NEW
Font size
WorksheetsIT Audit Berbasis Risiko sesuai best practice POJK dan ISO
Total questions: 10
Worksheet time: 3mins
Definisi Audit adalah aktivitas sebagai berikut
proses sistematis yang dilakukan untuk perolehan dan penilaian bukti-bukti
memberikan gambaran kondisi tertentu yang berlangsung di perusahaan apakah sudah sesuai dengan standar/kriteria tertentu
yang difokuskan pada pengumpulan bukti last period di perusahaan
Benar semua
Peran dan posisi fungsi internal audit (termasuk IT audit) dalam sistem pengendalian internal di organisasi adalah
1st line of defense
2nd line of defense
3rd line of defense
Semua line (1st line sampai 3rd line of defense)
Metodologi atau tahapan/aktivitas yang terakhir dari audit TI menurut best practice IIA-Institut Internal Audit adalah
Collecting evidence
Evaluating evidence
Planning and scoping
Communicating audit result
Metodologi atau tahapan audit TI yang pertama dilakukan menurut ISACA-IS Audit and Control Association
Determine what risk might interfere with reaching the objectives
Decide what controls should be in place to mitigate risks
Test the control
Identify business objectives and the information system that support them
Which of the following is the correct answer the type of risk treatment
Risk mitigation
Risk acceptance
Risk transfer/sharing
All answer are correct
Which of the following definition is true/correct according to best practice ISO 27005
Threat : A negative action that may harm a system
Vulnerabilities : A weakness that allows a threat to cause harm
Risk : The potential that a chosen action or activity will lead to a loss
All answer are correct
Control access to physical facilities is example of which one of the following type control
preventive
detective
corrective
compensatory
Which of the following is NOT example of IT General Control
Policies and procedures that related to many applications and IT support
SDLC-Software Development Life Cycle
Security and user access management
input, process and output of transaction in computer software/application
Peraturan Otoritas Jasa Keuangan yang mengatur penyelenggaraan TI pada Bank Umum adalah
POJK 38/2016
POJK 77/2016
POJK 12/2018
POJK 11/2022
Best Practice standar internasional untuk keamanan informasi adalah
PRINCE2
ITIL4
TOGAF
ISO 27000
