Chapter 1 - SOC PLANNING AND PERFORMING Flashcards

1
Q

What is SOC For Cybersecurity??

A

examination that describes an entity’s cybersecurity risk management program and related controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 5 trust Services categories?

A

Security, Availability, Processing Integrity, Confidentiality, Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is disclosure important for subsequent events?

A

It is required so users of the report are not misled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where is the disclosure presented in the Soc report?

A

in the description of the company’s system or management’s assertion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who determines if Disclosure is needed if there’s a subsequent event? What should Auditor do?

A

The auditor should request that management evaluate the breach and determine if a disclosure is needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who are the intended users of a Soc 1

A

User auditor, user entities, and service org management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does NIST Cybersecurity Framework Profile do?

A

Identifies the outcome a company has prioritized to remediate control gaps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What method does the Subcompany have to provide a Management representation letter? What do they both contain?

A

inclusive not carved out & description of sub companies services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are you called if a company retains responsibility for controls and monitors you?

A

A vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should an auditor do if a subsequent event becomes known?

A

Perform additional procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is used to measure of evaluate managements description of the system?

A

Aicpa dc section 200 description criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is used to measure of evaluate managements description of the system?

A

Aicpa dc section 200 description criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What criteria is used to prove controls were designed, implemented, and operated to provide assurance ?

A

Aicpa TSP section 100 trust services criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does an auditor determine materiality?

A

-Misstatements
-qualitative and quantitative factors
-the circumstances, nature, size, and extent of misstatements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What forms the basis for the auditors opinion of the systems description, control design, and control effectiveness?

A

Managements written representation

17
Q

When is it okay to give a disclaimer of opinion? What do others get if not pervasive?

A

Scope limitation if material and pervasive, if not its a qualified opinion

18
Q

What phase does the auditor obtain a signed management rep letter?

A

Reporting