Preview

Kanwee

Good Essays
Open Document
Open Document
6415 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Kanwee
Legislative Audit Division State of Montana

Report to the Legislature June 2006

06DP-05
Information System Audit

Data Center Review

Department of Administration

This report contains five multi-part recommendations addressing:

Implementing an overall process to ensure threats to the data center are addressed.

Implementing safeguards over physical security to deter unauthorized access. Strengthening safeguards to mitigate water and earthquake-related threats.

Coordinating disaster recovery efforts.

Defining responsibilities for data center security and coordination.

Direct comments/inquiries to: Legislative Audit Division
Room 160, State Capitol PO Box 201705
Helena MT 59620-1705

Help eliminate fraud, waste, and abuse in state government. Call the Fraud Hotline at 1-800-222-4446 statewide or 444-4446 in Helena.

INFORMATION SYSTEM AUDITS

Information System (IS) audits conducted by the Legislative Audit Division are designed to assess controls in an IS environment. IS controls provide assurance over the accuracy, reliability, and integrity of the information processed. From the audit work, a determination is made as to whether controls exist and are operating as designed. In performing the audit work, the audit staff uses audit standards set forth by the United States Government Accountability Office.

Members of the IS audit staff hold degrees in disciplines appropriate to the audit process. Areas of expertise include business, accounting and

You May Also Find These Documents Helpful

  • Good Essays

    Game Solutions is a computer games company which has its Head Office located in Glasgow, where all administrative processes are conducted. However, all other functions are sited at four other locations in the UK in order to ensure optimum cost efficiency of the research and production functions in terms of staff, facilities, travel among others. All locations are networked together with a server placed at each location to facilitate communication and data transfer. Access to all files on the Head Office server is permitted by each of the other locations; although it is the responsibilities of the Site Managers to restrict access as he considers appropriate.…

    • 578 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    The list below contains the findings, weaknesses, or vulnerabilities discovered during the site security assessment. Some of the issues listed here are coalesced from more than one section of the assessment…

    • 2011 Words
    • 10 Pages
    Powerful Essays
  • Good Essays

    Information technology and financial audits primary objectives are to ensure data integrity, safety, secure and operational effectiveness for Kudler’s business processes. Internal audit will provide an opinion on the accuracy and fairness of the financial statements. “This fairness evaluation is conducted in the context of generally accepted accounting principles (GAAP) and requires application of generalized auditing standards” (Bargranoff, 2008).…

    • 986 Words
    • 4 Pages
    Good Essays
  • Good Essays

    The three strategies for testing internal controls would first be to assess a control risk based on user controls. This can be done by comparing computer-generated output with the source documents that can support the transactions. The second strategy would be by planning for a low control risk assessment based on application controls. This means that the auditor should test the computer application controls, test the computer general controls, and test the manual follow up of the exceptions noted by the application controls. The last strategy would be planning for a high control risk assessment based on general controls and manual follow up. When an auditor test the general controls they can usually learn about the effectiveness of the design and testing application controls.…

    • 627 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    The purpose of this audit work program is to assess, at a high level, and validate key controls in place for Information and Communication. Inadequate or ineffective controls in this area may give rise to financial and operational risks.…

    • 948 Words
    • 4 Pages
    Satisfactory Essays
  • Good Essays

    It Auditing Essay Example

    • 2323 Words
    • 10 Pages

    5. When evaluating the collective effect of preventive, detective or corrective controls within a process, an IS auditor should be aware of which of the following?…

    • 2323 Words
    • 10 Pages
    Good Essays
  • Better Essays

    Cobit Framework

    • 21108 Words
    • 85 Pages

    The Information Systems Audit and Control Association is a leading global professional organisation representing individuals in more than 100 countries and comprising all levels of IT — executive, management, middle management and practitioner. The Association is uniquely positioned to fulfil the role of a central, harmonising source of IT control practice standards for the world over. Its strategic alliances with other groups in the financial, accounting, auditing and IT professions are ensuring an unparalleled level of integration and commitment by business process owners. The Information Systems Audit and Control Association was formed in 1969 to meet the unique, diverse and high technology needs of the burgeoning IT • Its professional education programme offers technical and management conferences on five continents, as well as seminars worldwide to help professionals everywhere receive highquality continuing education. • Its technical publishing area provides references and…

    • 21108 Words
    • 85 Pages
    Better Essays
  • Good Essays

    Perform process documentation and tests of controls which will be used to support management’s overall evaluation…

    • 127890 Words
    • 695 Pages
    Good Essays
  • Better Essays

    edp audit

    • 8484 Words
    • 34 Pages

    The extent to which the auditor needs to understand the computer system is dependent upon the preliminary audit strategy selected:…

    • 8484 Words
    • 34 Pages
    Better Essays
  • Powerful Essays

    Ch 1 SM FINALca

    • 10085 Words
    • 35 Pages

    Obtain Evidence About Controls: The outcome is an understanding of the client’s major internal control practices and whether the controls are sufficient to mitigate the risk of material misstatements in a company’s financial statements.…

    • 10085 Words
    • 35 Pages
    Powerful Essays
  • Good Essays

    The auditor has to decide whether he can place reliance on the internal control. If internal control is adequate, he can restrict nature, timing and extent of his checking accordingly. If not, he is left with no alternative but to resort to detailed checking.…

    • 511 Words
    • 3 Pages
    Good Essays
  • Good Essays

    Representatives of recognised Internal Audit and Internal Control Professional Associations, such as IFACI and The IIA.…

    • 596 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Audit

    • 1721 Words
    • 7 Pages

    To do an audit, there must be information in a verifiable form and some standards (criteria) by which the auditor can evaluate the information.…

    • 1721 Words
    • 7 Pages
    Satisfactory Essays
  • Powerful Essays

    Kanaran

    • 1018 Words
    • 5 Pages

    Supervisor(s): Lieven Vandevelde I. I NTRODUCTION The electrical system is traditionally fed by large centralized power plants connected to the power transmission network. Recently, because of environmental considerations, technological developments and tax incentives for renewables, the grid architecture is changing from centralized to decentralized energy supply with distributed generators (DGs) connected to the utility grid. The DG technology may include microturbines, fuel cells, wind, photovoltaics (PV), internal combustion engines, etc. Because of the small size of the emerging DG, the generators can be positioned near the consumers, which reduces the amount of energy lost in the power transfer across the transmission lines. DG can also lead to improved reactive power support and voltage profile, removal of transmission bottlenecks, usage of environmental friendly resources (by private-owned, low-voltage connected on-site generation) and postponement of investments in new transmission systems and large-scale generators. As DGs are increasingly being connected to the utility grid, their task is changing from back-up elements to primary energy resources. One of the advantages of distributed generation, the increase of reliability of the electrical energy supply, can be realized by the introduction of the microgrid concept. A microgrid is a cluster of supply, storage and load elements connected to the low-voltage distribution sys—————————————————–…

    • 1018 Words
    • 5 Pages
    Powerful Essays
  • Powerful Essays

    Auditing

    • 24678 Words
    • 99 Pages

    ‘Two main objects of an audit are detection and prevention of errors and frauds.’ Comment. Can auditing prevent them?…

    • 24678 Words
    • 99 Pages
    Powerful Essays