wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IT Audit Berbasis Risiko sesuai best practice POJK dan ISO

Total questions: 10

Worksheet time: 3mins

Name
Class
Date
1.

Definisi Audit adalah aktivitas sebagai berikut

a)

proses sistematis yang dilakukan untuk perolehan dan penilaian bukti-bukti

b)

memberikan gambaran kondisi tertentu yang berlangsung di perusahaan apakah sudah sesuai dengan standar/kriteria tertentu

c)

yang difokuskan pada pengumpulan bukti last period di perusahaan

d)

Benar semua

2.

Peran dan posisi fungsi internal audit (termasuk IT audit) dalam sistem pengendalian internal di organisasi adalah

a)

1st line of defense

b)

2nd line of defense

c)

3rd line of defense

d)

Semua line (1st line sampai 3rd line of defense)

3.

Metodologi atau tahapan/aktivitas yang terakhir dari audit TI menurut best practice IIA-Institut Internal Audit adalah

a)

Collecting evidence

b)

Evaluating evidence

c)

Planning and scoping

d)

Communicating audit result

4.

Metodologi atau tahapan audit TI yang pertama dilakukan menurut ISACA-IS Audit and Control Association

a)

Determine what risk might interfere with reaching the objectives

b)

Decide what controls should be in place to mitigate risks

c)

Test the control

d)

Identify business objectives and the information system that support them

5.

Which of the following is the correct answer the type of risk treatment

a)

Risk mitigation

b)

Risk acceptance

c)

Risk transfer/sharing

d)

All answer are correct

6.

Which of the following definition is true/correct according to best practice ISO 27005

a)

Threat : A negative action that may harm a system

b)

Vulnerabilities : A weakness that allows a threat to cause harm

c)

Risk : The potential that a chosen action or activity will lead to a loss

d)

All answer are correct

7.

Control access to physical facilities is example of which one of the following type control

a)

preventive

b)

detective

c)

corrective

d)

compensatory

8.

Which of the following is NOT example of IT General Control

a)

Policies and procedures that related to many applications and IT support

b)

SDLC-Software Development Life Cycle

c)

Security and user access management

d)

input, process and output of transaction in computer software/application

9.

Peraturan Otoritas Jasa Keuangan yang mengatur penyelenggaraan TI pada Bank Umum adalah

a)

POJK 38/2016

b)

POJK 77/2016

c)

POJK 12/2018

d)

POJK 11/2022

10.

Best Practice standar internasional untuk keamanan informasi adalah

a)

PRINCE2

b)

ITIL4

c)

TOGAF

d)

ISO 27000