课程: Building a Data-Driven Audit

免费学习该课程!

今天就开通帐号,24,700 门业界名师课程任您挑!

Fieldwork and access controls

Fieldwork and access controls

- Let's add to our Zulily.com example from the last video. The employee was able to steal about $260,000 in electronic payments and more than $40,000 in merchandise by specifically making several changes to the e-commerce system's software code. These changes accomplished three separate tasks. One, it diverted the shipping charges on customer purchases to a personal account. Two, it double charged some customers for shipping, and three, it allowed for the purchase of merchandise for pennies on the dollar. The fraudster was able to change this code because part of their job required them to have access to this system's code for testing purposes. This is a good segue to our next topic: Access Controls. The main objective of access controls is to manage who has access to the resources and data within an organization. Employees should only have access to things that are needed to complete the required tasks for their role and nothing more. Access control audits are important to help…

内容