




版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
Informationsystemsauditing2015YingQianITApplicationControlsObjectivesforITApplicationControlsControlsandpossibletestsforInputtingProcessingOutputtingTechniquesforauditingapplicationcontrolBusinessapplicationsGeneralLedgerInventoryControlSalesManufacturingResourcePlanning(MRP)DistributionRequirementsPlanning(DRP)HumanResourcesPayroll…ApplicationControlCosteffectiveandefficientmeanstomanageriskReliantontheeffectivenessontheITgeneralcontrolenvironmentApproachvariesforcomplexversusplexenvironmentsApplicationControlsObjectivesInputdataisaccurate,complete,authorized,andcorrectDataisprocessedasintendedinanacceptabletimeperiodOutputandstoreddataisaccurateandcompleteArecordismaintainedtotrackdataprocessingfrominputtostoragetooutputBenefitsofApplicationcontrolsReliabilityReduceslikelihoodoferrorsduetomanualinterventionBenchmarkingRelianceonITgeneralcontrolcanleadtoconcludingtheapplicationcontrolsareeffectiveyeartoyearwithoutre-testingTimeandcostsavingsTypicallyapplicationcontrolstakelesstimetotestandonlyrequiretestingonceaslongastheITgeneralcontrolsareeffectiveInputandAccessControlsDatachecksandvalidationAutomatedauthorization,approval,andoverrideAutomatedsegregationofdutiesandaccessrightsPendeditemsDatachecksandvalidationControlsReasonablenessandlimitchecksonfinancialvalues.Formatandrequiredfieldchecks;standardizedinputscreens.Sequencechecks(missingitems)rangechecks,andcheckdigits.Crosschecks(certainpoliciesareonlyvalidwithcertainpremiumtablecodes).Validations(storedtableanddrop-downmenuofvaliditems).PossibleTestsConductasampletestofeachscenario.Observeattemptstoinputincorrectdata.Determinewhocanoverridecontrols.Iftabledriven,determinewhocanchangeeditsandtolerancelevels.Automatedauthorization,approval,andoverrideControlsAuthorizationandapprovalrights(ofexpensesorclaimpaymentsorcreditoveracertainthreshold)areallocatedtousersbasedontheirrolesandtheirneedtousetheapplication.Overridecapability(e.g.,approvalofunusuallylargeclaims)isrestrictedbytheuser’sroleandneedtousetheapplicationbymanagement.PossibleTestsConducttestsbasedonuseraccessrights.Testaccessprivilegesforeachsensitivefunctionortransaction.Reviewaccessrightsthatsetandamendconfigurableapprovalandauthorizationlimits.AutomatedsegregationofdutiesandaccessrightsControlsIndividualswhosetupapprovedvendorscannotinitiatepurchasingtransactions.Individualswhohaveaccesstoclaimsprocessingshouldnotbeabletosetuporamendapolicy.PossibleTestsTestingbasedonuseraccessrights.Reviewofaccesstosetandamendconfigurablerolesormenustructures.PendeditemsControlsAgingreportsshowingnewpolicyitemswithpleteprocessingarerevieweddailyorweeklybysupervisors.Pendingfileswherethereisinsufficientinformationavailabletoprocesstransactions.PossibleTestsReviewagingresultsandevidenceofsupervisorreviewprocedures.Walkthroughasampleofitemstoandfromtheagingreportorpendingfile.FileandDataTransmissionControlsFiletransmissioncontrolsDatatransmissioncontrolsFiletransmissioncontrolsControlsChecksforcompletenessandvalidityofcontent,includingdateandtime,datasize,volumeofrecords,andauthenticationofsource.PossibleTestsObservetransmissionreportsanderrorreports.Observevalidityandcompletenessparametersandsettings.Reviewaccesstosetandamendconfigurableparametersonfiletransfers.DatatransmissioncontrolsControlsApplicationofselectedinputcontrolstovalidatedatareceived(keyfields,reasonableness,etc.).PossibleTestsTestsamplesofeachscenario.Observeattemptstoinputincorrectdata.Determinewhocanoverridecontrols.Iftabledriven,determinewhocanchangeeditsandtolerancelevels.BatchInputtingcontrolBatchInputAuthorizationBatchControlsandBalancingErrorReportingandHandlingBatchIntegrityinOnlineorDatabasesystemsBatchInputAuthorizationSignaturesonbatchformsOnlineaccesscontrolsUniquepasswordsWorkstationidentificationSourcedocumentsBatchControlsandBalancingtotalmonetaryamounttotalitemstotaldocumentshashtotalsmanualtotalsareinagreementwiththecomputertotalsErrorReportingandHandlingWhathappenstoabatchthathasanerror:dowerejectonlythetransaction?dowerejectthewholebatch?doweholdthebatchinsuspensependingcorrection?dowejustprocessthebatchandflagtheerror?InputControlTechniquesTransactionlogReconciliationofdataDocumentationErrorcorrectionproceduresAnticipating;TransmittallogCancellationofsourcedocuments.DataValidationEditsandControlsSequencecheckLimitcheckRangecheckValiditycheckReasonablenesscheckTablelookupsExistencecheckKeyverificationCheckdigitCompletenesscheckDuplicatecheckLogicalRelationshipcheckProcessingControlsAutomatedfileidentificationandvalidationAudittrailsandoverridesDataextraction,filtering,andreportingInterfacebalancingAutomatedfunctionalityandagingDuplicatechecksAutomatedfileidentificationandvalidationControlsFilesforprocessingareavailableandcomplete.PossibleTestsReviewprocessforvalidationandtestoperation.AudittrailsandoverridesControlsAutomatedtrackingofchangesmadetodata,associatingthechangewithaspecificuser.Automatedtrackingandhighlightingofoverridestonormalprocesses.PossibleTestsReviewreportsandevidenceofreviews.Reviewaccesstooverridenormalprocesses.Dataextraction,filtering,andreportingControlsExtractroutineoutputsareassessedforreasonablenessandcompleteness.Automatedallocationoftransactions(forreinsurancepurposes,furtheractuarialprocesses,orfundallocation).Evaluationofdatausedtoperformestimationforfinancialreportingpurposes.PossibleTestsReviewdesignofextractroutineagainstdatafilesused.Reviewsupervisoryassessmentofoutputfromextractroutineforevidenceofregularreviewandchallenges.Reviewsampleofallocationsforappropriateness.Reviewprocesstoassessextracteddataforcompletenessandvalidity.InterfacebalancingControlsAutomatedcheckingofdatareceivedfromfeedersystems(e.g.,payroll,claimsdata,etc.)intodatawarehousesorledgersystems.Automatedcheckingthatbalancesonbothsystemsmatchor,ifnot,anexceptionreportisgeneratedandused.PossibleTestsInspectinterfaceerrorreports.Inspectvalidityandcompletenessparametersandsettings.Reviewaccesstosetandamendconfigurableparametersoninterfaces.Inspectevidenceofmatchreportschecksanderrorfileprocessing.AutomatedfunctionalityandagingControlsFileextractsfromdebtorslistingtoprovidemanagementwithdataonagetransactions.PossibleTestsTestsampleoflistingtransactionstovalidateappropriatenessofagingprocessing.DuplicatechecksControlsComparisonofindividualtransactionstopreviouslyrecordedtransactionstomatchfields.Comparisonofindividualfilestoexpecteddates,times,sizes,etc.PossibleTestsReviewaccesstosetandamendconfigurableparametersonduplicatetransactionsorfiles.Reviewprocessforhandlingrejectedfilesortransactions.ProcessingControlsTechniqueRun-to-runtotalsLimitchecksReasonablenessverificationofcalculatedamountsDatafilecontroltechniqueParitycheckingTransactionlogsVersionUsageFileupdatingandmaintenanceauthorizationOutputControlDidtheinformationdistributedgettotheappropriaterecipient?
Wherewasthesensitivereportprinted?
Wasdistributioncontrolled?Howlongarethesensitivereportsretainedandaretheystoredinaprotectedenvironment?
OutputcontrolGeneralledgerpostingSubledgerpostingGeneralledgerpostingControlsAllindividualandsummarizedtransactionspostingtogeneralledger.PossibleTestsSampleofinputandsubledgersummarytransactionstracedtothegeneralledger.SubledgerpostingControlsAllsuccessfultransactionspostingtosubledger
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經(jīng)權益所有人同意不得將文件中的內容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 二零二五版貨車個人運輸合同范例
- 車輛掛靠單位協(xié)議書二零二五年
- 二零二五未成年工保護規(guī)定
- 二零二五版辦公用品采購協(xié)議合同
- 二零二五版金融債券抵押合同范例
- 個人轉讓單位合同樣本
- 法律咨詢服務協(xié)議合同書
- 從化區(qū)叉車租賃合同標準文本
- 買路合同樣本
- 二零二五版家裝公司施工安全免責的協(xié)議書
- 醫(yī)保基金監(jiān)管培訓課件
- 2024高考復習必背英語詞匯3500單詞
- 3課 《赤壁賦》公開課一等獎創(chuàng)新教學設計【中職專用】高一語文高教版2023-2024-基礎模塊下冊
- 第5章 層次分析法課件
- 情感糾紛案件調解協(xié)議書
- 咯血護理疑難病例討論
- 《車間主任培訓》課件
- 感染性休克急救流程及應急預案
- 《保障農(nóng)民工工資支付條例》宣傳冊
- 加強疾病預防控制體系信息化建設的實施方案
- 幼兒園優(yōu)質公開課:小班語言《小兔乖乖》課件
評論
0/150
提交評論