Information Systems Audit Report: Departmental Findings and Analysis

Verified

Added on  2022/12/22

|11
|3438
|93
Report
AI Summary
This Information Systems Audit Report presents an in-depth analysis of five WA organizations: the Department of Health, the Department of Mines, Industry Regulation and Safety, the Office of State Revenue, the Western Australian Electoral Commission, and the Key Start Housing Scheme Trust. The report evaluates each organization's information systems, focusing on data security, system vulnerabilities, and operational efficiency. The audit identifies critical findings, including deficiencies in data access controls, password management, system backups, and adherence to data privacy regulations. Specific issues highlighted include blurred decision-making in the Department of Health's system, deficient accession controls in the Department of Mines, Industry Regulation and Safety, and vulnerability in the Office of State Revenue's data systems. The report also addresses the Western Australian Electoral Commission's security failures and the Key Start Housing Scheme Trust's vulnerabilities. The report discusses the professional, legal, and ethical responsibilities of an IT Auditor. The report concludes with recommendations for improving data security, enhancing system reliability, and optimizing operational processes to mitigate risks and ensure compliance. This report is a valuable resource for understanding the challenges and best practices in information systems auditing and IT governance within the context of these specific organizations.
Document Page
Information Systems
Audit Report
tabler-icon-diamond-filled.svg

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
Table of Contents
Identify the audit focus and scope...................................................................................................1
Describe audit findings in the Department of Health......................................................................2
Describe audit findings in the Department of Mines, Industry Regulation and Safety...................3
Describe audit findings in the Office of State Revenue...................................................................4
Describe audit findings in the Western Australian Electoral Commission......................................5
Describe audit findings in the Key Start Housing Scheme Trust....................................................6
Discuss the professional, legal, and ethical responsibilities of an IT Auditor.................................7
References:.......................................................................................................................................8
Document Page
Identify the audit focus and scope
Basic professional applications at 5 organisations are reviewed. Each presentation is
essential to the management of the organisation and might impact investors, with the
community, if the presentation and associated procedures are not operated properly.
The 5 organisation presentations studied were: Patient Remedial Record Structure –
Branch of Well-being, Occupancy Pledges Administration Structure – Branch of Mines,
Business Guideline and Security, Primary Homebased Proprietor Allowance Virtual
Structure – Workplace of Public Income, Voting Administration Structure WA – Western
Australian Voting Instruction, Key smart Structure – Key start Housing Structure Belief
(Hanes, Chee, Mutch and Cherian, 2019).
Presentation evaluations appeared at the organized dealing out and management of
information in the next classifications: Strategies and measures – are proper and assist
dependable dealing out of data, Safety of delicate data – controls occur to guarantee
unity, privacy and accessibility of data at all periods, Information input – data recorded is
correct, absolute and sanctioned, Hold-up and retrieval – is proper and in location in the
case of a hardship, Information output – virtual or hard print information are correct and
absolute, Information dealing out – data is treated as planned, in an accepted period,
Separation of responsibilities – no workforce execute or can execute clashing work,
Audit track – Administered over dealings journals guarantee past is correct and absolute,
Master file care, boundary administered, information formulation managed over
information formulation, aggregation and dealing out of beginning booklets guarantee
data is correct, absolute and punctual earlier the information reach out the presentation.
Experimentation of the upstairs classifications of management is a component in period
measure. It is dependent on an illustration of key management and procedures that are
planned to acquire sensible confidence around whether the presentation works as
conscious and that the data it comprises and records is dependable, approachable and
barred. Experimentation of some of those administration might highlight failing in their
designing or execution that rises the hazard that the presentation’s data might be allergic
to cooperate. Nevertheless, test is not designed to particularly find out whether data has
remained cooperated (Baker, Kessler, Kaiser and Smith, 2019).
1
Document Page
Describe audit findings in the Department of Health
Various Western Australian hospitals uses application such as patient medication report
structure to formulate patient medication reports virtually addressable. This system
captures delicate data such as patient identification and surgical reports.
A minor amount of hospitals diagonally the Well-being structure use the system. It is
utilized to make over automated advancement records throughout work and to picture
broadsheet surgical reports and capture them, naturally at the last of a patient’s incident
of work. The Branch of Investment secure the system in place of the DoH. The seller was
granted a declaration for only above $20 million in overall in 2013. The declaration was
for the first five-year time dated with two choices to widen for an entire of additional five
years. The acquisition program declared the awaited targets of the structure were to: cut
down trust on and expenditure of keeping an appropriate report, surge patient condition
by rendering fast coincident accession to surgical records, streamline enterprise
procedures by introducing more economic record acquiring practices. The system has
been provided to varied level at hospitals diagonally the Public containing Bunbury,
Busselton, Royal Perth, Fremantle and Fiona Stanley Hospital. Well-being Care Facilities
renders the substructure to assist the system across all hospices (Beament, Ewens, Wilcox
and Reid, 2018).
Blurred decision-making and deficiency in digitization scheme has affected the execution
of the system, absence of proper declaration administration means the DoH cannot be
definite if it is on plan and acquiring what it cashed for automatic procedures could
cooperate the economic use of the Application and weak data safety controls place
delicate records at hazard of improper accession and misuse.
The Department of Health (DoH) is still to determine if all medication well-being reports
will be figured across Western Australia. This has affected the composition of foreseen
effective additions and enhancements in patient work reports across the Well-being
structure from the execution of the system. Miserable declaration administration means
the DoH don’t know if the seller is efficaciously conveying the system and how it is
following in contradiction of the $20 million declaration. To generate amply advised
judgement around its forthcoming use the DoH necessarily to realize the entire
expenditure of supplying the system. The system permits workers to capture and
2
tabler-icon-diamond-filled.svg

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
accession medication reports for patients. Nevertheless, there are different administration
problems, containing automatic workarounds and captured boundaries, that resulted to
uneconomical utilise of the system. Safety exposure also have the possibilities to picture
private patient data to improper accession and misappropriation (Allan, 2019).
Describe audit findings in the Department of Mines, Industry Regulation and
Safety
The Tenancy Bonds Management System (TBMS) is utilised by the Branch of Mines,
Business Rule and Security (DMIRS) to handle the dealing out of inhabited and lengthy
stay occupancy pledges. The application captures private data containing respective
driver’s authorisation and finance information.
A safety bond is a direct expense made by an occupant to refuge any pending charges at
the termination of an occupancy. The bond is detained in reliance by the Bond manager,
which is DMIRS. To execute this purpose, DMIRS utilises the TBMS to hold back an
appropriate relationship and dealings reports as needed underneath the Residential
Tenancies Act 1987. Bonds can be stuck with DMIRS, by posting, emailing or an
individual. DMIRS utilises the TBMS to dealing out bond procedures and renders
progress, administration and covering utilities. It is a customised system, formulated and
retained by DMIRS. The TBMS is utilised by certified actual land brokers to interact
bonds utilising the cyberspace gateway, Bonds Online. The Judges Law court also utilises
the application for judicature systematically bond clearances return to the occupant. In
September 2016, it happened compulsory for actual land brokers to gatehouse pledges
utilising Bonds Online (Wright, 2019).
Deficient accession controls addition the hazard of unlicensed access or misuse, safety
exposure are not well handled, leaving TBMS unprotected to attacks, delicate
information is at hazard of vulnerability due to deficient safety controls, deficient
observation means unlicensed accession or alteration may go undiscovered, data
engineering hazards to the TBMS have not been assessed, backup experiment and
upgraded certification is needed to guarantee current and effectual assistance for the
TBMS.
The TBMS aids DMIRS to handle the allegation, fluctuation and removal of occupancy
bonds. Nevertheless, DMIRS’s actual safety management are not effectual in
3
Document Page
safeguarding the privacy, unity and accessibility of the data it captures. Private occupant
data is at hazard of vulnerability because of pathetic code word, deficient operator
governance and miserable information governance activities. Application reliability is
also at hazard because of lacking application upgrades, deficient circumstance
observation, deficiency of hazard measurements and outdated system assist certification.
Data allocation with 3rd person is not safe, which is 1st elevated with DMIRS in 2016.
This additions the hazard of unlicensed accession to private data and necessarily to be
examined (McCLEAN, Cross and Reed, 2021).
Describe audit findings in the Office of State Revenue
The First Home Owner Grant Online application (FHOG Online) is utilised by the Office
of State Revenue (OSR) to render a once-in-a-lifetime cost for worthy primary
homebased proprietors who are purchasing or structuring a fresh resident. The system
incorporates private individual data about grant appliers, considering bank account
information.
The OSR is an enterprise component of the Branch of Investment. It manages gross
legislations and permits or allow strategy, containing the FHOG. The FHOG helps
worthy primary resident proprietors to purchase or develop a homebased holdings as their
chief location of house. The allow procedure is a common duty amongst the OSR and the
Branch of Funds. OSR acquires systems and evaluates worthiness for permissions. Funds
is accountable for spending the currency to worthy allow appliers. FHOG systems can be
deposited via sanctioned brokers or straight with the OSR. Systems are transcribed and
administered in the FHOG digital application. The application was formulated and is
well-kept by a 3rd person seller. In 2016-17, near 15,630 permitted systems were
transcribed and administered in FHOG digitally (Burns, Hendriks, Mayberry and
Pelliccione, 2019).
Private data is at hazard of unlicensed accession due to deficient safety controls, no
separatism of responsibility increases the hazard of grants being issued unsuitably,
automatic processes are uneconomical and increase the hazard of mistakes, miserable IT
manages to make FHOG digital more compromising to unlicensed accession
The FHOG digital application captures and processes allow systems and expenditures as
4
Document Page
needed. Though it didn’t discover any cases of improper accession or misapplication, private
data, containing applier financial information, is at hazard of vulnerability because of deficient
data safety and casual alteration administration process. There are also extended automatic
procedures which has prepared OSR’s use of the application uneconomical and highlights the
hazard of faults (Davidoss, Wormald and Hinton-Bayre, 2018).
Describe audit findings in the Western Australian Electoral Commission
The Election Management System WA (EMSWA) is utilised by the Western Australian
Electoral Commission (WAEC) to handle voting associated data. This reckons EMSWA
capturing a digital voting reel and transcription and tally ballots for Public overall votes. The
application captures elector private data like address, title, contact number and birth day.
The WAEC targets to give all Western Australians with approachable, economical and
advanced superiority election and registration facilities. It is accountable for holding back
the Country’s voting reel and management of governmental appointments, native
administration appointments and some additional enactment and non-statutory elections.
WAEC also boost society knowingness of the election procedures. In the National overall
voting on 11 March 2017, there were 1,593,222 individuals registered to ballot and
1,411,829 ballots were calculated. Accomplished vote paper data was transcribed and
prepared via EMSWA, which is formulated and well-kept by WAEC (Atkinson, 2019).
Safety failing additions the hazard of improper accession and misuse of voter private
data, WAEC doesn’t have registered procedures to retrieve the EMSWA succeeding a
leading incidental or interruption, WAEC doesn’t have knowledge whether improper or
unlicensed alteration are successful to the EMSWA data, automatic processes are
uneconomical and addition the hazard of faults in the EMSWA
The EMSWA system fundamentally accomplishes its aim. However, it discovered an
amount of problems that may cooperates the safety and wholeness of delicate
information, considering voter identification information. While it didn’t discover any
cases of improper accession or mismanagement, private data is at hazard because of
deficient password controls, unencrypted information and minimum following or
observation of alteration made to the information. The accessibility of the system is also
at hazard due to a deficiency of registered and experimented hardship improvement
program. Uneconomical automatic movement of information from another affiliated
5
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
foundation into the EMSWA application might cooperates the wholeness of the data in
the EMSWA application (Southwell, 2019).
Describe audit findings in the Key Start Housing Scheme Trust
Key start Housing Scheme Trust utilises the Key smart system to handle home lend
interrogation, request processing, agent commissions and borrowings. The system
captures private data including debt applier’s evidence of identification, bank account
information, matrimony state and evidence of occupation.
Key start was constituted in 1989 by the Western Australian administration to renders
safe and low-deposit residential debts to Western Australians. Key start allocates,
sanction, carry off and assertion of its homebased credits utilising the Key smart system.
Appliers can deposit their debt system to Key start in individual at an agency place or in a
digital way. They can also utilise an agent, who can get into the borrowings on the
applier’s in place of utilising the Key smart agent portal. Borrowings applications
involves private data such as evidence of identification, fiscal regimes, marital status and
evidence of occupation. Once the debt is ultimate, Key start utilises Key smart to pull off
the existence of the debt and give agent payments as commissions. Sanctioned applicants
can also position their debt state through the Key smart customer portal. The Keys mart
system was build internal. In 2017, it was utilised to prepare a normal of 306 systems and
sanction of almost $62.6 million valuable of borrowings each calendar month
(Alexander, Powell, Deroche and Dougherty, 2019).
Deficient user administration and weak securities additions the hazard of unlicensed
accession to debt data, exposure exist due to deficient constellation of software upgrades
Key smart accomplishes its role, enabling Key start Accommodation Structure Belief to
handle the management of its organization. Nevertheless, to amended defend the
customer's private and credit data, Key start requires to improve the safety of the system.
This considers amended user accession administration, powerful passwords and daily
software upgrades (Nath, Othman and Laswad, 2019).
Discuss the professional, legal, and ethical responsibilities of an IT Auditor
Ethics as moralistic rule leading an individual's action or commercial enterprise practices.
The code of ethics for information technology auditors sets forward four regulation:
6
Document Page
Integrity: Customer anticipate auditors to carry on commercial enterprise principles and
guidance, Objectivity: Auditors must execute employment free from prejudice,
impartiality and self-serving actions, Confidentiality: Auditors should only share data
with sanctioned stakeholders and Competency: Constant occupational evolution
guarantee auditors to stay actual and well-educated.
While ethics incarnate one of the foundation in the vocational obligations of auditors,
they must also match to judicial regulation. They must investigate the evolution of those
regulations in the Securities and Exchange Act of 1933 and find out about particular
legislations and directions in this society of training (Alexander, Georgiou, Siette and
Deroche, 2019).
Certified public accountants (CPAs) in an auditing capability are needed to: Increase the
perceptive of the company and its management, Measure interior control processes and
examine account balances and fiscal dealings.
In public listed institutions are compulsory to employ CPAs to audit their fiscal based on
the Securities and Exchange Act of 1933. Auditors must go for rigorous directions and
procedures and are held responsible for physical faults. They determines three chief
activities that could lend auditors in warm water, they summarised the following:
Producing authorities incorporating false physical information, Excluding physical
information and unsuccessful to consider data to misdirect (Gates, Meyerson, Baysari and
Westbrook, 2019).
The Act of 1933 presents an illustration enactment law, which is national laws. Auditors
must also match state laws and communal legislations or judicial sentiments issued by
magistrates.
7
Document Page
References:
Books and Journals
Alexander, G.L., Georgiou, A., Siette, J. and Deroche, C., 2019. Exploring information
technology (IT) sophistication in New South Wales residential aged care
facilities. Australian Health Review. 44(2). pp.288-296.
Alexander, G.L., Powell, K., Deroche, C.B. and Dougherty, M., 2019. Building consensus
toward a national nursing home information technology maturity model. Journal of the
American Medical Informatics Association. 26(6). pp.495-505.
Allan, S., 2019. The Review of the Western Australian Human Reproductive Technology Act
1991 and the Surrogacy Act 2008 (Part 1). Independent Review of the HRT and
Surrogacy Acts (WA)(Report: Part 1).
Atkinson, J.E.A., 2019. Western Australian Midwives’ Experience and Understanding of
Clinical Supervision (Doctoral dissertation, The University of Western Australia).
Baker, B., Kessler, K., Kaiser, B. and Smith, A., 2019. Non‐traumatic musculoskeletal pain in
Western Australian hospital emergency departments: A clinical audit of the prevalence,
management practices and evidence‐to‐practice gaps. Emergency Medicine
Australasia. 31(6). pp.1037-1044.
Beament, T., Ewens, B., Wilcox, S. and Reid, G., 2018. A collaborative approach to the
implementation of a structured clinical handover tool (iSoBAR), within a hospital
setting in metropolitan Western Australian: A mixed methods study. Nurse education in
practice, 33, pp.107-113.
Burns, S.K., Hendriks, J., Mayberry, L. and Pelliccione, L., 2019. Evaluation of the
implementation of a relationship and sexuality education project in Western Australian
schools: protocol of a multiple, embedded case study. BMJ open. 9(2). p.e026657.
Davidoss, N.H., Wormald, R. and Hinton-Bayre, A., 2018. An 11-year tertiary level audit of
surgical pathology of the parotid in Western Australia. Australian Journal of
Otolaryngology, 1.
Gates, P.J., Meyerson, S.A., Baysari, M.T. and Westbrook, J.I., 2019. The prevalence of dose
errors among paediatric patients in hospital wards with and without health information
technology: a systematic review and meta-analysis. Drug safety. 42(1). pp.13-25.
Hanes, G., Chee, J., Mutch, R. and Cherian, S., 2019. Paediatric asylum seekers in Western
Australia: Identification of adversity and complex needs through comprehensive
refugee health assessment. Journal of paediatrics and child health. 55(11). pp.1367-
1373.
McCLEAN, K.I.M., Cross, M. and Reed, S., 2021. An audit of obesity data and concordance
with diagnostic coding for patients admitted to Western Australian Country Health
Service hospitals. AJAN-The Australian Journal of Advanced Nursing. 38(1).
Nath, N., Othman, R. and Laswad, F., 2019. External performance audit in New Zealand public
health: a legitimacy perspective. Qualitative Research in Accounting & Management.
Southwell, R., 2019. The Steering Towards Readiness Framework: The Lived Experience of
Clinical Facilitators in Identifying, Assessing and Managing Students at Risk of Not
Being Ready to Practice as Beginning Practitioners Within Western Australian Health
Settings.
8
tabler-icon-diamond-filled.svg

Secure Best Marks with AI Grader

Need help grading? Try our AI Grader for instant feedback on your assignments.
Document Page
Wright, M., 2019. Patient involvement in healthcare projects: A mixed method study on the
perspectives of project staff in Western Australian (WA) public hospitals and health
services.
9
chevron_up_icon
1 out of 11
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]