IT Flashcards
A parity check is..
Not an input control. It is a hardware control that makes certain each piece of data has the appropriate odd or even number of data components, or data bits.
Distributed Processing Environment
Various processes are performed separately by the individuals responsible in their locations and are integrated into a central system
Define “Integrated Test Facility (ITF).”
Dummy division and fictitious transactions ran along with client data (Use auditor and client data in the client’s computer system)
* Another use of ITF is embedded audit modules
What is the purpose of test data procedures?
To process known errors to see if the client’s system catches them. The auditor only needs to include those errors that are important to the auditor (that is, the auditor need not include every possible type of error). There may be a danger of contaminating the client’s database with the test data.
Who should have responsibility of modifying and adapting operating system software?
System Analysts
Describe a hot site..
Location has redundant hardware and software that’s already configured and ready to preserve the continuity in disaster
What are VANs?
Links files of different companies together (connects trading partners)
Systems Development Life Cycle
- Planning- feasibility study to determine objectives, is existing system meeting requirements, etc
- Analysis- define problem and qualitative solutions (custom or vendor supplied)
- Design- baseline for system and specs needed, or select purchased system (proposal)
- Development- use specs to program formalized process, unit testing (watch for scope creep); if purchased configure new system to org needs
- Testing- establish actual operation, final testing and user sign off (meet needs? intended objectives?)
- Implementation- implement formal process, assess adequacy, cost/benefit, ROI, end user management
- Maintenance- monitoring and support, training
COBIT 5 core principles
- Meeting stakeholders needs
- End to end application (seamless governance a sa whole and mngmt of IT apply to all components)
- Development of single integrated framework
- Enabling a holistic approach
- Separating governance from management
Application controls include:
Preventative
Detective
Corrective
** They are NOT company wide controls
Test Data
Data- Auditor
Program- Client
Controlled Reprocessing
Data - Client
Program- Client, but auditor computer
ITF
Data - Auditor and client
Program- Client
Parallel Simulation
Data- Client
Program- Auditor (going around their system)
Primary purpose of disaster recovery plan
To specify the steps required to resume operations