4. When management outsources IT they also are able to outsource their management responsibility under SOX for ensuring adequate IT controls.
True or False
5. If properly documented, the Disaster Recovery Plan need not be tested.
True or False
4) False
Management may outsource their organisation's IT functions but they cannot outsource their management responsibilities under SOX for ensuring adequate IT controls. The PCAOB specifically states in its Auditing Standard- 2, that the use of service organisation does not reduce managements responsibility to maintain effective internal control over financial reporting. Rather, user management should evaluate controls at the service organisation, as well as related controls at the user company, when making its assessment about internal control over financial reporting.
5) False
Tests should be performed periodically to provide a measure of the preparedness of personnel and identify omissions or bottlenecks in the plan.
Get Answers For Free
Most questions answered within 1 hours.