REVIEW Flashcards
1
Q
Third Normal Form (3NF) ** review normalization*
A
- Normalization reduces data redundancy and eliminates undesirable characteristics like insertion, update, and deletion anomalies.
- 3NF: eliminate any attributes that depend on both the primary key and other non-key attributes. Attributes should not have transitive dependencies (where they rely on other non-key attributes.
2
Q
Role of service auditor vs. Service org management
A
- service org management responsible for preparing the description of the system.
- ## service org management: responsible for determining control objectives
3
Q
Trust services supplemental criteria COSO components:
A
-
4
Q
COBIT core
A
- BAI (Build, Acquire, and Implement)
- APO (Align, Plan, and Organize)
- EDM (Evaluate, Direct, and Monitor)
- DSS (Deliver, Service, and Support)
5
Q
Security assessment report (SAR) procedures
A
- Examination (the process of analyzing, observing, and reviewing one or more assessment objects, such as job roles, security specifications, security activities, or relevant operational controls)
- interviewing (the method that involves having individual or group discussions to better understand, collect, and evaluate evidence)
- testing (the process of testing assessment objects that reflect how the object performs in its current state compared to a target or expected rate.
6
Q
service auditor
A
- service auditors are not required to be independent of the user entities but only the responsible party like the service organization in a SOC engagement.
7
Q
Eight components of ERP (Enterprise Risk Management) when applying to risk profile
A
- Internal Environment
- Objective Setting
- Event Identification
- Risk Assessment
- Risk Response
- Control Activities
- Information and Communication
- Monitoring
8
Q
A