IT Processes & Controls Flashcards
What is COBIT, and what is included in the basic framework?
COBIT is a widely used international standard that aims to align IT and business goals/strategies to help mgmt ID how much to invest in IT security and auditing. The basic framework includes objectives surrounding business processes, planning & organization, acquisition and implementation, delivery & support, and monitoring.
What is SaaS?
Software-as-a-Service: The use of the cloud to access software.
What is PaaS?
Platform-as-a-Service: The use of the cloud to create software.
What is IaaS?
Infrastructure-as-a-Service: The use of the cloud to access virtual hardware.
What are the risks of cloud-based computing?
- Increased risk of data loss
- Increased risk of system penetration by hackers, etc.
- Diligence in vendor screening and selection is essential to security and success
What are the OLAP and OLTP?
Online Analytical Processing System - incorporates data warehouse and mining capabilities within the ERP and is primarily concerned with providing an integrated view of transactions for analysis.
Online Transaction Processing - records day to day operational transactions and enhances visibility throughout the system and is primarily concerned with data collection.
What is the cold site approach to disaster recovery?
Hardware and records are delivered to a new site after a disaster occurs. Less expensive but more risky than a hot site approach, where data and information processing equipment is in place beforehand.
What individual role is in charge of overall program logic and functionality?
The Lead Systems Analyst is generally responsible for direct contact with the end user and development of program logic/functionality.
In an IT environment, what is the role of the end user?
Identifying problems and proposing initial solutions
What implementation approach divides users into small groups and trains one group at a time on the new system?
Pilot
What is the ‘Cold Turkey’ implementation approach?
AKA ‘sink or swim’ - the old system is dropped and the new system is put in place all at once.
At which stage is the requirements definition document signed?
System analysts work with end users to understand and document biz processes and system requirements during the ANALYSIS stage.
What is the principal duty of the IT Steering Committee?
Approving and prioritizing system development proposals.
What is the Systems Documentation?
Provides an overview of program and data files, processing logic, and interactions with each of the other programs and systems and is appropriate for the auditor to gain familiarity with the system.
What is a reasonableness check?
This type of verification looks at the values in 2 related fields to ensure that they make sense as a unit.
What is a source code comparison?
Used to compare an archived version of a program to the program actually in use; may be used to verify that no unauthorized changes have been made.
What are the common forms of application input/origination control?
Edit check, closed loop verification, reasonableness check, batch controls. . .
What is the primary objective of data security controls?
To ensure that storage media are subject to authorization prior to access, change, or destruction.