Question

In: Accounting

You are the technology auditor for a medium size online retailer. With the growth, it has...

You are the technology auditor for a medium size online retailer. With the growth, it has been very difficult for the Information Technology (IT) group to keep up with the hardware requirements and new software for all the various smartphone applications. Although there would be reduction of most of the IT staff the CIO has done a complete analysis of moving to a Cloud Computing solution with Amazon Web Services. With this change, all IT functions for the primary application of customer order processing and fulfillment would be handled through Amazon. The reduction in ongoing costs would be almost fifty percent along with major capital expenditures for upgrades if they were to keep processing in-house. Much of the in-house technology is outdated from a web application and regulatory standpoint.

Amazon Web Services is the largest provider of integrated Cloud Computing Services and offers a complete set of infrastructure and application services. Many organizations have lowered costs, including your competitors allowing them to lower costs and gain market share. One of the key benefits of cloud computing is the opportunity to replace up-front capital infrastructure expenses with low variable costs that scale as the business grows.

You have been asked by senior management to assist with the Amazon project and the evaluation of the controls.

a. Describe the five most significant areas of controls concern that you would like to express to the senior management in the transition to Amazon? Make sure your control concerns are consistent with the facts of the case.

b. How would you propose the organization get comfortable with the controls at Amazon    prior to signing the contract? Be specific.

c. Assuming the contract is signed and processing moves to Amazon, what role can internal auditing play in providing assurance to the company. Let’s assume that internal auditing will not be able to perform on-site audits.

Solutions

Expert Solution

(a) 1. Security of data transfer must be ensured. Make sure your data is travelling from a secure channel. Data should always be encrypted and authenticated.

2. Software interface must be secure. Authentication and access control techniques should be used.

3. Data stored in cloud must be secured. It is the major concern in cloud computing. Cloud providers should be responsible for security of data storage.

4. Access control is another major concern. Access should be provided to an aunthicated person. Cloud provider should establish a proper system to provide aunthicated access.

5. Confidentiality is another area of control.

(b) Organization should signed a written contract with amazon. All these controls should be mentioned in contract agreement. Organization must study of above mentioned controls before signing any agreement.

(c) Role of internal auditor to ensure the three main areas confidentialty, integrity and availability. Auditor must ensure that data is not availabe for unauthorised person. Data must be integrated and should be available when it is needed.  


Related Solutions

You are an auditor of a retailer that operates entirely online and has no physical inventory...
You are an auditor of a retailer that operates entirely online and has no physical inventory on site beyond that necessary to operate. What auditing techniques would you use to check on sales, cost of goods sold, expenses, receivables, and cash? You may use a specific firm as an example.
You are the ISO for a medium size company that works in paper, but not any...
You are the ISO for a medium size company that works in paper, but not any paper but the paper that US dollars are made on. Write an incident flow chart for some catastrophes happening to your company. Include a flow chart based on the situation. You make up the catastrophe, man-made or nature or freak accident.
Imagine that you are an IT manager in a medium-size organization with 200 IT professionals. The...
Imagine that you are an IT manager in a medium-size organization with 200 IT professionals. The CIO has asked you to develop a presentation covering the “top 10 things the IT professional needs to know about IT risk.” Utilizing our course materials and other, solid sources from the web and library, and other course materials you have studied, develop a set of notated presentation slides that cover what your CIO wants. Hint: Start by defining risk and distinguishing it from...
Consider the following independent situations: 1. You are the auditor of Hail Pty Ltd a medium...
Consider the following independent situations: 1. You are the auditor of Hail Pty Ltd a medium sized furniture manufacturer. Your audit firm has finalised the financial statements after the client has substantially prepared the accounting records. However, the client admits to having limited knowledge of identifying and calculating impairment and has asked for your assistance. You have proposed a number of adjustments to account for the impairment of assets. 2. You are the auditor of Travel Time Ltd, a large...
When you order from an online retailer, the data you provide is not protected by US...
When you order from an online retailer, the data you provide is not protected by US privacy law. Does this fact cause you to reconsider setting up an account with a stored credit card number? What is the advantage of storing the credit card number? Do you think the advantage is worth the risk? Are you more willing to take the risk with some companies than with others? If so, state the criteria you use for choosing to take the...
Margaret is a supervisor in the online sales division of a large clothing retailer. She has...
Margaret is a supervisor in the online sales division of a large clothing retailer. She has let it be known that she is devoted to the firm and plans to build her career there. Margaret is hard-working and reliable, has volunteered for extra projects, has taken in-house development courses, and joined a committee dedicated to improving employee safety on the job. She undertook an assignment to research ergonomic office furniture for the head of the department and gave up several...
A small independent book retailer owns a shop and an online web store. The retailer is...
A small independent book retailer owns a shop and an online web store. The retailer is investigating whether there is a difference in purchase behaviour (the type of book purchased) when customers make a purchase in-store compared to buying online. The retailer looks at all the purchases of business, language and fiction books both online and in-store on a randomly selected day. The results are shown in the table belowTable: Number of books purchased online and in-store categorised by book...
You are the manager of a large but privately held online retailer that currently uses 17...
You are the manager of a large but privately held online retailer that currently uses 17 unskilled workers and 6 semiskilled workers at its warehouse to box and ship the products it sells online. Your company pays its unskilled workers the minimum wage but pays the semiskilled workers $12.75 per hour. Thanks to government legislation, the minimum wage in your state will increase from $10.25 per hour to $10.75 per hour on July 24, 2017. Discuss the short-run implications of...
You are a partner in a medium-size CPA firm and want to convince your partners that...
You are a partner in a medium-size CPA firm and want to convince your partners that your firm should update the way it conducts audits in order to become more competitive. Specifically, you believe the company should make use of up-to-date data analytics technology. Write a memo to your partners to explain what data analytics technology is and the advantages to using it. Chapter 10 (From Effective Writing A Handbook for Accountants by May) contains suggestions on memo organization and...
You are a partner in a medium-size CPA firm and want to convince your partners that...
You are a partner in a medium-size CPA firm and want to convince your partners that your firm should update the way it conducts audits in order to become more competitive. Specifically, you believe the company should make use of up-to-date data analytics technology. Write a memo to your partners to explain what data analytics technology is and the advantages to using it.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT