COBIT refers to
Blog
IT auditing involves
IT auditing involves
Jeff is considering insuring against cyberattack that may le…
Jeff is considering insuring against cyberattack that may lead to damage to computer equipment risk. His company is currently valued at $50,000 (estimated wealth). If he suffers damage, he will likely lose $25,000 of his company’s wealth. If he gets insurance, then the insurance will cost (premium) $1000 and a payout in case of damages of $26,000. He knows from his IT Analyst that the expected value of his company’s wealth without insurance can be calculated aswhile with insurance can be calculated aswhere W = wealth, L = loss due to damages, A = insurance payout, b = insurance premium, =likelihood of attack. Given that attack happens with a probability of 0.4, what is the expected value of his company’s wealth with and without insurance?
Tools used to identify risks include all of the following ex…
Tools used to identify risks include all of the following except
What is not considered a form of documentation in a system i…
What is not considered a form of documentation in a system implementation?
The financial operations required at month-end for closing r…
The financial operations required at month-end for closing reasons guarantee that specific transactions in one application system align with the general ledger postings. Which sort of application risk do they mitigate?
COBIT’s generally accepted IT practices or control objective…
COBIT’s generally accepted IT practices or control objectives help employees, managers, executives, and auditors in:
There are three types of changes: X, Y, and Z. X changes typ…
There are three types of changes: X, Y, and Z. X changes typically have minimal impact on daily operations and can be implemented or backed out quickly and easily. Y changes potentially have a greater impact on operations. They frequently affect many users and typically have lengthy, complex implementation and back-out procedures. Z change is any change, major or minor, that must be made quickly without following standard change control procedures. Management must approve such changes before they are undertaken or implemented.What are X, Y, and Z?
The breadth and depth of knowledge required to audit IT and…
The breadth and depth of knowledge required to audit IT and systems are extensive and may include
According to X, Y is a process effected by an entity’s board…
According to X, Y is a process effected by an entity’s board of directors, management, and other personnel, applied in strategy settings and across the enterprise. It is designed to identify potential events that may affect the entity, manage risks within its risk appetite, and provide reasonable assurance regarding the achievement of entity objectives.What are X and Y?