Risk Management
Compliance
Audit Processes
IT Controls
Cincinnati Trivia
100

What are 3 types of IT risks?

Data breaches, system downtime, malware attack, inappropriate access, etc.

100

The purpose of an IT Audit is to..

To evaluate the effectiveness of IT controls and compliance with policies.

100

The first step in an IT audit is..

Planning and scoping.

100

What is an IT Control (description not examples)

A policy or procedure in place to ensure the integrity and security of IT systems.

100

What is Cincinnati's famous style of chili called?

Cincinnati Chili

200

What is risk management?

The process of identifying, analyzing, and evaluating risks.

200

SOX stands for..

Sarbanes-Oxley Act.

200

Auditing of IT systems ensures..

Adherence to policies and regulations.

200

What type of control helps prevent unauthorized access to systems?

Access controls help prevent unauthorized access to systems by requiring users to authenticate their identity.

200

What is the name of Cincinnati's major league soccer team?

FC Cincinnati

300

How is risk management related to IT audit?

Both aim to identify, assess, and mitigate risks within the organizations IT environment.

300

Why is compliance crucial for our department?

Compliance ensures that we adhere to laws, regulations, and industry standards, thereby safeguarding the organization from legal penalties, enhancing operational efficiency, and maintaining stakeholder trust.

300

The primary purpose of an IT audit is to what?

Evaluate the effectiveness, efficiency, and security of an organization's IT systems and controls, ensuring they meet regulatory requirements and support business objectives. 

300

Segregation of duties refers to what?

SOD refers to dividing responsibilities among different individuals to reduce the risk of fraud and errors.

300

What annual festival celebrates Cincinnati's German heritage?

Oktoberfest Zinzinnati

400

Why is it important to assess risks in IT?

To understand their potential impact and prioritize actions to mitigate them. 

400

Why are regular IT audits important?

Identify vulnerabilities, ensure compliance, improve overall effectiveness over IT governance, etc.

400

What is the purpose if an audit report?

The purpose of the audit report is to summarize the findings and recommendations from the audit, providing insights for improving IT systems and controls.

400

What is an example of a physical IT control?

An example of a physical IT control is security cameras that monitor access to server rooms.

400

What famous ice cream brand originated in Cincinnati?

Graeter's Ice Cream

500

How does the IT audit process help with risk management?

By identifying potential risks and vulnerabilities in IT systems, evaluating the effectiveness of existing controls, and providing recommendations to mitigate those risks and enhance overall security.

500

Why is EY's role crucial for us as Internal Auditors?

They provide an unbiased and specialized assessment of the organizations IT systems, HELPING us identify overlooked risks, ensure regulatory compliance, and improve overall IT governance.

500

What form is used for documenting all controls and control updates for the entire IT audit department?

The 302 file.

500

Why should IT controls be regularly updated? (Think 302 Updates)

IT controls should be regularly updated to keep up with new security threats and ensure they remain effective.

500

What famous bridge connects Cincinnati to Covington?

The John A Roebling Suspension Bridge