Risk Analysis Flashcards
Risk Analysis in the context of an audit
Is the activity that is used to determine the areas that warrant additional examination and analysis.
IT Framework majors activities
- Risk governance
- Risk evaluation
- Risk Response
First phase of a risk analysis
An evaluation of the business processes.
Purpose of evaluating business purpose
To determine the purpose, importance, and effectiveness of business activities
Why an auditor performs a threat analysis
to identify and catalog risks
What is a threat analysis
an activity whereby the auditor considers a large body of possible threats and selects those that have some reasonable possibility of occurrence, however small.
Impact
A short description of the results if the threat is actually realized.
Possible mitigating controls
This is a list of one or more countermeasures that can reduce the probability or the impact of the threat, or both.
When the IS auditor is conducting a risk analysis prior to an audit,
risk mitigation may take the form of additional audit scrutiny on certain activities during the audit.