Chapter 15—IT Controls Part I: Sarbanes–Oxley and IT Governance
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their organization’s
internal controls over financial reporting.
ANS: F PTS: 1
2. Both the SEC and the PCAOB requires management to use the COBIT framework for assessing internal
control adequacy.
ANS: F PTS: 1
3. Both the SEC and the PCAOB requires management to use the COSO framework for assessing internal
control adequacy.
ANS: F PTS: 1
4. A qualified opinion on management’s assessment of internal controls over the financial reporting system
necessitates a qualified opinion on the financial statements?
ANS: F PTS: 1
5. The same internal control objectives apply to manual and computer-based information systems.
ANS: T PTS: 1
6. To fulfill the segregation of duties control objective, computer processing functions (like authorization
of credit and billing) are separated.
ANS: F PTS: 1
7. To ensure sound internal control, program coding and program processing should be separated.
ANS: T PTS: 1
8. Some systems professionals have unrestricted access to the organization’s programs and data.
ANS: T PTS: 1
9. Application controls apply to a wide range of exposures that threaten the integrity of all programs
processed within the computer environment.
ANS: F PTS: 1
10. The Database Administrator should be separated from systems development.
ANS: T PTS: 1
11. A disaster recovery plan is a comprehensive statement of all actions to be taken after a disaster.