Showing posts with label Ch3. Show all posts
Showing posts with label Ch3. Show all posts

Monday, January 7, 2013

File Interrogations

File interrogation would encompass the following;
  • Objective setting - see internal audit planning process
  • File requirements (determination of)
  • Field Selection within the database - then decide
  • Where to store
  • How much to select and
  • Obtain the data (possibly a pilot) and fine tune
  • Prepare reports
Typical interrogations may include the following;
  • Ensuring liabilities are not un/der-recorded
  • Review invalid invoices, duplication
  • Review of firewall logs
  • Payroll existence tests
  • GP analysis
  • Completeness of transactions

Computer Forensics

Computer forensics is defined as



techniques used to enable secure collection of computer data and analysis which can be admissible as evidence.

The two key principles of computer forensics are evidential integrity and evidential continuity. Evidential integrity is that the evidence taken must be an exact copy. Evidential continuity means that the chain of events between data contact and evidence presentation must be unbroken.

Throughout a computer forensic exercise, it is important to document all steps thoroughly. When deciding what you need it is important to collect the data you might need for a variety of scenarios. It is good practice to assume that the case may end up in litigation. Remembering that unauthorised seizure can be criminal, it is critical to gain proper permission when gathering evidence. Illegal seizure of equipment or data would lead to an evidential fail.

Care should be taken when gathering evidence as there is a risk that the computer equipment is booby trapped and a poorly executed information gathering may destroy important evidence (e.g dates). Fishing expeditions often result in evidential fails. The use of specialists should be considered. They would often take images of the data to preserve the integrity of the  source data.

How the evidence is retained is important as you must be able to account for evidence at all times post seizure. To ensure evidential integrity forensic software locks data when it is extracted. Failure to perform similar steps would be the third and final example of an evidential fail.
 







Sunday, January 6, 2013

Ethical Hacking

Hacking can be defined as unauthorised access to computer systems. The 1990 Computer Misuse Act made hacking an illegal activity.

Ethical hacking is the legitimate investigation of system security flaws using tools and techniques known to be employed by hostile attackers. It is also known as penetration testing.

The main purpose of ethical hacking is to discover the risks which you may be exposed to. The main drawbacks are that
  • It is at a single point in time.
  • The hackers resources are constrained by time and money which may not be the case with an actual hacker.
  • The ethical hacker may not have the requisite expertise.
You also have to consider the trustworthiness of the hacker.

As result ethical hacking should not be seen as a panacea. It should be complemented by other IT controls aimed at preventing or detecting unauthorised remote access including patch control management, strong access controls and monitoring use of systems.

CAAT - Audit Analysis

Here are some ways that CAAT can be used for audit analysis;
  • Information retrieval - e.g. JET, identify patterns, shifts or trends, duplicate records
  • Network security - e.g. system overrides, access authorities,
  • Fraud detection - e.g. transaction analysis. Comparing supplier and payroll records
  • Audit reporting and management tools
  • Continuous monitoring
  • E-commerce security
See file interrogation for ways that the above may be carried out.

CAAT for audit analysers faces the following problems. Information may be;




  • Confidential
  • Hard to retrieve
  • Encrypted
  • Spread over Several Systems


  • Ways of tackling this CHESSS problem are




    • building an audit team with these specialist skills
    • libraries of information describing retrieval routines


    Users should be aware of the risks of erroneous extrapolation and inappropriate disclosure related to use of analysis derived from CAATs.



       
       
     


     

     
     
     
     

    CAATS

    These fall under 4 headings.