← All CSC Flashcard Decks

Security Control Auditing Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Control Auditing flashcards as text
  1. Under the COSO Internal Control – Integrated Framework, which component addresses the organization's commitment to integrity and ethical values?

    Answer: Control Environment

    The Control Environment is the foundational component of COSO that sets the tone at the top, including commitment to integrity and ethical values.

  2. During a vulnerability assessment audit, an auditor finds that critical patches are applied within 72 hours but the policy requires 24 hours. What type of gap is this?

    Answer: Operating effectiveness gap

    An operating effectiveness gap means the control exists and is designed correctly but does not perform as required during actual execution.

  3. When auditing encryption controls, which factor is MOST important to verify for data at rest on a database server?

    Answer: That database columns containing sensitive data use AES-256 or equivalent encryption

    For data at rest, auditors verify that sensitive fields are encrypted using strong algorithms like AES-256 at the storage layer, not transport encryption.

  4. A CIS Controls audit maps findings to the Implementation Group (IG) framework. Which IG is recommended as the minimum baseline for all enterprises regardless of size?

    Answer: IG1

    CIS IG1 represents the essential cyber hygiene controls that all organizations should implement regardless of size, resource, or risk profile.

  5. Which audit evidence type carries the highest reliability when evaluating the existence of a security control?

    Answer: System-generated logs obtained directly by the auditor

    Evidence obtained directly by the auditor from source systems is more reliable than evidence provided by the auditee, which could be manipulated.

  6. An auditor is assessing a change management process. Which control objective should be verified FIRST to ensure unauthorized changes cannot reach production?

    Answer: Development and production environments are separated

    Separation of development and production environments is foundational — without it, developers can push unauthorized changes directly to production regardless of other controls.

  7. In a HIPAA security rule audit, which safeguard category covers workstation use policies and physical access to ePHI systems?

    Answer: Physical safeguards

    HIPAA Physical Safeguards govern physical access to electronic systems housing ePHI, including workstation use, access controls, and device disposal.