0% found this document useful (0 votes)
12 views7 pages

CIS Auditing: E-Commerce Systems Overview

The document discusses auditing in a CIS environment, focusing on electronic commerce systems, network infrastructure, and security measures. It highlights the risks associated with internet commerce, including consumer fraud and internal security threats within organizations. Additionally, it emphasizes the importance of trust, data integrity, and compliance with privacy regulations in the evolving landscape of online transactions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views7 pages

CIS Auditing: E-Commerce Systems Overview

The document discusses auditing in a CIS environment, focusing on electronic commerce systems, network infrastructure, and security measures. It highlights the risks associated with internet commerce, including consumer fraud and internal security threats within organizations. Additionally, it emphasizes the importance of trust, data integrity, and compliance with privacy regulations in the evolving landscape of online transactions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Auditing in a CIS Environment: Module 12 • Digital product delivery systems (streaming,

downloads)
Electronic Commerce Systems
Packet Switching
- refer to the technologies, platforms, and processes that
• Internet messages are broken into small packets, each
enable organizations and individuals to buy, sell, exchange,
taking potentially different routes.
and manage goods, services, and information
electronically. • Packets contain addressing and sequencing data and are
reassembled at the destination.
They include all components that support digital transactions,
such as: Virtual Private Networks (VPNs)
1. Online Transaction Platforms A VPN is a private, secure network connection built on top of a
public network like the Internet
• Online stores, marketplaces, and virtual malls
Why VPNs are important
• Shopping carts and payment gateways
• They allow employees to access company systems remotely
• Electronic Data Processing & Transmission
as if they are physically in the office.
• Electronic Funds Transfer (EFT)
• They protect sensitive information from hackers when using
• Electronic Data Interchange (EDI) public networks (e.g., airport Wi-Fi).

• Internet-based order processing Intranets

3. Network Infrastructure • An Intranet is a secure, closed network that uses Internet


technologies (like web browsers, web servers) to share
• Internet technologies (websites, browsers, URLs, IP
information, tools, policies, documents, and communication
addresses)
within an organization.
• Intra-organizational networks (LANs, WANs)
Extranets
• VPNs and extranets
 An extranet is a restricted, password-protected section of a
4. Security & Control Systems network designed for business partners, suppliers, or
customers—not for the public.
• Encryption

• Authentication
World Wide Web (WWW)
• Firewalls
The World Wide Web is a vast system of interlinked documents and
• Access controls resources accessed via the Internet.
• Supporting Applications What it consists of: Web pages written in HTML (HyperText Markup
• Customer relationship management (CRM) Language) , Websites hosted on servers, Browsers (Chrome, Edge,
Safari) that display information, URLs (Uniform Resource Locator)
• Supply chain management (SCM) that serve as web addresses
2. Transaction Level
- Organizations at this level use the Internet to accept
Internet Addressing
customer orders or place purchase orders with suppliers.
1. E-mail Addresses - format: username@domainname - This level introduces most of the risks associated with e-
commerce.
- a unique electronic identifier that specifies the destination mailbox
for sending and receiving electronic messages. 3. Distribution Level
2. URL Address (Uniform Resource Locator) - This level introduces most of the risks associated with e-
commerce.
A URL address is the specific web address used to locate a resource - At this level, the organization sells and delivers digital
on the World Wide Web. products directly over the Internet.
3. IP Address (Internet Protocol Address) - In addition to transaction-level risks, firms must guarantee
that digital products are delivered correctly and only to
An IP address is a unique numerical identifier assigned to each legitimate customers.
device connected to a network or the Internet.

Benefits from Internet Commerce Intranet Risks


Virtually all types of businesses have benefited in some way from - Intranets, which connect employees across local and wide-
Internet commerce. area networks, face significant internal security threats—
primarily from employees who misuse their access. Because
Some potentially significant benefits include:
employees understand system controls and sometimes have
• Access to a worldwide customer and/or supplier extensive privileges, they pose one of the greatest risks,
base. especially those who are disgruntled or recently terminated.

• Reductions in inventory investment and carrying Key Intranet Risks


costs.
1. Unauthorized Internal Actions
• The rapid creation of business partnerships to fill
• Employees may steal data, commit fraud, sabotage
market niches as they emerge.
systems, or sell company secrets due to motives
• Reductions in retail prices through lower marketing such as revenge, curiosity, or financial gain. Valuable
costs. assets like trade secrets, accounting data, and
confidential records are particularly vulnerable.
• Reductions in procurement costs.
2. Message Interception (Sniffing)
• Better customer service
• Data traveling through shared network channels—
Internet Business Models
including passwords, emails, and financial files—can
- At this basic level, the Internet is used only to display be intercepted using sniffer software. Although used
information about the company, its products, and its by administrators for diagnostics, these tools can be
policies—usually through a website. exploited by criminals, especially when intranets
connect to the Internet.
- This level is mainly informational—no business transactions
occur. 3. Access to Corporate Databases
• Employees with database access can view, alter, or b. Theft of Passwords
copy sensitive data such as social security numbers, Criminals create deceptive websites that require
customer lists, credit card information, or users to register with an email and password.
proprietary formulas. Outsiders also bribe • Since many people reuse the same password across
employees to manipulate financial records. Losses multiple accounts, attackers use captured
from insider financial fraud and trade secret theft passwords to access bank accounts, email, or
can reach millions of dollars. company systems.
c. Consumer Privacy Issues
4. Privileged Employees
Privacy concerns discourage many potential online
• Middle managers and IT personnel, who often have buyers.
override privileges, are more frequently involved in • Surveys show that many people avoid Internet
insider crimes than lower-level employees. commerce due to fears about misuse of personal
data.
5. Reluctance to Prosecute • Privacy advocacy groups (CDT, EFF, EPIC) push for
• Many organizations historically avoided reporting stronger protections.
intrusions due to fear of negative publicity. This d. Cookies and Privacy Concerns
trend is improving, but reluctance still helps repeat Cookies are small files stored on a user’s computer to
offenders. improve website efficiency.
However, they also raise privacy issues:
• Background checks are becoming more common— • Websites can track user behavior, preferences,
and legally necessary—due to the doctrine of browsing history, and even personal details like
negligent hiring liability, which holds employers email or ZIP code.
responsible if inadequate screening leads to • This information creates user profiles that online
employee crimes. Laws now protect employers who marketers use for targeted advertising or mailing
share truthful, non-malicious information about lists.
former employees. e. Cookies and Security Risks
Internet Risks Cookies can also create security vulnerabilities:
• Some sites store unencrypted passwords in cookies,
- Internet commerce exposes both consumers and businesses making them readable by anyone with access to the
to significant risks. As more people transact online, cyber computer.
fraud grows, leading many consumers to view the Internet • Malicious websites can use JavaScript to scan and
as unsafe—especially regarding credit card security and steal cookie files, exposing personal data and login
personal privacy. information.
1. Risks to Consumers
a. Theft of Credit Card Numbers Risks to Businesses in Internet Commerce
This is one of the biggest barriers to online • Businesses face major risks when using the Internet for
commerce. commerce. Three significant threats are IP spoofing, denial
• Hackers may steal large batches of credit card data of service (DoS) attacks, and malicious programs.
from poorly secured websites.
• Fraudsters may create fake online stores to collect 1. IP Spoofing
card numbers and then disappear.
• Attackers disguise their IP address to appear as a
trusted source.
3. Malicious Programs
• This allows them to bypass security, commit fraud, Viruses, worms, logic bombs, and Trojan horses can:
steal data, or send false orders. • Corrupt databases
• Damage operating systems
Because the source appears legitimate, companies may act on fake
• Capture passwords
requests, leading to financial loss
• Disable networks
2. DoS and DDoS Attacks (Denial of Service/ Distributed Denial of These threats affect both Internet and internal networks
Service) (intranets) and present broader security concerns beyond
just e-commerce
DoS attacks aim to overload a business’s web server so it cannot
serve legitimate users. This is especially harmful to companies that Security, Assurance, and Trust in Electronic Commerce
rely on online transactions. - Trust is essential for successful electronic commerce. To
Main types: build trust, organizations must (1) implement strong
technical security controls and (2) reassure customers and
• SYN Flood: Attackers send many connection partners that these controls are effective.
requests but never finish the handshake. This clogs
server ports, blocking legitimate traffic.
Key Security Technologies
• Smurf Attack: Attackers spoof the victim’s IP and
send ping requests to an entire network. The 1. Encryption
network replies to the victim all at once, Encryption converts readable data (cleartext) into coded
overwhelming it. data (ciphertext) to protect it during storage or
transmission.
• Distributed DoS (DDoS): Large-scale attack using
thousands of infected “zombie” computers • Private key (symmetric) encryption uses one shared
(botnets). Because attacks come from everywhere, key for both encoding and decoding (e.g., AES).
they are extremely hard to stop. • Public key encryption uses a pair of keys—one
3. Malicious Programs public, one private—to reduce the risk of key
exposure (e.g., RSA).
Viruses, worms, logic bombs, and Trojan horses can:
• A digital envelope combines both approaches for
• Corrupt databases efficiency and security.
• Damage operating systems 2. Digital Authentication
• Capture passwords - Encryption alone cannot prove message integrity or sender
identity.
• Disable networks - A digital signature verifies that a message came from the
real sender and was not altered.
These threats affect both Internet and internal networks (intranets)
- A digital certificate, issued by a trusted certification
and present broader security concerns beyond just e-commerce
authority (CA), confirms the sender’s identity.
3. Firewalls 2. Choice – Allow individuals to choose whether sensitive
A firewall protects an organization’s internal network information (e.g., health, religion, race) can be shared.
(intranet) from unauthorized access via the Internet.
3. Onward Transfer – Share data only with third parties who
• Network-level firewalls screen basic traffic.
also follow Safe Harbor principles.
• Application-level firewalls enforce stricter checks
using proxy services. 4. Security & Data Integrity – Keep information accurate,
complete, current, and protected against unauthorized
Seals of Assurance
access or misuse.
- To increase consumer trust in online businesses, several
5. Access – Permit individuals to view, correct, or delete their
third-party organizations issue “seals of assurance” that
personal data unless overly burdensome.
companies can display on their websites. These seals
indicate that the business meets specific standards in areas 6. Enforcement – Ensure compliance, provide remedies for
such as privacy, security, ethical practices, and system violations, and impose sanctions for non-compliance.
reliability. Each organization focuses on different aspects of
trustworthiness. Audit Implications of XBRL

Major Seal Providers - eXtensible Business Reporting Language -It is a


standardized language for electronic communication of
business and financial data, allowing organizations to
prepare, share, and analyze financial statements in a
structured, computer-readable format.

The use of XBRL presents several important concerns for


auditors:

1. Taxonomy Creation – Errors in building the XBRL taxonomy


can lead to incorrect data mapping, causing financial
information to be misrepresented. Strong controls are
necessary to ensure taxonomies are created accurately.

Safe Harbor Agreement and International Privacy Compliance 2. Validation of Instance Documents – After data is tagged and
stored, XBRL instance documents (the actual reports) must
To address privacy concerns in global data transfers, the U.S.–EU
be independently verified. Auditors need procedures to
Safe Harbor Agreement (approved in 2000) established
confirm that the correct tags and taxonomies were applied
minimum privacy protection standards. U.S. companies must
before these reports are published online.
either join Safe Harbor or prove they meet its rules in order to
do business with the EU. 3. Audit Scope and Timeframe – Traditional audits cover
printed financial statements, but XBRL enables real-time
To meet Safe Harbor requirements, organizations must follow six
financial reporting on the internet. This raises questions
principles:
about whether auditors should extend their responsibilities
1. Notice – Inform individuals about what data is collected, to continuous online data, including accompanying textual
why, and who it is shared with. information.
Continuous Auditing Authentication

• Auditors must adopt techniques to review transactions • Traditional proof of authenticity (paper documents) is no
continuously or in real time. longer available in e-commerce.

• Requires intelligent control agents (software) programmed • Identity is verified using digital signatures and digital
with audit rules. certificates.

• Agents scan electronic transactions for anomalies and look • Accountants must develop technical skills to understand and
for patterns. evaluate these tools.

• If no valid explanation is found, the system issues an alert or Nonrepudiation


exception report to the auditor.
• Ensures parties cannot deny participating in a transaction.
Electronic Audit Trails
• Critical for verifying sales, receivables, purchases, and
• In EDI systems, transactions are automatically generated liabilities.
and transmitted through value-added networks (VANs).
• Digital signatures and certificates replace signed paper
• Audit responsibilities may extend to trading partners and documents as evidence.
the VANs involved.
Data Integrity
• Validation may require:
• Even authenticated, nonrepudiated data may be altered
• Direct review of systems of all parties, or during transmission. Alterations are harder to detect in
digital environments.
• Collaboration between auditors of the client, trading
partners, and VAN provider. • Auditors must understand:

Confidentiality of Data • Document digests (hash functions)

• Open, interconnected systems increase exposure to internal • How digital signatures safeguard data integrity.
and external intruders.
Access Controls
• Auditors must understand:
• Controls must restrict or detect unauthorized access to
• Cryptographic techniques for protecting stored and systems.
transmitted data.
• Internet-connected organizations face higher risks from
• Encryption quality and key management external attackers.
procedures.
• Accounting firms must be skilled in evaluating access control
• Mission-critical information now extends beyond traditional effectiveness.
financial data, requiring a broader internal control
A Changing Legal Environment
assessment.
• The rise of Internet commerce has expanded the risk
assessment responsibilities of accountants.
• Online business operates in an evolving legal environment
filled with new and unpredictable risks.

• Accountants must now understand the domestic and


international legal implications of electronic transactions.

• A simple online ordering webpage can expose a company to


multiple jurisdictions and possibly conflicting laws.

• New legal challenges include issues related to:

• Taxation

• Privacy

• Security

• Intellectual property

• Libel

• Accountants must be prepared to give clients quick,


accurate guidance on these emerging legal questions.

You might also like