Becker - ISC S4 Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/39

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:06 PM on 8/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

40 Terms

1
New cards

SOC (1) Engagement

The examination and reporting on controls at a service organization that are likely to be relevant to user entities’ internal control over financial reporting

Restricted to management of the service organization, user entities of the service organization’s system, and the independent auditors of such user entities

It does not include potential users of the service organization

*Assesses controls relevant to financial reporting*

2
New cards

SOC (2) Engagement

The examination and reporting on the security, availability, or processing integrity of a system and the confidentiality or privacy of the information processed by the system

Intended for use by those who have sufficient knowledge and understanding of the service organization, the services it provides, and the system used to provide those services

*Assesses controls relevant to security, availability, processing integrity, confidentiality, or privacy*

3
New cards

SOC (3) Engagement

The service auditor reports on whether controls within the system were effective to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved based on the applicable trust services criteria

Does not include a description of the system and/or a description of the service auditor’s tests of controls and the results thereof

Ordinarily for general users

*Assesses controls relevant to security, availability, processing integrity, confidentiality, or privacy*

4
New cards

SOC for Cybersecurity Engagement

Examine and report on a description of the entity’s cybersecurity risk management program and the effectiveness of controls with that program

5
New cards

SOC for Supply Chain Engagement

Examine and report on an entity’s controls over the security, availability, processing integrity, confidentiality, or privacy of a system used to produce, manufacture, or distribute products

6
New cards

Type (1) SOC Report

A report on the fairness of the presentation of management’s description of the service organization’s system and suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date

Includes management’s description of the service organization’s system, a written assertion by management of the service organization about whether the description is fairly presented and controls are suitably designed as of a specified date, and a report that expresses an opinion

*Covers the system design as of a given point in time*

7
New cards

Type (2) SOC Report

A report on the fairness of the presentation of management’s description of the service organization’s system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period

Includes management’s description of the service organization’s system, a written assertion by management of the service organization about whether the description is fairly presented and controls are suitably designed/operating effectively throughout a period, and a report that expresses an opinion and includes a description of the tests of controls and results

*Covers both the design and operating effectiveness over a period of time*

8
New cards

True

A SOC 3 report is always issued as a Type 2 report.

True or False?

9
New cards

Confidentiality, Availability, Processing Integrity, Privacy, Security (CAPPS)

What are the five trust services criteria?

10
New cards

2, 3

What 2 types of SOC engagements are trust services criteria applicable for?

11
New cards

COSO Framework

A widely accepted control framework utilized by entities to establish and implement an effective system of internal control and includes five components that are supported by 17 principles

12
New cards

Control Environment, Risk Assessment, Information/Communication, Monitoring, Existing Control Activities (CRIME)

What are the five COSO principles?

13
New cards

No

Does the Security trust services criteria have additional criteria (or a series)?

14
New cards

A Series

The additional criteria for the Availability trust services criteria

Focuses on an entity’s ability to ensure all systems are continuously available as needed by maintaining/monitoring processing capacity, identifying/responding to threats, and ensuring a recovery plan is in place and tested

15
New cards

PI Series

The additional criteria for the Processing Integrity trust services criteria

Includes considerations related to creating, using, and communicating quality information so that objectives will be met regarding product/service specifications, controls for completeness/accuracy, productivity, and system specifications

16
New cards

C Series

The additional criteria for the Confidentiality trust services criteria

Ensures that confidential information is handled appropriately

17
New cards

P Series

The additional criteria for the Privacy trust services criteria

Relates to collecting personal data, obtaining consent when collecting/using that data, using data for specific purposes only, managing access to individuals’ data responsibly, disclosing policies to third parties and individuals properly, maintaining complete/accurate records, and monitoring/enforcing practices in place

18
New cards

Control Activities

Which COSO component includes the trust services supplemental criteria?

19
New cards

Unmodified (Unqualified) Opinion

The service auditor’s opinion that, in all material respects, based on the criteria described in management’s assertion:

  1. Management’s description of the system fairly presents the system that was designed and implemented

  2. The controls stated in management’s description of the system were suitably designed

  3. The controls stated in management’s description of the system operated effectively (Type 2 only)

20
New cards

Complementary User Entity Controls, Complementary Subservice Organization Controls (CUECs, CSOCs)

If the application of these is necessary to achieve the related control objectives stated in management’s description of the service organization’s system, a statement to that effect needs to be made

21
New cards

Complementary Subservice Organization Controls (CSOCs)

Controls implemented at the subservice organization necessary to achieve the control objectives stated in management’s description of the service organization’s system

22
New cards

Complementary User Entity Controls (CUECs)

Controls that are necessary to be implemented by the user entity, in combination with the service organization’s controls, to provide reasonable assurance that the control objectives stated in management’s description of the service organization’s system (SOC 1) or the service organization’s service commitments and system requirements (SOC 2) were achieved

23
New cards

Qualified Opinion

States that except for the effects of the matter(s) giving rise to the modification, the description is presented in accordance with the description criteria and the controls were suitabily designed and operating effectively (Type 2), in all material respects

Material, but not pervasive

Only the opinion section of the report changes for SOC 1, service auditor’s responsibility and opinion sections of the report change for SOC 2

24
New cards

Adverse Opinion

States that the description misstatements, either individually or in the aggregate, are material and pervasive, or deficiencies in the design or operation of controls are material and pervasive

Only the opinion section of the report changes for SOC 1, service auditor’s responsibility and opinion sections of the report change for SOC 2

25
New cards

Disclaimer of Opinion

States that the auditor does not express an opinion

The first sentence of the service auditor’s report is revised to state “We were engaged to examine”

The report omits statements indicating what standards require of the practitioner, that the practitioner believes the evidence obtained is sufficient/appropriate to provide a reasonable basis for the opinion, and describing the nature of the engagement

26
New cards

Inclusive Method

Method of addressing the services provided by a subservice organization in which the description of the service organization’s system includes a description of the nature of the services provided by the subservice organization and the components of their system used to provide services to the service organization

27
New cards

Carve-Out Method

Method of addressing the services provided by a subservice organization in which the CSOCs of the subservice organization are excluded from the description of the service organization’s system and from the scope of the engagement

Identifies the nature of the services performed by the subservice organization and the types of controls expected to be performed at the subservice organization

28
New cards

Description Misstatement

The term used when describing errors or omissions in the description of the service organization’s system

29
New cards

Deviation (Exception)

Identified misstatements resulting from the failure of a control to operate in a specific instance

30
New cards

Deficiency in Design

When a control necessary to meet control objectives is missing or improperly designed so that even if it operates as designed, control objectives would not be achieved

31
New cards

Deficiency in Operating Effectiveness

When a properly designed control fails to operate as designed or when the person performing the control does not possess the competency necessary to perform the control effectively

32
New cards

System

The infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve one or more of the organization’s specific business objectives in accordance with management-specified requirements

“How we do what management says we need to do”

33
New cards

Infrastructure

Individual physical or virtual resources, or a collection of resources, that support a service organization’s environment

May include physical structures or hardware such as buildings, servers, switches, file storage devices, survelliance equipment, mobile devices, and internally or externally connected networks

34
New cards

Software

Applications and programs that support the operations of an IT system such as operating systems, middleware, database structures and retrieval mechanisms, external web-based applications, internally shared applications, and details describing those systems or how they function

35
New cards

System Requirements

Define how the system should function to meet the service commitments, comply with laws and regulations, and achieve other objectives

36
New cards

Nature

How controls are tested

Involves making inquiries and performing other procedures such as inspection, observation, or reperformance to obtain evidence about how the control was applied, the consistency with which the control was applied, by whom or by what means the control was applied, etc

37
New cards

Extent

The number of procedures performed and the size of the sample

Considers the tolerable rate of deviation, expected rate of deviation, the frequency with which the control operates, the relevance/reliability of the evidence, the length of the testing period, significance of control, etc

38
New cards

Timing

When the controls are tested and the frequency of testing

Factors include the period of time during which the information will be available, whether the control leaves a trail, and the significance of the control

39
New cards

Nature, Extent, Timing (NET)

The service auditor is responsible for determining the ____, _____, and _____ of procedures necessary to obtain sufficient and appropriate audit evidence about the operating effectiveness of controls throughout the engagement period.

40
New cards

Subsequent Events

Transactions/events that occur after the engagement period but prior to the date of the service auditor’s report that could have a signficant effect on the description, the suitability of design of controls, the operating effectiveness of controls, or management’s assertion