Exam 14: Auditing It Controls Part I: Sarbanes-Oxley and It Governance
Explain why certain duties that are deemed incompatible in a manual system may be combined in an automated environment? Give an example.
In an automated environment it would be inefficient and contrary to the objectives of automation to separate such tasks as processing and recoding a transaction among several different application programs merely to emulate a manual control model.Further,the reason for separating tasks is to control against the negative behavior of humans; in an automated environment the computer performs the tasks,not humans.
What is a recovery operations center? What is its purpose?
A recovery operations center (ROC)or hot site is a fully equipped backup data center that many companies share.In addition to hardware and backup facilities,ROC service providers offer a range of technical services to their clients,who pay an annual fee for access rights.In the event of a major disaster,a subscriber can occupy the premises and,within a few hours,resume processing critical applications.
Computer fraud can take many forms,including each of the following except
D
The database administrator should be separated from systems development.
Which organizational structure is most likely to result in good documentation procedures?
Internal control in a computerized environment can be divided into two broad categories.What are they? Explain each.
Substantive testing techniques provide information about the accuracy and completeness of an application's processes.
Both the SEC and the PCAOB require management to use the COBIT framework for assessing internal control adequacy.
In a computer-based information system,which of the following duties needs to be separated?
Which of the following is not a requirement in management's report on the effectiveness of internal controls over financial reporting?
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)