Chapter 4 Flashcards

1
Q

Auditing Standard No. 5

A

An audit of internal control of financial reporting that is integrated with an audit of financial statement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

(AICPA) Auditing Standards Board of the American Institute of Cerfied Public Accounts (AICPA)

A

Is an organization that issues and maintains auditing standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

(CVOSO) Committee of Sponsoring Organizations of the Treadway Commission

A

An organization that provides guidance to executive management on organizational governance, internal controls, and risk management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Control Activities

A

Provides the details on how to achieve control objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

(COBIT) Control objectives for information and related technology.

A

A framework providing best practices for IT governance and control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Control Objectives

A

States the high-level organizational goal of information system measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Descriptive control

A

Measures to be applied to a system that are high level and provide a lot of flexibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ERM) Enterprise risk management framework

A

The process organizations use to manage risks related to achieving their goals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Framework

A

A conceptual set of rules and ideas that provide structure to a complex and challenging situation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

(ISMS) Information Security Management System

A

A set of policies governing information security management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

(ITGI) Information Technology Governance Institute

A

A research think tank that provides resources on IT governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Integrated audit

A

An audit that combines the assessment of financial reporting along with the assessment of related IT controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

(IEC) International Electrotechnical Commission

A

An internation, nonprofit organization that publishes global standards on electrotechnology, or all things electronic and electric.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

(ISO) International Organization for Standardization

A

The worlds largest publisher of wordwide standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ISACA

A

A global professional organization that provides resources and guidance around IT governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO/IEC 27002

A

An information security code of practice that provides good practices for information security management.

17
Q

(ITAF) IT ASSURANCE FRAMEWORK

A

A framework for IT assurance, created by ISACA.

18
Q

NIST 800-53

A

Recommended security controls developed by NIST.

19
Q

NIST 800-53A

A

A guide for assessing security controls developed by NIST.

20
Q

(PDCA) PLAN-DO-CHECK-ACT

A

An iterative process for continuous improvement.

21
Q

Prescriptive control

A

Detailed and specific measures to be applied to a system.

22
Q

(RACI) Responsible, accountable, consulted, and informed

A

A table used to document the Responsibility, Accountability, Consulted and informed characteristics for tasks and roles.

23
Q

Risk IT

A

A framework based on guiding principles to effectively manage risk.

24
Q

(SAS 70) Statement on Auditing Standards No. 70: Service Organizations

A

A widely recognized and accepted auditing standard for service organizations.

25
Q

VAL IT

A

A framework that governs IT investments, created by ISACA.