4IT governance & internal control
- 4.1IT governance and COBIT
Covers IT governance (the responsibility of executive management, and alignment of IT strategy with business strategy), which ties the use of IT to business goals and controls it, and COBIT, the framework that organizes its control objectives, building the judgment an auditor needs to decide from which viewpoint to evaluate whether IT governance is functioning.
- 4.2The six components of internal control and COSO
Covers the six basic components of internal control (control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT) and their relationship to the COSO framework (which has five components—it does not include response to IT), building the judgment to diagnose which component's absence a control deficiency stems from.
- 4.3J-SOX (the internal control reporting system)
Covers the internal control reporting system (J-SOX) under the Financial Instruments and Exchange Act—the mechanism in which management self-assesses the effectiveness of internal control over financial reporting, prepares and submits an internal control report, and an auditor audits it—building the judgment to diagnose scope narrowing (a top-down, risk-based approach) and deficiency classification (a material weakness that should be disclosed).
- 4.4IT controls (IT general controls and IT application controls)
Covers the difference between IT general controls (ITGC) (access management, program change management, development/deployment, operations management), which control the IT foundation, and IT application controls (input/processing/output controls), which safeguard the accuracy, completeness, and validity of individual business processing, plus the dependency that ★if ITGC is not effective, IT application controls cannot be relied on either, building the judgment to diagnose how a control deficiency propagates.

