What is the COBIT framework?
What is the COSO framework?
What is the COSO definition of “Internal Controls”?
What is the definition of Control Deficiency (CD)?
What is the definition of Material Weakness (MW)?
What is the definition of Significant Deficiency (SD)?
What SAS No defines the following terms:
(1) Control Deficiency
(2) Material Weakness and
(3) Significant Deficiency
What are 7 key axioms that affect affect the management of controls?
RRECOCD
(1) Controls are responsibility of mgmt.
(2) Controls can only provide reasonable assurance.
(3) There is always possibility of error, even in automated controls.
(4) There is always possibility of circumvention of controls.
(5) There is always possibility of mgmt override of controls.
(6) Control environment changes over time.
(7) Possible that downstream manual controls mitigate IT risk.
What are the 3 general types of Controls?
(1) Manual (human intervention)
(2) Automated (application control)
(3) Hybrid (partly manual and automated aka “IT-dependent”)
What are Manual Controls?
What are Automated Controls?
What are examples of Hybrid Controls?
What are 4 primary processes (Domains) under COBIT?
PO AI DS M
(1) Planning and Organizing (PO)
(2) Acquire and Implement (AI)
(3) Deliver and Support (DS)
(4) Monitor and Evaluate (M)
What is the IT Assurance Framework (ITAF)?
What are 3 components when Scoping an IT Audit?