SOC Controls Flashcards

(2 cards)

1
Q

If an associate is allowed to perform a control that they are not competent enough to perform, is this a design flaw, implementation flaw, or operating flaw?

A

DESIGN FLAW.

If the control doesn’t require competent personnel by design, that’s a design flaw

Design flaw: Control doesn’t require or ensure competent personnel.

Operating flaw: Control requires competent personnel, but they don’t perform it properly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In a Type 2 audit, control operating effectiveness is tested over a specific time period - does management’s description of the control system and control design/implementation also have to be tested of the same time period or are they tested as of a point in time like a Type 1 audit?

A

YES

In a Type 2 audit, ALL are tested OVER A SPECIFIED TIME PERIOD, none at a point in time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly