Chapter 7Controlling Information Systems: Introduction to
Enterprise Risk Management and Internal Control Key
1. Organizational governance is a process by which organizations select objectives, establish processes to
achieve objectives, and monitor performance.
2. Fraud is the possibility that an event or action will cause an organization to fail to meet its objectives (or
goals).
3. Management is responsible for establishing and maintaining an adequate system of internal control.
4. A major reason management must exercise control over an organization’s business processes is to provide
reasonable assurance that the company is in compliance with applicable laws and regulations.
5. Expected gross risk is a function of the initial expected gross risk, reduced risk exposure due to controls, and
cost of controls.
6. Under the Sarbanes Oxley Act of 2002, the section on Auditor Independence establishes an independent
board to oversee public company audits.
7. Under the Sarbanes Oxley Act of 2002, the section on Corporate Responsibility requires a company’s CEO
and CFO to certify quarterly and annual reports.
8. Under the Sarbanes Oxley Act of 2002, the section on Enhanced Financial Disclosures requires each annual
report filed with the SEC to include an internal control report.
9. Under the Sarbanes Oxley Act of 2002, the section on Corporate Tax Returns conveys a sense of the Senate
that the corporate federal income tax returns be signed by the treasurer.
10. Management’s legal responsibility to prevent fraud and other irregularities is implied by laws such as the
Foreign Corrupt Practices Act.
11. Risks are those events that could have a negative impact on organization objectives.
12. Opportunities are events that could have a positive impact on organization objectives.
13. Risk assessment is the entity’s identification and analysis of relevant risks to the achievement of its
objectives, forming a basis for determining how the risks should be managed.
14. The control environment reflects the organization’s general awareness of and commitment to the importance
of control throughout the organization.
15. External directives are the policies and procedures that help ensure that management directives are carried
out.
16. Establishing and maintaining a viable internal control system is the responsibility of management.
17. Monitoring is a process that assesses the quality of internal control performance over time.
18. The external environment is a system of integrated elements¾people, structures, processes, and
procedures¾acting together to provide reasonable assurance that an organization achieves both its operations
system and its information system goals.
19. A fraud is a deliberate act or untruth intended to obtain unfair or unlawful gain.
20. SAS No. 99 emphasizes auditors should brainstorm fraud risks, increase professional skepticism, use
unpredictable audit test patterns, and detect management override of internal controls.
21. According to the 2008 Report to the Nation on Occupational Fraud and Abuse, frauds are more likely to be
detected by audits or internal controls than through tips.
22. A computer crime technique called worm involves the systematic theft of very small amounts from a
number of bank or other financial accounts.
23. A computer abuse technique called a back door involves a programmer’s inserting special code or passwords
in a computer program that will allow the programmer to bypass the security features of the program.
24. A logic bomb is a computer abuse technique in which unauthorized code is inserted in a program, which,
25. Salami slicing is program code that can attach itself to other programs (i.e., “infect” those programs), that
can reproduce itself, and that operates to alter the programs or to destroy data.
26. Ethical behavior and management integrity are products of the “corporate culture”.
27. The control matrix is a computer virus that takes control of the computer’s operating system for malicious
purposes.
28. The control goal called efficiency of operations strives to assure that a given operations system is fulfilling
the purpose(s) for which it was intended.
29. Ensuring the security of resources is the control goal that seeks to provide protection of organization’s
resources from loss, destruction, disclosure, copying, sale, or other misuse of an organization’s resources.
30. The control goal of ensuring input materiality strives to prevent fictitious items from entering an
information system.
31. Valid input data are appropriately authorized and represent actual economic events and objects.
32. The control goal of input accuracy is concerned with the correctness of the transaction data that are entered
into a system.
33. Business process control plans relate to those controls particular to a specific process or subsystem, such as
billing or cash receipts.
34. A sale to a customer is entered into the system properly, but the event does not accurately update the
customer’s outstanding balance. This type of processing error would be classified as a user error.
35. A batch of business events is accurately entered into a business event data store, but the computer operator
fails to use the data to update master data. This type of processing error would be classified as an operational
error.
36. A corrective control plan is designed to discover problems that have occurred.
37. A process by which organizations select objectives, establish processes to achieve objectives, and monitor
performance is:
38. A process, effected by an entity’s board of directors, management and other personnel, applied in strategy
settings and across the enterprise, designed to identify potential events that may effect the entity, and manage
risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives
is:
39. A manager of a manufacturing plant alters production reports to provide the corporate office with an inflated
perception of the plant’s cost effectiveness in an effort to keep the inefficient plant from being closed. This
action would be classified as a(n):
40. The ERM framework addresses four categories of management objectives. Which category concerns high-
level goals, aligned with and supporting its mission?
A. Compliance
41. The ERM framework addresses four categories of management objectives. Which category addresses the
effective and efficient use of resources?
42. The ERM framework addresses four categories of management objectives. Which category addresses the
reliability of the financial statements?
43. The ERM framework addresses four categories of management objectives. Which category of concerns laws
and regulations?
44. The ERM framework is comprised of eight components. Which component includes the policies and
procedures established and implemented to help ensure the risk responses are effectively carried out?
45. Risk assessment is best described by:
A. Internal and external events affecting achievement of an entity’s objectives must be identified, distinguishing
between risks and opportunities.
46. Which component of the ERM framework is best described here: Management selects whether to avoid,
accept, reduce, or share risk – developing a set of actions to align risks with the entity’s risk tolerances and risk
appetite.
A. control activities
47. Which component of the ERM framework is best described here: Internal and external events affecting
achievement of an entity’s objectives must be identified, distinguishing between risks and opportunities.
Opportunities are channeled back to management’s strategy or objective-setting processes.
48. This component of the ERM framework that encompasses the tone of an organization and sets the basis for
how risk is viewed and addressed by an entity’s people, including risk management philosophy and risk
appetite, integrity and ethical values and the environment in which they operate
49. This component of the ERM framework concerns the entirety of enterprise risk management and is
accomplished through ongoing management activities, separate evaluations, or both.
50. Approvals, authorizations, verifications, reconciliations, reviews of operating performance, security
procedures, supervision, audit trails, and segregation of duties are examples of:
51. Events that could have a negative impact on organizational objectives:
A. Controls
52. Events that could have a positive impact on organizational objectives:
53. Who is legally responsible for establishing and maintaining an adequate system of internal control?
A. the board of directors
54. The major reasons for exercising control of the organization’s business processes include:
A. to provide reasonable assurance that the goals of the business are being achieved
55. The effect of an event’s occurrence is:
56. The section of Sarbanes Oxley that establishes an independent board to oversee public company audits is:
57. The section of Sarbanes Oxley that prohibits a CPA firm that audits a public company from engaging in
certain nonaudit services with the same client is:
58. The section of Sarbanes Oxley that requires a company’s CEO and CFO to certify quarterly and annual
reports is:
59. The section of Sarbanes Oxley that requires each annual report filed with the SEC to include an internal
control report is:
A. Title I – Public Company Accounting Oversight Board
60. The section of Sarbanes Oxley that requires financial analysts to properly disclose in research reports any
conflicts of interest they might hold with the companies they recommend is:
61. The section of Sarbanes Oxley that makes it a felony to knowingly destroy, alter, or create records and or
documents with the intent to impede, obstruct, or influence an ongoing or contemplated federal investigation
and offers legal protection to whistle blowers is:
62. The section of Sarbanes Oxley that sets forth criminal penalties applicable to CEOs and CFOs of up to $5
million and up to 20 years imprisonment if they knowingly or willfully certify false or misleading information
contained in periodic reports is:
A. Title V – Analysts Conflicts of Interests
63. The section of Sarbanes Oxley that provides for fines and imprisonment of up to 20 years to individuals who
corruptly alter, destroy, mutilate, or conceal documents with the intent to impair the document’s integrity or
availability for use in an official proceeding, or to otherwise obstruct, influence or impede any official
proceeding is:
A. Title V – Analysts Conflicts of Interests
64. Which of the following is not a requirement of SOX Section 404?
A. Evaluate the design of the company’s controls to determine if they adequately address the risk that a material
misstatement of the financial statements would not be prevented or detected in a timely manner.
65. This framework was issued in 1996 (and updated in 2007) by the Information Systems Audit and Control
Association (ISACA) because of the influence of IT over information systems, financial reporting and auditing.
D. All of the above.
66. As described in COSO, elements of a control environment might include the following:
A. commitment to the importance of control
67. ____ are the policies and procedures that help ensure that the risk responses are effectively carried out.
A. Control environment
68. ____ is a process that evaluates the quality of internal control performance over time.
A. Control environment
69. Which of the following statements regarding a system of internal control is false?
D. The development of an internal control system is the responsibility of management.
70. ____ sets the tone of the organization, influencing the control consciousness of its people.
D. Monitoring
71. According to the 2008 Report to the Nation on Occupational Fraud and Abuse, frauds are more likely to be
detected by:
A. audits
72. A deliberate act or untruth intended to obtain unfair or unlawful gain is a(n):
73. A computer abuse technique called a ____ involves inserting unauthorized code in a program, which, when
activated, may cause a disaster, such as shutting the system down or destroying files.
74. A computer abuse technique called a ____ involves a virus that replicates itself on disks, in memory, or
across networks.
75. A(n) ____ is a computer abuse technique where unauthorized instructions are inserted into a program to
systematically steal very small amounts, usually by rounding to the nearest cent in financial transactions.
76. A control goal that is a measure of success in meeting a set of established goals is called:
77. Establishing a viable internal control system is primarily the responsibility of:
78. As a result of an inadequate design, a production process yields an abnormally high amount of raw material
scrapped. Which control goal is being violated?
79. The information process control goal which relates to preventing fictitious events from being recorded is
termed:
D. ensure effectiveness of operations
80. A business event which is not properly authorized is an example of:
81. Achieving which control goal requires that all valid objects or events are captured and entered into a
system’s database once and only once?
A. ensure input validity
82. Failing to record a customer’s order for the purchase of inventory violates the control goal of:
83. Discrepancies between data items recorded by a system and the underlying economic events or objects they
represent are a violation of the control goal of:
84. Assuring that the accounts receivable master data reflects all cash collections recorded in the cash receipts
event data addresses the control goal of:
A. ensure input accuracy
85. Assuring that cash collections recorded in the cash receipts event data are credited to the right customer in
the accounts receivable master data addresses the control goal of:
A. ensure input accuracy
86. Which of the following is a control goal regarding master data?
D. ensure input completeness
87. Why is there usually no control goal called update validity?
88. A programming error causes the sale of an inventory item to be added to the quantity on hand attribute in
the inventory master data. Which control goal was not achieved?
A. ensure update completeness
89. The business process objectives that an internal control system is designed to achieve are:
90. These are applied to all IT service activities.
91. A tool designed to assist you in evaluating the potential effectiveness of controls in a business process by
matching control goals with relevant control plans is:
92. Information-processing policies and procedures that assist in accomplishing control goals are known as:
93. ____ relate to a specific AIS process, such as billing or cash receipts.
94. Control plans that relate to a multitude of goals and processes are called:
95. Control goals of operations processes include:
A. validity
96. Controls that stop problems from occurring are called:
97. A control that involves reprocessing transactions that are rejected during initial processing is an example of:
98. A process captures only authorized transactions but fails to record them only once. Which control goal does
this fail to achieve?
A. Validity
99. The correct sequence of the control hierarchy, from top to bottom, is:
100. ______________________________ is a process, effected by an entity’s board of directors, management
and other personnel, applied in strategy settings and across the enterprise, designed to identify potential events
that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance
regarding the achievement of entity objectives.
101. ______________________________ is a process by which organizations select objectives, establish
processes to achieve objectives, and monitor performance.