Exam 14: Auditing It Controls Part I: Sarbanes-Oxley and It Governance

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Section 404 requires management to make a statement identifying the control framework used to conduct their assessment of internal controls.Discuss the options in selecting a control framework.

(Essay)
4.9/5
(33)

What is the empty shell?

(Essay)
4.8/5
(37)

Describe how a corporate IT function can overcome some of the problems associated with distributed data processing.

(Essay)
4.7/5
(30)

Which of the following is not an essential feature of a disaster recovery plan?

(Multiple Choice)
4.9/5
(31)

Which of the following is not true?

(Multiple Choice)
4.8/5
(41)

Which of the following is true of disaster recovery as a service (DRaaS)?

(Multiple Choice)
5.0/5
(35)

Why is inadequate documentation a chronic problem?

(Essay)
5.0/5
(44)

Explain why reduced security is an outsourcing risk.

(Essay)
4.8/5
(29)

The fundamental difference between internal and external auditing is that

(Multiple Choice)
4.7/5
(38)

Explain the outsourcing risk of failure to perform.

(Essay)
4.9/5
(37)

Both the SEC and the PCAOB have expressed an opinion as to which internal control framework an organization should use to comply with SOX legislation.Explain.

(Essay)
4.9/5
(29)

Describe the two broad groupings of information system controls that are specified by COSO.

(Essay)
4.8/5
(38)

Discuss the key features of Section 302 of the Sarbanes-Oxley Act.

(Essay)
4.9/5
(44)

The IT audit focuses on systems where technology plays a material role and thus makes the entire audit process more complex.

(True/False)
4.8/5
(26)

Distinguish between errors and irregularities.Which do you think concern auditors the most?

(Essay)
4.9/5
(36)

Internal auditors assist external auditors with financial audits to

(Multiple Choice)
4.7/5
(35)

The financial statements of an organization reflect a set of management assertions about the financial health of the business.All of the following describe types of assertions except

(Multiple Choice)
4.8/5
(31)

Which concept is not an integral part of an audit?

(Multiple Choice)
4.8/5
(40)

Define database management fraud.

(Essay)
4.9/5
(32)

Briefly explain how a SSAE 16 report is used in assessing internal controls of outsourced facilities.

(Essay)
4.7/5
(40)
Showing 41 - 60 of 129
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)