Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

Information Systems Control Audit May 13

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5

PAPER 6: INFORMATION SYSTEMS CONTROL & AUDIT Important questions for May 2013

Disclaimer
The questions marked are purely predicted based on examination trends. The team involving drafting of the below questions does not have any access to Board of Studies, examination boards, committees or any other body of ICAI. Students are advised to use this as a supplementary study material, and not as the ONLY material for exams. The team does not bear any responsibility for appearance or non-appearance of the below marked questions.

THESE ARE PROBABLES, NOT ACTUALS !!

CHAPTER 1

INFORMATION SYSTEMS CONCEPTS 1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. What is Information ? What are its characteristics ? What are the characteristics of an effective MIS & the Myths about MIS? Describe the pre-requisites of an effective MIS. What is an EIS. Discuss its characteristics. Principles of EIS Design. Brief note on Expert Systems. Short note on TPS & its features (along with a diagram) Characteristics of CBIS. Short Note on Operations Support Systems Differentiate between : Internal Information & External Information Differentiate between : Programmed Decisions & non-Programmed Decisions

CHAPTER 2

SYSTEMS DEVELOPMENT LIFE CYCLE METHODOLOGY 1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. Reasons for failure of Systems Development Discuss Prototyping approach to Systems development. (steps/advs/disadvs) What is feasibility study ? explain various studies. What are the various fact finding techniques used in system analysis. Present System and Proposed System analysis. Discuss various system development tools. : Flow Chart & DFD with examples Describe the Vendor Evaluation Criterion in selection of a system Discuss the various stages in an in-house program development [Important Program Debugging] Discuss the three vendor evaluation techniques. Discuss System Testing. System Development Methodology SDLC IS Audit perspective & Risks associated Operations Manual. Explain the important activities during conversion strategies. System Development approaches : a) Incremental b) Agile Flow Charts as in Study Material a) sum of squares from 1 to 50 b) arrange data in ascending order c)read a number N and print all its divisors d) sum of digits of any number. E) sum of 50 natural no. f) largest of three nos. g) Computing Factorial N (N!)

!!!!! Surprise question

16.

CA Ganesh Kumar B N B.Com., ACA, CISA (USA)


ca.ganeshbn@gmail.com Ph : 09972 317521

www.shrishankara.com
ca.ganeshbn@gmail.com

CHAPTER 3

CONTROL OBJECTIVES 1. 2. 3. 4. 5. 6. 7. 8. 9. Effects of Computers on IS Audit & Internal Controls Functions, Roles & Responsibility of an IS Auditor. Steps in IS Audit. Categories of Controls (in Brief different categories and its components) Audit Trail Objectives. Encryption, Cryptography, PKI Firewall and its types SLA Various Technical Exposures, Asynchronous attack Techniques and Computer Crime exposures. 10. Virus, Anti-Virus and types of Anti-Virus software. 11. Physical Controls measures 12. Controls for Environmental exposures

CHAPTER 4

TESTING - GENERAL & AUTOMATED CONTROLS 1. 2. 3. 4. Various Phases of IS Control Audit Discuss components that an auditor must document during the testing phase What are the different levels of test plans? Audit Tools & Continues Audit Techniques

**
CHAPTER 5

RISK ASSESSMENT METHODOLOGIES AND APPLICATIONS 1. 2. 3. 4. 5. 6. 7. Define terms - risk, threat, vulnerability, attack, exposure and Residual Risk ? Differentiate between Systematic & Unsystematic Risk. Various Risk evaluation techniques How Risk ranking is performed ? What are the different Risk Strategies ? How is risk mitigated in an organisation? ( Risk Mitigation techniques) Insurance types and areas of covergae

CA Ganesh Kumar B N B.Com., ACA, CISA (USA)


ca.ganeshbn@gmail.com Ph : 09972 317521

www.shrishankara.com
ca.ganeshbn@gmail.com

CHAPTER 6

BUSINESS CONTINUITY PLANNING & DISASTER RECOVERY PLANNING 1. 2. 3. 4. 5. 6. 7. What is BCP & what are the various phases of developing a business continuity plan? Describe various Backup techniques. Describe various alternate site facilities & reciprocal agreements. What is the importance of back-up redundancy? Describe the various disaster recovery testing? Describe the testing procedure? Audit tools techniques in BCP & DRP testing Short note on a. BIA b. Single point failure

CHAPTER 7

AN OVERVIEW OF ERP 1. 2. 3. 4. 5. 6. 7. 8. What are the various benefits are an ERP. Also enumerate its features. Myths about ERP. Write a note on Business Process Re-engineering. Steps in Implementation of an ERP & ERP Evaluation. Write short note on Post implementation review. Risk & Governance in Implementation of an ERP List a few ERP Packages Important modules in SAP: a. Treasury Management b. Cost Control c. Material Management

CHAPTER 8

IS AUDITING STANDARDS , GUIDELINES, BEST PRACTICES Short Notes on 1. ISO 27001: Areas of Focus 2. CMM & levels 3. CoCo, COSO 4. HIPAA Safeguards 5. Systrust & Webtrust

CA Ganesh Kumar B N B.Com., ACA, CISA (USA)


ca.ganeshbn@gmail.com Ph : 09972 317521

www.shrishankara.com
ca.ganeshbn@gmail.com

CHAPTER 9

DRAFTING OF IS SECURITY POLICY, AUDIT POLICY, IS AUDIT REPORTING 1. What are the objectives of information security? How does an information security policy help in achieving those objectives? 2. What are the various types of Information Security Policy? 3. Access control in Information Security 4. What role is Information Systems Audit policy expected to play in ensuring information security? What are the objectives of IS Audit? 5. IS Audit Plan INFORMATION TECHNOLOGY ACT 1. IT AMENDMENT ACT, 2008 2. Definitions 3. Electronic signature 4. Chapter IV Time, place and receipt of records 5. Penal Provisions 6. Power of Central and State Govt 7. Liability of Companies 8. Cyber Appellate Tribunal

CHAPTER 10

ALL THE BEST


Simplified Approach to ISCA
(ISCA Text Book for CA Final CA Ganesh Kumar B N)

Publishers: CCH India

http://www.cchindiastore.com/home-academic
Also available on Flipkart.com , Infibeam.com, bigbookshop.com CA Ganesh Kumar B N B.Com., ACA, CISA (USA)
ca.ganeshbn@gmail.com Ph : 09972 317521

www.shrishankara.com
ca.ganeshbn@gmail.com

You might also like