Ch.5 It Governance Test Questions & Answers 3rd Edition - Accounting Info Systems Controls 3e Complete Test Bank by Leslie Turner. DOCX document preview.
ACCOUNTING INFORMATION SYSTEMS/3e
TURNER / WEICKGENANNT/COPELAND
Test Bank: CHAPTER 5: IT Governance
NOTE: All new or adjusted questions are in red. New questions are identified by the letter A as part of the question number; adjusted questions are identified by the letter X as part of the question number.
End of Chapter Questions:
- IT governance includes all but which of the following responsibilities?
- Aligning IT strategy with the business strategy
- Writing programming code for IT systems
- Insisting that an IT control framework be adopted and implemented
- Measuring IT’s performance
- Which phase of the system development life cycle includes determining user needs of the IT system?
- Systems planning
- Systems analysis
- Systems design
- Systems implementation
- Which of the following is not part of the system design phase of the SDLC?
- Conceptual design
- Evaluation and selection
- Parallel operation
- Detailed design
- Which of the following feasibility aspects is an evaluation of whether the technology exists to meet the need identified in the proposed change to the IT system?
- Technical feasibility
- Operational feasibility
- Economic feasibility
- Schedule feasibility
- The purpose of the feasibility study is to assist in
- Selecting software
- Designing internal controls
- Designing reports for the IT system
- Prioritizing IT requested changes
- Within the systems analysis phase of the SDLC, which of the following data collection methods does not involve any feedback from users of the IT system?
- Documentation review
- Interviews using structured questions
- Interviews using unstructured questions
- Questionnaires
- A request for proposal (RFP) is used during the
- Phase-in period
- Purchase of software
- Feasibility study
- In-house design
- Which of the following steps within the systems implementation phase could not occur concurrently with other steps, but would occur at the end?
- Employee training
- Data conversion
- Software programming
- Post-implementation review
- Each of the following are methods for implementing a new application system except:
- Direct cutover
- Parallel
- Pilot
- Test
- A retail store chain is developing a new integrated computer system for sales and inventories in its store locations. Which of the following implementation methods would involve the most risk?
- Direct cutover
- Phased-in implementation
- Parallel running
- Pilot testing
- The use of the SDLC for IT system changes is important for several reasons. Which of the following is not part of the purposes of the SDLC processes?
- As a part of strategic management of the organization
- As part of the internal control structure of the organization
- As part of the audit of an IT system
- As partial fulfillment of management’s ethical obligations
- Confidentiality of information is an ethical consideration for which of the following party or parties?
- Management
- Employees
- Consultants
- All of the above
TEST BANK - CHAPTER 5 - MULTIPLE CHOICE
- The process of determining the strategic vision for the organization, developing the long-term objectives, creating the strategies that will achieve the vision and objections, and implementing those strategies is referred to as:
- IT Governance
- Strategic Governance
- Strategic Management
- IT Management
- A structure of relationships and processes to direct and control the enterprise in order to achieve the enterprise’s goals by adding value while balancing risk versus return over IT and its processes is called:
- IT Governance
- Strategic Governance
- Strategic Management
- IT Management
- To fulfill the management obligations that are an integral part of IT governance, management need not focus on:
- Aligning IT strategy with the business strategy
- Hiring an acceptable IT manager
- Measuring IT’s performance
- Insisting that an IT control framework be adopted and implemented
- Which of the following is not one of the approaches used to achieve the management of an IT control framework?
- Information Systems Audit and Control Association control objectives for IT
- The International Organization for Standardization 17799, Code of Practice for Information Security Management
- The Information Technology Infrastructure Library
- Sarbanes-Oxley Act section on IT Controls
- OBIT is an acronym for which of the following?
- Control Objectives for Business and Information Technology
- Control Objectives for Information and related Technology
- Center of Business and Informative Technology
- Control Operations for Information Technology
- A group of senior managers selected to oversee the strategic management of IT is called:
- IT Strategic Committee
- IT Governance Committee
- Chief Information Officer (CIO)
- IT Management
- The formal process that many organizations use to select, design, and implement IT systems is the:
- Systems Development Life Cycle
- Control Objectives for IT
- Practice for Security Management
- Information Technology Development
- The IT governance committee is made up of many different individuals within the organization. Which of the following would not be one of those individuals?
- Chief Information Officer
- Chief External Auditor
- Chief Executive Officer
- Top Managers from User Departments
- The evaluation of long-term, strategic objectives and prioritization of the IT systems in order to assist the organizations in achieving its objectives is called:
- Systems Planning
- Systems Analysis
- Systems Design
- Systems Implementation
- The phases of the SDLC include all of the following except:
- Systems Planning
- Systems Implementation
- Systems Analysis
- Systems Purchasing
- This phase of SDLC involves the planning and continuing oversight of the design, implementation, and use of the IT systems.
- Systems Analysis
- Systems Implementation
- Systems Planning
- Systems Design
- Which is the correct flow of the SDLC?
- Systems Planning, Systems Design, Systems Analysis, Operation and Maintenance, Systems Implementation
- Systems Planning, Systems Analysis, Systems Design, Systems Implementation, Operation and Maintenance
- Systems Design, Systems Analysis, Systems Planning, Systems Implementation, Operation and Maintenance
- Systems Design, Systems Planning, Systems Implementation, Operation and Maintenance, Systems Analysis
- The decision to buy or design software directly follows which step in the system design flowchart?
- Conceptual Design
- Systems Analysis
- Evaluation and Selection
- Systems Planning
- The study of the current system to determine the strengths and weaknesses and the user needs of that system is called:
- Systems Analysis
- Systems Design
- Systems Planning
- Systems Implementation
- This phase of SDLC requires the collection of data about the system and the careful scrutiny of those data to determine areas of the system that can be improved.
- Systems Planning
- Systems Implementation
- Systems Analysis
- Systems Purchasing
- The creation of the system that meets user needs and incorporates the improvements identified by the systems analysis phase is called:
- Systems Planning
- Systems Design
- Systems Analysis
- Operation and Maintenance
- The set of steps undertaken to program, test, and activate the IT system as designed in the system design phase is called:
- Systems Planning
- Systems Implementation
- Systems Design
- Systems Analysis
- The most common way to test software is to use which of the following?
- Test Data
- Parallel Testing
- Process Conversion Testing
- process testing
- The regular, ongoing, functioning of the IT system and the processes to fix smaller problems, or bugs, in the IT system is called:
- Systems Analysis
- Systems Planning
- Operation and Maintenance
- Systems Implementation
- During this phase of the SDLC, management should request and receive ongoing reports about the performance of the IT system.
- Operation and Maintenance
- System Analysis
- Systems Design
- Systems Planning
- Software Programming involves all of the following except:
- Training Employees
- Software Testing
- Data Conversion
- Documenting the System
- The expanded SDLC presented in the textbook expands the processes within the system design phase. This is necessary because:
- It necessary for most companies to create their own software.
- The design phase needs to include the programming activities of self-created software.
- There is usually more than one software or system type that will meet the needs of the organization.
- Many organizations require a change in the type of operating system along with any changes in software.
- The Evaluation and Selection cycle of the expanded SDLC would not include which of the following steps?
- Design or buy the system selected.
- Identify the alternative system approaches.
- Evaluate the fit of each of the alternatives to company needs.
- Implement the alternative selected.
- The process of matching alternatives system models to the needs identified in the system analysis phase is called:
- Conceptual Design
- Systems Analysis
- Systems Planning
- Evaluation and Selection
- All of the following steps come after the evaluation of RFPs and Software in the system design process except:
- Selecting Software
- Purchasing software
- Determining modifications to software
- Hiring a consultant
- The process of assessing the feasibility and fit of each of the alternative conceptual approaches and selecting the one that best meets the organization’s needs is termed:
- Conceptual Design
- Evaluation and Selection
- Systems Analysis
- Systems Implementation
- The process of designing the outputs, inputs, user interfaces, databases, manual procedures, security and controls, and documentation of the new system is referred to as:
- Conceptual Design
- Software Selection
- Systems Design
- Detailed Design
- When attempting to prioritize IT projects, the IT governance committee needs to consider:
- The assessment of IT systems and their match to strategic organizational objectives.
- The feasibility of each of the requested modifications or upgrades.
- Both of the above
- None of the above
- A company has stated that the main strategic objective is to improve the accounts payable function within the organization. There are limited resources for IT upgrades and modifications. The IT governance committee has received IT update requests from the public relations department, human services, and vendor satisfaction department. Given this information, which would likely be the first upgrade implemented?
- Public relations would be first because it would include all areas of the business - vendors, employees, and customers.
- Vendor satisfaction would be first because it would be most in line with the strategic objective of the company.
- Human services would be the first because the employees are the ones who are most affected by changes in the IT departments.
- It is not possible to make a decision without further information.
- The need to match IT systems to organizational objectives emphasizes the need for the IT governance committee to include top management as its members because:
- These managers establish strategic objectives and are in the best position to assess the fit of the IT systems to those objectives.
- These managers are in a position to allocate resources and or time to the projects.
- Both of the above
- None of the above
- The realistic possibility of affording, implementing, and using the IT systems being considered is referred to as:
- Feasibility
- Rationality
- Sequentiality
- Ranking
- The assessment of the realism of the possibility that technology exists to meet the need identified in the proposed change to the IT system is called:
- Operational Feasibility
- Economic Feasibility
- Schedule Feasibility
- Technical Feasibility
- The assessment of the realism of the possibility that the current employees will be able to operate the proposed IT system is referred to as:
- Operational Feasibility
- Economic Feasibility
- Schedule Feasibility
- Technical Feasibility
- The assessment of the costs and benefits associated with the proposed IT system is referred to as:
- Operational Feasibility
- Economic Feasibility
- Schedule Feasibility
- Technical Feasibility
- The assessment of the realistic possibility that the proposed IT system can be implemented within a reasonable amount of time is called:
- Operational Feasibility
- Economic Feasibility
- Schedule Feasibility
- Technical Feasibility
- Typical steps within the systems analysis phase of the SDLC would not include which of the following?
- Preliminary Investigation
- Survey of the Current System
- Economic Feasibility
- Determination of User Information Needs
- The purpose of this step in the systems analysis phase is to determine whether the problem or deficiency in the current system really exists and to make a “go” or a “no-go” decision.
- Survey of the Current System
- Determination of User Information Needs
- Business Process Reengineering
- Preliminary Investigation
- A detailed study of the current system to identify weaknesses to improve upon and strengths that should be maintained is referred to as:
- Preliminary Investigation
- System Survey
- Process Reengineering
- Determination of User Information Needs
- Watching the steps that employees take as they process transactions in the system is referred to as:
- Investigation
- Interrogation
- Observation
- Interview
- The detailed examination of documentation that exists about the system to gain an understanding of the system under study is called a(n):
- Documentation Review
- Systems Audit
- System Survey
- Records Observation
- Face-to-face, verbal questioning of users of an IT system to determine facts or beliefs about the system are called:
- Interrogation
- User Review
- Interviews
- System Survey
- Structured Question
- Oral Question
- Unstructured Question
- Range Question
- Structured Question
- Oral Question
- Unstructured Question
- Range Question
- A written, rather than an oral, form or questioning of users to determine facts or beliefs about a system is referred to as a(n):
- Interview
- Questionnaire
- Interrogation
- System Survey
- The purpose of this phase is to question the current approaches in the system and to think about better ways to carry out the steps and processes of the system.
- Systems Analysis
- Systems Survey
- Analysis of Systems Survey
- Preliminary Investigation
- The fundamental rethinking and radical redesign of business processes to bring about dramatic improvements in performance is called:
- Business Process Reengineering
- Process Redesign
- Business Analysis and Design
- Business Process Design and Analysis
- The many sets of activities within the organization performed to accomplish the functions necessary to continue the daily operations are referred to as:
- Business Systems
- Business Processes
- Business Activities
- Business Functions
- The systems analysis report, which is sent to the IT governance committee, will inform the committee of all of the following, except:
- The results of the systems survey
- User needs determination
- Detailed design
- Recommendations regarding the continuation of the project
- This document is sent to each software vendor offering a software package that meets the user and system needs and is sent to solicit proposals.
- Requested Software Package
- Request for Proposal
- System Software Request
- Software Vendor Needs
- When a vendor returns a request for proposal, it will include all of the following, except:
- Match of the system and user needs
- Description of the software
- The technical support it intends to provide
- Prices for the software
- After all of the RFPs have been received, either the IT governance committee or the project team will evaluate the proposals in order to select the best software package. Things that must be considered would include:
- The match of the system and the user needs to the features of the software
- Testimonials from other customers who use the software
- Reputation and reliability of the vendor
- All of the above
- This phase of the systems design for in-house development of software involves the identifying the alternative approaches to systems that will meet the needs identified in the system analysis phase.
- Request for proposal
- Conceptual design
- Systems concept
- Systems analysis
- The process of assessing the feasibility and fit of each of the alternative conceptual approaches and selecting the one that best fits the organization’s needs is called:
- Conceptual Design
- Systems Design
- Evaluation and Selection
- Systems Implementation
- During this process, the project team must consider the number of employees, their capabilities and expertise, and any supporting systems necessary to operate each alternative design.
- Operational feasibility
- Technical feasibility
- Economic feasibility
- Schedule feasibility
- The purpose of this analysis is to determine which of the alternative designs is the most cost effective.
- Operational feasibility
- Technical feasibility
- Economic feasibility
- Schedule feasibility
- In this feasibility, the project team must estimate the total amount of time necessary to implement the each alternative design.
- Operational feasibility
- Technical feasibility
- Economic feasibility
- Schedule feasibility
- Which of the following is NOT one of the approaches to cloud computing?
- Software as a Service
- Internet Clouds
- Platform as a Service
- Private Clouds
- All of the following are issues with cloud computing except for:
- Decreased physical security protocols
- Increased Accessibility
- Increased reliance on 3rd party providers
- Increased risk of hackers
- Considerations related to adopting or increasing cloud computing usage, include:
- The customer support provided by the cloud vendor
- The service level agreement with the cloud provider
- The manner of monitoring the could service usage
- All of the above
- The purpose of this phase of systems design is to create the entire set of specifications necessary to build and implement the system.
- Detailed design
- Evaluation and selection
- Operational design
- Detailed analysis
- In the detailed design stage of systems design it is necessary that the various parts of the system be designed. The parts of the system to be designed at this point would include all of the following, except:
- Outputs
- Inputs
- Program Code
- Data Storage
- Reports and documents, such as income statements, aged accounts receivable reports, checks, and invoices are referred to as:
- Outputs of the system
- Data storage
- Internal controls
- Inputs of the system
- The forms, documents, screens, or electronic means used to put data into the accounting system are called:
- Outputs of the system
- Data storage
- Internal controls
- Inputs of the system
- Which of the following is not a method of data input?
- Keying in data with a keyboard from data on a paper form
- Electronic data interchange
- Bar code scanning
- Viewed on the screen
- There are many different types of documentation necessary to operate and maintain an accounting system. These types of documentation include all of the following, except:
- Flowcharts
- Operator Manuals
- Output Examples
- Entity Relationship Diagrams
- A system conversion method in which the old and the new systems are operated simultaneously for a short time.
- Direct cutover conversion
- Phase-in conversion
- Pilot conversion
- Parallel conversion
- A system conversion method in which on a chose date the old system operation is terminated and all processing begins on the new system.
- Direct cutover conversion
- Phase-in conversion
- Pilot conversion
- Parallel conversion
- A system conversion method in which the system is broken into modules, or parts, which are phased in incrementally and over a longer period.
- Direct cutover conversion
- Phase-in conversion
- Pilot conversion
- Parallel conversion
- A system conversion method in which the system is operated in only one or a few sub-units of the organization.
- Direct cutover conversion
- Phase-in conversion
- Pilot conversion
- Parallel conversion
- When the manager of the primary users of the system is satisfied with the system, an acceptance agreement will be signed , the enforce of which makes it much more likely that project teams will seek user input and that the project team will work hard to meet user needs.
- System Conversion
- Post-Implementation Acceptance
- Usr Review
- User Acceptance
- A review of the feasibility assessments and other estimates made during the projects, the purpose of which is to help the organization learn from any mistakes that were made and help the company avoid those same errors in the future.
- System Design Life Cycle
- Post-Implementation Review
- User Acceptance
- System Conversion Review
- During the operation of an IT system, it is necessary that regular reports are received by management to monitor the performance of the system. These reports would include all of the following, except:
- IT Security and Number of Security Problems
- IT Customer Satisfaction
- Downtime of IT System
- User Acceptance of the IT System
- Which of the following is not a part of IT performance?
- IT load usage and excess capacity
- Downtime of IT systems
- Maintenance hours on IT systems
- IT security and breach issues
- Which of the following is not a major purpose served by the continual and proper use of the IT governance committee and the SDLC?
- The fulfillment of ethical obligations
- The strategic management process of the organization
- The conversion of the system
- The internal control structure of the organization
- The careful and responsible oversight and use by management of the assets entrusted to management is called:
- IT Governance
- Stewardship
- Fiduciary Control
- System Access
- Employee Ethical considerations, related to IT governance, would include which of the following?
- Maintain a set of processes and procedures that assure accurate and complete records.
- Confidentiality for those who serve on the project teams.
- Not to disclose proprietary information from the company to clients.
- Carefully consider the impact of system changes and to be ethical in the manner in which the changes are processed.
- When an organization hires consultants to assist with any phase or any phases of the SDLC, there are at least four ethical obligations. Which of the following is not one of those obligations?
- Bid the engagement fairly, and completely disclose the terms of potential cost increases.
- Bill time accurately to the client and do not inflate time billed.
- Do not oversell unnecessary services or systems to the client.
- Make an honest effort to participate, learn the new system processes, and properly use the new system.
- Which of the following relationships would be allowed for a CPA firm?
- Offering IT consulting services and completing the external audit.
- Completing the external audit and maintaining the bookkeeping work.
- Internal audit outsourcing and financial information systems design and implementation.
- Providing fairness opinions and completing the external audit.
TEST BANK - CHAPTER 5 - TRUE /
- IT governance is an issue for executives and top management. Lower level managers and the board of directors are outsiders in the process.
- In order to meets it obligation of corporate governance, the board of directors must oversee IT.
- In order to match company strategy to IT systems, the company needs to have an IT governance committee and a formal process to select, design, and implement IT systems.
- Either the IT governance or the system development life cycle is necessary in the strategic management of IT systems.
- Once the system development life cycle has determined the priority it places on IT systems, the IT governance committee will manage the development, implementation, and use of the systems.
- The IT governance committee should constantly assess the long-term strategy of the company and determine the type of IT systems to purchase, develop and use.
- The systems development life cycle is responsible for the oversight and management of the IT governance committee.
- Accounting software was often not available in the early days of computers which required that the organization would develop, program, and implement their in-house accounting software.
- Once the systems development life cycle (SDLC) is complete, it is not necessary to restart the cycle unless something is brought to the attention of the IT governance committee to indicate that another cycle is required.
- It is likely that the IT governance committee will go back through the phases of the SDLC to design new and improved IT systems.
- In the modern IT environment, it is necessary for an organization to follow each of the steps in the SDLC in the order presented.
- The exact steps in the SDLC and/or their sequence are not as important as is the need to formalize and conduct those steps completely and consistently.
- The IT governance committee will be constantly monitoring the IT system to look for fraud and system abuse.
- If the operational feasibility determines that the operation will require new training of employees, then the proposed upgrade or modification should be rejected.
- When the IT governance committee uses both the strategic match and the feasibility study, they will be better able to prioritize proposed changes to the IT systems.
- When the IT governance committee has made the decision as to which IT upgrades and/or modifications are to be made, their job is complete.
- Data collection in the system survey step of systems analysis involves documentation review only.
- The purpose of observation in the system survey is to enable the project team to gain an understanding of the processing steps within the system.
- During a documentation review, the team would examine only relevant documentation of the proposed upgrade or modification.
- In order to gain a complete understanding of the system under study, the project team should seek the opinions and thoughts of those who use the system in addition to observation and documentation review.
- The face-to-face nature of an interview is advantageous due to the fact that the interviewer can clear up any misunderstandings as they occur and can follow up with more questions, depending on the response of the interviewee.
- One advantage of the interview process is efficiency.
- One advantage to the use of questionnaires is that they an be answered anonymously, which allows the respondent to be more truthful without fear of negative consequences.
- The determination of user requirements is often discovered through the use of observation and documentation review.
- The analysis phase is the critical-thinking stage of systems analysis.
- IT and business process reengineering have mutually enhancing relationships. The business processes should be supported by the IT capabilities.
- Business process reengineering takes place at the systems design stage of the SDLC.
- The last step of the systems analysis phase is to prepare a systems analysis report that will be delivered to the IT governance committee.
- The steps within the design phase of the SDLC are the same, whether the organization intends to purchase software or to design the software in-house.
- In general, purchased software is more costly but more reliable than software designed in-house.
- While it is not necessary to hire a consulting firm, many organizations find that the special expertise of consulting firms is most beneficial in the design and implementation of accounting system software.
- When in the systems design phase and creating an in-house accounting software, the feasibility aspect is the same as in the systems planning stage.
- In general, designs that require more complex technology have a higher feasibility than designs with less complex technology.
- When a company is revising systems, there are intangible benefits that are difficult to estimate in dollars. These intangible benefits should be included in the project team’s report.
- The incorporation of cloud computing requires a careful, controlled approach to system design related to the costs and benefits. Other issues are not important.
- Cloud computing results in greater availability, but also requires greater security and processing integrity.
- The cost of cloud computing is normally related to a period of time, and not to the use of the service.
- Because the users of reports need the reports on an ongoing basis as part of their jobs, it is critical to have user feedback in the design of the details of the output reports.
- In general, the manual input method is less error prone that the electronic methods.
- In the detailed design phase, all of the individual steps within a process must be identified and designed.
- The internal controls within a system must be designed in the implementation stage.
- It would not be necessary for the programming staff to have interaction with the accounting staff during the systems implementation process, as all systems design was previously completed.
- Software should never be implemented before it is tested.
- It is essential that accountants oversee the data conversion from the old system to the new system to make sure that all accounting data is completely and correctly converted.
- The file or database storage for the new accounting system is always
bedifferent from the old system. - The longest and most costly part of the SDLC is the operation and maintenance.
- During the operation phase of the IT system, it is necessary that management receive regular reports that will enable management to determine whether IT is aligned with business strategy and meeting the objectives of the IT system.
- Once the SDLC has identified which types of IT systems are appropriate for the company, the IT governance committee becomes the mechanism to properly manage the development, acquisition, and implementation of the IT system.
- Each organization may approach IT governance in a different manner, but each organization should establish procedures for IT governance.
- The AICPA Trust Principles failed to include any reference to the internal control structure of the IT systems.
- Diligent adherence to the SDLC process, by management, is part of fulfilling its ethical obligations of stewardship and fraud prevention.
- As the result of the passage of the Sarbanes-Oxley Act, CPA firms have unlimited ability to provide non-audit services to their audit clients.
- SO 1 Management obligations in IT governance
Describe the activities that IT management should focus on when working to fulfill the obligations that are inherent in IT governance.
- SO 2 Systems Development Life Cycle
List and briefly describe each of the five stages in the Systems Development Life Cycle (SDLC)
Document Information
Connected Book
Accounting Info Systems Controls 3e Complete Test Bank
By Leslie Turner