Sunteți pe pagina 1din 16

Computer-Assisted Audit

Techniques [CAATs]

IT Auditing & Assurance, 2e, Hall &


IT Auditing & Assurance, 2e, Hall & Singleton
Singleton
IT Audit vs Audit Conventional ?
Lembar Kerja Pemeriksaan
Arround The Computer
Contoh:
 Apakah kebijaksanaan pengamanan penggunaan aplikasi telah
memperhatikan prinsip-prinsip umum kontrol aplikasi yang meliputi
:
• Pemisahaan tugas …….antara … pengguna, operasi, dan
pengembangan Y/T
• Penggunaan … hanya …. yang berwenang Y/T
• Menjamin …. data … telah divalidasi Y/T
• Menjamin … data yang ditransfer benar dan lengkap
Y/T
• Tersedianya jejak audit yang memadai serta penelaahan oleh pihak
yang berwenang Y/T
• Tersedianya prosedur restart dan recovery Y/T
CAATs
Karakteristik pemilihan CAATs tools
adalah :

 Ease of use
 Ease of data extraction
 The ability to access a wide variety of data files from
different platforms
 The ability to integrate data with different format
 The ability to define fields and select from standard
formats
 Menu-driven functionality for processing analysis
commands
 Simplified query building and adjustments
 Logging features
What is data?
 Bits and Bytes
 Characters
 ASCII and EBCDIC Characters
 Fields/Data Elements; Records; Files/Tables/Datasets
 Fixed-Length Records vs. Variable-Length Records
 Data is Information

Contoh data file extensions:


.fil, .txt, .dat, .csv, .wks, .xls, .doc, .wpd, .dbf, .mdb, datasets
(mainframe), .db2 (mainframe)
How to Access the Data
• Mainframe: Use data extract utilities (i.e. JCL/SYNCSORT) to access the data and
download it in an ASCII-compatible format for further analysis on your PC.

• Oracle or other relational databases from “mid-range” computers: Run a query (SQL)
to extract the relevant data and copy it down to an ASCII-compatible format. Or, some
database applications, such as Oracle and PeopleSoft, have data extract or reporting utilities
that you can run without the need to ask for assistance from your IS Department (as long as
appropriate levels of access have been granted).

• Data Warehouses/LANs/Microcomputers: Certain ASCII data files may already be readily


available, or queries may be run to obtain the data.

• FTP (File Transfer Protocol): A utility used for transferring data from a “source” system to
your local system/environment.
Tipe data yang diterima ACL adalah :
Audit Command Language (ACL)

Features ACL offers:


Ease of use
Built-in audit and data analysis functionality
Interactive interrogation capabilities
Unlimited file size capability
Ability to read multiple data types
High quality reporting features
The ACL Document
 An ACL document contains
batches, input file definitions,
indexes, views, and
workspaces and their
specified formats. The
computerized data and
information that ACL
analyzes is called a data file.
The data files never change.
The components shown in
the document box below are
the elements that you create
and manipulate
Menu Bar

S-ar putea să vă placă și