Chapter 15IT Controls Part I: SarbanesOxley and IT Governance
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their organization’s
internal controls over financial reporting.
ANS: F PTS: 1
2. Both the SEC and the PCAOB requires management to use the COBIT framework for assessing internal
control adequacy.
ANS: F PTS: 1
3. Both the SEC and the PCAOB requires management to use the COSO framework for assessing internal
control adequacy.
ANS: F PTS: 1
4. A qualified opinion on management’s assessment of internal controls over the financial reporting system
necessitates a qualified opinion on the financial statements?
ANS: F PTS: 1
5. The same internal control objectives apply to manual and computer-based information systems.
ANS: T PTS: 1
6. To fulfill the segregation of duties control objective, computer processing functions (like authorization
of credit and billing) are separated.
ANS: F PTS: 1
7. To ensure sound internal control, program coding and program processing should be separated.
ANS: T PTS: 1
8. Some systems professionals have unrestricted access to the organization’s programs and data.
ANS: T PTS: 1
9. Application controls apply to a wide range of exposures that threaten the integrity of all programs
processed within the computer environment.
ANS: F PTS: 1
10. The Database Administrator should be separated from systems development.
ANS: T PTS: 1
11. A disaster recovery plan is a comprehensive statement of all actions to be taken after a disaster.
ANS: T PTS: 1
12. IT auditing is a small part of most external and internal audits.
ANS: F PTS: 1
13. Assurance services is an emerging field that goes beyond the auditor’s traditional attestation function.
ANS: T PTS: 1
14. An IT auditor expresses an opinion on the fairness of the financial statements.
ANS: F PTS: 1
15. External auditing is an independent appraisal function established within an organization to examine and
evaluate its activities as a service to the organization.
ANS: F PTS: 1
16. External auditors can cooperate with and use evidence gathered by internal audit departments that are
organizationally independent and that report to the Audit Committee of the Board of Directors.
ANS: T PTS: 1
17. Tests of controls determine whether the database contents fairly reflect the organization’s transactions.
ANS: F PTS: 1
18. Audit risk is the probability that the auditor will render an unqualified opinion on financial statements
that are materially misstated.
ANS: T PTS: 1
19. A strong internal control system will reduce the amount of substantive testing that must be performed.
ANS: T PTS: 1
20. Substantive testing techniques provide information about the accuracy and completeness of an
application’s processes.
ANS: F PTS: 1
MULTIPLE CHOICE
1. Which of the following is NOT an implication of section 302 of the Sarbanes-Oxley Act?
a.
Auditors must determine, whether changes in internal control has, or is likely to, materially
affect internal control over financial reporting.
b.
Auditors must interview management regarding significant changes in the design or
operation of internal control that occurred since the last audit.
c.
Corporate management (including the CEO) must certify monthly and annually their
organization’s internal controls over financial reporting.
d.
Management must disclose any material changes in the company’s internal controls that
have occurred during the most recent fiscal quarter.
ANS: C PTS: 1
2. Which of the following is NOT a requirement in management’s report on the effectiveness of internal
controls over financial reporting?
a.
A statement of management’s responsibility for establishing and maintaining adequate
internal control user satisfaction.
b.
A statement that the organizations internal auditors has issued an attestation report on
management’s assessment of the companies internal controls.
c.
A statement identifying the framework used by management to conduct their assessment of
internal controls.
d.
An explicit written conclusion as to the effectiveness of internal control over financial
reporting.
ANS: B PTS: 1
3. In a computer-based information system, which of the following duties needs to be separated?
a.
program coding from program operations
b.
program operations from program maintenance
c.
program maintenance from program coding
d.
all of the above duties should be separated
ANS: D PTS: 1
4. Supervision in a computerized environment is more complex than in a manual environment for all of the
following reasons except
a.
rapid turnover of systems professionals complicates management’s task of assessing the
competence and honesty of prospective employees
b.
many systems professionals have direct and unrestricted access to the organization’s
programs and data
c.
rapid changes in technology make staffing the systems environment challenging
d.
systems professionals and their supervisors work at the same physical location
ANS: D PTS: 1
5. Adequate backups will protect against all of the following except
a.
natural disasters such as fires
b.
unauthorized access
c.
data corruption caused by program errors
d.
system crashes
ANS: B PTS: 1
6. Which is the most critical segregation of duties in the centralized computer services function?
a.
systems development from data processing
b.
data operations from data librarian
c.
data preparation from data control
d.
data control from data librarian
ANS: A PTS: 1
7. Systems development is separated from data processing activities because failure to do so
a.
weakens database access security
b.
allows programmers access to make unauthorized changes to applications during execution
c.
results in inadequate documentation
d.
results in master files being inadvertently erased
ANS: B PTS: 1
8. Which organizational structure is most likely to result in good documentation procedures?
a.
separate systems development from systems maintenance
b.
separate systems analysis from application programming
c.
separate systems development from data processing
d.
separate database administrator from data processing
ANS: A PTS: 1
9. All of the following are control risks associated with the distributed data processing structure except
a.
lack of separation of duties
b.
system incompatibilities
c.
system interdependency
d.
lack of documentation standards
ANS: C PTS: 1
10. Which of the following is not an essential feature of a disaster recovery plan?
a.
off-site storage of backups
b.
computer services function
c.
second site backup
d.
critical applications identified
ANS: B PTS: 1
11. A second site backup agreement between two or more firms with compatible computer facilities to assist
each other with data processing needs in an emergency is called
a.
internally provided backup
b.
recovery operations center
c.
empty shell
d.
mutual aid pact
ANS: D PTS: 1
12. The major disadvantage of an empty shell solution as a second site backup is
a.
the host site may be unwilling to disrupt its processing needs to process the critical
applications of the disaster stricken company
b.
intense competition for shell resources during a widespread disaster
c.
maintenance of excess hardware capacity
d.
the control of the shell site is an administrative drain on the company
ANS: B PTS: 1
13. An advantage of a recovery operations center is that
a.
this is an inexpensive solution
b.
the initial recovery period is very quick
c.
the company has sole control over the administration of the center
d.
none of the above are advantages of the recovery operations center
ANS: B PTS: 1
14. For most companies, which of the following is the least critical application for disaster recovery
purposes?
a.
month-end adjustments
b.
accounts receivable
c.
accounts payable
d.
order entry/billing
ANS: A PTS: 1
15. The least important item to store off-site in case of an emergency is
a.
backups of systems software
b.
backups of application software
c.
documentation and blank forms
d.
results of the latest test of the disaster recovery program
ANS: D PTS: 1
16. Some companies separate systems analysis from programming/program maintenance. All of the
following are control weaknesses that may occur with this organizational structure except
a.
systems documentation is inadequate because of pressures to begin coding a new program
before documenting the current program
b.
illegal lines of code are hidden among legitimate code and a fraud is covered up for a long
period of time
c.
a new systems analyst has difficulty in understanding the logic of the program
d.
inadequate systems documentation is prepared because this provides a sense of job security
to the programmer
ANS: C PTS: 1
17. All of the following are recommended features of a fire protection system for a computer center except
clearly marked exits
b.
an elaborate water sprinkler system
c.
manual fire extinguishers in strategic locations
a.
evaluating internal controls
b.
preparing financial statements
c.
expressing an opinion
d.
analyzing financial data
Auditors must maintain independence.
IT auditing is independent of the general financial audit.
d.
IT auditing can be performed by both external and internal auditors.
IT audits
b.
evaluation of operational efficiency
d.
internal auditors perform all of the above tasks