Accounting · CPA

CPA ISC (Information Systems and Controls)

IT audit, data management, and systems controls topics tested on the CPA ISC discipline section.

40 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Get FlashKeepers for iPhone
In information security, what does the CIA triad stand for?
Confidentiality, Integrity, and Availability
What is the purpose of general IT controls (ITGCs)?
To ensure the overall IT environment is stable, secure, and reliable so that application controls can be relied upon
What are application controls?
Controls built into software that prevent, detect, or correct errors during transaction processing
What is the primary focus of a SOC 1 report?
Controls at a service organization relevant to a user entity's internal control over financial reporting
What is the primary focus of a SOC 2 report?
Controls related to security, availability, processing integrity, confidentiality, or privacy at a service organization
What is the difference between a SOC report Type I and Type II?
Type I evaluates the design of controls at a single point in time; Type II evaluates operating effectiveness over a period of time
What is COBIT primarily used for?
A framework for IT governance and management of enterprise IT control objectives
What is the COSO Internal Control Integrated Framework used for?
Designing, implementing, and evaluating the effectiveness of internal control across an organization, including IT
What is segregation of duties?
Dividing key tasks among different people so no one person can both commit and conceal an error or fraud
What is the purpose of a change management control?
To ensure changes to systems or programs are authorized, tested, and approved before being moved into production
What is the standard order of phases in the systems development life cycle (SDLC)?
Planning, analysis, design, development, testing, implementation, and maintenance
What is an access control?
A safeguard that restricts who can view or use system resources based on identity and authorization
What are the three general categories of authentication factors?
Something you know, something you have, and something you are
What is multi-factor authentication (MFA)?
A login method requiring two or more independent authentication factors before granting access
What is the primary purpose of a firewall?
To monitor and control incoming and outgoing network traffic based on defined security rules

25 more cards in the app