Governance and Risk Management
COSO Frameworks
IT Controls Overview
IT Application Controls
College Football Potpourri
100
A process conducted by the board of directors to authorize, direct and oversee management toward the achievement of the organization’s objectives.
What is GOVERNANCE
100
Common name for the National Commission on Fraudulent Financial Reporting, chaired by James C. Treadway, Jr.
What is COSO?
100
IT-related controls that span the entire IT function and impact the confidentiality, integrity and availability of all IT systems.
What are GENERAL CONTROLS (or GCCs)
100
THREE areas that IT application controls typically fall into.
What are (1) INPUT, (2) PROCESSING, (3) OUTPUT
100
LARGEST college football stadium.
What is MICHIGAN STADIUM?
200
"The possibility that an event will occur and adversely affect the achievement of an objective.”
What is RISK
200
“A process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”
What is COSO's DEFINITION OF ENTERPRISE RISK MANAGEMENT (ERM)?
200
Controls that eliminate the likelihood of instances of non-compliance from occurring.
What are PREVENTIVE CONTROLS?
200
Signature or initials to indicate someone authorized the event. Ensures data input arises from a valid business event and appropriate authorizations have been obtained.
What are APPROVALS?
200
College football program with highest winning percentage all time (teams with over 600 wins)
Who are MICHIGAN WOLVERINES?
300
A life cycle set of activities used to identify, analyze and treat risks.
What is RISK MANAGEMENT
300
The four risk response strategies that management may use to ensure that the risk portfolio is aligned with risk appetite and risk tolerance
What are (1) AVOIDANCE, (2) ACCEPTANCE, (3) SHARING / TRANSFERENCE, (4) REDUCTION / MITIGATION?
300
THREE forms of authenticating you are who you say you are.
What are (1) SOMETHING YOU KNOW, (2) SOMETHING YOU HAVE, (3) SOMETHING YOU ARE?
300
Input controls that identifies when data in a particular field are in wrong format.
What are NUMERIC-ALPHABETIC CHECKS?
300
Team which holds the NCAA record for most consecutive Top 5 finishes
What is FLORIDA STATE UNIVERSITY (14 years in a row: 1987 - 2000)?
400
"The amount of variance in a particular risk that management is willing to allow" VS. "the amount of risk that an enterprise is willing to take on in pursuit of its goals and objectives."
What is the difference between RISK TOLERANCE and RISK APPETITE?
400
The FIVE inter-related components of COSO's Internal Control Framework (ICF)
What are (1) CONTROL ENVIRONMENT, (2) RISK ASSESSMENT, (3) CONTROL ACTIVITIES, (4) INFORMATION & COMMUNICATION, (5) MONITORING
400
FOUR environments typically seen in a well-controlled change management infrastructure.
What are (1) DEV, (2) QA/TEST, (3) STAGING, (4) PROD
400
Processing controls that use a sum of any numeric data existing for all batch documents, such as a total of customer numbers or purchase order numbers. Can determine if inputs have been altered (accuracy) , added (validity), or deleted (completeness).
What are HASH TOTALS?
400
Competitors in first inter-collegiate college football game.
Who are PRINCETON and RUTGERS (1869)?
500
The 5 Generic Steps / Processes in a basic Risk Management Framework
What are (1) Asset Identification, (2) Threat Quantification / Qualification, (3) Vulnerability Assessment, (4) Controls Gap Remediation, (5) Residual Risk Treatment
500
The EIGHT inter-related components of COSO's ERM Framework.
What are (1) INTERNAL ENVIRONMENT, (2) OBJECTIVE SETTING, (3) EVENT IDENTIFICATION, (4) RISK ASSESSMENT, (5) RISK RESPONSE, (6) CONTROL ACTIVITIES, (7) INFORMATION & COMMUNICATION, (8) MONITORING
500
Three most important GCCs
What are (1) PHYSICAL AND LOGICAL SECURITY, (2) CHANGE MANAGEMENT, (3) DISASTER RECOVERY / BUSINESS CONTINUITY
500
An output file where applications often direct their output to a disk initially, to be printed later when the printer becomes available.
What is a SPOOL FILE or SPOOLING?
500
THREE universities where John Heisman coached FOOTBALL.
What are (1) Oberlin College, (2) University of Akron, (3) Auburn, (4) Clemson, (5) Georgia Tech, (6) University of Pennsylvania, (7) Washington & Jefferson College, (8) Rice University