CMIS 455 – Assignment 3
Cameron Cross – ID # 3310097
Part 1 – Short Answer
Question 1
a) SAS stands for “Statements of Auditing Standards” and SAS No.99 involves what the auditors are
required to do in terms of the consideration of fraud in an audit of financial statements. There
are several responsibilities that SAS No.99 requires auditors to do. They are listed below:
– Understand fraud and know why it is committed
– Auditors must discuss the risk of material misstatements that are fraudulent in nature and
what financial statement areas are susceptible to fraud
– Obtain information by seeking fraud risk factors, performing tests on company records and
discussing with the board of directors, management and the audit team about if previous
fraudulent activities have occurred or if they know of any current fraudulent activities. Revenue
is usually the source of a lot of fraudulent activities, and therefore it is important that extra care
is taken around these accounts
– Information gathered is then used to identify, assess and respond to fraud risks. Auditors
respond to fraud risks by changing the timing, nature, and extend of their audit procedures.
Management override controls should also be considered here
– Evaluate audit test results, by determining materiality, or the impact on financial statements,
as well as if any identified misstatements indicate fraudulent activity
– Communicate and record (or document) their findings to the audit committee and
management
– Requires auditors to take a technology focus because of the impact that technology can have
on fraud risk. SAS requires auditors to recognize this impact and also notes that auditors can use
this technology to design auditing procedures with a fraud focus
b) Computer fraud is basically when a computer is used to commit fraud. Computer attacks are
basically computer fraud techniques that perpetrators can use. Hackers can use many different
software packages or code to gain access to a company’s information or intellectual property.
Hackers can hijack your computer, essentially taking over control of the computer. They can use
a botnet that can be used to attack systems or even spread malware. Hackers can also use a
DOS (denial of service) attack to crash systems or websites. Companies that are connected to
the internet have a higher risk of these. There is actually a staggering number of computer
attacks and abuse occurring every day. All of these previously laid out computer attack and