CMIS 455 Assignment 3
Cameron Cross ID # 3310097
Part 1 Short Answer
Question 1
a) SAS stands for “Statements of Auditing Standards” and SAS No.99 involves what the auditors are
required to do in terms of the consideration of fraud in an audit of financial statements. There
are several responsibilities that SAS No.99 requires auditors to do. They are listed below:
– Understand fraud and know why it is committed
– Auditors must discuss the risk of material misstatements that are fraudulent in nature and
what financial statement areas are susceptible to fraud
– Obtain information by seeking fraud risk factors, performing tests on company records and
discussing with the board of directors, management and the audit team about if previous
fraudulent activities have occurred or if they know of any current fraudulent activities. Revenue
is usually the source of a lot of fraudulent activities, and therefore it is important that extra care
is taken around these accounts
– Information gathered is then used to identify, assess and respond to fraud risks. Auditors
respond to fraud risks by changing the timing, nature, and extend of their audit procedures.
Management override controls should also be considered here
– Evaluate audit test results, by determining materiality, or the impact on financial statements,
as well as if any identified misstatements indicate fraudulent activity
– Communicate and record (or document) their findings to the audit committee and
management
– Requires auditors to take a technology focus because of the impact that technology can have
on fraud risk. SAS requires auditors to recognize this impact and also notes that auditors can use
this technology to design auditing procedures with a fraud focus
b) Computer fraud is basically when a computer is used to commit fraud. Computer attacks are
basically computer fraud techniques that perpetrators can use. Hackers can use many different
software packages or code to gain access to a company’s information or intellectual property.
Hackers can hijack your computer, essentially taking over control of the computer. They can use
a botnet that can be used to attack systems or even spread malware. Hackers can also use a
DOS (denial of service) attack to crash systems or websites. Companies that are connected to
the internet have a higher risk of these. There is actually a staggering number of computer
attacks and abuse occurring every day. All of these previously laid out computer attack and
abuse techniques all have to do with computer fraud. These computer abuse and attack
techniques can be used by perpetrators to gain access to a companies system (or website or
PC’s etc.…) and then the perpetrator could install a keylogger and then be able to record
employee passwords and then have unrestricted access to company files. Computer attack and
abuse techniques essentially help perpetrators commit computer fraud. There is a vast selection
of computer attack and abuse techniques that perpetrators can use to assist with committing
fraud that I have not mentioned.
c) COBIT 5 is the most recent framework and describes effective management and governance of
information technology practices. This means that it takes an information technology approach
that helps organizations achieve their objectives utilizing information technology. COBIT 5
includes four main domains; APO (align, plan and organize), BAI (build, acquire, and implement),
DSS (Deliver, Service, Support), MEA (monitor, evaluate and assess). COSO stands for Committee
of Sponsoring Organizations and is a private sector group that issued Internal Control
Integrated Framework. COSO’s integrated framework is also an internal control framework that
has a more integrated internal control focus. This has become widely accepted as the authority
on internal controls. Companies often try to incorporate these rules, regulations and policies to
help provide controls over business activities. COSO’s Integrated Framework includes five main
components. These components are; Control Environment, Risk Assessment, Control Activities,
Information and Communication and Monitoring. Given the more recent pressures for
companies to analyze risk and develop risk management strategies, COSO also introduced COSO
ERM (Enterprise Risk Management) Framework. COSO’s ERM framework is best described with
the aid of a picture.
(Romney, 01/2014, p. 195)
This cube represents an organization as a whole and assesses the various metrics on the
front of the cube (Internal Environment, Objective setting…) against each business unit (right
side of the cube) The important part about this framework is that it has an entirely risk focused
approach. The top of the cube helps to break down risk into categories to more easily be able to
assess the risk. This cube greatly simplifies the company procedures to assess risk because it
provides a much more guided approach. A company can measure the risk level for reporting in a
certain division by completing the assessments on the front of the cube.
Now that we understand what each of the three frameworks are, we can discuss their
similarities and differences. As for similarities, they are all frameworks that assist companies
achieve their objectives (including legislative and legal requirements). All three are frameworks
that assist in providing a more structured approach to assist with meeting requirements or
objectives. They can all be used together to help the firm achieve all of its objectives. Each
framework can pretty much be considered a layer. The main similarity is that they are all
frameworks to assist the company in achieving some sort of organizational objective.
The main differences between them are their focuses. COSO mainly focuses on
enhancing internal controls and to deter fraud. COBIT focuses on assisting organizations achieve
objectives with and about information technology.
d) Embedded audit modules are