Tuesday, 22 October 2013

ISCA Nov 2013 - CA Final Modelpaper - 1

FINAL COURSE: GROUP – II

PAPER – 6: INFORMATION SYSTEMS CONTROL & AUDIT
Question No. 1 is compulsory.
Attempt any five questions from the remaining six Questions.

                                                                


1.       ABC Udyog, a leading automobile company is having several manufacturing units, located in   different parts of the world and manufacturing several types of automobiles. The units are   working on legacy systems using an internet and collating information, but using different    software and varied platforms (Operating Systems) which do not allow communication with   each other. This results in huge inflow of duplicate data. The company wishes to centralize and consolidate the information flowing from its manufacturing units in a uniform manner across various levels of the organizations, so that the necessary data required for preparing MIS reports, budget, and profit/loss accounts etc. could be available timely.   The company decided to engage XYZ consultancy Services for the development of new system. Being a Senior Project Leader of the Consultancy Services, you are entrusted with the responsibilities of handling this project.

       Read the above carefully and answer the following:

a)     ‘What areas are required to be studied in order to know about the present system?
b)     ‘What are various backup techniques? Which backup technique you will recommend and why?

c)      Which Information system would meet the exact requirement of ABC Udyog? Discuss its Characteristics.

d)     As an IS Auditor, what are the steps to be followed by you while conducting IT auditing? (5 × 4 = 20 Marks)

Question 2 :

a)     COBIT 5  Enablers  (7 Marks)
b)     Discuss major misconceptions about MIS in brief?  (3 Marks )
c)      Discuss major threats due to cyber crimes? (6 Marks)

 

Question 3

a)     Discuss major advantages of continuous auditing techniques.. (4 Marks)

b)     Discuss the ‘Acceptance of Digital Signature Certificate’ under Section 41 of Information Technology (Amendment) Act, 2008  (6 Marks)
c)      What are the major points that are required to be taken into consideration for the proper implementation of Physical and Environmental Security with reference to Information  Security Policy (6 Marks)

Question 4
a)     On what factors does Information requirement depends ? ( 6 Marks)

b)     Discuss the phases of ISMS ?  ( 5 Marks )

c)      Discuss the categories under which various strategies are made to manage the risk  ( 5 Marks)

Question 5
(a)   Discuss the effect of computer on Internal control? (5 Marks )
(b)   Discuss RAD approach along with its Strength and Weaknesses?  (8 Marks)
(c) State the significance of Single point failure analysis?   (3 Marks )

Question 6
(a)   Role of IS Auditor in Physical access control? (5 Marks)
(b)   What are the components of Decision Support System? (5 Marks)
(c)   Discuss Section 77A of ITAA 2008 - Compounding of Offences (6 Marks)

Question 7
Write short notes on any four of the following:  ( 4 x 4 = 16 M)
(a)   CMM  (4 Marks)
(b)   Objective of Information Security  (4 Marks)
(c)   Compensatory control (4 Marks)
(d)   Business engineering ( 4 Marks)
(e)  Snapshot (4 Marks)


Friday, 6 September 2013

Probable Question Paper

PAPER – 6: INFORMATION SYSTEMS CONTROL & AUDIT
Question No. 1 is compulsory.
Attempt any five questions from the remaining six Questions.

                                                                          
1.          XYZ Ltd. is a leading company in FMCG sector and has a large number of coffee chains across India. The company uses ERP system for all its business operations and for recording sales at each outlet. The company has customized ERP, which is connected to a central server. The company’s new business models and new methods presume that the information required by the business managers is available all the time; it is accurate, it is reliable and no unauthorized disclosure of the same is made. Further, it is also presumed that the virtual business organization is up and running all the time on 24×7 basis. However, in reality, the technology-enabled and  technology-dependent organizations are more vulnerable to security threats in this highly connected world.

         Read the above carefully and answer the following:

a)     ‘What are the tasks that are required to be performed by XYZ ltd after implementation of ERP Package?
b)     ‘Access Control plays a key role in the implementation of information security policies’. What are the points to be taken into consideration while implementing such controls?

c)      What are the duties of certifying authorities as per Section 30 of Information Technology (Amendment) Act, 2008.

d)     What are the fundamental factors that must be considered while deciding type of storage backup media.  (5 × 4 = 20 Marks)


Question 2 :

a)     A Company is offering a wide range of products and services to its customers. It relies heavily on its existing information system to provide up-to-date information. The company wishes to enhance its existing system. You being an  information system auditor, suggest how the investigation of the present information system should be conducted so that it can be further improved upon.                       (8 Marks)

b)     State different categories of IS Audits?  (4 Marks )

c)      What is Digital Signature? How does the Information Technology (Amendment) Act 2008 enable the authentication of records using digital signatures? (4 Marks)

 


Question 3

a)     What are the major issues that should be addressed by an Information Security Policy. (4 Marks)
b)     Discuss the major strengths of agile methodologies. (4 Marks)
c)      What is Scarf ? What types of information is collected by using Scarf by the auditors ? (8  Marks)

Question 4
a)     Explain the term Systrust & Web trust along with the criteria’s specified by AICPA for practitioners engaged in such certifications ? ( 6 Marks)

b)     State the charters tics of Computer based information systems?  ( 5 Marks )

c)      Discuss the categories under which various strategies are made to manage the risk  ( 5 Marks)

Question 5
(a)   What is hacking? How does Hackers hack ? (6 Marks )
(b)   Discuss Final acceptance testing? (6 Marks)
(c) What does Single point failure mean? State the significance of Single point failure analysis?   (4 Marks )

Question 6
(a)   State the fundamental concepts related to CMM Model? (5 Marks)
(b)   What are the components of Expert System? (5 Marks)
(c)   What is meant by Asynchronous attacks? State different forms of Asynchronous attacks?    (6 Marks)

Question 7
Write short notes on any four of the following:  ( 4 x 4 = 16 M)
(a)   Objectives of BCP (4 Marks)
(b)   Powers of CAT        (4 Marks)
(c)   Compensatory control (4 Marks)
(d)   Delphi Technique ( 4 Marks)
(e)   HIPPA (4 Marks)


Friday, 2 August 2013

Amendment in CA Final - ISCA Syllabus - Applicable for Nov 2014 attempt .


Important Announcement
Sub: Revision of syllabus of Group – II – Paper – 6 Information Systems Control and Audit

As per the decision of the Council taken at its 324th held in March, 2013, it is notified for information of students and the public at large that the examination in the following papers effective from November 2014 examination and onwards shall be held as per the revised syllabus, as specified by the Council in terms of its authority as vested in Regulation 28E (3) and 31(iii) in respect of Intermediate (IPC)/Accounting Technician Examination and Final Examination respectively.

Final Course, 
Group-II, 
Paper-6: Information Systems Control and Audit  
(One Paper – Three Hours - 100 Marks)

Level of Knowledge: Advanced Knowledge

Objective: “To develop competencies and skill-sets in evaluation of controls and relevant evidence gathering in an IT environment using IT tools and techniques for effective and efficient performance of accounting, assurance and compliance services provided by a Chartered Accountant”.

Contents

1. Concepts of Governance and Management of Information Systems  
Governance, Risk and compliance and relationship between governance and management. Role of information technology and IS Strategy in business strategy, operations and control , business value from use of IT, business impact of IS risks different types of Information Systems Risks, IS Risk management overview, IT Compliance overview – Role and responsibilities of top management as regards IT-GRC. Role of Information Systems Assurance. Overview of Governance of Enterprise IT and COBIT 

2. Information Systems Concepts
Overview of information systems in IT environment and practical aspects of application of information systems in enterprise processes. Information as a key business asset and its relation to business objectives, business processes and relative importance of information systems from strategic and operational perspectives. Various types of business applications, overview of underlying IT technologies. 

3. Protection of Information Systems
Need for protection of Information systems, types of controls, IT general controls, logical access controls & application controls. Technologies and security management features, IS Security Policies, procedures, practices, standards and guidelines, IT controls and control objectives, Role of technology systems in
control monitoring, segregation of duties. Impact of IT controls on Internal controls over financial reporting,
cyber frauds and control failures.

4. Business Continuity Planning and Disaster recovery planning
Assessing Business Continuity Management, Business Impact Analysis and Business Continuity Plans,
Disaster recovery from perspective of going concern, Recovery Strategies 

5. Acquisition, Development and Implementation of Information Systems (SDLC)
Business process design (integrated systems, automated, and manual interfaces), Software procurement, RFP process, evaluation of IT proposals, computing ROI, Computing Cost of IT implementation and cost
benefit analysis, systematic approach to SDLC and review of SDLC controls at different stages. 

6. Auditing & Information Systems
Different types of IS audit and assurance engagements. Evaluating IT dependencies for audit planning. 
Overview of continuous auditing. Auditing Information Systems- Approach methodology, and standards for auditing information systems. IS Audit planning, performing an IS audit, rules of digital evidence, best practices and standards for IS audit. Reviewing General Controls, Application Controls, Application control reviews: Review of controls at various levels/layers such as: Parameters, user creation, granting of access rights, input, processing and output controls.

7. Information Technology Regulatory issues
Overview of Specific section of IT Act 2008 & Rules as relevant for assurance: Electronic Contracting,
digital signatures, cyber offences, etc. Need for systems audit as per various regulations such as: SEBI
Clause 49 listing requirements and internal controls, systems control & audit requirements as per RBI,
SEBI, IRDA. Concepts of Cyber forensics/Cyber Fraud investigation, Overview of Information Security
Standards ISO 27001, ISAE 3402/SA 402, ITIL


8. Emerging Technology: 
Overview of Cloud Computing, Software as a Service, Mobile Computing & BYOD, Web 2.0 & social media, Green IT and related security and audit issues



Happy learning .

Committed to your Success
Praveen Jain .






Thursday, 18 July 2013

ISCA Classes - Hyderabad Branch ICAI


Please be noted that there shall be no class on Saturday ( 20th July , 2013) .
Sorry for the inconvenience caused .

See you on Sunday . Timings 6.45 am . 

Thursday, 11 July 2013

CBDT Directive Regarding Grant Of TDS Credit In Mismatched Cases


Pursuant to the judgement of the Delhi High Court in Court on Its Own Motion vs. UOI 352 ITR 273, the CBDT has issued Instruction No. 5/2013 F.No.275/03/2013-IT(B), dated 8.07.2013 stating that when an assessee approaches the AO with requisite details and particulars in the form of TDS certificate as evidence against any mismatched amount, the AO will grant credit of TDS to the assessee after ascertaining whether the deductor has made payment of the TDS to the Government.

Sunday, 7 July 2013

Judicial Update


Judicial update:
In one of the case, the return of the assessee was processed u/s 143(1) of I T Act 1961 and later on the AO reopened the assessment u/s 148 on three grounds. One of the allegations was that as per report in form 3CEB,the assessee had intl transactions with associted enterprises and therefore determination of arm's length price is required. The AO did not make any addition on the first two allegations but made certain additions in respect of above allegation in view of report of TPO. the question arose whether it could be a valid reason for reopening. 

The hon'ble Del HC has held that this could not be said to be any reason u/s 148 since not supported by any material. 354 ITR 549

ACE Strategic Management - Study Material for CA Inter (Paper 6B) by CA CS Praveen Jain

  Hello Everyone! 👋 I'm thrilled to share that I’ve just launched my 18th book as an author! 📘✨ And what better day to announce this ...