CPA - IT Flashcards
COBIT focuses on IT controls and is intended for use by IT managers, IT professionals, and internal and external auditors
Enterprise architecture
An organization’s enterprise architecture is its efforts to understand, manage, and plan for IT assets
Enterprise-wide or Enterprise Resource Planning (ERP) systems
ERPs provide transaction processing, mgmt support, and decision-making support in a single, integrated, organization-wide package
Goals of ERP systems
- Global visibility
- cost reductions
- Employee empowerment (improved communcation and decison making)
- “Best practices”
An enterprise resource planning (ERP) system has which of the following advantages over multiple independent functional systems?
Modificaitons can be made to each module w/out affecting other modules
Online transaction processing (OLTP) system
The modules comprising of core business functions: sales, production, purchasing, payroll, financial reporting etc -> think operational data for the eorganization
Online analytical processing (OLAP) system
Incorporates data warehouse and data mining capabilities w/in the ERP
Cloud Delivery Service Models
- Infrastructure as service (IaaS) - Use of the cloud to access a virtual data center of resrouces (e.g. AWS)
- Platform as service (PaaS) - A development environment for creating cloud-based software and program using cloud-based services (Salesforce.com)
- Software as service (SaaS) - Remote access to software (Office 365 etc.)
Good internal control in a computer system requires that operators, programmers, and the library function be segregated.
systems analyst is responsible for designing the computer system, including the goals of the system and means of achieving those goals, based upon the nature of the business and its information needs. The systems analyst also must outline the data processing system for the computer programmer with system flowcharts.
systems programmers are given responsibility for maintaining system software, including operating systems and compilers.
In relation to data management activities, the data owner’s primary role is __________, the data steward’s primary role is _____________, and the data custodian’s primary role is ____________________.
Answer: Accontability, responsible, responsible
The Systems Development Life Cycle (SDLC) is the traditional methodology for developing information systems. In which phase of the SDLC would the activity of identifying the problem(s) that need to be solved most likely occur?
Answer: Planning
Planning is the first phase of the SDLC and this information is needed before most of the analysis phase activities can be initiated.
The steps in the systems development life cycle are analysis, design, build, test, and implement.
A direct changeover involves implementation of a new system without the possibility of reverting to the old system. It is often a risky strategy.
Operational systems
support day-to-day activities of the business (i.e. purchasing of goods and services, manufacturing activities, sales t ocustomer, payroll etc.)
Management Information Systems (MISs)
Systems designed to support routine management problems based primarily on data form transaction processing systems
Order data elements by size
Files: are composed of
Records: are composed of
Fields: are composed of
Data values: are composed of
Bytes (characters): are composed of
Bits: the smallest storage element in a computer system
A data mart is a type of data warehouse that is customized for an organization.
An overall description of a database, including the names of data elements, their characteristics, and their relationship to one another, would be defined by using a
data definition language
During the annual audit, it was learned from an interview with the controller that the accounting system was programmed to use a batch processing method and a detailed posting type. This would mean that individual transactions were
Assigned to groups before posting, and each transaction had its own line entry in the appropriate ledger
A company has a significant e-commerce presence and self-hosts its website. To assure continuity in the event of a natural disaster, the firm should adopt which of the following strategies?
Establish a off-site mirrored website
Establishing an off-site mirrored Web server would provide for continuous duplication of data in geographically separated locations.
Compared to online real-time processing, batch processing has which of the following disadvantages?
Stored data are current only after the update processes
Business analytics
“the science and art of discovering and analyzing patterns, IDing anomalies, and extracting other useful info in data for application to a business issue or problem
data lake
an unfiltered pool of big data
data warehouse
structured, filtered data repository for solving business problems
Common challenges in data governance
- It’s hard to quantify the benefits of data governance and management -> thus, underinvestment in these activities is common
- Unclear as to who is responsible for data ownership
- Complying w/increasing regulation of data ownership
- Too much data (data deluge)
Data classification defines the privacy and security properties of data
data taxanomy categorizes the data within the organization’s structure and hierarchy
The data life cycle overviews the steps in managing and preserving data for use and reuse
RACI acronym -> illustrates the data stewardship roles of the data owner, steward, and custodian across the data life cycle
Responsible - Does the work to complete the task
Accountable - Delegates the work and is the lats one to review the task or deliverable before completion
Consulted - Deliverables are strengthened by review and consultation from multiple team members
Informed - Informed of project progress
data architecture
the structure and interaction of the major types and sources of data, logical data assets, physical data assets and data management resources of the enterprise
Metadata
a set of data that describes and gives further detail about a dataset
Criteria for describing data
3 criteria for describing data
- The description includes the dataset’s purpose
- The desciption of the set of data is complete and accurate; it includes the 10 elements:
P(opulation)
U(nits)
R(ecords)
P(recision)
S(ample)
S(ources)
T(ime)
U(ncertainty)
F(ields)
F(ilters)
3. The data description identifies information that hasn’t been included within the set of data or description but is necessary to understand each data element and the population
5 IT security principles specified by the AICPA Assurance Services Executive Committee (ASEC)
- Security - A top mgmt issue. Security is the foundations of systems reliability
- Availability - whether the system is operational and usable as specified in committments and agreements
- Processing integrity - does the system of internal control help ensure taht the system processes info as intended w/out errors or manipulations?
- Confidentiality - whether confidential info is proectected consistent w/organization’s commitments and agreements
- Privacy - addresses whether the system’s collection, use, retention, disclosure, and disposal of personal info conforms to its own commitments and w/the criteria set forth in GAAP
7 categories of assessing IT security principles
- Organization and management
- Communications
- Risk management, and design and implementation of controsl
- Control monitoring
- Logical and physical access controls
- System operations
- Change Management