!!!|A+ GRADED|EXAM READY|95% SUCCESS
Audit Charter - ANSWER a formal document that contains:
1. scope of the audit functions
2. authority of the audit functions
3. responsibility of the audit functions
Audit Universe - ANSWER An inventory of all the functions/processes/units under the
organization
Qualitative Risk Assessment - ANSWER Risk is assessed using qualitative parameters,
such as high, medium, and low
Quantitative Risk Assessment - ANSWER Risk is assessed using numerical parameters
and is quantified
Risk Factors - ANSWER Factors that have an impact on risk. The presence of those
factors increases the risk, whereas the absence of those factors decreases the risk.
An audit plan helps to identify and determine the following aspects: - ANSWER The
objective of the audit
The scope of the audit
The periodicity of the audit
The meme gets if the audit team
The method of audit
1
, EDI - ANSWER Electronic Data Interchange
Semantic Nets - ANSWER A knowledge base that conveys meaning
Knowledge interface - ANSWER Stores expert-level knowledge
Data Interface - ANSWER Stores data for analysis and decision making
What is the major risk of EDI transactions? - ANSWER The absence of agreement (in
the absence of a trading partner agreement, there could be uncertainty related to specific
legal liability).
What is the objective of encryption? - ANSWER To ensure the integrity and
confidentiality of transactions.
How are inbound transactions controlled in an EDI environment? - ANSWER Inbound
transactions are controlled via logs of the receipt of inbound transactions, the use of
segment count totals, and the use of check digits to detect transportation and transcription
errors.
What is the objective of non-repudiation? - ANSWER Non-repudiation ensures that a
transaction is enforceable and that the claimed sender cannot later deny generating and
sending the message.
SOP - ANSWER Standard Operating Procedure
Preventative Controls - ANSWER controls that deter problems before they arise
Deterrent Controls - ANSWER Security controls that attempt to discourage individuals
from causing a security incident.
2