Week 6 - Cybersecurity Flashcards
(16 cards)
Define AIS controls
The measures and procedures put in place to safeguard organisations financial information and digital assets
What are the primary goals of AIS controls
- Protect organisations from financial fraud
- Ensure organisations comply with regulations established for processing and using financial data
What are the objectives of implementing internal controls in an organisation
- Safeguard assets
- Provide accurate and reliable financial information
- Promote and improve operational efficiency
- Maintain records to report them accurately
What are general controls
These are concerned with an oganisations’ operational efficiency
What are application controls
Concerned with safeguarding organizations’ accuracy, validity, completeness and authorization of transactions
What does general controls consist of
- Access controls
- Segregation of duties
- Change management controls
- Backup and recovery procedures
What do application controls consist of
- Input controls
- Processing controls
- Output controls
Who/what can identify the important AIS control frameworks
- Committee of Sponsoring Organizations of the Treadway Commission (COSO)
- Control Objectives for Information and Related Technologies (COBIT)
- Enterprise Risk Management (ERM)
- International Organization for Standardization (ISO)
What is COSO
A set of guidelines that help organizations to relevant establish internal controls, improve governance and prevent fraud
What are the components of COSO
- Control environment
- Risk assessment
- Control activities
- Information and communication
- Montioring activities
What is ERM
Process used by BOD to use strategy, identify events that may affect the entity, assess, manage risk
What is COBIT
A framework that helps organizations to monitor and improve IT governance
What are the 5 principles of COBIT
- Meeting stakeholder needs
- Covering the enterprise end to end
- Applying a single integrated framework
- Enabling a holistic approach
- Seperating governance from management
What is the 5 governance model of COBIT
- EDM - Evaluate, direct, monitor
- APO - Align, plan, organize
- BAI - Build, acquire, implement
- DSS - Deliver, service, support
- MEA - Monitor, evaluate, assess
What is ISO
An independant, non-governmental organization that develops international standards for products, services, systems and process
What are the ISO standards relevant to AIS
- ISO 27001: Information security management
- ISO 20000: IT service management
- ISO 22301: Business continuity management
- ISO 31000: Risk management