History of information technology auditing
Encyclopedia
Information Technology
Information technology
Information technology is the acquisition, processing, storage and dissemination of vocal, pictorial, textual and numerical information by a microelectronics-based combination of computing and telecommunications...

 Auditing (IT auditing) began as Electronic Data Process
Electronic data processing
Electronic Data Processing can refer to the use of automated methods to process commercial data. Typically, this uses relatively simple, repetitive activities to process large volumes of similar information...

 (EDP) Auditing and developed largely as a result of the rise in technology in accounting systems
Accounting software
Accounting software is application software that records and processes accounting transactions within functional modules such as accounts payable, accounts receivable, payroll, and trial balance. It functions as an accounting information system...

, the need for IT control, and the impact of computers on the ability to perform attestation services. The last few years have been an exciting time in the world of IT auditing as a result of the accounting scandals and increased regulation. IT auditing has had a relatively short yet rich history when compared to auditing as a whole and remains an ever changing field.

The introduction of computer technology into accounting systems changed the way data
Data
The term data refers to qualitative or quantitative attributes of a variable or set of variables. Data are typically the results of measurements and can be the basis of graphs, images, or observations of a set of variables. Data are often viewed as the lowest level of abstraction from which...

 was stored, retrieved and controlled. It is believed that the first use of a computerized accounting system was at General Electric
General Electric
General Electric Company , or GE, is an American multinational conglomerate corporation incorporated in Schenectady, New York and headquartered in Fairfield, Connecticut, United States...

 in 1954. During the time period of 1954 to the mid-1960s, the auditing profession was still auditing around the computer. At this time only mainframe computer
Mainframe computer
Mainframes are powerful computers used primarily by corporate and governmental organizations for critical applications, bulk data processing such as census, industry and consumer statistics, enterprise resource planning, and financial transaction processing.The term originally referred to the...

s were used and few people had the skills and abilities to program computers
Computer programming
Computer programming is the process of designing, writing, testing, debugging, and maintaining the source code of computer programs. This source code is written in one or more programming languages. The purpose of programming is to create a program that performs specific operations or exhibits a...

. This began to change in the mid-1960s with the introduction of new, smaller and less expensive machines. This increased the use of computers in businesses and with it came the need for auditors to become familiar with EDP concepts in business
Business
A business is an organization engaged in the trade of goods, services, or both to consumers. Businesses are predominant in capitalist economies, where most of them are privately owned and administered to earn profit to increase the wealth of their owners. Businesses may also be not-for-profit...

. Along with the increase in computer use, came the rise of different types of accounting systems. The industry soon realized that they needed to develop their own software and the first of the generalized audit software (GAS) was developed. In 1968, the American Institute of Certified Public Accountants
American Institute of Certified Public Accountants
Founded in 1887, the American Institute of Certified Public Accountants is the national professional organization of Certified Public Accountants in the United States, with more than 370,000 CPA members in 128 countries in business and industry, public practice, government, education, student...

 (AICPA) had the Big Eight (now the Big Four
Big Four auditors
The Big Four are the four largest international professional services networks in accountancy and professional services, which handle the vast majority of audits for publicly traded companies as well as many private companies, creating an oligopoly in auditing large companies...

) accounting firms participate in the development of EDP auditing. The result of this was the release of Auditing & EDP. The book included how to document EDP audits and examples of how to process internal control reviews.

Around this time EDP auditors formed the Electronic Data Processing Auditors Association (EDPAA). The goal of the association was to produce guidelines, procedures and standards for EDP audits. In 1977, the first edition of Control Objectives was published. This publication is now known as Control Objectives for Information and related Technology
COBIT
COBIT is a framework created by ISACA for information technology management and IT Governance. It is a supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks.-Overview:...

 (CobiT). CobiT is the set of generally accepted IT control objectives for IT auditors. In 1994, EDPAA changed its name to Information Systems Audit and Control Association (ISACA). The period from the late 1960s through today has seen rapid changes in technology from the microcomputer
Microcomputer
A microcomputer is a computer with a microprocessor as its central processing unit. They are physically small compared to mainframe and minicomputers...

 and networking
Computer network
A computer network, often simply referred to as a network, is a collection of hardware components and computers interconnected by communication channels that allow sharing of resources and information....

 to the internet
Internet
The Internet is a global system of interconnected computer networks that use the standard Internet protocol suite to serve billions of users worldwide...

 and with these changes came some major events that change IT auditing forever.

The formation and rise in popularity of the Internet and E-commerce have had significant influences on the growth of IT audit. The Internet influences the lives of most of the world and is a place of increased business, entertainment and crime. IT auditing helps organizations and individuals on the Internet find security while helping commerce and communications to flourish.

Major Events

There are five major events in U.S. history which have had significant impact on the growth of IT auditing. These are the Equity Funding scandal, the development of the Internet and E-commerce, the 1998 IT failure at AT&T
AT&T
AT&T Inc. is an American multinational telecommunications corporation headquartered in Whitacre Tower, Dallas, Texas, United States. It is the largest provider of mobile telephony and fixed telephony in the United States, and is also a provider of broadband and subscription television services...

, the Enron
Enron
Enron Corporation was an American energy, commodities, and services company based in Houston, Texas. Before its bankruptcy on December 2, 2001, Enron employed approximately 22,000 staff and was one of the world's leading electricity, natural gas, communications, and pulp and paper companies, with...

 and Arthur Andersen LLP
Arthur Andersen
Arthur Andersen LLP, based in Chicago, was once one of the "Big Five" accounting firms among PricewaterhouseCoopers, Deloitte Touche Tohmatsu, Ernst & Young and KPMG, providing auditing, tax, and consulting services to large corporations...

 scandal, and the September 11, 2001 Attacks
September 11, 2001 attacks
The September 11 attacks The September 11 attacks The September 11 attacks (also referred to as September 11, September 11th or 9/119/11 is pronounced "nine eleven". The slash is not part of the pronunciation...

.

These events have not only heightened the need for more reliable, accurate, and secure systems but have brought a much needed focus to the importance of the accounting profession. Accountants certify the accuracy of public company financial statements
Financial statements
A financial statement is a formal record of the financial activities of a business, person, or other entity. In British English—including United Kingdom company law—a financial statement is often referred to as an account, although the term financial statement is also used, particularly by...

 and add confidence to financial markets. The heightened focus on the industry has brought improved control and higher standards for all working in accounting, especially those involved in IT auditing.

Equity Funding Corporation of America

The first known case of misuse of information technology
Information technology
Information technology is the acquisition, processing, storage and dissemination of vocal, pictorial, textual and numerical information by a microelectronics-based combination of computing and telecommunications...

 occurred at Equity Funding Corporation of America
Equity Funding
Equity Funding Corporation of America was a Los Angeles-based U.S. financial conglomerate that marketed a package of mutual funds and life insurance to private individuals in the 1960s and 70s...

. Beginning in 1964 and continuing on until 1973, managers for the company booked false insurance policies to show greater profits
Profit (accounting)
In accounting, profit can be considered to be the difference between the purchase price and the costs of bringing to market whatever it is that is accounted as an enterprise in terms of the component costs of delivered goods and/or services and any operating or other expenses.-Definition:There are...

, thus boosting the price of the stock
Stock
The capital stock of a business entity represents the original capital paid into or invested in the business by its founders. It serves as a security for the creditors of a business since it cannot be withdrawn to the detriment of the creditors...

 of the company. If it wasn't for a whistle blower, the fraud may have never been caught. After the fraud
Fraud
In criminal law, a fraud is an intentional deception made for personal gain or to damage another individual; the related adjective is fraudulent. The specific legal definition varies by legal jurisdiction. Fraud is a crime, and also a civil law violation...

 was discovered, it took the auditing firm Touche Ross
Deloitte Touche Tohmatsu
Deloitte Touche Tohmatsu Limited , commonly referred to as Deloitte, is one of the Big Four accountancy firms along with PricewaterhouseCoopers , Ernst & Young, and KPMG....

 two years to confirm that the insurance policies were not real. This was one of the first cases where auditors had to audit through the computer rather than around the computer.

AT&T

In 1998 AT&T suffered an IT failure that impacted worldwide  major switch failed due to software and procedural errors and left many credit card
Credit card
A credit card is a small plastic card issued to users as a system of payment. It allows its holder to buy goods and services based on the holder's promise to pay for these goods and services...

 users unable to access funds for upwards this bring to the forefront our reliance in IT services and remind us of the need for assurance in our computer systems.

Enron and Arthur Andersen

The Enron and Arthur Andersen LLP scandal led to the demise of a foremost Accounting firm, an investor
Investor
An investor is a party that makes an investment into one or more categories of assets --- equity, debt securities, real estate, currency, commodity, derivatives such as put and call options, etc...

 loss of more than 60 billion dollars and the largest bankruptcy
Bankruptcy
Bankruptcy is a legal status of an insolvent person or an organisation, that is, one that cannot repay the debts owed to creditors. In most jurisdictions bankruptcy is imposed by a court order, often initiated by the debtor....

 in U.S. history. Arthur Andersen was recently found guilty of obstruction of justice
Obstruction of justice
The crime of obstruction of justice, in United States jurisdictions, refers to the crime of interfering with the work of police, investigators, regulatory agencies, prosecutors, or other officials...

 for their role in the collapse of the energy giant. This scandal had a significant impact on the Sarbanes-Oxley Act
Sarbanes-Oxley Act
The Sarbanes–Oxley Act of 2002 , also known as the 'Public Company Accounting Reform and Investor Protection Act' and 'Corporate and Auditing Accountability and Responsibility Act' and commonly called Sarbanes–Oxley, Sarbox or SOX, is a United States federal law enacted on July 30, 2002, which...

and was a major self-regulation violation.

External links

The source of this article is wikipedia, the free encyclopedia.  The text of this article is licensed under the GFDL.
 
x
OK