REVIEW Flashcards

1
Q

Third Normal Form (3NF) ** review normalization*

A
  • Normalization reduces data redundancy and eliminates undesirable characteristics like insertion, update, and deletion anomalies.
  • 3NF: eliminate any attributes that depend on both the primary key and other non-key attributes. Attributes should not have transitive dependencies (where they rely on other non-key attributes.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Role of service auditor vs. Service org management

A
  • service org management responsible for preparing the description of the system.
  • ## service org management: responsible for determining control objectives
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Trust services supplemental criteria COSO components:

A

-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

COBIT core

A
  • BAI (Build, Acquire, and Implement)
  • APO (Align, Plan, and Organize)
  • EDM (Evaluate, Direct, and Monitor)
  • DSS (Deliver, Service, and Support)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security assessment report (SAR) procedures

A
  • Examination (the process of analyzing, observing, and reviewing one or more assessment objects, such as job roles, security specifications, security activities, or relevant operational controls)
  • interviewing (the method that involves having individual or group discussions to better understand, collect, and evaluate evidence)
  • testing (the process of testing assessment objects that reflect how the object performs in its current state compared to a target or expected rate.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

service auditor

A
  • service auditors are not required to be independent of the user entities but only the responsible party like the service organization in a SOC engagement.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Eight components of ERP (Enterprise Risk Management) when applying to risk profile

A
  • Internal Environment
  • Objective Setting
  • Event Identification
  • Risk Assessment
  • Risk Response
  • Control Activities
  • Information and Communication
  • Monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly