IT General Controls
IT General Controls
IT General Controls
Charles Broom
IS Assurance Manager
[email protected]
ALASBO 12/11/2013
Page 1
Agenda
What are IT General Controls?
Why should an accountant/business professional care?
Common issues found
Encryption
Questions
ALASBO 12/11/2013
Page 2
Computer Operations
ALASBO 12/11/2013
Page 3
ALASBO 12/11/2013
Page 4
Operating System
Application
ALASBO 12/11/2013
Page 5
Database
N
e
t
w
o
r
k
ALASBO 12/11/2013
Page 6
OS
- Password settings (why is this such a big deal?)
- Administrative access
ALASBO 12/11/2013
Page 7
Database
- Access to change outside the application
- Monitoring
ALASBO 12/11/2013
Page 8
Just letters
Letters &
numbers
Letters, numbers
& symbols
0.006 seconds
0.01 seconds
0.03 seconds
0.292 seconds
0.91 seconds
3.26 seconds
13.2 minutes
1.20 hours
8.17 hours
24.7 days
7.93 months
8.41 years
3.53 years
44.9 years
799 years
10
183 years
3,100 years
75,900 years
11
9,530 years
214,000 years
7,215,000 years
12
496,000 years
14,772,000 years
685,388,000 years
ALASBO 12/11/2013
Page 9
Computer Operations
What happens automatically?
Batch processing
Transfers between systems
How is that controlled?
Who can touch the servers? (Ignorance is not a control)
ALASBO 12/11/2013
Page 10
ALASBO 12/11/2013
Page 11
AU 314
The auditor must obtain a sufficient
understanding of the entity and its
environment, including its internal control, to
assess the risk of material misstatement of the
financial statements whether due to error or
fraud, and to design the nature, timing, and
extent of further audit procedures.
ALASBO 12/11/2013
Page 12
ALASBO 12/11/2013
Page 13
NO
ALASBO 12/11/2013
Page 14
Computer Operations
ALASBO 12/11/2013
Page 15
Common issues
Administrative Access
Who is good?
Who is bad?
Databases
Monitoring
Program Change
Policies
Access
Monitoring
ALASBO 12/11/2013
Page 16
Encryption
Hardware vs. Software based
Symmetrical vs. Asymmetrical
Good enough?
ALASBO 12/11/2013
Page 17
Questions
ALASBO 12/11/2013
Page 18