CISA: Domain #2, Part A: IT Governance
All documents for this subject (37)
Seller
Follow
lydiaomutho
Content preview
BEC CPA Exam
COSO Framework assists Management and the Board of Directors by: - ANS-Effectively
applying Internal Control
Determining the requirements of an effective system
Allow judgement and flexibility in the design of I/C
Identify and analyze risks, and develop effective responses
Eliminate redundant, ineffective, or inefficient controls
Extend I/C application beyond financial reporting
Three Objective of COSO Framework - ANS-Operations, Reporting, Compliance Objectives
Operations Objective - ANS-The effectiveness and efficiency of an entity's operations. Include
operational and financial performance goals, as well as safeguarding assets
Reporting Objective - ANS-Reliability, timeliness, and transparency of an entity's external and
internal financial and non-financial reporting
Financial Reporting Objective - ANS-- Make sure financial statements are reported fairly in
accordance with GAAP
- Present relevant and material information
Financial Reporting Risks - ANS-- Risk that financial statements are not in accordance with
GAAP
Fraud Risk - ANS-- Represents risk of material misstatement as a result of fraud
Compliance Objective - ANS-Entity is adhering to all applicable laws and regulations
COSO Components of I/C - ANS-Control Environment
Risk Assessment
Information and Communication
Monitoring
Existing Control Activities
COSO Component - Control Environment - ANS-Processes, structures, and standards that
provide the foundation for an entity to establish a system of I/C.
Established through "tone at the top"
-Commit to ethics/integrity
-Board independence/oversight
-Organizational structure
-Commit to competence
COSO Component - Information and Communication - ANS-Support identification, capture, and
exchange of information in a timely/useful manner.
-Obtain and Use info
-Internal Communication
-External Communication
Obtain and Use information - ANS-Entity obtains/generates or and uses relevant, high quality
information to support function of I/C
COSO Component - Monitoring Activities - ANS-Process of Assessing the quality of I/C
performance over time by assessing design/operation of controls, and taking necessary
corrective action
- Ongoing separate evaluations
- Communication of deficiencies
COSO Component - Existing Control Activities - ANS-Set forth by entity's policies and
procedures to ensure management directives are in place
-Select/Develop I/C activities,
-Technology controls
-Deploy through policy/procedure
Enterprise Risk Management - ANS-COSO issued ERM, to assist organizations in developing
responses to risk. Apply strategy across enterprise to ID events, manage risk appetite, provide
reasonable assurance
-All entity's exist to create SH value
-Intent is to effectively deal with uncertainty, evaluate risk, build value
-Value Maximized when strategy balances risk/return and efficiency/effectiveness
ERM objectives - ANS-Strategic - high level goals to achieve mission
Operations - achieve objectives, effective/efficient use
Reporting- Reliable/consistent reporting
Compliance- Laws/Regulations
ERM Components - ANS-- Internal Environment
- Set Objectives
- Event ID
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller lydiaomutho. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $7.99. You're not tied to anything after your purchase.