| PLEX86 | ||
SarbanesOxleyChris Mason my claim was that much of the audit paradigm is looking for inconsistencies ... and that if the auditor is only looking at information coming from a single source .... say the corporate IT operation ... then a reasonably intelligent fraud operation can leverage the IT operation to guarantee that all the information looked at by the auditors are consistent. frequently, a basic security premise is multiple independent operations. Corporate IT operation can collapsed everything into a single operation ... which can be leveraged to invalidate basic auditing buttumptions. MORE of the same, single stuff ... isn't going to create multiple, independent operations (corporate IT operation can be leveraged to generate as much as needed). there has been some claims that this inherit flaw in the current auditing operations is somewhat implicitly recognized ... and that is why sarbanes-oxley also has the section on informants (hoping that other sources of information will come forward that can highlight inconsistencies via other means). Value of an old IBM PS2 CL57 SX Laptop 3328 somewhat related blog https:--www.financialcryptography.com-mt-archives-000711.html to some extent paypal was providing online... any implicit buttumption about independent information sources as part of auditing paradigm (looking for inconsistencies) ... might also imply that audit would have to find other methods of coming up with independent information sources. for instance if one corporation lists operations with another corporation ... that the information from all corporations involved in such interactions might need to be validated for consistency. however, that somewhat is a change to the current auditing paradigm.
|
||||
Value of an old IBM PS2 CL57 SX Laptop 3328 Alt Folklore Computers from Newsgroups The #1 Usenet Provider on the Internet
|
||||