Exam 17: IT Controls : Systems Development Program Changes and Application Controls
When using the test data method,the presence of multiple error messages indicates a flaw in the preparation of test transactions.
False
Which of the following is an input control?
A
Contrast the black box approach to IT auditing and the white box approach.Which is preferred?
The black box approach is not concerned with the application's internal workings.The auditor examines documentation of the system,interviews personnel,and bases the evaluation on the logical consistency between input and output.This method is often referred to as "auditing-around-the-computer" because there is no examination of data as it is processed.The white box approach,also called "auditing-through-the-computer," relies on knowledge of the internal workings of the systems and actually tests the application in action with test data having known results.Several white box techniques are available.These include the test data method,base case evaluation,tracing,the integrated test facility,and parallel simulation.This method makes the computer a tool of the audit as well as its target.
Input controls are intended to detect errors in transaction data after processing.
What control issue is related to reentering corrected error records into a batch processing system? What are the two methods for doing this?
Explain how application version numbers can be used as a audit toll for assessing program change controls.
Tracing is a method used to verify the logical operations executed by a computer application.
An inventory record indicates that 12 items of a specific product are on hand.A customer purchased two of the items,but when recording the order,the data entry clerk mistakenly entered 20 items sold.Which check could detect this error?
A computer operator was in a hurry and accidentally used the wrong master file to process a transaction file.As a result,the accounts receivable master file was erased.Which control would prevent this from happening?
The white box tests of program controls are also known as auditing through the computer.
The results of a parallel simulation are compared to the results of a production run in order to judge the quality of the application processes and controls.
Which of the following is an example of an input error correction technique?
Define each of the following input controls and give an example of how they may be used:
a.Missing data check
b.Numeric/alphabetic data check
c.Limit check
d.Range check
e.Reasonableness check
f.Validity check
Auditors do not rely on detailed knowledge of the application's internal logic when they use the __________________________ approach to auditing computer applications.
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)