Chap 7 Information-Technology Risk And Controls Flashcards

1
Q

Information systems (I S) auditor

A

An auditor who works extensively in the area of computerize information systems and has deep I T risk, control, and audit expertise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Database

A

A large depository of data, typically contained in many linked files, and stored in a manner that allows the data to be easily accessed, retrieved, and manipulated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Big data

A

A term used to refer to the large amount of constantly streaming digital information, massive increase in the capacity to store large amounts of data, and the amount of datat processing power required to manage, interpret, and analyze the large volumes of digital information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ERP system

A

A modular software system that enables an organization to integrate its business process using a single operating database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

EDI

A

The computer-to-computer exchange of business documents in electronic form between an organization and it’s trading partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

I T governance

A

The leadership, structure, and oversight processes that ensures the organization’s IT supports the objectives and strategies of the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IT risk management

A

The process conducted by management to understand and handle the IT risks and opportunities that could affect the organization’s ability to achieve its objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IT standards

A

Support IT policies by more specifically defining what is required to achieve the organization’s objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IT organization and management controls

A

Provide assurance that the organization is structured with clearly defined lines of reporting and responsibility and has implemented effective control processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IT physical and environmental controls

A

Protect information system resources from accidental or intentional damage, misuse, or loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Physical access controls

A

Provide security over tangible IT resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Logical access controls

A

Provide security over software and information imbedded in the system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

IT outsourcing

A

Transferring IT functions to an outside provider to achieve cost reductions while improving service quality and efficiency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Integrated auditing

A

IT risk and control assessments are assimilated into assurance engagements conducted to access process-level reporting, operations, and/or compliance risk and controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

GTAG

A

Provides internal auditors with guidance that will help them better understand the governance, risk management, and control issues surrounding IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

GAIT

A

Describes the relationships among financial reporting risks, key process controls, automated controls and other critical IT functionality, and key IT general controls

17
Q

Bring your own device (BYOD)

A

A policy whereby organizations allow associates to access business email, calendars, and other data on their personal laptops, smart phones, tablets, or other devices