Chapter 11 Flashcards

Using IT for Fraud Exam & Fin Forensics (27 cards)

1
Q

What does an informational technology audit consist of:

A
  1. Planning
  2. Test of Controls
  3. Substantive Testing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

General Framework for viewing IT risks and Controls

A
  • IT ops, data management systems
  • New system development & integration
  • system maintenance
  • System back up & Contingency planning
  • Electronic Commerce
  • Control over computer operations
  • Big Data, Data Analytics, Computer aided Audit tools and techniques
  • Application controls,: source docs, data coding, batch, validation, record, examination of application input system
  • Processing Controls: Ensure processed data maintain s integrity as moves withing systems
  • Output controls: Spooling, print programs, monitor waste, identify responsibility
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IT Audits and Asurrance Activs

Black box approach vs White Box Approach

A

Black Box Approach:
- Develop understanding of system
- Test integrity of data & system

White Box Approach:
- System Walk Throughs
- authencity
- accuracy
- completeness
- redundancy
- access audit trail
- rounding error test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Shortcomings w/ IT audits and assurance

A
  • IT personnel can collude to conceal fraud
  • Professiona may susbtitute inapprop versionof software to change data
  • Mus ensure entire control environment is examined
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Shortcomings of Digital Evidence

A
  • Files and docs can easily be given misleading or coded names and words encrypted
  • Hard to get search warrant to gather evidence
  • Must follow warrant details to properly execute and collect valid data
  • Warrant and subpeona required to obtain digital evidence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Benefits of Digital Evidence

A
  • Helps sift through and organize large amounts of evidence - w/ speed and accuracy
  • Electronic imaging
  • Computer forensics
  • Help maintain good work paper
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Tools Commonly used to Gather Digital Evidence

Road Masster & EnCase

A

RoadMasster:
- Portable computer forensic lab
- Acquire and Analyze electronic data
- Preview & image hard drives
- Completely remove & ERase stored files and programs from hard drives

EnCase
- Investigate & analyze electronic data in multiple plateforms
- Identify info despite efforts to hide, cloak, or delete data
- Manage large volumes of computer evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How to recover deleted files?

A

Deleted files are not removed from hard drive
- Until comp reuses space where file resides, the data in the file will remain intact

Defrag command
- reogranize hard drive for more efficient data storage
- may make deleted files unrecoverable

Undelete Software
- Search for clues about location of disk space where deleted file resides
- Examin unallocated disk space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How to recover deleted emails?

A
  • Emails are stored in mail folders
  • Each folder is a sep file

Prior to compaction, deleted emails may be recovered using software

E-discovery rules: require orgs to provide electronic files going back in time
- Probability of detailed email recovery is greatly enhance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Caveats of Restoring Data

A
  • More sophisticated approach
  • restoring lost file under more challenging circumstance
  • Stop Writing to drive to increase recoverability
  • High security or privacy software make harder to restoring files
  • ## Manual restoration may be needed - Cost Benefit Analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Targeted approach for Detection in the Digital Env

A
  1. Examiner should consider more clearly defining the characteristics of data identified as anomolie
  2. May stratify preliminary results to identify subgroups more likely to be of concern
  3. Examiner may determing that a particular data analytics technqiue is not effective and data should examine diff
  4. Risk assessment necessary: identify major concerns and focus points
  5. Scope Limitation: Serve to focus and shape examination

Consider data sources and accuracy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Examples of Data extraction and Analysis Software Function

A
  • Sorting
  • Record selection and extraction
  • Joining files
  • Multifile processing
  • Verify multiples of number
  • Compliance verification
  • Duplicate searches
  • Horizontal and vertical ratio analysis
  • DAte Functions
  • Recalc
  • Transac and balances exceeding expectation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Sales Analysis: Example of Queries

A
  • Report of all system overrides and sales exception
  • Returns and allowances by sotre
  • Summarize trends by customer type, products, sales person
  • Compare sales to outstanding receivables
  • Generate correlation btw demand or supply and sales price
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

General ledger Analysis: Example Queries

A
  1. Select specific journal entries
  2. Actual to budget comp
  3. Analyze and confirm ledger accounts for legit transac
  4. Speed through reconciliation
  5. Calc fin ratio
  6. % ratios btw account

en Ledger analysis: Ex

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cash Disbursement Queries Examples

A
  • Sumamrize cash disbursement by account, bank, dep, and vendor
  • Verify audit trail for all disbursement by purchase order, dep, or vendor
  • Generate vendor cash acativity summary analysis
  • Identify disbusement by dep, supervisor approval, or amnt limits
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Excel Use

A

Staple Analytical and presentation tool
- helps run benfords law test

17
Q

Use of Idea Data Analysis Software

A

Interactive Data Extraction and Analysis
- Generalized audit software
- import diff file formats
- benfords law analuses
- Compare and recalc invoice

18
Q

What is the Audit Control Language tool?

A

Audit analytics and continuous monitoring software
- Ensure int controls compliance
- Investigate and detect fraudulent activity
- Continuous auditing
- indep verification of transactional data
- helps with regulatory compliance
- held secure data access

19
Q

Role of Graphics and Graphics Software in an investigation

A
  1. Investigative tool
  2. Identify holes
  3. Communicate investifative findings, conclusion and Result
20
Q

4 types of graphics software

A
  1. Association matrix
  2. Link Charts
  3. Flow Diagrams
  4. Timeline
21
Q

Use and function of Association Matrix

A
  • Identifies Major Players who are central to an investigation
  • Idenify linkages between players
  • Starting point for reflecting important data in a simplified format
  • Helps investigator visually see important links
22
Q

Use and Function of a Link Chart

A
  • More complex than assoc matrix
  • Graphically represents important relationship between ppl businesses, and orgs
  • Creates graphic rep of known and suspected associations involved in crim activ
23
Q

Use and Function of Flow Diagrams

A

Analyze movement of events, activs and commodities
* Help discover meaning of activs and importance to the investigation

24
Q

Use and Function of Timelines

A

Chronologically organize info about events or activs

  • Helps determine what has or may occur and the impact the actions had
25
Examples of Grphical Software
**Tableau:** data visualization tool enables user to **create interactive visual** analytics in a dash board **Microsoft Visio:** Create simple and complicated diagrams
26
What is Case Management Software?
- Manages case data and organizes in a meaning ful way - Present info for use in reports - Used to initiate investigation
27
Case Management Software Tools | Analyst Notebook i2 Lexis-Nexis CaseMap
Analyst Notebook i2 - Visualize complex schems - Organize and analyze large volumes of seemingly unrelated data -Bring clarity to complex investig, scheme, and scenarios Increase Evidence Management efficieny LexisNexis CaseMap - central repository case knowledge - Organize info, facts, evidence, documents, people , case issues and law - evaluates relationships btw diff atrics of case fo - Timemap: timelines - Textmap: transcription - NoteMap: Outlines - DepPrep: Preparing witnesses