Information Technology Governance Flashcards
(107 cards)
Relating to IT governance, what is the best action an LARGE organization can take to increase internal control effectiveness? This does not apply to small organizations.
Segregation of duties
Relating to IT governance, what is the best action an SMALL organization can take to increase internal control effectiveness?
Engaging the owner in the activities of the business. This is an important COMPENSATING control.
- The uniformity of transaction processing is higher in automated than manual systems. True or false?
- A greater level of control is necessary in automated than manual systems. True or false?
Statement one = true
Statement two = false
An automated computerized accounting system ________ the incidences of clerical errors and __________ the incidences of systematic errors.
- Reduce instances of clerical errors. System automatically checks for errors.
- Increases instances of systematic errors. Errors in programming can occur.
Do computerized systems increase or decrease the need for access controls (logical and physical)?
Increase. Because computerized systems actually increase the number of points where the system can be accessed, increasing the need for both physical and logical access controls.
What is a key characteristic that distinguishes computer processing to manual processing? (Hint: related to data entry)
Computer processing virtually eliminates computational errors.
How does computerized accounting systems (online real-time processing) differ from manual accounting systems with regards to job functions?
It is common for computerized systems to combine functions that would be considered incompatible in a manual system.
With regards to accounting systems, ledgers, journals, and invoices are part of what accounting system?
Manual
With regards to accounting systems, e-vouchers, automated transactions, and concentration of information are part of what accounting system?
Automated
Are audit trails easier to follow and more transparent in automated or manual accounting systems?
Automated
Processing speed, fewer idiosyncratic errors, and lower likelihood of intrusion are advantages of what accounting system?
Automated
An automated system requires controls related to people, software, and hardware. Are access controls more or less of important in automated system as to manual?
More important. Highly important.
Compared to manual systems, automated systems have
1. ________ risks related to remote access
2. ________ risks related to concentration of information
3. ________ opportunities for directly observing processes
Answer: Either increase or decrease
- Increase risks for remote access
- Increase risks for concentration of info
- Decreased opportunities for observing processes
______ processing errors are the MOST IMPORTANT risk related to computer accounting systems.
Systematic
Authorization is often _____ in online systems. (Hint: automated or manual)
Automated
Do both manual and automated accounting systems require stringent internal controls? Can they both produce inaccuracy in financial reporting?
Yes and yes
Balancing risk versus return is over IT and its processes and strategically managing and acquiring IT resources in support of the organization’s mission is the primary goal of what?
IT Governance
Is COBIT (Control Objectives for Information and related Technology) a required framework that should be adopted and implemented?
No it’s not required. There are many IT governance models and frameworks that an organization can implement.
There are four domains and processes of IT COBIT framework. They are?
- Planning and organization
- Acquisition and implementation
- Delivery and support
- Monitoring
What are seven desired information attributes of COBIT framework?
- Effective
- Efficient
- Confidential
- Integrity
- Available
- Compliant
- Reliable
COBIT provides a framework for ______ and management of _________.
- IT Governance
2. Enterprise IT
Guiding managers, users, and auditors to adopt best practices related to the management of information technology is an important purpose of what?
COBIT.
Using the company’s IT strategic plan to consider how implementing something detracts or aligns with company’s business objectives is part of what domain in COBIT?
Planning and organization
Assessing how to acquire, implement, or develop IT solutions that address business objectives and integrate with critical business process is part of what domain of COBIT?
Acquisition and implementation