These are the 4 ITGC Domains
What are:
Access to Programs and Data
Change Management
Program Development
Computer Operations
What are the follow up items from an interview commonly referred to and how quickly should you send them out?
What are action items and what is immediately following the interview?
This is the risk that audit procedures will fail to detect material misstatement.
What is audit risk?
Batch Jobs are monitored for failure daily.
What is Computer Operations?
Best Practice is to replicate this often
What is every 15 minutes?
These are the different layers of an IT environment.
What are Network, Operating System, Application, and Database layers?
Name two of the 5 ways an interview can be held.
What are:
- Face-to-Face
- WebEx
- Video Call
- Phone
These two risk make up the risk of material misstatement.
What is Inherent Risk and Control Risk?
Requests for New Access must be approved by IT and user's supervisor
What is Access to Programs and Data?
A full blue circle indicates this status for an EGA.
The controls restricting developers from accessing production code would be included in this domain
What is Program Changes?
These are the 3 phases of effective interviewing.
What are:
Prepare for the Interview
Conduct the Interview
Take Action
When the risk of material misstatement is higher, the audit procedures should be _________.
What is increased?
New system developments are designed using the Business Requirements Document.
What is Program Development?
This is where you go to find all of the EGAs assigned to you
What is the Dashboard view?
Of the following domains, this domain is considered more risky: Access to Programs and Data or Computer Operations
Why?
What is Access to Programs and Data?
In general Access to Programs and Data will contain higher risk controls. Access to Programs and Data often relate to restricted access of financial data or appropriate segregation of duties. While back ups and job scheduling, and the help desk function are important activities they are typically farther from the financial data.
During the interview "Joe" thought this actor was cute in the Avengers Movie. (Note: Remembering key interviewing details is important)
Who is Chadwick Boseman?
These are the audit teams that are responsible for considering risk.
What are all audit teams?
An IT Director reviews all changes to production code on a weekly basis
What is Change Management?
This is the real time Aura version
What is Aura Online?
This is the primary reason we test ITGCs
What is to ensure the continued operating effectiveness of application controls and automated accounting procedures?
These are examples of benefits of providing an agenda prior to the interview
What is:
- Everyone is more prepared
- To ensure you cover all relevant topics
- To refer to after the meeting
When comparing two entities who provide the same products or services, this will be a consideration in assessing risk.
What is Industry?
Daily back ups are performed for all systems
What is Computer Operations?
This view in Aura is where you document test results of controls
What is Execute View?