EDP auditing in the 1980's or the vanishing paper trail

Richard E. Andersen · ACM SIGSAC Review · 1981

This paper is designed to provide an overview of (1) traditional auditing methodology and (2) the reasons why these methods must be modified and adapted in order to cope with the "vanishing paper trail" inherent in today's (and tomorrow's) increasingly on-line, data base-oriented, distributed processing, EDP environment. The three basic types off audits (general, administrative, and applications) will be discussed. Examples of flagrant, and not-so-flagrant, computer crimes will be presented. Practical and proposed solutions for the reduction of these types of DP crimes in the 1980's will be examined. The major thrust of the paper, however, will address the importance of the applications-oriented audit. The paper will discuss the concept of Computer Management Technology (CMT), and show that this is in reality a type of on-going auditing task. Alternatives will be examined for measuring, managing and controlling key functional areas that have a definite interactive effect on the availability of resources and the performance of system components (or both) in a data processing installation.

Read the paper · More papers on PaperTik