ICAEW ARF · Chapter 12 · Question 5 of 9
A company processes all of its sales orders through a cloud-based system and keeps no manual records. Which control best mitigates the risk that a ransomware attack makes its sales data permanently unavailable?
Test yourself: pick an answer
Reveal answer & explanation
Correct answer: C) Regular back-ups are held securely, separated from the live network, and restoring data from them is tested periodically
Explanation
Heavy dependence on a single IT system means a cyber attack could destroy or lock the company's records. Secure back-ups kept separately from the live network, with restoration tested, allow the data to be recovered if the live system is compromised. This is a general IT control. Sequential numbering, credit limits and range checks are controls over individual transactions and do nothing to recover lost data.
More Risk, information flows, sustainability assurance and reporting MCQs
- Q7Late in an audit, the finance director explains a large, unusual journal entry posted just before the year end and says that no supporting…
- Q8Which of the following is a typical role of an entity's internal audit function?
- Q9A company prepares sustainability-related disclosures in accordance with IFRS Sustainability Disclosure Standards and engages a…
- Q1Which of the following best describes business risk, as distinct from the components of audit risk?
- Q2A manufacturer's main product is being displaced by a cheaper rival technology, and the manufacturer's sales volumes fell sharply in the…
