Risk Analysis Flashcards

1
Q

Risk Analysis in the context of an audit

A

Is the activity that is used to determine the areas that warrant additional examination and analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IT Framework majors activities

A
  • Risk governance
  • Risk evaluation
  • Risk Response
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

First phase of a risk analysis

A

An evaluation of the business processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Purpose of evaluating business purpose

A

To determine the purpose, importance, and effectiveness of business activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why an auditor performs a threat analysis

A

to identify and catalog risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a threat analysis

A

an activity whereby the auditor considers a large body of possible threats and selects those that have some reasonable possibility of occurrence, however small.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Impact

A

A short description of the results if the threat is actually realized.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Possible mitigating controls

A

This is a list of one or more countermeasures that can reduce the probability or the impact of the threat, or both.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When the IS auditor is conducting a risk analysis prior to an audit,

A

risk mitigation may take the form of additional audit scrutiny on certain activities during the audit.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly