Install our extension to search inside any video instantly.

Final Paper 3: AAA&PE | Topic: Ch12: Digital Auditing and Assurance | Session 2 | 22 July 2026

Added:
371 views11likes3:20:10theicaiOriginal Release: 2026-07-22

Cyber risk is defined as the combination of digital assets, threats, weak controls, and business impact, where digital assets include IT systems, financial data, customer information, vendor master data, passwords, intellectual property, ERP systems, and operational systems. The three-stage framework for understanding cyber risk involves: (1) Assessing the cyber risk by identifying potential attacks like malware, phishing, and denial of service; (2) Impact analysis to understand potential losses including regulatory costs, business interruption, data loss, reputational damage, and going concern issues; (3) Managing the cyber risk through a five-component security framework: Identify (periodic risk assessments, asset inventory, classification), Protect (training, access controls, password policies), Detect (monitoring systems, intrusion detection), Respond (incident response procedures), and Recover (disaster recovery plans, business continuity plans). Auditors must evaluate these components to understand how management manages cyber risk, and when evaluating controls around vendor management, they should assess who is responsible, how requests are authenticated, and how transactions are initiated, authorized, recorded, and processed.