COSO Framework Components Flashcards

S2 M1

1
Q

serves as the foundation for a company’s risk appetite, helping a company understand the level at which it wants to outsource technology functions

A

internal environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

management should understand how outsourcing tech functions will help it reach, or potentially hinder, its objectives

A

objective setting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

management must understand how adopting a CSP could make event identification more complex, or easier

A

event identification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

management should understand the risks of its cloud strategy, understanding the impact to its risk profile, inherent & residual risk, & the likelihood of the impact of all risks

A

risk assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

management should determine whether its risk response will be to avoid risk, reduce its likelihood, share the risk by transferring a portion of it to another entity, or accept the risk

A

risk response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

the organization should understand how traditional controls (detective, preventative, automated, & manual) & entity-level controls are modified in a cloud environment

A

control activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

management should understand how operating in the cloud will affect the timeliness, availability, & dissemination of info & communication

A

information & communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

management should modify its monitoring mechanisms to accommodate new complexities introduced by adopting a cloud solution

A

monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly