ITGC and App Controls

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/79

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:48 PM on 8/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

80 Terms

1
New cards

relationship bw AIS, ERP, and IT

house of information

<p>house of information</p>
2
New cards

what are the 2 main options for AIS acquisition?

In house development, and purchased systems

3
New cards

advantages of purchased systems

  • lower cost

  • quicker to implement

  • customizable thru modules

  • reputable, certified vendor

  • may be only option for small biz


4
New cards

disadvantages of purchased systems

  • dependent on vendor

  • not fully customizable

  • may be inflexible when change is needed


5
New cards

ERP systems

purchased software packages designed to meet all of an organization’s information needs; offer a large number of modules that are integrated into one system

6
New cards

client server model

a user’s computer accesses the ERP system via powerful host comupter (server) that runs ERP app; client sends requests, server responds

7
New cards

server

a special-purpose computer that runs programs that provide services to multiple other companies

8
New cards

IT control types

application controls, and IT general controls

9
New cards

application controls

controls that are part of the AIS that help ensure transactions are recorded appropriately (ex: 3 way match)

10
New cards

ITGCs

controls that are part of the underlying IT infrastructure that help ensure that this infrastructure is dependable (ex: passwords, fire suppression, ticketing systems)

11
New cards

relevance of components

if a component fails, the AIS fails; auditors must consider controls over each component

12
New cards

list of underlying components

operating system (OS), network, database (DB), and physical equipment

13
New cards

operating system

a helper; program that runs and manages other programs; performs three main tasks:

  • schedules jobs

  • allocates resources

  • interfaces w/ peripherals


14
New cards

peripherals

printers, monitors

15
New cards

networks

facilitate the exchange of information bw people and computers; the use of common physical resources (hard drives, printers)

16
New cards

local area network

cover small geographic area

17
New cards

wide area network

cover large geographic area

18
New cards

intranet

private, restricted, closed network for specific groups of people

19
New cards

internet

global, open network interconnecting a bunch of smaller networks; aka a WAN

20
New cards

nodes

computers or peripherals

21
New cards

address

used to direct data to specific computer

22
New cards

bandwidth

rates at which the carrier can transmit data

23
New cards

switch

helps configure the network to preserve BW

24
New cards

router

sends messages along the best path

25
New cards

packets

messages are chopped up into these smaller pieces

26
New cards

database

collection of information that is:

  • stores electronically

  • access electronically via ERP or direct query


27
New cards

retrieve data

data is read

28
New cards

update data

data is modified or inserted

29
New cards

database administrator

person repsonsible for managing DB resources:

  • determine how the DB is organized

  • set policies

  • secures the DB

  • performs maintenance

  • creates and maintains a data dictionary (nature of data in fields and columns)


30
New cards

logical access

electronic access to the IT environment, including each of its components; aka logging in

31
New cards

logical access risk and controls (overarching)

risk: unauthorized electronic access

controls: ITGCs that restrict access

32
New cards

Why is granting access a problem and what could happen?

current and former employees, hackers might gain unauthorized logical access to change, modify, destroy data, overwhelm resources, or install malicious programs for personal gain, bc they’re disgruntled, or moral/ethical/political stance

33
New cards

LAC - granting access

not the intended users due to insufficient processes or procedures around granting access

controls: background checks, new rights approved by admin in advance

34
New cards

test of LAC - granting access

  • inquire about the company’s policy

  • select sample of users and verify:

    • background check

    • approval

    • reasonable access = function


35
New cards

removing LAC - controls

  • access rights verified periodically by admin

  • if employee leaves or changes, HR requests access rights be modified/removed

    • access rights of inactive users are removed


36
New cards

test of LAC - removing access

  • obtain doc of periodic review of employee access

  • obtain list of terminated employees and determine whether access was removed on a timely basis

  • obtain list of users that reflects the dat of their last login


37
New cards

LAC - employee credentials

risk: log-in credentials of legit users are compromised

controls: comp requires employees have strong passwords, strong authentication process, training for phishing and social engineering

38
New cards

test of LAC - employee credentials

  • inquire about the policy regarding credentials

  • sample of users and verify passwords are strong and that strong authentication process is being used

  • inspect stored passwords and verify they are properly encrypted

    • inspect docs related to any recent education campaigns related to phishing/social engineering


39
New cards

LAC - default passwords

risk: using default PW that come with the purchased ERP system and not changing them

control: change default passwords

40
New cards

test of LAC - default pw

log in to the system w/ a known default pw and determine if access is denied

41
New cards

LAC - firewalls and IPSs

risk: able to access the company’s private intranet and transmit data across it

controls: firewalls and intrusion prevention systems are put in place to restrict access to company intranets

42
New cards

firewalls

systems of software/hardware that prevent unauthorized access to private intranets

  • looks at packet address and destination address

  • limited if spoofing address

  • stop unauthorized access


43
New cards

intrusion prevention systems

systems of software/hardware that prevent unauthorized access to private intranets

  • look at packet contents, comparing them to a DB of malicious content

  • limited if DB of malicious content is incomplete

  • identify unauthorized access


44
New cards

test of LAC - firewalls and IPSs

  • inquire and observe to determine if firewalls and IPSs have been put into place

  • have IT specialists help assess the adequacy of these programs


45
New cards

LAC - monitoring sensitive activity

risk: individuals w/ system admin or superuser access to components of the IT environment compromise security settings or take advantage of authority

controls: audit trails turned on and reviewed periodically

46
New cards

audit trails

logs of activity that deter individuals from abusing authority and allow organizations to detect unintended changes to security settings; usually autonomous feature of an OS package

47
New cards

types of audit trails

  • keystroke monitoring - tracks everything the user does

  • event monitoring - summarize key events


48
New cards

test of LAC - monitoring sensitive activity

  • obtain list of user IDs w/ system admin and determine whether level of access is appropriate given function

  • determine whether admin is logged and the accounts cannot change th elog settings or alter the logs

  • obtain evidence logs are reviewed by the comp

  • inspect the logs for unusual activity


49
New cards

LACS - mitigating damage

risk: damage to data or systems will occur following breach

controls: anti-virus software, sensitive data is encrypted

50
New cards

test of LAC - mitigating damage

  • observe whether latest version of anti-virus software is used

  • verify data is properly encrypted


51
New cards

physical access

tangible access to the IT environment, including each of its components

52
New cards

physical access risks

  • explosing from gas mains or nearby chemical facilities

  • floods

  • earthquakes

  • fires

  • heat from temp control failures

  • excessive dust or pollen

  • unauthorized personnel


53
New cards

physical controls - preventatitve

  • solid material computer center

  • located in own bldg, raised floor

  • connected to utilities via underground power lines

  • temp and humidity control systems (70-75*F, 50% humid)

  • air filtration systems

  • fire alarms

  • appropriate fire suppression system (NO sprinklers)

  • uninterruptable power supply (generator)

  • physically locked


54
New cards

auditing preventative controls

  • inspect architectural plans

  • observe computer center

  • obtain fire marshal records of fire dectection and suppression systems

  • verify systems are fault tolerant w/ backup power sources

  • observe access process

  • inspect access logs and security tape footage


55
New cards

physical controls - backup

  • once a day, create copy of DB

  • all changes to DB should be logged

  • at periodic checkpoints, comp should reconcile the log of DB changes against the DB


56
New cards

testing backup controls

  • verify backup is being performed routinely and frequently (several times a day)

  • verify the backup copies of the DB are stored off-site (separate from company location or cloud storage w/ vendor)


57
New cards

disaster recovery plan

a formal set of procedures designed to help a company survive in the event of a disaster; restoring mission critical functions

58
New cards

mutual aid pact

2+ orgs agree to help each other with their data processing needs

59
New cards

cold site (empty shell)

the company buys or leases a building that will be used as the new computer center

60
New cards

hot site (recovery operations center)

the comp has access to a fully equipped computer center, but shares w/ others (from a 3rd party vendor)

61
New cards

internally provided backup

the comp has a fully equipped computer center and owns it

62
New cards

paper assessment

employees read the plan and provide feedback

63
New cards

discussion

groups meet to talk thru the plan

64
New cards

simulation

a hypothetical disaster is presented and employees work thru how they would respond

65
New cards

parallel test

the company tries to process data via the backup system, but does not shut down the primary system

66
New cards

cutover test

primary systems are shut off and the comp tries to process data via the backup system

67
New cards

auditing the DRP

verify DRP is adequate for dealing with disasters

  • inspect comp’s list of mission critical apps for completeness

  • inquire w/ members of the recovery team to evaluate preparedness

  • inspect documentation regarding new data processing site (i.e. lease contracts, in contrast w/ hot site)


68
New cards

why do modifications result in risk?

  • programming errors —> data integrity problems

  • new programs can disrupt data processing

  • new programs don’t work well w/ existing programs

  • developers implement unauthorized changes

  • bad actors use opportunity for fraud


69
New cards

change management (CM) controls

  • initiated by users who are responsible for specifying the need met

  • evaluated and jointly authorized by IT and user supervisors

  • tested in development environment before they are implemented in the production environment

  • access to source code and configurations should be restricted

  • all changes should be logged

  • key configuration settings are reviewed periodically


70
New cards

testing CM controls

  • select sample of changes, verify changes were properly initiated, approved, and tested

  • examine change log for suspicious changes or access by unusual personnel

  • obtain documentation to see periodic review of configuration settings


71
New cards

app controls: processing

automated version of transaction processing controls that exist in more manual systems (ex: automated credit check control, enforcement of approval rules, 3 way match)

72
New cards

error messages

  • missing data checks (blanks)

  • alpha numeric checks (letters in number fields, vice versa)

  • limit check

  • validity check (value doesn’t match)

  • sign check


73
New cards

role

groups users together according to the system resources they need to perform their jobs; more than one individual can be assigned a role and each individual can have multiple roles; roles restrict access to certain modules, transactions, and permissions

74
New cards

best practices for role based access

  • no unnecessary roles

  • rules of least access (avoid separation of duties violations)

  • monitoring


75
New cards

role examples

  • user

  • manager

  • supervisor

  • read

each department (PO or AP) would have their own

76
New cards

black box approach

auditing around the computer; auditor reperforms what the system is doing w/o bothering to gain understanding of the internal workings of the system; is it behaving in an appropriate way?

77
New cards

white-box approach

auditing through the computer; gain an in-depth understanding of the internal workings of the system, the auditor can test the system more directly w/o reperformance; how does the system work?

78
New cards

configuration test

WB technique; auditor verifies the system setting or underlying program logic are appropriate given the control

  • out of the box controls - screenshot settings

  • custom controls - inspect source code


79
New cards

test data method

WB technique; the auditor initiates a transaction, sends it thru, and assesses whether system is behaving as expected

  • test of one

  • check valid and invalid transactions

  • create data and decide on environment (development vs production)

  • integrated test facility - test using data from live/real data but without interfering with the real data


80
New cards

embedded audit monitor

WB technique; audit software is added to the ERP system that automatically gathers information relevant to controls and automatically flags unusual transactions for further review (not external)