IS 414 CH. 7 (VOCAB) Flashcards

1
Q

Threat/event

A

Any potential adverse occurrence or unwanted event that could injure the AIS or the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Exposure/impact

A

The potential dollar loss should a particular threat become a reality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Likelihood

A

The probability that a threat will come to pass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Internal controls

A

The processes and procedures implemented to provide reasonable assurance that control objectives are met

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Preventive controls

A

Controls that deter problems before they arise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Detective controls

A

Controls designed to discover control problems that were not prevented

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Corrective controls

A

Controls that identify and correct problems as well as correct and recover from the resulting errors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

General controls

A

Controls designed to make sure an organization’s information system and control environment is stable and well managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Application controls

A

Controls that prevent, detect, and correct transaction errors and fraud in application programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Belief system

A

System that describes how a company creates value, helps employees understand management’s vision, communicates company core values, and inspires employees to live by those values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Boundary system

A

System that helps employees act ethically by setting boundaries on employee behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Diagnostic control system

A

System that measures, monitors, and compares actual company progress to budgets and performance goals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Interactive control system

A

System that helps managers to focus subordinates’ attention on key strategic issues and to be more involved in their decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Foreign Corrupt Practices Act (FCPA)

A

Legislation passed to prevent companies from bribing foreign officials to obtain business; also requires all publicly owned corporations maintain a system of internal accounting controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Sarbanes-Oxley Act (SOX)

A

Legislation intended to prevent financial statement fraud, make financial reports more transparent, provide protection to investors, strengthen internal controls at public companies, and punish executives who perpetrate fraud
(most important business orientated legislation in the last 80 years)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Public Company Account Oversight Board (PCAOB)

A

A board created by SOX that regulates the auditing profession
Sets and enforces auditing, quality control, ethics, independence, and etc)
Consists of 5 people appointed by the Securities and Exchange Commission (SEC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Control Objectives for Information and Related Technology (COBIT)

A

A security and control framework that allows (1) management to benchmark the security and control practices of IT environments, (2) users of IT services to be assured that adequate security and control exists, and (3) auditors to substantiate their internal control opinions and advise on IT security and control matters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Committee of Sponsoring Organizations (COSO)

A

A private-sector group consisting of the American Accounting Associations, the AIPCA, the Institute of Management Accountants, and the Financial Executives Institute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Internal Control - Integrated Framework (IC)

A

A COSO framework that defines internal controls and provides guidance for evaluating and enhancing internal control systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Enterprise Risk Management -

A

Integrated Framework (ERM) A COSO framework that improves the risk management process by expanding (adds three additional elements) COSO’s Internal Control - Integrated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Internal environment

A

The company culture that is the foundation for all other ERM components as it influences how organizations establish strategies and objectives; structure business activities; and identify, assess, and respond to risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Risk appetite

A

The amount of risk a company is willing to accept to achieve its goals and objectives. To avoid undue risk, risk appetite must be in alignment with company strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Audit committee

A

The outside, independent board of director members responsible for financial reporting, regulatory compliance, internal control, and hiring and overseeing internal and external auditors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Policy and procedures manual

A

A document that explains proper business practices, describes needed knowledge and experience, explains document procedures, explains how to handle transactions, and lists the resources provided to carry out specific duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Background check

A

An investigation of a prospective or current employee that involves verifying their educational and work experience, talking to references, checking for a criminal record or credit problems, and examining other publicly available information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Strategic objectives

A

High-level goals that are aligned with and support the company’s mission and create shareholder value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Operations objectives

A

Objectives that deal with the effectiveness and efficiency of company operations and determine how to allocate resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Reporting objectives

A

Objectives to help ensure the accuracy, completeness, and reliability of company reports; improve decision making; and monitor company activities and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Compliance objectives

A

Objectives to help the company comply with all applicable laws and regulations

30
Q

Event

A

A positive or negative incident or occurrence from internal or external sources that affects the implementation of strategy or the achievement of objectives


31
Q

Inherent risk

A

The susceptibility of a set of accounts or transactions to significant control problems in the absence of internal controls

32
Q

Residual risk

A

The risk that remains after management implements internal controls or some other response to risk

33
Q

Expected loss

A

The mathematical product of the potential dollar loss that would occur should a threat become a reality (called impact or exposure) and the risk or probability that the threat will occur (called likelihood)

34
Q

Control activities

A

Policies, procedures, and rules that provide reasonable assurance that control objectives are met and risk responses are carried out

35
Q

Authorization

A

Establishing policies for employees to follow and then empowering them to perform certain organizational functions. Authorizations are often documented by signing, initialing, or entering an authorization code on a document or record

36
Q

Digital signature

A

A means of electronically signing a document with data that cannot be forged

37
Q

Specific authorization

A

Special approval an employee needs in order to be allowed to handle a transaction

38
Q

General authorization

A

The authorization given employees to handle routine transactions without special approval

39
Q

Segregation of accounting duties

A

Separating the accounting functions of authorization, custody, and recording to minimize an employee’s ability to commit fraud

40
Q

Collusion

A

Cooperation between two or more people in an effort to thwart internal controls

41
Q

Segregation of systems duties

A

Implementing control procedures to clearly divide authority and responsibility within the information system function

42
Q

Systems administrator

A

Person responsible for making sure a system operates smoothly and efficiently

43
Q

Network manager

A

Person responsible for ensuring that applicable devices are linked to the organizations networks and that the networks operate properly

44
Q

Security management

A

People that make sure systems are secure and protected from internal and external threats

45
Q

Change management

A

Process of making sure changes are made smoothly and efficiently and do not negatively affect systems reliability, security, confidentiality, integrity, and availability

46
Q

Users

A

People who record transactions, authorize data processing, and use system output

47
Q

Systems analysts

A

People who help users determine their information needs and design systems to meet those needs

48
Q

Programmers

A

People who take the analysts’ design and develop, code, and test computer programs

49
Q

Computer operators

A

People who operate the company’s computers

50
Q

Information system library

A

A collection of corporate databases, files, and programs stored in a separate storage area and managed by the system librarian

51
Q

Data control group

A

People who ensure that source data is properly approved, monitor the flow of work, reconcile input and output, handle input errors to ensure their correction and resubmission, and distribute systems outputPeople who ensure that source data is properly approved, monitor the flow of work, reconcile input and output, handle input errors to ensure their correction and resubmission, and distribute systems output

52
Q

Steering committee

A

An executive-level committee to plan and oversee the information systems function

53
Q

Strategic master plan

A

A multiple-year plan that lays out the projects the company must complete to achieve its long-range goals and the resources needed to achieve the plan

54
Q

Project development plan

A

A document that shows how a project will be completed

55
Q

Project milestones

A

Points where progress is reviewed and actual and estimated completion times are compared

56
Q

Data processing schedule

A

A schedule that shows when each data processing task should be performed

57
Q

Systems performance measurements

A

Ways to evaluate and assess a system

58
Q

Throughput

A

The amount of work performed by a system during a given period of time

59
Q

Utilization

A

The percentage of time a system is used

60
Q

Response time

A

How long it takes for a system to respond

61
Q

Postimplementation review

A

Review, performed after a new system has been operating for a brief period, to ensure that it meets its planned objectives

62
Q

Systems integrator

A

An outside party hired to manage a company’s systems development effort

63
Q

Analytical review

A

The examination of the relationships between difference sets of data

64
Q

Audit trail

A

A path that allows a transaction to be traced through a data processing system from point of origin to output or backward from output to point of origin

65
Q

Computer security office (CSO)

A

An employee independent of the information system function who monitors the system disseminates information about improper system uses and their consequences, and reports to top management

66
Q

Chief compliance officer (CCO)

A

An employee responsible for all the compliance tasks associated with SO and other laws and regulatory rulings

67
Q

Forensic investigators

A

Individuals who specialize in fraud, most of whom specialized training with law enforcement agencies such as the FBI or IRS or have professional certifications such as Certified Fraud Examiner (CFE)

68
Q

Computer forensics specialists

A

Computer experts who discover, extract, safeguard, and document computer evidence such that its authenticity, accuracy, and integrity will not succumb to legal challenges

69
Q

Neural networks

A

Computing systems that imitate the brain’s learning process by using a network of interconnected processors that perform multiple operations simultaneously and interact dynamically

70
Q

Fraud hotline

A

A phone number employees can call to anonymously report fraud and abuse