COSO Framework Components Flashcards
S2 M1
serves as the foundation for a company’s risk appetite, helping a company understand the level at which it wants to outsource technology functions
internal environment
management should understand how outsourcing tech functions will help it reach, or potentially hinder, its objectives
objective setting
management must understand how adopting a CSP could make event identification more complex, or easier
event identification
management should understand the risks of its cloud strategy, understanding the impact to its risk profile, inherent & residual risk, & the likelihood of the impact of all risks
risk assessment
management should determine whether its risk response will be to avoid risk, reduce its likelihood, share the risk by transferring a portion of it to another entity, or accept the risk
risk response
the organization should understand how traditional controls (detective, preventative, automated, & manual) & entity-level controls are modified in a cloud environment
control activities
management should understand how operating in the cloud will affect the timeliness, availability, & dissemination of info & communication
information & communication
management should modify its monitoring mechanisms to accommodate new complexities introduced by adopting a cloud solution
monitoring