received from
input to the time data is stored into database or output as results.
Output Controls To ensure that data content available to users, data format, timeliness of
data and how data is prepared and routed to users.
Database Responsible to provide functions to define, create, modify, delete and read
Controls data in an information system. It maintains procedural data-set of rules to
perform operations on the data to help a manager to take decisions.
Audit Trail Controls
Two types of audit trails that should exist in each subsystem:
An Accounting Audit Trail- To maintain a record of events within the subsystem.
An Operations Audit Trail- To maintain a record of the resource consumption
associated with each event in the subsystem.
We shall now discuss Audit Trails for Application Controls in detail:
8.1) Boundary Controls:
This maintains the chronology of events that occur when a user attempts to gain access
to and employ systems resources.
a) Accounting Audit Trail:
All material application oriented events that occur within the boundary subsystem should
be recorded in the accounting audit trail.
The following data associated with an event might be kept:
Authentication information supplied Start and Finish Time
Resources requested Number of Sign-on attempts
Action privileges requested Resources provided/denied
Terminal Identifier Action privileges allowed/denied
This data allows management or auditors to recreate the time series of events that occurs
when a user attempts to gain access and employ system resources.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.25
Academy Ch. 6 – Auditing of Information System
b) Operations Audit Trail:
Resource usage from log-on to log-out time.
Log of Resource consumption
8.2) Input Controls
This maintains the chronology of events from the time data and instructions are captured
and entered into an application system until the time they are deemed valid and passed
onto other subsystems within the application system.
a) Accounting Audit Trail
The following data associated with an event might be kept:
The identity of the person who entered the data into the system.
The time and date when the data was captured.
The identifier of the physical device used to enter the data into the system.
The account or record to be updated by the transaction.
The standing data to be updated by the transaction.
b) Operations Audit Trail
The following data might be kept:
Time to key in a source document or an instruction at a terminal.
Number of read errors made by an optical scanning device.
Number of keying errors identified during verification.
Time taken to invoke an instruction using a light pen versus a mouse.
8.3) Communication Controls
This maintains a chronology of the events from the time a sender dispatches a message to
the time a receiver obtains the message.
a) Accounting Audit Trail
The following data might be kept:
Unique identifier of the source node.
Unique identifier of each node in the network that traverses the message.
Unique identifier of the person authorizing dispatch of the message.
Time and date at which the message was dispatched.
Message sequence number
The image of the message received at each node traversed in the network.
b) Operations Audit Trail:
The following data might be kept:
Number of messages that have traversed each node.
Queue lengths at each node.
Number of errors occurring on each link or at each node.
Number of retransmissions that have occurred across each link.
Log of system restarts.
Message transit times between nodes.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.26
Academy Ch. 6 – Auditing of Information System
8.4) Processing Controls
The audit trail maintains the chronology of events from the time data is received from the
input to the time data is dispatched to the database, communication, or output subsystems.
a) Accounting Audit Trail
The following data might be kept:
To trace the processing performed on a data item.
When triggered transactions occur, processing subsystems should write the identity of
the process that initiated the triggered transaction and the conditions that resulted in
the triggered transactions in the audit trail.
b) Operations Audit Trail
The following data might be kept:
A comprehensive log on hardware consumption - CPU time used, secondary storage
space used, and communication facilities used.
A comprehensive log on software consumption - compilers used, file management
facilities used.
8.5) Database Controls
The audit trail maintains the chronology of events that occur either to the database
definition or the database itself.
a) Accounting Audit Trail
The following data might be kept:
To attach before images and after images of the data item on which a transaction is
applied to the audit trail.
Any modifications or corrections to audit trail transactions accommodating the
changes that occur within an application system.
b) Operations Audit Trail
The following data might be kept:
To maintain a chronology of resource consumption events that affects the database.
8.6) Output Controls
The audit trail maintains the chronology of events that occur from the time the content of
the output is determined until the time users complete their disposal of output
because it no longer should be retained.
a) Accounting Audit Trail
The following data might be kept:
What output was presented to users?
Who received the output?
When the output was received?
What actions were taken with the output?
b) Operations Audit Trail
To maintain the record of resources consumed – graphs, images, report pages, printing
time and display rate to produce the various outputs.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.27
Academy Ch. 6 – Auditing of Information System
Part 9 - Audit of Application Security Controls:
The objective of this exercise is to establish whether the application security controls are
operating effectively to protect the confidentiality, integrity & availability of information.
Approach to Application Security Audit
Application Security audit is being looked from usage perspective.
Application security audit should be based on a layered approach.
Layered approach is based on the activities being undertaken at various levels of
management, namely supervisory, tactical and strategic.
For this, auditors need to have a clear understanding of the following:
Business process for which the application has been designed.
The source of data input to and output from the application.
The various interfaces of the application under audit with other applications.
The roles, descriptions, user profiles & user groups that can be created in an application.
The policy of the organization for user access.
Various layers and related audit issues are discussed as follows:
1) Operational Layer:
This is basic layer, where user access decisions are generally put in place.
The operational layer audit issues include:
a) User Accounts and Access Rights:
This includes defining unique user accounts and providing them access rights appropriate
to their roles and responsibilities.
Auditor needs to always ensure the use of unique user IDs, & these need to be traceable to
individual for whom created.
b) Password Controls:
In general, password strength should be set defining:
Password minimum length Automated lockout after three
Password age attempts
Password non-repetition
Auditor needs to check whether there are applications where password controls are weak.
If such instances are found, then auditor may look for compensating controls.
c) Segregation of Duties:
As frauds due to collusions increases, importance of segregation of duties also increases.
Segregation of duties is a basic internal control that prevents or detects errors and
irregularities by assigning to separate individuals’ responsibility for initiating & recording
transactions and custody of assets to separate individuals.
Example to illustrate:
Record keeper of asset must not be asset keeper.
Maker must not be checker.
Cashier who creates a cash voucher in system, must not have right to authorize payments.
Auditor needs to check that there is no violation of above principle.
Any violation may have serious repercussions, & needs to be communicated immediately to
those charged with governance.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.28
Academy Ch. 6 – Auditing of Information System
2) Tactical Layer:
This is management layer, which includes supporting functions such as:
Security administration
IT risk management
Tactical Layer audit issues include:
a) Timely updates to user profiles, like creating/deleting & changing user accounts:
Auditor needs to check that any change to user rights is made through a formal process
including approval from manager of the employee.
b) IT Risk Management:
This function is another important function performed, it includes the following activities:
Assessing risk over key application controls
Conducting a regular security awareness programme on application user.
Enabling application users to perform a self-assessment.
Monitoring peripheral security in terms of updating antivirus software.
An auditor should understand the risk associated with each application and obtain a report on
periodic risk assessment on the application or self- assessment reports on the application.
c) Interface Security:
This relates to application interfaced with another application in an organization.
An auditor needs to understand that data flow to and from the application.
Security of the interfaced data is also important, especially when unencrypted methods of
transmission are used for data transmission.
d) Audit Logging and Monitoring:
Regular monitoring the audit logs is required.
The same is not possible for all transactions, so must be done on an exception reporting basis.
3) Strategic Layer:
This is the layer used by TOP management.
It includes the:
Overall information security governance
Security awareness
Supporting information security policies and standards
Strategic layer issues include:
At this layer, the top management takes action in form of:
Drawing up security policy
Security training
Security guideline and reporting.
A comprehensive security programme fully supported by top management & communicated
well to the organisation is of paramount importance to succeed in information security.
The security policy should be supported and supplemented by detailed standards & guidelines.
Auditor needs to check whether all these aforementioned guidelines have been properly
framed and are they capable of achieving the business objectives.
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.29
Academy Ch. 6 – Auditing of Information System
Important Questions:
1) Discuss the issues relating to the performance of evidence collection and understanding
the reliability of controls.
2) Explain the set of skills that is generally expected of an IS auditor.
3) Explain major types of IS Audits in brief.
4) Explain major stages of IS Audits in brief.
5) An important task for the auditor as a part of his/her preliminary evaluation is to gain a
good understanding of the technology environment and related control issues. Explain
major aspects that should be considered in this exercise.
6) What do you understand by SCARF technique? Explain various types of information
collected by using SCARF technique in brief.
7) What are the key steps that can be followed for a risk-based approach to make an audit
plan? Explain in brief.
8) Write short notes on the following:
a) Snapshots c) Source Document Controls
b) Audit Hooks d) Data Coding Controls
9) Describe major advantages of continuous audit techniques.
10) Describe major disadvantages and limitations of Continuous Audit techniques.
11) Explain three major ways by which audit trails can be used to support security objectives.
12) Discuss major audit issues of operational layer with reference to application security audit.
13) What are the factors that influence an organization towards controls and audit of
computers?
14) Discuss the points relating to ‘Legal Considerations and Audit Standards’ to be considered
by an IS auditor as a part of his/her preliminary review.
15) Discuss Integrated Test Facility (ITF) technique of continuous audit in detail with the help
of examples.
16) What are the major aspects that should be thoroughly examined by an IS Auditor during
the audit of Environmental Controls? Explain in brief.
17) Discuss audit trails of the following with reference to Application Security Audit in brief.
a) Input Controls d) Database Controls
b) Output Controls e) Boundary Controls
c) Communication Controls f) Processing Controls
18) Discuss major audit issues of Tactical Layer with reference to Application Security Audit.
19) Write short notes on the following:
a) Basic Plan with reference to IS Audit
b) Continuous Auditing
c) Continuous and Intermittent Simulation (CIS) technique
d) Strategic Layer with reference to application security audit
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123
Yuvraj Bachhawat’s CA Final - ISCA 6.30
Academy Ch. 6 – Auditing of Information System
CA YUVRAJ BACHHAWAT (DISA)
(M) 7096111123