IT audit, data management, and systems controls topics tested on the CPA ISC discipline section.
40 cards · basic cards · AI-written, checked twice. Edit anything.
- In information security, what does the CIA triad stand for?
- Confidentiality, Integrity, and Availability
- What is the purpose of general IT controls (ITGCs)?
- To ensure the overall IT environment is stable, secure, and reliable so that application controls can be relied upon
- What are application controls?
- Controls built into software that prevent, detect, or correct errors during transaction processing
- What is the primary focus of a SOC 1 report?
- Controls at a service organization relevant to a user entity's internal control over financial reporting
- What is the primary focus of a SOC 2 report?
- Controls related to security, availability, processing integrity, confidentiality, or privacy at a service organization
- What is the difference between a SOC report Type I and Type II?
- Type I evaluates the design of controls at a single point in time; Type II evaluates operating effectiveness over a period of time
- What is COBIT primarily used for?
- A framework for IT governance and management of enterprise IT control objectives
- What is the COSO Internal Control Integrated Framework used for?
- Designing, implementing, and evaluating the effectiveness of internal control across an organization, including IT
- What is segregation of duties?
- Dividing key tasks among different people so no one person can both commit and conceal an error or fraud
- What is the purpose of a change management control?
- To ensure changes to systems or programs are authorized, tested, and approved before being moved into production
- What is the standard order of phases in the systems development life cycle (SDLC)?
- Planning, analysis, design, development, testing, implementation, and maintenance
- What is an access control?
- A safeguard that restricts who can view or use system resources based on identity and authorization
- What are the three general categories of authentication factors?
- Something you know, something you have, and something you are
- What is multi-factor authentication (MFA)?
- A login method requiring two or more independent authentication factors before granting access
- What is the primary purpose of a firewall?
- To monitor and control incoming and outgoing network traffic based on defined security rules