Chapter 2
Auditing IT
Governance
Control
2
Learning 1. Understand the risks of 3. Understand the key elements
Objectives incompatible functions and
how to structure the IT
of a disaster recovery plan.
function.
2. Be familiar with the controls
and precautions required to 4. Be familiar with the benefits,
ensure the security of an risks, and audit issues related
organization’s computer to IT outsourcing.
facilities.
“
Chapter Outline
3
Information Technology Governance
Structure of the Information Technology
Function
The Computer Center
Disaster Recovery Planning
Outsourcing of the IT Function
Information
Technology
Governance
5
Information
Technology Key Objective:
Governance Reduce risk
Ensure that investsment in IT resources add
value to the organization.
6
IT Governance Three IT governance issues addressed by SOX
Controls and the COSO internal control framework:
Organizational structure of the IT function.
Computer center operations.
Disaster recovery planning.
Structure of
the Corporate
IT Function
8
Two Organizational 1. Centralized Data Processing System
Model
2. Distributed Data Processing System
9
10
Primary Service Areas: 11
Database Administration
• responsible for the security and integrity of the database.
Data Processing
• manages the computer resources used to perform the day – to day
processing of transactions.
Data Conversion
• Transcribes transaction data from hard-copy source documents into
computer input.
Computer Operations
• Manages the conversion of electronic files produced in data
conversion.
Data Library
• A room adjacent to computer operations that provides safe storage
for the off-line data files.
System Development and Maintenance
• System Development – responsible for analyzing user needs and
designing new systems to satisfy those needs. Key participants are
system professionals, end users and stakeholders.
• System Maintenance - assumes responsibility for keeping the
system current with user needs.
12
1. Separating Systems Development from
Segregation of Computer Operations
Incompatible IT 2. Separating Database Administration
Functions from Other Functions
3. Separating New Systems Development
from Maintenance
13
14
Alternative 1. Inadequate documentation a chronic
Organization of problem.
Systems
Development
Problems 2. When system programmer has
maintenance responsibilities, potential
for fraud is increased
15
The Distributed
Model
16
17
Risks 1. Inefficient use of resources
Associated with 2. Destruction of audit trails.
DDP
3. Inadequate segregation of
duties.
4. Hiring qualified professionals
5. Lack of standards.
18
Advantages of
DDP ○ Cost Reductions
○ Improved Cost Control Responsibility
○ Improve User Satisfaction
○ Backup Flexibility
19
Controlling the Implement a corporate IT function:
DDP Central testing of commercial software and
Environment hardware.
User services to provide technical help.
Standard-setting body.
Personnel review.
20
Audit procedures in a centralized IT
organization:
Audit
Objective ○ Review relevant documentation to determine
if individuals or groups are performing
incompatible functions.
○ Review systems documentation and
maintenance records to verify maintenance
programmers are not designers.
○ Observe to determine if segregation policy is
being followed.
21
Audit procedures in a distributed IT organization:
Review relevant documentation to determine if
individuals or groups are performing
Audit incompatible duties.
Objective Verify corporate policies and standards are
published and provided to distributed IT units.
Verify compensating controls are in place when
needed.
Review system documentation to verify
applications, procedures and databases are in
accordance with standards.
The Computer
Center
23
Physical location:
The Computer Directly affects risk of destruction
Center from a disaster.
Away from hazards and traffic.
Construction:
Ideally: single-story, solidly constructed
with underground utilities.
Windows should not open and an air
filtration system should be in place.
24
Access:
Should be limited with locked doors,
The Computer cameras, key card entrance and sign-in
Center logs.
Air conditioning
should provide appropriate temperature
and humidity for computers.
Fire suppression:
Alarms, fire extinguishing system,
appropriate construction, fire exits.
25
Fault tolerance is the ability of the system
to continue operation when part of the
The Computer system fails.
Center Total failure can occur only if multiple
components fail.
Redundant arrays of independent disks
(RAID) involves using parallel disks with
redundant data and applications so if one
disk fails, lost data can be
reconstructed.
Uninterruptible power supplies.
26
Auditor must verify that physical
controls and insurance coverage are
Audit Procedures: adequate.
The Computer
Procedures include:
Center
Tests of physical construction.
Tests of the fire detection system.
Tests of access control.
Tests of RAID.
Tests of the uninterruptible power supply.
Tests of insurance coverage.
Disaster Recovery
Planning
28
29
1. Identify critical applications
Disaster 2. Create a disaster recovery team:
Recovery
Planning 3. Provide second-site backup
4. Specify back-up and off-site storage
procedures
Identify critical applications:
Short-term survival requires restoration of cash flow generating
functions.
Applications supporting those functions should be identified and
prioritized in the restoration plan.
Task of identifying critical items and prioritizing applications requires
active participation of user departments, accountants and auditors.
30
31
Create a disaster recovery team:
Team members should be experts in their areas and have assigned
tasks.
Provide second-site backup:
Necessary ingredient in a DRP is that it provides for duplicate data
processing facilities following a disaster.
Specify back-up and off-site storage procedures
All data files, applications, documentation and supplies needed to
perform critical functions should be automatically backed up and stored
at a secure off-site location.
32
Mutual aid pact is an agreement between
organizations to aid each other with data
Second-Site
processing in a disaster.
Backups
Empty shell or cold site plan involves
obtaining a building to serve as a data
center in a disaster.
Recovery depends on timely
availability of hardware.
33
Recovery operations center or hot site
plan is a fully equipped site that many
Second-Site
companies share.
Backups
Internally provided backup may be
preferred by organizations with many
data processing centers.
34
○ Operating Systems Backup
Back Up and Off ○ Application Backup
Site Storage
○ Backup Documentation
Procedures
○ Backup Data Files
○ Backup Supplies and Source Documents
○ Testing the DRP
35
To verify DRP is a realistic solution, the following tests may be
DRP Audit performed:
Procedures Evaluate adequacy of backup site arrangements.
Review list of critical applications for completeness.
Verify copies of critical applications and operating systems are
stored off-site.
Verify critical data files are backed up in accordance with the
DRP.
Verify that types and quantities of items specified in the DRP
exist in a secure location.
Verify disaster recovery team members are current employees
and aware of their assigned responsibilities.
Outsourcing
the IT
Function
37
Benefits of IT outsourcing include:
Outsourcing the IT Improved core business processes.
Function Improved IT performance.
Reduced IT costs.
38
Commodity IT assets which are not
unique to an organization and easily
Outsourcing the IT
acquired in the marketplace.
Function
Specific IT assets which are unique and
support an organization’s strategic
objectives.
39
○ Failure to perform.
Risks Inherent ○ Vendor exploitation.
to IT
○ Outsourcing costs exceed benefits.
Outsourcing
○ Reduced security.
○ Loss of strategic advantage.
40
Use of a service organization does not reduce
management’s responsibilities under SOX for
Audit ensuring adequate IT internal controls.
Implications of SSAE 16 replaced SAS 70 and is the
IT Outsourcing definitive standard by which auditors
can gain knowledge that processes and
controls at third-party vendors are
adequate to prevent or detect
material errors.
Report provides a description of service provider’s
description using either the carve-out or the
inclusive method