Information Technology Flashcards

1
Q

System Flowchart

A

A graphic representation of a data processing application that depicts the interaction of all the computer programs for a given system, rather than the logic for an individual computer program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Program Flowchart

A

A graphic representation of the logic (processing steps) of a computer program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Internal Control Flowchart/Document Flowchart

A

A graphic representation of the flow of documents from one department to another, showing the source flow and final disposition of the various copies of all documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Decision Table

A

Decision Tables use a matrix format that lists set of conditions, and the actions that result from various combinations of these decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Flow Diagram (DFD)

A

Presents logical flows of data and functions in a system. For example, a data flow diagram for the delivery of goods to a customer would include a symbol for the warehouse from which the goods are shipped and a symbol representing the customer. It would not emphasize details such as computer processing and paper outputs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

T/F

If a transaction is incorrectly processed, the auditor should suggest a way to fix the control, and re-process the transaction.

A

FALSE

Suggesting fixes is out of the scope of an audit and is dangerously close to consulting services.

The auditor should consider the effect that the issue will have on control risk. The auditor also should obtain an understanding of how the incorrect processing of transactions is resolved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Ineffective general controls by themselves ____ (always/never/could) ____ (cause/allow) misstatements

A

Ineffective general controls by themselves never cause misstatements but they could allow misstatements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What represents a disadvantage for an entity that keeps microcomputer-prepared data files rather than manually prepared files?

A

It is usually easier for unauthorized persons to access and alter the files. Manual files only need to be physically secure; but computer data needs to be both physically and logically secure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When reviewing the extent and nature of the risks to internal controls associated with IT, an auditor should consider what?

A

1) Whether the entity has responded adequately to the risks arising from IT by establishing effective controls
2) Whether controls over IT systems are effective when they maintain the integrity of information and the security of the data such systems process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe a Completeness Test and how it is useful

A

A completeness check is a verification that all data required to process a given type of transaction has been entered in the required data fields. If missing data is detected, the operator is generally prompted to enter or complete the submission before it will be accepted for processing. This is a control that prevents errors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How are Application Controls Classified?

A

Input Controls
Processing Controls
Output Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The extent and nature of the risk to internal control associated with IT are dependent on the nature and characteristics related to the entity’s

A

information system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Application controls pertain to

A

processing of individual applications in an IT environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Input controls relate most appropriately to (3 items)

A

rejection, correction, and resubmission of data that was initially incorrect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

There are four basic categories of input to be controlled

A

1) transaction entries
2) file maintenance transactions
3) inquiry transaction entries
4) error correction transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

An advantage of using parallel simulation, instead of performing tests of controls without a computer, is that

A

the size of the sample can be greatly expanded at relatively little additional cost.

17
Q

What factors related to control activities impact an auditor’s consideration of the effect of IT on internal control (3 items)

A

1) Information Processing
2) Segregation of Duties
3) Physical Controls

18
Q

Application Controls pertain to

A

processing of individual applications in an IT environment.

19
Q

Application Controls are designed to

A

achieve specific control objectives related to specific accounting tasks.

20
Q

Application Controls can be performed by…

A

automated IT and/or user-based controls.

21
Q

T/F

Application controls can be performed by IT (automated) or by individuals.

A

True

When application controls are performed by people interacting with IT, they may be referred to as user controls.