Computer System Audits: Bread Crumbs or Blazed Trees

Year
1992
Author(s)
W. Lee Zaugg - Wackenhut Services, Inc.
Abstract
When an auditor approaches your computer system to follow the data trail, has the path been marked with Hansel and Gretel-like \"bread crumbs\" which may have been devoured, crushed beyond identity, or blown away, or does the path have clearly \"blazed trees\" which unmistakably lead to the right \"destination?\" This paper addresses topics which previously may have escaped your attention, but which will definitely improve your chances of surviving an audit. For example, unless the entire data flow in your system can be followed (even reconstructed), then significant doubt exists as to the validity of the data. Therefore, the clearer the audit trail, the fewer the questions from your auditor, and the less time you will have to spend recreating transactions or writing lengthy explanations in answer to audit findings. So will it be TRAILS or TALES? Having well-marked \"trails\" will eliminate many horror \"tales.\"