ISC

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/13

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

14 Terms

1
New cards

5 components of COSO framework

CRIME

Control environment

Risk assessment

Info and communication

Monitoring activities

Existing control activities

2
New cards

SOC 1

  • Internal controls financial reporting (ICFR)

  • Type 1 or 2

  • Restricted: service org mgmt, user entities, auditors

  • No “potential” users

3
New cards

SOC 2

  • CAPPS controls; S mandatory

  • Trust Services Criteria (TSC)

  • Type 1 or 2

  • Restricted: service org mgmt and other specified parties

  • Test of controls description/results

4
New cards

SOC 3

  • CAPPS controls

  • TSC for general use

  • Type 2 only

  • Nonrestricted

  • No description of system and no test of controls description/results

5
New cards

CAPPS controls

  • Confidential: maintain protected info

  • Available: operating systems

  • Processing integrity: inputs/outputs

  • Privacy: personal info collected/used/retained/disposed

  • Security: against unauthorized access

6
New cards

Type 1 SOC report

  • Specified date

  • Fairness of mgmt description

  • Control design

  • No test of controls description & results

7
New cards

Type 2 SOC report

  • Throughout period

  • Fairness of mgmt description

  • Control design & operating effectiveness

  • Test of controls description & results

8
New cards

SOC 2, Type 1

SOC 2, Type 2

SOC 3, Type 2

  • S2, T1: design only, NO op effectiveness and NO test of controls/result

  • S2, T2: design, op effectiveness, and test of controls/results

  • S3: design and op effectiveness, but NO test of controls/results

9
New cards

Control environment principles

EBOCA

  • Ethics & integrity

  • Board independence & oversight

  • Org structure

  • Commitment to competence

  • Accountability

10
New cards

Risk assessment principles

SAFR

  • Specify objectives

  • Assess changes

  • Fraud potential

  • Risks analyzed

11
New cards

Info & communication principles

OIE & FACT

12
New cards
13
New cards
14
New cards