Preview

Kanwee

Good Essays
Open Document
Open Document
6415 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Kanwee
Legislative Audit Division State of Montana

Report to the Legislature June 2006

06DP-05
Information System Audit

Data Center Review

Department of Administration

This report contains five multi-part recommendations addressing:

Implementing an overall process to ensure threats to the data center are addressed.

Implementing safeguards over physical security to deter unauthorized access. Strengthening safeguards to mitigate water and earthquake-related threats.

Coordinating disaster recovery efforts.

Defining responsibilities for data center security and coordination.

Direct comments/inquiries to: Legislative Audit Division
Room 160, State Capitol PO Box 201705
Helena MT 59620-1705

Help eliminate fraud, waste, and abuse in state government. Call the Fraud Hotline at 1-800-222-4446 statewide or 444-4446 in Helena.

INFORMATION SYSTEM AUDITS

Information System (IS) audits conducted by the Legislative Audit Division are designed to assess controls in an IS environment. IS controls provide assurance over the accuracy, reliability, and integrity of the information processed. From the audit work, a determination is made as to whether controls exist and are operating as designed. In performing the audit work, the audit staff uses audit standards set forth by the United States Government Accountability Office.

Members of the IS audit staff hold degrees in disciplines appropriate to the audit process. Areas of expertise include business, accounting and

You May Also Find These Documents Helpful

  • Good Essays

    Information technology and financial audits primary objectives are to ensure data integrity, safety, secure and operational effectiveness for Kudler’s business processes. Internal audit will provide an opinion on the accuracy and fairness of the financial statements. “This fairness evaluation is conducted in the context of generally accepted accounting principles (GAAP) and requires application of generalized auditing standards” (Bargranoff, 2008).…

    • 986 Words
    • 4 Pages
    Good Essays
  • Good Essays

    Nt1330 Unit 4

    • 694 Words
    • 3 Pages

    Responsible personnel review the following: audit results, customer feedback, process performance and product conformity, status of preventive…

    • 694 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Understanding internal controls is necessary to plan and complete the audit. The audit is not designed to obtain any type of reasonable assurance about these controls. If any significant deficiencies within the internal control system are discovered during the audit we will express concern to management, and the audit team will be made aware our findings.…

    • 483 Words
    • 2 Pages
    Satisfactory Essays
  • Better Essays

    We will review all data collected and ascertain that information and work is in compliance with statutes, regulations, GAAP, SFAS, and IFRS. We will also ascertain that the data is in compliance with the code of ethics for professional auditors (Apra, 2009).…

    • 1183 Words
    • 5 Pages
    Better Essays
  • Good Essays

    Game Solutions is a computer games company which has its Head Office located in Glasgow, where all administrative processes are conducted. However, all other functions are sited at four other locations in the UK in order to ensure optimum cost efficiency of the research and production functions in terms of staff, facilities, travel among others. All locations are networked together with a server placed at each location to facilitate communication and data transfer. Access to all files on the Head Office server is permitted by each of the other locations; although it is the responsibilities of the Site Managers to restrict access as he considers appropriate.…

    • 578 Words
    • 3 Pages
    Good Essays
  • Good Essays

    The three strategies for testing internal controls would first be to assess a control risk based on user controls. This can be done by comparing computer-generated output with the source documents that can support the transactions. The second strategy would be by planning for a low control risk assessment based on application controls. This means that the auditor should test the computer application controls, test the computer general controls, and test the manual follow up of the exceptions noted by the application controls. The last strategy would be planning for a high control risk assessment based on general controls and manual follow up. When an auditor test the general controls they can usually learn about the effectiveness of the design and testing application controls.…

    • 627 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    The list below contains the findings, weaknesses, or vulnerabilities discovered during the site security assessment. Some of the issues listed here are coalesced from more than one section of the assessment…

    • 2011 Words
    • 10 Pages
    Powerful Essays
  • Satisfactory Essays

    The purpose of this audit work program is to assess, at a high level, and validate key controls in place for Information and Communication. Inadequate or ineffective controls in this area may give rise to financial and operational risks.…

    • 948 Words
    • 4 Pages
    Satisfactory Essays
  • Better Essays

    Cobit Framework

    • 21108 Words
    • 85 Pages

    The Information Systems Audit and Control Association is a leading global professional organisation representing individuals in more than 100 countries and comprising all levels of IT — executive, management, middle management and practitioner. The Association is uniquely positioned to fulfil the role of a central, harmonising source of IT control practice standards for the world over. Its strategic alliances with other groups in the financial, accounting, auditing and IT professions are ensuring an unparalleled level of integration and commitment by business process owners. The Information Systems Audit and Control Association was formed in 1969 to meet the unique, diverse and high technology needs of the burgeoning IT • Its professional education programme offers technical and management conferences on five continents, as well as seminars worldwide to help professionals everywhere receive highquality continuing education. • Its technical publishing area provides references and…

    • 21108 Words
    • 85 Pages
    Better Essays
  • Good Essays

    Perform process documentation and tests of controls which will be used to support management’s overall evaluation…

    • 127890 Words
    • 695 Pages
    Good Essays
  • Better Essays

    edp audit

    • 8484 Words
    • 34 Pages

    The extent to which the auditor needs to understand the computer system is dependent upon the preliminary audit strategy selected:…

    • 8484 Words
    • 34 Pages
    Better Essays
  • Satisfactory Essays

    Audit

    • 1721 Words
    • 7 Pages

    To do an audit, there must be information in a verifiable form and some standards (criteria) by which the auditor can evaluate the information.…

    • 1721 Words
    • 7 Pages
    Satisfactory Essays
  • Good Essays

    The auditor has to decide whether he can place reliance on the internal control. If internal control is adequate, he can restrict nature, timing and extent of his checking accordingly. If not, he is left with no alternative but to resort to detailed checking.…

    • 511 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    Ch 1 SM FINALca

    • 10085 Words
    • 35 Pages

    Obtain Evidence About Controls: The outcome is an understanding of the client’s major internal control practices and whether the controls are sufficient to mitigate the risk of material misstatements in a company’s financial statements.…

    • 10085 Words
    • 35 Pages
    Powerful Essays
  • Powerful Essays

    Auditing

    • 24678 Words
    • 99 Pages

    ‘Two main objects of an audit are detection and prevention of errors and frauds.’ Comment. Can auditing prevent them?…

    • 24678 Words
    • 99 Pages
    Powerful Essays