C5 C11: Giáo Trình Kiểm Soát và Kiểm Toán Hệ Thống Thông Tin Kế Toán

Giáo trình nghiên cứu C5 c11 giáo trình kshtttkt english, trình bày lý thuyết rõ ràng, minh họa ví dụ thực tế, phù hợp sinh viên .

Trường đại học

Trường Đại Học

Chuyên ngành

Kiểm Soát và Kiểm Toán Hệ Thống Thông Tin Kế Toán

Người đăng

Ẩn danh

Thể loại

giáo trình

2016

226
12
0

Phí lưu trữ

55 Point

Mục lục chi tiết

5. CHAPTER 5: FRAUD

6. CHAPTER 6: COMPUTER FRAUD AND ABUSE TECHNIQUES

7. CHAPTER 7: INTERNAL CONTROL AND ACCOUNTING INFORMATION SYSTEMS

8. CHAPTER 8: CONTROLS FOR INFORMATION SECURITY

9. CHAPTER 9: CONFIDENTIALITY AND PRIVACY CONTROLS

10. CHAPTER 10: PROCESSING INTEGRITY AND AVAILABILITY CONTROLS

11. CHAPTER 11: AUDITING COMPUTER-BASED INFORMATION SYSTEMS

Tóm tắt

I. Tổng quan về Giáo Trình Kiểm Soát và Kiểm Toán Hệ Thống Thông Tin Kế Toán

Giáo trình này cung cấp cái nhìn tổng quan về kiểm soát hệ thống thông tinkiểm toán thông tin kế toán. Nó giúp người học hiểu rõ các khái niệm cơ bản và tầm quan trọng của việc kiểm soát trong môi trường kế toán hiện đại. Các hệ thống thông tin kế toán ngày càng trở nên phức tạp, đòi hỏi các biện pháp kiểm soát hiệu quả để bảo vệ dữ liệu và đảm bảo tính chính xác.

1.1. Khái niệm về Hệ Thống Thông Tin Kế Toán

Hệ thống thông tin kế toán (AIS) là một tập hợp các thành phần giúp thu thập, lưu trữ và xử lý thông tin tài chính. AIS không chỉ hỗ trợ trong việc lập báo cáo tài chính mà còn giúp quản lý thông tin kế toán một cách hiệu quả.

1.2. Tầm quan trọng của Kiểm Soát trong Kế Toán

Kiểm soát trong kế toán là cần thiết để ngăn ngừa gian lận và sai sót. Nó đảm bảo rằng thông tin tài chính được xử lý một cách chính xác và bảo mật, từ đó tạo niềm tin cho các bên liên quan.

II. Các Thách Thức trong Kiểm Soát Hệ Thống Thông Tin Kế Toán

Mặc dù có nhiều lợi ích, nhưng việc kiểm soát hệ thống thông tin kế toán cũng đối mặt với nhiều thách thức. Các vấn đề như gian lận, lỗi phần mềm và sự cố bảo mật có thể gây ra thiệt hại lớn cho tổ chức.

2.1. Gian Lận trong Hệ Thống Thông Tin

Gian lận có thể xảy ra dưới nhiều hình thức khác nhau, từ việc thao túng số liệu đến việc sử dụng thông tin sai mục đích. Điều này không chỉ ảnh hưởng đến tính chính xác của báo cáo tài chính mà còn làm giảm uy tín của tổ chức.

2.2. Rủi Ro từ Lỗi Phần Mềm và Hệ Thống

Lỗi phần mềm có thể dẫn đến việc mất mát dữ liệu hoặc thông tin không chính xác. Các tổ chức cần có các biện pháp kiểm soát để phát hiện và khắc phục các lỗi này kịp thời.

III. Phương Pháp Kiểm Soát Hệ Thống Thông Tin Kế Toán Hiệu Quả

Để đảm bảo an toàn cho hệ thống thông tin kế toán, các tổ chức cần áp dụng nhiều phương pháp kiểm soát khác nhau. Những phương pháp này không chỉ giúp phát hiện gian lận mà còn bảo vệ thông tin nhạy cảm.

3.1. Kiểm Soát Nội Bộ và Quy Trình

Kiểm soát nội bộ là một phần quan trọng trong việc bảo vệ tài sản và thông tin của tổ chức. Các quy trình kiểm soát nội bộ cần được thiết lập rõ ràng và thực hiện nghiêm túc để giảm thiểu rủi ro.

3.2. Sử Dụng Công Nghệ Thông Tin trong Kiểm Soát

Công nghệ thông tin đóng vai trò quan trọng trong việc kiểm soát hệ thống thông tin kế toán. Việc áp dụng các phần mềm kiểm toán và phân tích dữ liệu giúp phát hiện các bất thường và gian lận một cách nhanh chóng.

IV. Ứng Dụng Thực Tiễn của Kiểm Soát Hệ Thống Thông Tin Kế Toán

Việc áp dụng các biện pháp kiểm soát trong hệ thống thông tin kế toán không chỉ giúp bảo vệ thông tin mà còn nâng cao hiệu quả hoạt động của tổ chức. Các nghiên cứu cho thấy rằng các tổ chức có hệ thống kiểm soát tốt thường có hiệu suất tài chính cao hơn.

4.1. Kết Quả Nghiên Cứu về Kiểm Soát

Nghiên cứu cho thấy rằng các tổ chức áp dụng kiểm soát nội bộ hiệu quả có thể giảm thiểu thiệt hại do gian lận và sai sót. Điều này không chỉ bảo vệ tài sản mà còn tạo ra môi trường làm việc an toàn hơn.

4.2. Các Trường Hợp Thành Công trong Kiểm Soát

Nhiều tổ chức đã thành công trong việc áp dụng các biện pháp kiểm soát hiệu quả, từ đó nâng cao uy tín và sự tin tưởng từ khách hàng. Những trường hợp này có thể được sử dụng làm mô hình cho các tổ chức khác.

V. Kết Luận và Tương Lai của Kiểm Soát Hệ Thống Thông Tin Kế Toán

Tương lai của kiểm soát hệ thống thông tin kế toán sẽ phụ thuộc vào sự phát triển của công nghệ và các phương pháp kiểm soát mới. Các tổ chức cần liên tục cập nhật và cải tiến hệ thống kiểm soát của mình để đối phó với các thách thức mới.

5.1. Xu Hướng Mới trong Kiểm Soát

Xu hướng sử dụng trí tuệ nhân tạo và học máy trong kiểm soát hệ thống thông tin đang ngày càng phổ biến. Những công nghệ này có thể giúp phát hiện gian lận một cách nhanh chóng và chính xác hơn.

5.2. Tương Lai của Kiểm Toán và Kiểm Soát

Tương lai của kiểm toán và kiểm soát sẽ ngày càng gắn liền với công nghệ. Các chuyên gia cần trang bị kiến thức và kỹ năng mới để đáp ứng nhu cầu ngày càng cao trong lĩnh vực này.

16/07/2025
C5 c11 giáo trình kshtttkt english

Trích đoạn nội dung tài liệu

Control and Audit of PA R T Accounting Information Systems II CHAPTER 5 Fraud CHAPTER 6 Computer Fraud and Abuse Techniques CHAPTER 7 Internal Control and Accounting Information Systems CHAPTER 8 Controls for Information Security CHAPTER 9 Confidentiality and Privacy Controls CHAPTER 10 Processing Integrity and Availability Controls CHAPTER 11 Auditing Computer-Based Information Systems 125 M05_ROMN4021_14_SE_C05.indd 125 20/10/16 12:06 PM CHAPTER Fraud 5 LEARNING OBJECTIVES After studying this chapter, you should be able to: 1. Explain the threats faced by modern information systems. Define fraud and describe both the different types of fraud and the auditor’s responsibility to detect fraud. Discuss who perpetrates fraud and why it occurs, including the pressures, opportunities, and rationalizations that are present in most frauds.

Define computer fraud and discuss the different computer fraud classifications. Explain how to prevent and detect computer fraud and abuse. I N T E G R AT I V E C A S E Northwest Industries Jason Scott is an internal auditor for Northwest Industries, a forest products company. On March 31, he reviewed his completed tax return and noticed that the federal income tax withholding on his final paycheck was $5 more than the amount indicated on his W-2 form.

He used the W-2 amount to complete his tax return and made a note to ask the payroll department what happened to the other $5. The next day, Jason was swamped, and he dis- missed the $5 difference as immaterial. On April 16, a coworker grumbled that the company had taken $5 more from his check than he was given credit for on his W-2. When Jason realized he was not the only one with the $5 discrepancy, he investigated and found that all 1,500 employees had the same $5 discrepancy.

He also discovered that the W-2 of Don Hawkins, the payroll programmer, had thousands of dollars more in withholdings reported to the Internal Revenue Service (IRS) than had been withheld from his paycheck. Jason knew that when he reported the situation, management was going to ask ques- tions, such as: 1. What constitutes a fraud, and is the withholding problem a fraud? 2. How was the fraud perpetrated? What motivated Don to commit it? 126 M05_ROMN4021_14_SE_C05.

Why did the company not catch these mistakes? Was there a breakdown in controls? 4. How can the company detect and prevent fraud? 5. How vulnerable is the company’s computer system to fraud? Introduction As accounting information systems (AIS) grow more complex to meet our escalating needs for information, companies face the growing risk that their systems may be compromised. Recent surveys show that 67% of companies had a security breach, over 45% were targeted by organized crime, and 60% reported financial losses.

The four types of AIS threats a company faces are summarized in Table 5-1. TABLE 5-1 Threats to Accounting Information Systems THREATS EXAMPLES Natural and political disasters Fire or excessive heat Floods, earthquakes, landslides, hurricanes, tornadoes, blizzards, snowstorms, and freezing rain War and attacks by terrorists Software errors and equip- Hardware or software failure ment malfunctions Software errors or bugs Operating system crashes Power outages and fluctuations Undetected data transmission errors Unintentional acts Accidents caused by human carelessness, failure to follow established procedures, and poorly trained or supervised personnel Innocent errors or omissions Lost, erroneous, destroyed, or misplaced data Logic errors Systems that do not meet company needs or cannot handle intended tasks Intentional acts (computer Sabotage crimes) Misrepresentation, false use, or unauthorized disclosure of data Misappropriation of assets Financial statement fraud Corruption Computer fraud—attacks, social engineering, malware, etc.indd 127 20/10/16 12:06 PM 128 PART II CONTROL AND AUDIT OF ACCOUNTING INFORMATION SYSTEMS AIS Threats Natural and political disasters—such as fires, floods, earthquakes, hurricanes, tornadoes, bliz- zards, wars, and attacks by terrorists—can destroy an information system and cause many companies to fail. For example: ● Terrorist attacks on the World Trade Center in New York City and on the Federal Build- ing in Oklahoma City destroyed or disrupted all the systems in those buildings. ● A flood in Chicago destroyed or damaged 400 data processing centers.

A flood in Des Moines, Iowa, buried the city’s computer systems under eight feet of water. Hurricanes and earthquakes have destroyed numerous computer systems and severed communica- tion lines. Other systems were damaged by falling debris, water from ruptured sprinkler systems, and dust. ● A very valid concern for everyone is what is going to happen when cyber-attacks are militarized; that is, the transition from disruptive to destructive attacks.

For more on this, see Focus 5-1. FOCUS 5-1 Electronic Warfare Shortly after Obama was elected President, he autho- critical data, and illegally transfer money. They can also rized cyber-attacks on computer systems that run Iran’s cripple a nation’s armed forces, as they rely on vulnera- main nuclear enrichment plants. The intent was to delay ble computer networks.

All of these attacks are especially or destroy Iran’s nuclear-weapons program. The attacks scary because they can be done remotely, in a matter of were based on the Stuxnet virus, which was developed seconds, and done either immediately or at any predeter- with help from a secret Israeli intelligence unit. The attack mined date and time. A large-scale attack could create an damaged 20% of the centrifuges at the Natanz uranium unimaginable degree of chaos in the United States.

The enrichment facility (Iran denied its existence) by spinning most destructive attacks would combine a cyber-attack them too fast. This was the first known cyber-attack in- with a physical attack. tended to harm a real-world physical target. Both to be better able to use cyber weapons and to A hacker group that is a front for Iran retaliated using defend against them, the United States has created a distributed denial of service attacks (DDoS) to bring on- new U.

Cyber Command that will have equal footing line systems at major American banks to their knees. Most with other commands in the nation’s military structure. In denial of service attacks use botnets, which are networks addition, intelligence agencies will search computer net- of computers that the bot-herder infected with mal- works worldwide looking for signs of potential attacks on ware. However, the Iranians remotely hijacked and used the United States.

Cyber weapons have been approved “clouds” of thousands of networked servers located in for preemptive attacks, even if there is no declared war, if cloud computing data centers around the world. The at- authorized by the president—and if an imminent attack on tack inundated bank computers with encryption requests the United States warrants it. The implications are clear: (they consume more system resources), allowing the hack- the United States realizes that cyber weapons are going ers to cripple sites with fewer requests. The cloud services to be used and needs to be better at using them than its were infected with a sophisticated malware, which evaded adversaries.

detection by antivirus programs and made it very difficult Unfortunately, bolstering cyber security and safe- to trace the malware back to its user. The scale and scope guarding systems is significantly lagging the advance- of these attacks and their effectiveness is unprecedented, ment of technology and the constant development of as there have never been that many financial institutions new cyber-attack tools. Making it ever harder, advance- under simultaneous attack. ments such as cloud computing and the use of mobile Defense Secretary Leon E.

Panetta claimed that the devices emphasize access and usability rather than se- United States faces the possibility of a “cyber-Pearl Har- curity. Most companies and government agencies need bor” because it is increasingly vulnerable to hackers who to increase their security budgets significantly to de- could shut down power grids, derail trains, crash air- velop ways to combat the attacks. It is estimated that the planes, spill oil and gas, contaminate water supplies, and market demand for cyber security experts is more than blow up buildings containing combustible materials. They 100,000 people per year and the median pay is close to can disrupt financial and government networks, destroy six figures.indd 128 16/08/16 9:37 AM CHAPTER 5 FRAUD 129 Software errors, operating system crashes, hardware failures, power outages and fluc- tuations, and undetected data transmission errors constitute a second type of threat.

A federal study estimated yearly economic losses due to software bugs at almost $60 billion. More than 60% of companies studied had significant software errors. Examples of errors include: ● Over 50 million people in the Northeast were left without power when an industrial con- trol system in part of the grid failed. Some areas were powerless for four days, and dam- ages from the outage ran close to $10 billion.

● At Facebook, an automated system for verifying configuration value errors backfired, causing every single client to try to fix accurate data it perceived as invalid. Since the fix involved querying a cluster of databases, that cluster was quickly overwhelmed by hundreds of thousands of queries a second. The resultant crash took the Facebook system offline for two-and-a-half hours. ● As a result of tax system bugs, California failed to collect $635 million in business taxes.

● A bug in Burger King’s software resulted in a $4,334.33 debit card charge for four hamburgers. The cashier accidentally keyed in the $4.33 charge twice, resulting in the overcharge. A third type of threat, unintentional acts such as accidents or innocent errors and omis- sions, is the greatest risk to information systems and causes the greatest dollar losses. The Computing Technology Industry Association estimates that human errors cause 80% of secu- rity problems.

Forrester Research estimates that employees unintentionally create legal, regu- latory, or financial risks in 25% of their outbound e-mails. Unintentional acts are caused by human carelessness, failure to follow established proce- dures, and poorly trained or supervised personnel. Users lose or misplace data and acciden- tally erase or alter files, data, and programs. Computer operators and users enter the wrong input or erroneous input, use the wrong version of a program or the wrong data files, or mis- place data files.

Systems analysts develop systems that do not meet company needs, that leave them vulnerable to attack, or that are incapable of handling their intended tasks. Programmers make logic errors. Examples of unintentional acts include the following: ● A data entry clerk at Mizuho Securities mistakenly keyed in a sale for 610,000 shares of J-Com for 1 yen instead of the sale of 1 share for 610,000 yen. The error cost the com- pany $250 million.

● A programmer made a one-line-of-code error that priced all goods at Zappos, an online retailer, at $49.95—even though some of the items it sells are worth thousands of dollars. The change went into effect at midnight, and by the time it was detected at 6:00 A., the company had lost $1.6 million on goods sold far below cost. ● A bank programmer mistakenly calculated interest for each month using 31 days. Before the mistake was discovered, over $100,000 in excess interest was paid.

● A Fannie Mae spreadsheet error misstated earnings by $1. ● UPS lost a box of computer tapes containing sensitive information on 3.9 million Citigroup customers. ● Jefferson County, West Virginia, released a new online search tool that exposed the personal information of 1. ● McAfee, the antivirus software vendor, mistakenly identified svchost.exe, a crucial part of the Windows operating system, as a malicious program in one of its updates.

Hun- dreds of thousands of PCs worldwide had to be manually rebooted—a process that took 30 minutes per machine. A third of the hospitals in Rhode Island were shut down by the error. One company reported that the error cost them $2. A fourth threat is an intentional act such as a computer crime, a fraud, or sabotage, which is sabotage - An intentional deliberate destruction or harm to a system.

Information systems are increasingly vulnerable to act where the intent is to de- stroy a system or some of its attacks. Examples of intentional acts include the following: components.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ