CMA Final · Cost and Management Audit
Information Systems Security Audit for CMA Final Paper 17
Information Systems Security Audit is the review of an organisation's IT systems to check that data is secure, accurate and available, and that controls work. To solve questions, identify the risk in the scenario, name the matching control (general, application, access or recovery), and state what the auditor tests and reports.
What this chapter covers
This chapter in Paper 17, Cost and Management Audit, covers how an auditor examines computerised systems. You start with why IS audit is needed, then move to threats, controls, access, business continuity, the audit process with tools, and finally governance frameworks and cyber law.
The chapter links to the rest of the paper because cost records, ERP data and cost statements now come from IT systems. If the controls over those systems are weak, the cost auditor cannot rely on the figures. So you can treat this chapter as the base for judging the reliability of data used in cost audit and management audit work.
Questions are usually about application. You get a scenario, such as a manufacturing company with an ERP, and you must spot the weakness and suggest a control or an audit procedure. Learn the ideas well enough to apply them, not just to list them.
This chapter is mostly conceptual with clear categories, so it is one of the easier areas to score in if you prepare in a structured way. Paper 17 Section A has standalone MCQs and a case scenario with MCQs, and the classification-based content here suits both. The same ideas also help you in written answers on audit planning, evidence and reporting. Since you do not need heavy calculation, the time you put in gives a steady return.
Information Systems Security Audit: topics in the order to study them
- 1Information Systems Audit Overview and NeedIt sets the purpose, scope and objectives of IS audit, which gives context for every later topic.
- 2Information Security Concepts and ThreatsYou need the basics of confidentiality, integrity, availability and the common threats before studying controls that answer them.
- 3General IT Controls and Application ControlsThis is the core of the chapter. Controls are the response to the threats you just studied.
- 4Logical and Physical Access ControlsAccess control is a major part of general controls, so it is easier once you know the control categories.
- 5Business Continuity and Disaster Recovery PlanningIt covers what happens when controls fail or systems stop, so it follows prevention and detection.
- 6IS Audit Process, Tools and CAATsNow that you know what to test, you can learn how the auditor plans, tests and uses computer-assisted techniques.
- 7IT Governance Frameworks and Cyber LawThis is the top-level view that ties the earlier topics to management oversight and legal duties, so it works best as the last step.
How to prepare Information Systems Security Audit
Build the chapter from concept to control to audit procedure. Keep your notes short and organised in lists.
- Read each topic once for understanding and write a one-page summary in your own words.
- Make a table-style list of control types with an example of each, for instance preventive, detective and corrective controls, and general against application controls.
- Pair every threat with at least one control that addresses it, so you can answer scenario questions.
- Write out the steps of a business continuity plan and the difference between backup, recovery and continuity in simple terms.
- List common CAATs and what each does, then practise explaining how an auditor would use one on cost or inventory data.
- Solve MCQs topic by topic, and for each wrong answer note the exact word or condition you missed.
- In the last week, practise two or three scenario-based written answers that name the risk, the control and the audit test.
Common mistakes in Information Systems Security Audit
Mixing up general controls and application controls.
Fix: Ask whether the control applies to the whole IT environment or to one application. Keep one example of each in your notes.
Listing controls without linking them to the scenario.
Fix: Start each answer by naming the risk in the case, then give the control that fits it and what the auditor would test.
Confusing business continuity planning with disaster recovery planning.
Fix: Remember that continuity covers the whole business operation, while disaster recovery focuses on restoring IT systems and data.
Treating CAATs as only software names.
Fix: Learn what each technique does, what the auditor tests with it, and its limits.
Confusing logical and physical access controls.
Fix: Logical controls protect data and systems through software; physical controls protect equipment and buildings.
Ignoring governance and cyber law because they seem like theory.
Fix: Revise the main frameworks and legal provisions with their purpose in a short list, as MCQs often test them directly.
Last-day revision: Information Systems Security Audit
- IS security rests on confidentiality, integrity and availability.
- General IT controls cover the whole IT environment; application controls work within a specific application.
- Application controls are commonly grouped as input, processing and output controls.
- Preventive controls stop an error, detective controls find it, corrective controls fix it.
- Logical access controls protect data and software, for example through passwords and authorisation levels.
- Physical access controls protect hardware and premises, for example locks and restricted entry.
- A business continuity plan keeps operations running; a disaster recovery plan restores IT systems.
- Regular, tested and off-site backups are central to recovery.
- CAATs let the auditor test large volumes of data directly instead of relying only on samples.
- Segregation of duties reduces the chance of fraud and error in IT processes.
- IT governance links IT to business goals and manages IT risk.
- Check the exact wording of the IT Act provisions and framework names in your study material before the exam.
Information Systems Security Audit practice questions
- Which of the following best describes the purpose of a 'segregation of duties' control in a computerised cost accounting environment?
- An auditor reviewing a company's disaster recovery plan finds that backups are taken daily but have never been restored in a test. Which con…
- A firm's disaster recovery plan states that after an outage, systems must be running within 4 hours, and that no more than 30 minutes of tra…
- An auditor finds that a cost accounting application's database administrator can also approve journal entries and delete audit log records. …
- During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in t…
- During an IS audit of a manufacturing company's ERP, the auditor wants to confirm that a programmer cannot both modify production code and m…
- An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor …
- Which of the following is an example of an application control rather than a general IT control?
Information Systems Security Audit in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Information Systems Security Audit: frequently asked questions
Is Information Systems Security Audit important for CMA Final Paper 17?
Yes, it is part of Paper 17 and suits both MCQs and short written answers. The content is mostly conceptual, so steady preparation can earn you marks without heavy calculation.
How should I prepare for scenario-based MCQs from this chapter?
Practise identifying the risk first, then the control that addresses it. Read the options carefully, as several may sound correct but only one fits the situation in the case.
Do I need technical IT knowledge for this chapter?
You need to understand the ideas well, but not to be a technical expert. Focus on what each control does, why it is used and how an auditor checks it.
Is there negative marking in the MCQ section?
Neither the question papers nor the ICMAI prospectus provide for negative marking. You should still attempt every question with a reasoned choice rather than a random guess.