INFORMATION TECHNOLOGY AUDITING and ASSURANCE Copyright 2011 Cengage Learning, Inc. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. INFORMATION TECHNOLOGY AUDITING and ASSURANCE THIRD EDITION JAMES A.
HALL Lehigh University Australia • Brazil • Japan • Korea • Mexico • Singapore • Spain • United Kingdom • United States Copyright 2011 Cengage Learning, Inc. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. This is an electronic version of the print textbook.
Due to electronic rights restrictions, some third party may be suppressed. Edition review has deemed that any suppressed content does not materially affect the over all learning experience. The publisher reserves the right to remove the contents from this title at any time if subsequent rights restrictions require it. For valuable information on pricing, previous editions, changes to current editions, and alternate format, please visit www.com/highered to search by ISBN#, author, title, or keyword for materials in your areas of interest.
Copyright 2011 Cengage Learning, Inc. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Information Technology Auditing and © 2011 South-Western, Cengage Learning Assurance, Third Edition ALL RIGHTS RESERVED.
No part of this work covered by the copyright James A. Hall herein may be reproduced, transmitted, stored or used in any form or Editor-in-Chief: Rob Dewey by any means graphic, electronic, or mechanical, including but not limited to photocopying, recording, scanning, digitizing, taping, Web Acquisition Editor: Matt Filimonov distribution, information networks, or information storage and Developmental Editor: Margaret Kubale retrieval systems, except as permitted under Section 107 or 108 of Editorial Assistant: Ann Mazzaro the 1976 United States Copyright Act, without the prior written permission of the publisher. Senior Marketing Manager: Natalie King Content Project Management: ACL, the ACL logo, the ACL logo with the text, “Data you can trust. PreMediaGlobal Results you can see.” and “Audit Command Language” are trademarks or registered trademarks of ACL Services Ltd.
Senior Art Director: Stacy Jenkins Shirley Manufacturing Coordinator: Doug Wilke For product information and technology assistance, contact us at Production House/Compositor: Cengage Learning Customer & Sales Support, 1-800-354-9706. PreMediaGlobal For permission to use material from this text or product, Permissions Acquisition Manager/Photo: submit all requests online at www.com/permissions Further permissions questions can be e-mailed to Deanna Ettinger permissionrequest@cengage.com Permissions Acquisition Manager/Text: Mardell Glinski Schultz Library of Congress Control Number: 2010928362 Cover Designer: cmiller design Cover Image: © Getty Images ISBN-13: 9781439079119 ISBN-10: 1-4390-7911-0 South-Western Cengage Learning 5191 Natorp Boulevard Mason, OH 45040 USA Cengage Learning is a leading provider of customized learning solutions with office locations around the globe, including Singapore, the United Kingdom, Australia, Mexico, Brazil, and Japan. Locate your local office at: www.com/global Cengage Learning products are represented in Canada by Nelson Education, Ltd. To learn more about south-western cengage.com/south-western Purchase any of our products at your local college store or at our preferred online store www.com Printed in the United States of America 1 2 3 4 5 6 7 14 13 12 11 10 Copyright 2011 Cengage Learning, Inc.
All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. DEDICATION To my wife, Eileen, for her unwavering support, encouragement, and patience. Copyright 2011 Cengage Learning, Inc.
All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Brief Contents CHAPTER 1 Auditing and Internal Control 1 CHAPTER 2 Auditing IT Governance Controls 35 CHAPTER 3 Security Part I: Auditing Operating Systems and Networks 67 CHAPTER 4 Security Part II: Auditing Database Systems 129 CHAPTER 5 Systems Development and Program Change Activities 171 CHAPTER 6 Transaction Processing and Financial Reporting Systems Overview 223 CHAPTER 7 Computer-Assisted Audit Tools and Techniques 289 CHAPTER 8 Data Structures and CAATTs for Data Extraction 327 CHAPTER 9 Auditing the Revenue Cycle 393 CHAPTER 10 Auditing the Expenditure Cycle 469 CHAPTER 11 Enterprise Resource Planning Systems 545 CHAPTER 12 Business Ethics, Fraud, and Fraud Detection 585 Glossary 629 Index 637 vi Copyright 2011 Cengage Learning, Inc. All Rights Reserved.
May not be copied, scanned, or duplicated, in whole or in part. Contents CHAPTER 1 The Distributed Model 41 Auditing and Internal Control 1 Controlling the DDP Environment 45 The Computer Center 47 Overview of Auditing 2 Physical Location 47 External (Financial) Audits 2 Construction 47 Attest Service versus Advisory Services 2 Access 47 Internal Audits 3 Air Conditioning 48 External versus Internal Auditors 4 Fire Suppression 48 Fraud Audits 4 Fault Tolerance 48 The Role of the Audit Committee 5 Audit Objectives 49 Financial Audit Components 5 Audit Procedures 49 Auditing Standards 5 Disaster Recovery Planning 50 A Systematic Process 6 Identify Critical Applications 51 Management Assertions and Audit Objectives 6 Creating a Disaster Recovery Team 52 Obtaining Evidence 7 Providing Second-Site Backup 52 Ascertaining Materiality 7 Outsourcing the IT Function 57 Communicating Results 8 Risks Inherent to IT Outsourcing 58 Audit Risk 8 Audit Implications of IT Outsourcing 59 Audit Risk Components 8 Summary 60 Inherent Risk 8 Detection Risk 9 Audit Risk Model 9 CHAPTER 3 The Relationship Between Tests of Controls and Security Part I: Auditing Operating Systems Substantive Tests 10 and Networks 67 The IT Audit 10 Auditing Operating Systems 68 The Structure of an IT Audit 10 Operating System Objectives 68 Internal Control 11 Operating System Security 69 Brief History of Internal Control Legislation 12 Threats to Operating System Integrity 69 Internal Control Objectives, Principles, and Operating System Controls and Audit Tests 70 Models 14 Auditing Networks 75 Modifying Principles 14 Intranet Risks 76 The PDC Model 16 Internet Risks 77 Coso Internal Control Framework 17 Controlling Networks 80 Audit Implications of SOX 24 82 Controlling Risks from Subversive Threats Summary 26 92 Controlling Risks from Equipment Failure Auditing Electronic Data Interchange (EDI) 93 CHAPTER 2 EDI Standards 94 Auditing IT Governance Controls 35 Benefits of EDI 95 Financial EDI 97 Information Technology Governance 36 EDI Controls 99 IT Governance Controls 36 Access Control 99 Structure of the Information Technology Auditing PC-Based Accounting Systems 101 Function 36 PC Systems Risks and Controls 102 Centralized Data Processing 36 Summary 105 Segregation of Incompatible IT Functions 39 Appendix 106 vii Copyright 2011 Cengage Learning, Inc. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part.
viii Contents CHAPTER 4 Manual Systems 226 Security Part II: Auditing Database The Audit Trail 231 Computer-Based Systems 234 Systems 129 Documentation Techniques 236 Data Management Approaches 130 Data Flow Diagrams and Entity Relationship The Flat-File Approach 130 Diagrams 236 The Database Approach 132 System Flowcharts 239 Key Elements of the Database Environment 133 Program Flowcharts 249 Database Management System 133 Record Layout Diagrams 250 Users 136 Computer-Based Accounting Systems 251 The Database Administrator 138 Differences Between Batch and Real-Time The Physical Database 139 Systems 252 DBMS Models 141 Alternative Data Processing Approaches 253 Databases in a Distributed Environment 149 Batch Processing Using Real-Time Data Centralized Databases 150 Collection 256 Distributed Databases 151 Real-Time Processing 258 Concurrency Control 154 Controlling the TPS 258 Controlling and Auditing Data Management Data Coding Schemes 258 Systems 155 A System without Codes 258 Access Controls 155 A System with Codes 260 Summary 164 Numeric and Alphabetic Coding Schemes 261 The General Ledger System 264 CHAPTER 5 The Journal Voucher 264 Systems Development and Program The GLS Database 264 Change Activities 171 The Financial Reporting System 266 Sophisticated Users with Homogeneous Information Participants in Systems Development 172 Needs 267 Why Are Accountants and Auditors Involved Financial Reporting Procedures 267 with SDLC? 172 XBRL—Reengineering Financial Reporting 269 How Are Accountants Involved with XML 270 the SDLC? 172 XBRL 271 Information Systems Acquisition 173 The Current State of XBRL Reporting 275 In-House Development 173 Controlling the FRS 275 Commercial Systems 173 COSO Internal Control Issues 275 The Systems Development Life Cycle 175 Internal Control Implications of XBRL 278 Systems Planning—Phase I 177 Summary 278 Systems Analysis—Phase II 179 Conceptual Systems Design—Phase III 183 System Evaluation and Selection—Phase IV 187 CHAPTER 7 Detailed Design—Phase V 195 Computer-Assisted Audit Tools and Application Programming and Testing—Phase VI 195 Techniques 289 System Implementation—Phase VII 198 Application Controls 290 Systems Maintenance—Phase VIII 204 Input Controls 290 Controlling and Auditing the SDLC 204 Processing Controls 303 Controlling New Systems Development 205 Output Controls 306 The Controlling Systems Maintenance 206 Testing Computer Application Controls 310 Summary 213 Black-Box Approach 310 White-Box Approach 311 CHAPTER 6 Computer-aided Audit Tools and Techniques for Transaction Processing and Financial Testing Controls 314 Reporting Systems Overview 223 Test Data Method 314 The Integrated Test Facility 317 An Overview of Transaction Processing 224 Parallel Simulation 319 Transaction Cycles 224 Summary 320 Accounting Records 226 Copyright 2011 Cengage Learning, Inc. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Contents ix CHAPTER 8 Substantive Tests of Revenue Cycle Accounts 419 Data Structures and CAATTs for Data Revenue Cycle Risks and Audit Concerns 419 Understanding Data 420 Extraction 327 Testing the Accuracy and Completeness Assertions 423 Data Structures 328 Testing the Existence Assertion 429 Flat-File Structures 329 Testing the Valuation/Allocation Assertion 434 Hierarchical and Network Database Structures 336 Summary 435 Relational Database Structure, Concepts, and Appendix 436 Terminology 338 Relational Database Concepts 339 Anomalies, Structural Dependencies, and Data CHAPTER 10 Normalization 344 Auditing the Expenditure Cycle 469 Designing Relational Databases 350 Expenditure Cycle Activities and Technologies 469 Identify Entities 350 Purchases and Cash Disbursement Procedures Using Construct a Data Model Showing Entity Batch Processing Technology 470 Associations 352 Reengineering the Purchases/Cash Disbursement Add Primary Keys and Attributes to the Model 354 System 475 Normalize Data Model and Add Foreign Keys 355 Overview of Payroll Procedures 479 Construct the Physical Database 356 Expenditure Cycle Audit Objectives, Controls, and Prepare the User Views 358 Tests of Controls 482 Global View Integration 359 Input Controls 483 Embedded Audit Module 359 Process Controls 487 Disadvantages of EAMs 360 Output Controls 492 Generalized Audit Software 361 Substantive Tests of Expenditure Cycle Accounts 493 Using GAS to Access Simple Structures 361 Expenditure Cycle Risks and Audit Concerns 494 Using GAS to Access Complex Structures 361 Understanding Data 494 Audit Issues Pertaining to the Creation of Testing the Accuracy and Completeness Assertions 497 Flat Files 363 Review Disbursement Vouchers for Unusual Trends ACL Software 363 and Exceptions 498 Data Definition 364 Testing the Completeness, Existence, and Rights and Customizing a View 366 Obligations Assertions 503 Filtering Data 367 Summary 506 Stratifying Data 369 Appendix 507 Statistical Analysis 369 Summary 370 CHAPTER 11 Appendix 371 Enterprise Resource Planning Systems 545 CHAPTER 9 What Is an ERP? 546 ERP Core Applications 547 Auditing the Revenue Cycle 393 Online Analytical Processing 548 Revenue Cycle Activities and Technologies 393 ERP System Configurations 549 Batch Processing Using Sequential Files—Manual Server Configurations 549 Procedures 394 OLTP Versus OLAP Servers 549 Batch Processing Using Sequential Files—Automated Database Configuration 553 Procedures 397 Bolt-On Software 553 Batch Cash Receipts System with Direct Access Data Warehousing 554 Files 401 Modeling Data for the Data Warehouse 555 Real-Time Sales Order Entry and Cash Receipts 401 Extracting Data from Operational Databases 555 Point-of-Sale (POS) Systems 405 Cleansing Extracted Data 557 Daily Procedures 405 Transforming Data into the Warehouse Model 557 End-of-day Procedures 407 Loading the Data into the Data Warehouse Revenue Cycle Audit Objectives, Controls, and Database 558 Tests of Controls 407 Decisions Supported by the Data Warehouse 559 Input Controls 409 Supporting Supply Chain Decisions from the Data Output Controls 417 Warehouse 560 Copyright 2011 Cengage Learning, Inc.
All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part.