Index of Attributes
Overview
This page is an index, referencing Green Book Attributes (potential deviations) to parts of my story.
Control Environment

- Attribute 1.01
Tone at the Top
Standards of Conduct
Adherence to Standards of Conduct
- Attribute 2.01
Oversight Structure
- Attribute 2.02
- Attribute 2.03
- Attribute 2.04
- Attribute 2.05
- Attribute 2.06
- Attribute 2.07
- Attribute 2.08
Oversight for the Internal Control System
Input for Remediation of Deficiencies
- Attribute 3.01
Organizational Structure
Assignment of Responsibility and Delegation of Authority
Documentation of the Internal Control System
- Attribute 4.01
Expectations of Competence
Recruitment, Development, and Retention of Individuals
- Attribute 4.05
Succession and Contingency Plans and Preparation
- Attribute 5.01
Enforcement of Accountability
Consideration of Excessive Pressures
Risk Assessment
- Attribute 6.01
Definitions of Objectives
Definitions of Risk Tolerances
- Attribute 7.01
Identify Risks
Analyze Risks
Respond to Risks
- Attribute 8.01
Identify Risks Related to Fraud, Improper Payments, and Information Security
Types of Fraud and Fraud Risk Factors
Types of Improper Payments and Improper Payment Risk Factors
- Attribute 8.13
Types of Information Security Risk and Information Security Risk Factors
Analyze and Respond to Identified Risks
- Attribute 9.01
Identify Significant Changes
Establish a Change Assessment Process
Identify, Analyze and Respond to Risks Related to Significant Changes
Control Activities

- Attribute 10.01
Response to Risks
- Attribute 10.02
Design of Appropriate Types of Control Activities
Design of Automated and Manual Control Activities
Design of Preventive and Detective Control Activities
Design of Control Activities at Various Levels
- Attribute 10.14
- Attribute 10.15
- Attribute 10.16
- Attribute 10.17
- Attribute 10.18
- Attribute 10.19
- Attribute 10.20
Segregation of Duties
- Attribute 11.01
Response to Risks
- Attribute 11.02
Design of the Entity’s Information Technology
Design of Appropriate Types of General Control Activities
- Attribute 11.07
- Attribute 11.08
- Attribute 11.09
- Attribute 11.10
- Attribute 11.11
- Attribute 11.12
- Attribute 11.13
- Attribute 11.14
- Attribute 11.15
- Attribute 11.16
- Attribute 11.17
- Attribute 12.01
Documentation of Control Activities Through Policies and Procedures
Periodic Review of Control Activities
- Attribute 12.05
Information and Communication

- Attribute 13.01
Identification of Information Requirements
Relevant Data from Reliable Sources
- Attribute 13.04
Data Processed into Quality Information
- Attribute 14.01
Communication Throughout the Entity
Appropriate Methods of Communication
- Attribute 15.01
Communication with External Parties
Appropriate Methods of Communication
Monitoring

- Attribute 16.01
Establishment of a Baseline
Internal Control System Monitoring
Evaluation of Results
- Attribute 17.01
Reporting of Issues
Evaluation of Issues
- Attribute 17.05
Corrective Actions

