COBIT Flashcards

1
Q

COBIT Control Objectives for Information and RElated Technology
COBIT 5 five key principles

A
Stakeholder Drivers
Stakeholder Needs
   Value Creation 
    Realization of Benefits
    Optimization of Risk
    Optimal Use of Resources
Enterprise Goals
IT-RElated Goals
Enablers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Corbett five COBE IT five

A

COBE IT has five principles
Asserts that value creation is the most basic stakeholder need and that’s the fundamental goal of any enterprise.
Value creation in this model is achieved by balancing three components
Realization of benefits
Optimization which is not minimization of risk optimal use of resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

COBIT 5 What are the 5 Key Principles

A
  1. Meeting stakeholder needs
  2. Covering the Enterprise End to End
  3. Applying a Single Integrated Framework (regardless of hardware and software used)
  4. Enabling a Holistic Approach (enablers)
  5. Separating Governance from Management
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Enabling a Holistic Approach - What are the seven categories of enablers that support comprehensive IT governance and management.

A

Notice they are like the control environment characteristics in COSO

  1. Principles, Policies and Frameworks
  2. Processes
  3. Organizational Structures
  4. Culture, Ethics and Behavior
  5. Information
  6. Services, infrastructure and applications
  7. People, skills and competencies

Last three are classified as resources, the use of which must be optimized

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Of the seven categories of enablers, which are resources that must be optimized

A

Information
Services, Infrastructure and Applications
People, Skills and Competencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SEparating Governance from Management: What are the four responsibility areas that must be addressed

A

Plan
Build
Run
Monitor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Goals for the Information Security Program

A

Confidentiality
Availability
Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Steps to Creating an Information Security Plan

A

Identify Threats
Identify Risks
Design Controls to Compensate
Incorporate the Controls into Coherent, Enterprise-Wide Plan
Set forth Policies So People Are Aware of Expectations, both internal and external users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COBIT 5 - Steps in creating the information security plan. What are the two phases of risk analysis? P. 378

A

Determining the likelihood of risk
Determining the level of damage that good be done

Example: Sabotage could be very damaging but risk is low

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The Depreciation tax shield is?
Cash provided by recording depreciation.
A reduction in income taxes.

A

The answer is a reduction in income taxes.

Though it does contribute to cash flow, I guess the cash isn’t “provided” it’s just shielded from being an outflow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are generic controls.

A

Generic IT controls can be classified in the traditional 3 ways that internal controls are.
Preventive
Detective
Corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Preventative Controls two types

A

Physical and Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Physical Controls are

A

preventative controls (there are two here) the other is logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Logical Controls Are _________ controls

A

There are 2 here the other is physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Physical Preventative Control Example

A

Fences
Locked Doors
Security
Segregation of Duties Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What type of IT control is a segregation of duties policy

A

Physical preventive control (really?) It’s from the Gleim book.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are some examples of logical preventive controls.

A

These are all the input controls listed below. They make sure data is authorized, complete and accurate. There are online input and batch input controls.

Authorization (AP supervisor authorizes batch b4 submitted for recording)
Controls Programmed into the system - also known as edit routines
-Preformatting
Edit (field) checks
Limit (reasonableness) checks and range checks
Validity Checks
Sequence Checks
Closed Loop Verification
Check Digit Verification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Edit Check - Other name for it, type of check

A

Also called field check, input control, preventative

No invalid characters e.g., no letters in social security numbers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Limit Checks, other name, type, example

A

Reasonableness, preventative, input check

Hours worked cannot exceed 80 without authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

VALIDITY CHECKS

type, example

A

Input control, preventative

vendor must be in master file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Sequence Checks type, example

A

input, preventative
sort files on a key before matching
accounts payable transaction file and master filed sorted according to vendor number and should be in order
done before matching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Close-Loop Verifiation type, example

A

Input, Preventive

Sends input back to the computer after processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Check-Digit

Example, other name

A

Self Checking digits
Uses algorithm
used to catch keying errors such as dropped and transposed digits

24
Q

Zero balance checks type, example

A

input, preventative

reject anything where sum of all debits and credits does not equal 0

25
Q

Mutually Exclusive

There was a question that asked for the present value of two projects, what should you watch out for?

A

There was a lot of math figuring out the present value, then it asked which project to take. Both had present values, but if you failed to notice it said mutually exclusive and you could only pick one you’d have got it wrong.

26
Q
What is an internal rate of return?
time adjusted ROR
accounting ROR
payback period
net present value
A

notice that IRR is not a NPV, it’s a rate not a net

27
Q

Advantage of the IRR over the accounting ROR
recognition of salvage VU
emphasis on cash flows
recognition of time value of money

A

hey guess what accounting ROR considers salvage
accounting ROR cares about income, not cash flows so much
time value of money on 2 and 3

28
Q

Who cares about cash flows and who cares about net income.

A

IRR - cash flows

Accounting ROR - net income

29
Q

Formula for Accounting ROR

A

Annual Cash Flow - Depreciation

30
Q

How is salvage value handled in IRR and Accounting ROR

A

IRR discount it back - interesting though, do you discount it back if you figure out the depreciation, depreciation “shield”

Accounting - if you’re figuring the depreciation you take off the salvage value, as far as how ties are handled, I’m not sure

31
Q

Salvage Value
IRR?
Accounting ROR?

A

Yes both

32
Q

Depreciation
IRR
Accounting IRR

A

Yes both
IRR definitely use depreciation shield
Accounting ROR - use salvage to get the annual depreciation and add this to the cash flows

33
Q

ARR is not a cash flow calculation, it’s a net income calculation.
That being the case, I think you use salvage to get the depreciation, but ignore the incom tax effects of the depreciation shield

A

I have to get with this because I can’t get a straight answer out of the examples.

34
Q

Capital Budgeting - Two types of depreciation, one is relevant, other isn’t

A

Tax depreciation is relevant

Book is not

35
Q

Do not spend a lot of time on an accounting ROR question.

Tam is negotiating to purchase equipment that would cost $100,000 and would save $20,000 in after-tax cash costs (what should you notice here). Equipments useful life is 10 years with no residual value and would be depreciated by the straight line method. Accrual accounting ROR is what.

A

It says “after-tax” cash costs, now I would assume that means what you save in total cash after the depreciation is factored into the savings. But it doesn’t, it means we saved this much in cash expenses, but you haven’t considered the extra cost you’re going to have for depreciation on the new machine. So the calculation is:

Hey we have $20,000 less in expenses
But we have $10,000 more in depreciation
So we’re ahead by 10 grand or 10% of the $100,000.

36
Q

You figured out the accounting rate of return, now what do you compare it to.

A

I don’t know, I’m assuming the average cost of capital, or maybe it’s just that it’s positive.

Looks like compare it to company’s book rate of return.

37
Q

The accounting rate of return, why is it bad?

A

They can choose different methods of depreciation.
Comparing it to the company’s book rate is that the book rate is an average return on capital projects which are a combination of good and bad.

38
Q

When doing capital budgeting problems, must take into account not only the extra income, but what else?

A

The extra costs for depreciation.

39
Q

Accounting ROR

A

Average Increade in Accounting NEt INcome
divided by
Required Investment

denominator is not an average

40
Q

Detective Controls Definition

A

Call attention to errors that are already in the system before they cause a negative outcome

And

Call attention to someone trying to get into the system or using the system improperly

41
Q

Detective Controls Examples

A

Examination of Console logs
Examination of System logs (failed login attempts) - not really an error entered into the system now is it
Output Controls: Transaction logs, error listings, record counts, run-to-run totals

42
Q

What are OUtput Controls (other name, Example)

A
Detective Controls
Transaction Log
Error Listing
Record Counts
Run-to-Run Controls
43
Q

Run-to-Run Control. What type is it, what category is it.

A

Detective Output Control

The new financial balance should be the sum of the old balance plus the activity that was just processed.

44
Q

Error Listing - What type/category is it, example.

A

Detective Output Control

Exception report with all the transactions rejected by the system

45
Q

Record Count What Category/Type

A

Detective Output Control

Does the count - the records the user expected to be processed

46
Q

Transaction Log type/category/Example

A

Detective Output Control

Who logged into the application and did what

47
Q

Detective Output Controls Mneumonic

A
TERR2R
Transaction Logs
Error Listings (rejections)
Record Counts
Run-to-Run
48
Q

Distinguish Input From Output Controls - how

A

The input are narrow, specific, this field was entered wrong, this number was transposed, this batch total is wrong

The output are much more general and after the trigger is pulled. I really don’t see why. It’s touch because I just pulled up a slide that says “error reporting and handling is an input control” and the Gleim books says Error listings are output controls.

49
Q

Signatures on Batch forms or source documents
Online access controls
Unique Paswords

All of these are what type of control

A

Input authorization control

50
Q
What are these examples of?
Batch control totals
TOtal monetary items
total items
total documents
hash totals
A

Batch input controls

51
Q

Input, Processing, Output
There are many in the same category, it depends what the timing is
Don’t worry about input, processing, output or if you have to guess use the timing idea

A

If it’s immediate feedback, I’d say it’s an input control
If it’s after it’s entered then it’s a processing
All are built into the system

52
Q

If it’s a validity control it’s ___________, if. it’s a validation control it’s __________

A

Vendor exists

Validity = Input
Validation = Processing

Now how do you remember, I don’t know, validation sounds later?

53
Q

List of Processing Controls

A

Processing
Validation (it’s validity if it’s and input)
Completeness (are all the data there in the record)
Arithmetic (cross footing, zero balance dr and cr’s equal)
Sequence
Run-to-Run (can also be output, again if it occurs at the end it’s output)*
Key Integrity don’t know what this is

*So if you do a run-to-run along to way like check the batch total after each stage of processing then it’s a processing control, if you take the beginning balance, add the activity and check the ending balance it’s an output control

54
Q

Batch Controls Input

A

Management Release
Record Count - Batch is not released for processing until record count agrees
Financial Total - Batch is not released for processing unless total of patch - user calculated
HashTotal - Sum of numeric field - meaningless but shows all records have been entered, sum of SSI number, it says can follow through processing, but I don’t see examples of has totals as anything but input controls

55
Q

Input, Processing, Output 0 how to tell the difference

A

Look for the timing on some of them if before processing, input if during

56
Q

Two broad groups of IT Controls

A

General and Application