M2 S2 ISC CPA

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/63

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:29 PM on 8/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

64 Terms

1
New cards

Enterprise Resource Planning (ERP) Systems

Cross-functional systems that support different business functions and facilitates integration of information across departments (accounting, customer management, finnance, HR, inventory management)

  • Facilitates real-time communication between systems, operating under a centralized database

  • Transaction-oriented


2
New cards

Accounting Information System (AIS)

System that collects, records, stores accounting information, then complies the information using accounting rules to report both financial and non-financial information to decision makers in an enterprise

  • More specific in nature than ERP system


3 Subsystems (Modules) ←- Helps achieve objectives

  1. Transaction Processing System (TPS)

  2. Financial Reporting System (FRS)

  3. Management Reporting System (MRS)


5 Objectives:

  1. Valid transactions

  2. Properly classify transaction

  3. Recorded at correct value

  4. Recorded in correct accounting period

  5. Properly presented in f/s


3
New cards

Transaction Processing System (TPS)

Subsystem of an AIS that converts economic events into financial transactions (journal entries) and distributes the information to support daily ioperations

  • Covers three transaction cycles = Sales cycle, conversion cycle, expenditure cycle


4
New cards

Financial Reporting System (FRS)

Subsystem of an AIS that aggregates daily financial information from the TPS and other sources for infrequent events such as mergers, lawsuit settlements, natural disasters to enable timely regulatory and financial reporting

5
New cards

Management Reporting System (MRS)

Subsystem of an AIS that provides internal financial information to solve day-to-day business problems, such as budgeting, variance analysis, or cost-volume-profit analysis

6
New cards

Transaction Cycles

Core functions within an accounting department

  • Revenue cycle, purchasing and disbursement cycle, other processes that involve the recognition/ facilitation of transactions


7
New cards

Automation

Area of process improvement that describes the process of using technology to perform tasks without human intervention

  • Must understand business process thoroughly to replace it with business process automation facilitated by IT systems

  • Repetitive tasks


8
New cards

Shared Services

Area of process improvement that seeks out redundant services, combines them, and then share services within a group or organization

  • Typically involves software that is designed to process large batches of data


9
New cards

Outsourcing

Area of process improvement that is defined as the contracting of services to an external provider

  • Contractual relationship between organization and service provider

  • Supporting functions or back-office services for a fee

Risks associated with quality of service, reduced productivity, information security:

  1. Quality Risk ←- Produce/ service is defective

  2. Quality of Service ←- Poorly designed service

  3. Productivity ←- Not responsive

  4. Staff Turnover ←- Experienced/ valued staff leave org

  5. Language Skills ←- Offshoring = language barriers

  6. Security ←- Information shared with 3rd party provider

  7. Qualifications of Outsourcers ←- Credentials can be flawed

  8. Labor Insecurity ←- Fear of employees jobs’ being outsourced


10
New cards

Offshore Operations

Area of process improvement that relate to outsourcing services/ business functions to an external party in a different country

  • IT support

  • Business processes (call centers, tax compliance)

  • Software R&D

  • Knowledge processes (Requiring advanced knowledge / specialized skills)


11
New cards

Robotic Process Automation

Specific form of a business process automation that refers to the use of programs capable of extracting information from a specific user interface that can then initiate further processes based on the data extracted; a refinement of web scraping tools that scour the interent looking for specific text to collect material surronding it

  • Perform repetitive tasks that do not require skilled human labor ←- Can mimic human interaction

  • Simple, rule-based processes


12
New cards

Light Detection and Ranging (LiDAR)

Involves emitting laser pulses toward a target and measuring the time it takes to return to the sensor; example of how AI and machine learning supercharged an old technology to allow it to be successful in the advancement of self-driving cars

  • NOT RPA technology


13
New cards

Natural Language Processing (NLP) Software

Involves technology developed and sued to encode, decode, and interpret human languages so technology can perform tasks, interact with other humans, or carry out commands on other technological devices

  • Needed to build network embedded in IoT devices

  • Accounting applications = Parsing text document/ speeches made by executives to extract and catalog data


14
New cards

Neural Network

Form of technology that is modeled after neurons that facilitate the function of human or animal memory; key technology used in machine learnign applications

  • Involve:

    1. Input Layer: Different variables that feed into hidden layer

    2. Hidden Layer: Series of weights applied based on inputs selected, which directs the algorithm toward a given output

    3. Output (Results) Layer

  • Just as human responses’s change, its reactions is refined in the hidden layer by changes tp weights which yield differnt outcomes = Evidence of learning

  • Deep learning ←- Used to capture patterns in large volumes of data

  • Inference engines used in fraud detection


15
New cards

Artificial intelligence (AI)

Any system created to perform complex tasks that require human intelligence and judgement

  • Speech recognition, NLP, image recognition


16
New cards

Machine Learning (ML)

A subset of AI involving the use of algorithms and data sets supplied for computers to learn and make decisions

  • recommendation systems (e-commerce), auto-correct, predictive text input


17
New cards

Deep Learning

Subset of neural networks that is used to capture patterns in large volumes of data

  • Referred to as the “engine” of the hidden layer


18
New cards

Processing Integrity

System’s ability to initiate and complete transactions so that they are valid, accurate, completed timely, and authorized to meet a company’s objective

19
New cards

Integrity

Confidentiality and privacy of the details related to transactions involving data that identifies customers, patient health records, employees, or financial accounts

20
New cards

Deficiencies in Design

Defined by the AICPA in a SOC 2 engagement as a deficiency where necessary controls that are missing or existing controls that are not properly designed

  • Can identify of deficiency exists related to processing integrity by applying the Trust services Criteria

  • Evaluation:

    1. Understand management’s risk assessment process

    2. Evaluate link between controls in system description and Trust Services Criteria

    3. Determine if controls are in place and are being implemented

  • Can identify deficiency by using SOC 2 Report and compare to organizations system design documentation


21
New cards

Trust Services Criteria

SOC 2 Report; Can be used to assess deficiencies in design

  1. Security ← Can processes be circumvented?

  2. Availability ←- Where is data not made available/ prevented?

  3. Processing Integrity ←- Processes/ Methods that do not meet objectives

  4. Confidentiality ←- Evaluate processes/ employees who handle confidential data to identify potential data leakage

  5. Privacy ←- How is personal data used, stored, collected, disposed to identify potential data breaches

  • Controls are suitability designed if they meet criteria

    • Provide reasonable assurance that company’s system requirements & service commitments were achieved


22
New cards

ACIPA Description Criteria (SOC 2 Report)

Way to identify deficiencies in design related to processing integrity by comparing SOC 2 report to organization’s system design documentation

  • 2 items recommended to review: ←- Supports understanding of the system, services provided, and design of controls that must be disclosed by management

    1. Principle Service Commitment

    2. Principle System requirements


23
New cards

Deficiency in Operation

Deficiency in a SOC 2 engagement where a properly designed control does not operate as designed or is performed by a person who lacks authority or competence to perform control effectively

24
New cards

Test of Controls

Performed to determine if controls are operating effectively; test operating effectiveness of controls based on the trust services criteria

  • Service auditor obtains proper evidence about controls applied, consistency of application, and personnel who apply controls

    • Responsible for designing & performing test of controls ←- Inquiry, Re-perform, Observation, Review documentation

  • Change in service organization ←- Test controls before and after change

  • Deficiencies already identified = NOT required to test controls


25
New cards

COSO Internal Controls (Relating to IT Controls )

Control Activities:

  • Principle 11 - General controls over technology in order to achieve organizational objectives


Information and Communication:

  • Principle 13 - Organizations should acquire, create, and use quality information to support internal controls

  • Principle 14 - Effective communication of information is needed to support internal controls


26
New cards

Blockchain

Control system designed to govern the creation and distribution of Bitcoin

  • Bitcoin must be “mined” to confirm transactions = People perform cryptography

    • Ensures validation of crypto transaction

  • Created to prevent Bitcoin from being replicated and to limit its creation so there is a finite number

    • Resists alteration, validates bitcoin transactions, and is decentralized in nature (Can see every transaction for particular bitcoin)

    • Built in audit trail

  • Challenge = Decentralization where no organization has complete control

    • CanNOT engage service auditor to assess controls

  • 5 Components of COSO help evaluate risks associated with blockchain


27
New cards

Cryptography

Solving of complex mathematical equations

28
New cards

Avaliability

Being able to perform business functions or meet business objectives

  • System availability, human capital personnel availability


29
New cards

System Avaliability

An organization's strategic ability to recover from an incident; strategic ability to rebound

  • Having plans in place to support business resiliency, business continuity, system availability controls, crisis management, and disaster recovery.

    The business resiliency component foc

  1. Business Resiliency

  2. Business Continuity

  3. System Availability Controls

  4. Crisis Management

  5. Disaster Recovery

  6. Physical and IT Infrastructure Controls

  7. Uninterrupted Power Supply

  8. Redundancy and Backup

  9. Incident Response Plan


30
New cards

Business Resiliency

Integration of system availability controls, disaster recovery plans, business continuity plans, crisis management plans into a central set of procedures to consider whether a business can continue to operate or quickly return to operations without harm to people, information, assets; focuses on continuous operations and the ability to return to operations quickly

  • The overall integration of procedures implemented to keep operations running smoothly

  • Components

    1. Disaster Recovery (IT infrastructure disruptions)

    2. Business Continuity (Non-IT, operational, personnel functions

    3. Crisis Management (Large-scale incidents)


31
New cards

Business Continuity Plans

Comprehensive plans that have contingency mitigation procedures for business processes such as relocating employees, continuing product manufacturing, or maintaining the ability to make sales to customers in the event of a disaster. In a SOC 2® engagement, service auditors typically verify that business continuity plans are current, relevant to the organization's continuity of core operations, and reviewed periodically to make updates as the company evolves; Ability to continue delivering products/ services; operation focused

32
New cards

Disaster Recovery (DR)

Consists of an entity’s plans for restoring and continuing its IT function in the event of the destruction of program and data files and computer processing capability

  • Major component of a business resiliency program

  • Needed if processing cannot be quickly reestablished at the original processing site

  • Excluded = Short-term problems / outages


5 Steps in DR plan:

  1. Assess the risks

  2. Identify mission-critical applications and data

  3. Develop a plan for handling mission-critical applications

  4. Determine the responsibilities of the personnel involved in disaster recovery

  5. Test the disaster recovery plan


33
New cards

Cold Site

34
New cards

Warm Site

35
New cards

Hot Site

36
New cards


37
New cards

Business Impact Analysis (BIA)

Assessment that identifies business units, departments, and processes that are essential to the survival of an entity as well as the organizational impavt in the event of failute or disruption; Assessment performed to identify and assess risks in a business resiliency program

  • Identify how quickly essential business units/ processes can return to full operation

  • Identify resources needed to resume operations


High Impact (H)

Department…

  • Cannot operate without resource

  • Experiences a high recovery cost

  • Fail to meet organization’s objectives or maintain its reputation


Moderate/ Medium Impact (M)

  • Partially function temporarily

  • Experience some cost of recovery

  • Fail to meet organization’s objectives or maintain reputation


Low-Impact (L)

  • Operate for extended period of time

  • Effect on achieving objective’s or maintain reputation


Steps:

  1. Establish BIA Approach

  2. Identify Critical Resources

  3. Define Disruption Impacts

  4. Establish Losses (Assign threats probability of likelihood = ARO)

  5. Establish Recovery Priorities

  6. Create BIA Report

  7. Implement BIA Recommendations


38
New cards

Crisis Management Plans

Plans in place to lessen impact of a crisis, prootect people, protect organizational reputation, and return to operations ASAP

  • Addresses:

    1. Risk assessment of potential crises/ response

    2. Procedures for implementing plan

    3. Crisis response command center

    4. Roles & responsibilities

    5. Internal & external communication

    6. Properly train employees


39
New cards

System Availability Risk

Largest risk an organization faces

40
New cards

Monitoring

41
New cards

Replication

Copying and transferinng data

42
New cards

Annualized Rate of Occurrence (ARO)

Expected frequency of occurrences in a year

  • If an event occurs once every 15 years, then it would be 1 ÷ 15 = 0.0667.


43
New cards

Exposure Factor (EF)

The damage in terms of dollars, expresses as a % of an asset’s value


44
New cards

Single Loss Expectency (SLE)

The cost of an individual loss

  • SLE = Damaged Likelihood (EF) * Average cost of asset



45
New cards

Annualized Loss Expectancy (ALE)

The cost of a specific loss in a given year

= ALE = SLE * ARO

46
New cards

Resilience

An information system's ability to maintain essential operational capabilities even when operating under adverse conditions or stress. This means the system can continue functioning, even if at a reduced capacity, during challenging circumstances.

47
New cards
48
New cards
49
New cards


50
New cards
51
New cards
52
New cards
53
New cards
54
New cards
55
New cards
56
New cards
57
New cards
58
New cards
59
New cards
60
New cards
61
New cards
62
New cards
63
New cards
64
New cards