System access hotspots: Are auditors ignoring danger?
Susan Tyson, LuAnn Bean · Journal of Corporate Accounting & Finance · 2005
Abstract A recent survey found that only 54 percent of internal audit departments think information technology general controls are a critical part of complying with Sarbanes‐Oxley (SOX) Section 404. But management can't determine how effective its internal controls are without an in‐depth investigation of systems access security. Some internal auditors may be ignoring a lurking danger. So, the authors give detailed advice on how to secure hazardous system access hotspots. © 2005 Wiley Periodicals, Inc.