• Title/Summary/Keyword: IT Audit

Search Result 497, Processing Time 0.025 seconds

A Design on the Information Security Auditing Framework of the Information System Audit (정보시스템 감리에서의 정보보호 감리모형 설계)

  • Lee, Ji Yong;Kim, Dong Soo;Kim, Hee Wan
    • Journal of Korea Society of Digital Industry and Information Management
    • /
    • v.6 no.2
    • /
    • pp.233-245
    • /
    • 2010
  • This paper proposes security architecture, security audit framework, and audit check item. These are based on the security requirement that has been researched in the information system audit. The proposed information security architecture is built in a way that it could defend a cyber attack. According to its life cycle, it considers a security service and security control that is required by the information system. It is mapped in a way that it can control the security technology and security environment. As a result, an audit framework of the information system is presented based on the security requirement and security architecture. The standard checkpoints of security audit are of the highest level. It was applied to the system introduction for the next generation of D stock and D life insurance company. Also, it was applied to the human resources information system of K institution and was verified. Before applying to institutions, system developers and administrators were educated about their awareness about security so that they can follow guidelines of a developer security. As a result, the systemic security problems were decreased by more than eighty percent.

Fraud Management Accounting and Organizational Value Creation: Evidence from Listed Firms in Thailand

  • PHORNLAPHATRACHAKORN, Kornchai
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.8 no.7
    • /
    • pp.457-468
    • /
    • 2021
  • This study seeks to examine the effects of fraud management accounting on organizational value creation of listed firms in Thailand through internal audit function and internal audit effectiveness as the mediators of the study. In addition, governance culture and digital capability are hypothesized to affect fraud management accounting, internal audit function, and internal audit effectiveness. The 297 listed firms in Thailand are the samples of the study. The structural equation model is applied to test the research relationships. The results of the study indicate that, firstly, fraud management accounting has an effect on internal audit function, internal audit effectiveness, and organizational value creation. Secondly, internal audit function affects both internal audit effectiveness and organizational value creation. It also mediates the fraud management accounting-organizational value creation relationships. Thirdly, internal audit effectiveness affects organizational value creation and it mediates the fraud management accounting-organizational value creation relationships. Finally, governance culture affects fraud management accounting, internal audit function and internal audit effectiveness. Accordingly, executives can support, promote and enhance the applications of fraud management accounting in an organization, and utilize its concepts as the valuable tools in order to create best organizational practices and achieve their business goals in the current and future operations.

Determinants of Voluntary Audit of Small and Medium Sized Enterprises: Evidence from Vietnam

  • HA, Hanh Hong;NGUYEN, Anh Huu
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.7 no.5
    • /
    • pp.41-50
    • /
    • 2020
  • The paper investigates the factors that affect the demand for a voluntary audit of small and medium-sized enterprises (SMEs) in Vietnam. A structured questionnaire survey of 284 SMEs was employed, preceded by in-depth interviews with auditors and SMEs' managers. The research used logistic regression estimator to address econometric issues and to improve the accuracy of the regression coefficients. The results show that the degree of director's view on voluntary audit, related stakeholder, degree of recommendation, and firm size have a statistically significant positive effect on audit decisions of SMEs while degree of audit fee has a statistically significant negative effect, and degree of subjective norm does not affect. This indicated that SMEs are more likely to have an external audit if they have some typical features: it is becoming larger in terms of size, and the directors consider that the audit has a relative benefit outweighing its cost. The research results suggested that Vietnam Government should make a statutory audit of SMEs' financial statements rather than make it an option for SMEs. The auditing firms were also recommended to actively take their audit services to SMEs rather than waiting for the SMEs' managers to contact them for their services.

Design and Implementation of SQL Inspector for Database Audit Using ANTLR (ANTLR를 사용한 데이터베이스 감리용 SQL 검사기의 설계 및 구현)

  • Liu, Chen;Kim, Taewoo;Zheng, Baowei;Yeo, Jeongmo
    • KIPS Transactions on Software and Data Engineering
    • /
    • v.5 no.9
    • /
    • pp.425-432
    • /
    • 2016
  • As the importance of information audit is getting bigger, the public corporations invest many expenses at information system audit to build a high quality system. For this purpose, there are much research to proceed an audit effectively. In database audit works, it could audit utilizing a variety of monitoring tools. However, when auditing SQLs which might be affected to database performance, there are several limits related to SQL audit functionality. For this reason, most existing monitoring tools process based on meta information, it is difficult to proceed SQL audit works if there is no meta data or inaccuracy. Also, it can't detect problems by analysis of SQL's syntax structure. In this paper, we design and implement the SQL Inspector using ANTLR which is applied by syntax analysis technique. The overall conclusion is that the implemented SQL Inspector can work effectively much more than eye-checked way. Finally, The SQL inspector which we proposed can apply much more audit rules by compared with other monitoring tools. We expect the higher stability of information system to apply SQL Inspector from development phase to the operation phase.

Risk Management Functions and Audit Report Lag among Listed Saudi Manufacturing Companies

  • OMER, Waddah Kamal Hassan;ALJAAIDI, Khaled Salmen;AL-MOATAZ, Ehsan Saleh
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.7 no.8
    • /
    • pp.61-67
    • /
    • 2020
  • This paper examines whether the combination of risk management and audit committee functions are associated with audit report lag. Audit report lag is considered an important aspect of the financial reporting. The financial reports are the main source of information for shareholders through which they make their decisions and it assists in reducing the information asymmetry. As the internal control mechanisms substitute the external ones, the internal board committees formed by the board of directors can reduce the audit work and, consequently, reduces the audit report lag. A key committee is the risk management committee. This paper examines whether the combination of risk management and audit committee functions are associated with audit report lag. We posit that a combination of such functions in one committee refereed as audit committee affects the audit report delay. Data were obtained from 198 manufacturing companies listed on the Saudi Stock Exchange (Tadawul) for the years 2016-2018. A pooled OLS regression analysis shows that a combination of risk management and audit committee functions in a stand-alone committee named "audit committee" is associated with longer audit report lag. The outcomes suggest companies should prioritize the establishment of standalone risk management committee with activities separated from those of audit committees.

The Effect of KICPA Audit Proficiency on Discretionary Accruals (한국공인회계사회 감사숙련도가 재량적 발생액에 미치는 영향)

  • Kim, Nam-Hun;Lee, Yong-Kyu
    • Asia-Pacific Journal of Business
    • /
    • v.10 no.4
    • /
    • pp.31-47
    • /
    • 2019
  • The recently revised Act on External Audit has taken effect as of November 2018, where standard audit hour rule is included to enhance the audit quality requiring appropriate audit hour input. It has two issues, one is how much the standard audit hours should be and the other is how to control the auditor proficiency between positions when deciding standard audit hours. This paper focuses on the latter issue and studies if auditor proficiency measured with the KICPA position proficiency weight is economically meaningful and has audit quality implication. The KICPA proficiency weights of partner and junior CPA are 1.2, and 0.4 with senior CPA being 1. The results are as follows. First, we find that the audit proficiency decreases discretionary accruals, the proxy of audit quality. Second, the degree to which the audit proficiency decreases discretionary accruals is pronounced with non-big4 firm. The results imply that the KICPA position proficiency weight reflects auditor experiences which help to improve audit quality.

Determinants of Information Technology Audit Quality: Evidence from Vietnam

  • NGUYEN, Anh Huu;HA, Hanh Hong;NGUYEN, Soa La
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.7 no.4
    • /
    • pp.41-50
    • /
    • 2020
  • The paper aims to investigate auditors, auditing firms and other external factors that affect quality of information technology audit in Vietnam. We conducted 2 types of data collections including direct and on survey. For direct survey, we sent directly to auditors at the training classes organized by State Securities Exchanges Commission. An online survey was established and Google doc link was provided to the Big4 and non-Big4 auditors. We received 138 survey responses in that 90 auditors came from Big4 and 48 auditors from non-Big4 firms. The data are analyzed using a factor analysis and compare means approaches to illustrate the potential IT audit quality factors and identify differences between two groups of auditors. The results show that independence and accounting knowledge and audit skills are the most important factors. And since external auditors perform many assurance services, the independence is critical. The result also shows that the auditors need to have enough competent and professional skills when conducting an audit, especially within an IT environment that requires high quality. The findings suggest a similar pattern of two groups in the context of Vietnam and some factors of auditors and auditing firms appear to have a statistically significant impact on quality of IT audit.

THE RELATIONSHIP BETWEEN THE INFLUENCE FACTORS AND THE AUDITOR′S USE OF EDP AUDIT TECHNIQUES IN KOREAN ACCOUNTING FIRMS

  • Choe, Jong-Min
    • Management Science and Financial Engineering
    • /
    • v.3 no.2
    • /
    • pp.45-70
    • /
    • 1997
  • The objectives of this study are to suggest and empirically prove the relationship model for investigating influence factors on the use of EDP audit techniques, and to identify moderating effects of the task types of EDP audit on the relationships between the influence factors and the use of EDP audit techniques. The results of the empirical test suggested that there are significant (positive or negative) correlations between the use of some EDP audit techniques and the influence factors, such as audit education, auditor's familiarity and age, and effectiveness of the technique, etc. The significant differences in the use of EDP audit techniques were empirically proved in the ratio of audit fees and the audit structure. It was also proved that the relationships between the use of techniques and the influence factors are different according to the task types of EDP audit. This study proposed the technique and the auditor related implications of these findings for the successful fulfilment of EDP audit.

  • PDF

Audit Socialization and Professional Success: Evidence from Thailand

  • PHORNLAPHATRACHAKORN, Kornchai;NA KALASINDHU, Khajit
    • The Journal of Asian Finance, Economics and Business
    • /
    • v.7 no.12
    • /
    • pp.831-843
    • /
    • 2020
  • The objective of this study is to examine the effects of audit socialization and professional commitment on professional success of tax auditors in Thailand through individual learning as the moderator. The specific research questions are: (1) How audit socialization affects professional commitment, (2) How professional commitment influences professional success, and (3) How individual learning moderates the audit socialization-professional commitment relationships, the audit socialization-professional success relationships, and the professional commitment-professional success relationships. This study collected data from 249 tax auditors in Thailand by using questionnaire. To investigate the research relationships, both structural equation model and multiple regression analysis are implemented. Within the research results, audit socialization has a significant positive effect on professional commitment and professional success while professional commitment has an important positive influence on professional success. Similarly, individual learning positively moderates the professional commitment-professional success relationships. In summary, audit socialization is important for auditing professions and it is a key determinant of professional success. Thus, auditors need to pay attention to audit socialization through learning and understanding it and applying its concepts to audit works to increase auditors' professional success, continuous survival and long-term sustainability.

The Model of Information System Operating Audit for the Service Level Agreement (서비스 수준 협약에 따른 정보시스템 운영감리 모형)

  • Lee, Sung-Ho;Choi, Jin-Tak;Kim, Dong-Soo;Kim, Hee-Wan
    • Journal of Digital Convergence
    • /
    • v.10 no.6
    • /
    • pp.71-82
    • /
    • 2012
  • The interest in SLA in accordance with the development of IT outsourcing has increased due to the rapid development of information systems. Moreover, an awareness and necessity for the Information System Operating Audit has increased while an effective IT service management operations for information systems is needed desperately. However, information system operations and maintenance instructions of the National Information Society Agency operates due to the current information system operation, but the experience and the interpretation of the auditor determine the decision in the field. This paper introduces an operating audit model for the efficient management. This model is derived from the Korea Information Society Agency's operating instructions of the Information Systems Audit and their inspection services. The audit checklists were derived from the areas of service planning, service delivery, service support, and service management. Consequently, the operating audit model was proposed, and the suitability of this model was verified by experts' opinions on the survey.