Document Type

Thesis

Date of Award

5-31-1983

Degree Name

Master of Science in Industrial Engineering - (M.S.)

Department

Industrial and Management Engineering

First Advisor

James L. Rigassio

Abstract

Criteria Measurement in EDP Auditing is a planning technique to assist the Internal Audit function in systematically selecting software applications for budgeted audit reviews. The objective is to develop a risk analysis method, which is not time and labor intensive, that will minimize risk to the corporation and maximize audit effectiveness. The methodology does not consider probabilities or occurrence rates because risks to the EDP environment are extremely difficult to forecast with traditional techniques. The method provides for both objective and subjective risk determinations.

The approach is to measure software risk criteria for a specific data processing environment. Risk concerns are evaluated and assigned standard weights of importance. The weights are factors used to calculate a risk assessment score for each software application. A comparative analysis of application scores ranks each application by audit priority. Computer applications with the highest score are then budgeted for audit review.

A questionnaire on Criteria Measurement for EDP Applications was developed and distributed to key management of a paper company to solicit their responses for risk concerns. Each respondent was briefed and asked to indicate the relative importance, on a ten point scale, for each of the concerns listed. To provide a common frame of reference, each was asked to consider a typical software application in production at the Corporate Data Center. Responses to the questionnaire were evaluated to determine similar and conflicting concerns and to measure response dispersion. This was accomplished by computing the mean and standard deviation of all numerical responses to each question. The results of the computation were reviewed to measure criteria considered important to the organization and make an initial determination of standard weights. A majority response to the questionnaires indicated similar risk concerns. However, response dispersion to a few questions revealed a need for greater management understanding of risks associated with applications of varying technical complexity.

A Risk Assessment Worksheet was then developed to apply the standard weights to primary areas of concern and introduce subjectivity into the risk analysis. Several software applications were evaluated with the worksheet to examine the effectiveness of assigned weights and total scores. The applications were ranked by score and then compared to acceptable Internal Audit priorities for the applications. Results of the risk assessment showed that the method for assigning initial standard weights to risk criteria within the same operating environment is acceptable in differentiating software exposures to the organization. This method satisfactorily ranked the system applications by audit priority. However, because audit concerns dictate that subjective judgment be used to make a final determination of audit priorities, the technique may not provide a final solution for assigning priorities. The weights assigned to the various areas of concern for the risk assessment may have to be fine tuned to provide a better determination of exposures for all system applications.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.