Show Menu
Cheatography

Acct AIS Cheat Sheet (DRAFT) by

AIS section - cheat sheet

This is a draft cheat sheet. It is a work in progress and is not finished yet.

AIS

Control Activities
 
preven­tative
 
detective
 
corrective
Control Frame Works
 
COBIT
Control Objectives for Inform­ation and Related Technology
NIST
US National Institute of Standards and Technology
HIPPA
Health Insurance Portab­ility and Accoun­tab­ility Act
PCI DSS
Payment Card Industry Data Security Standard
CIS
Center for Internet Security
GDPR
General Data Protection Regulation
COSO Internal control
The Committee of Sponsoring Organi­zations of the Treadway Commission
Internal Controls == process designed to provide reasonable assurance regarding operat­ions, reporting and compliance

Conver­sions

Strategy in Risk order
Direct conversion
nightmare situation
Phased conversion
Rollout modules systemwide but not whole system
Pilot conversion
Single area implem­ent­ation before full roll out
Parallel conversion
Run both concurrent
Testing
Unit tests
component/ function in isolation
Integr­ation tests
ensure that the modules are talking to each other correctly
System tests
whole system functi­onality validation
User acceptance test (UAT)
confirm that it meets the business requir­ements
Perfor­mance tests
assess max load system speed and respon­siv­eness
Security tests
id data vulner­abi­lities
Regression tests
no lost functi­onality with updates
DOCUMENT DOCUMENT DOCUMENT
 

COSO Cube

TOP Objectives
SIDE Organi­zat­ional
FRONT Components

CRIME =
-Control Activities
-Risk Assessment
-Infor­mation and commun­ication
-Monit­oring
-Enviro­nment (most important)

Archit­ecture

Centra­lized
connects ALL users to one location
Decent­ralized
MULTIPLE locations that each maintain a copy of the data
Distri­buted
all the users and systems are directly connected to one another
ERP
Enterprise Resource Planning
Why?
Improve data integrity and transp­arency
 
Automate routine business processes
 
Enhance operat­ional efficiency
 
Supports scalab­ility and future growth
6 common modules
 
Financial accounting
 
SCM (Supply Chain Mgmt)
 
Production
 
CRM (Customer Relati­onship Mgmt)
 
Sales management
 
Human Resources Mgmt (HRM)

SOCs

SOC 1
Purpose
controls over financial reporting
 
Internal Control over Financial Reporting (ICFR)
Users
auditors and financial statement users
SOC 2
Purpose
controls over non-fi­nancial (opera­tional) controls
Users
Limited to parties stated in the report
SOC 3
Purpose
General Use Report
 
simplified version of the SOC2 report
Users
Interested Parties
   
SOC 1 Type 1
 
We have financial controls
SOC 1 Type 2
 
We have financial controls and we can prove that they are working
SOC 2 Type 1
 
We have operat­ional controls @ pit
SOC 2 Type 1
 
We have operat­ional controls and it has been tested over time