ProSyllabus Journal

Sr. Accountant Incentive Exam: IT Theory Section, Books and Topics

Section III, 20 marks: computer basics, MS Office, networks, the IT Act, information security, DBMS, and the CAG Standing Order on Auditing in an IT Environment of 06.08.2020.

By ProSyllabus Admin
Updated 2 days agoCAG Incentive Exam for Sr. Accountants · Syllabus · IT Theory
#IT theory CAG incentive exam#standing order auditing in an IT environment 2020#confidentiality integrity non-repudiability availability#DBMS normalization departmental exam#sr accountant incentive exam IT syllabus#CAG departmental exam IT Act 2000
Sr. Accountant Incentive Exam: IT Theory Section, Books and Topics

Checked 29 September 2026. From the revised syllabus of 12.07.2024 and the CAG Standing Order of 06.08.2020. The syllabus names the 2013 editions of the Microsoft Office books; if Exam Wing revises the list, this page changes. Nothing had been notified by 29 September 2026.

Section III of the Finance & Government Accounts paper is 20 marks of IT Theory. It is the section where the syllabus reads most like a textbook contents page: computers, Office software, networks, the IT Act, information security and databases. It also names one CAG document, the Standing Order on Auditing in an IT Environment of 06.08.2020, which gives exact definitions an MCQ can quote. This guide lists every topic, the books named against it, the Standing Order's definitions, and where the section overlaps the Regulations on Audit and Accounts in Section II. ProSyllabus is an independent study site, not part of the Comptroller and Auditor General of India, the Indian Audit and Accounts Department or the Controller General of Accounts. Every rule here is quoted or summarised from Exam Wing and field-office circulars and from the documents the syllabus names; the competent authority in your office decides every individual case.

Where other pages get this wrong

The one CAG document named in Section III is the Standing Order of 06.08.2020. It replaced Chapter 22 of MSO (Audit) 2002 and the 2006 IT Audit Manual, so notes built on those are out of date.

Commonly published instead: Older IT audit notes built on MSO (Audit) Chapter 22 or the 2006 Manual of Information Technology Audit.

The syllabus itself says the Standing Order "replaces existing Chapter 22 of MSO (Audit) 2002 and also the Manual of Information Technology Audit issued in 2006", and the Standing Order says the same on its first page.

4
topic blocks in Section III
6
books and documents named
8
information criteria defined in the Standing Order
20
marks

Revised syllabus (12.07.2024); Standing Order of 06.08.2020 para 2.2 (official).

The syllabus, block by block

BlockTopics namedReference named
1. Fundamentals of computers and ITIntroduction to computers and their components; MS Word, MS Excel, MS PowerPoint; operating system and its functions; LAN, WAN, Internet, server-client infrastructure, end-point devicesPeter Norton, Introduction to Computers; Microsoft Word 2013 Step by Step (Lambert & Cox); Excel 2013 Step by Step (Frye); PowerPoint 2013 Step by Step (Lambert & Cox)
2. IT Act, 2000The Information Technology Act, 2000 and subsequent amendmentsThe Information Technology Act, 2000
3. Protection of information assetsConfidentiality, integrity, non-repudiability and availability; privacy principles and principles of personally identifiable information; physical access and environment controlStanding Order on Auditing in an IT environment, 06.08.2020
4. Database management systemsDBMS and RDBMS basics, designing a database, normalization; integrity constraints (primary and foreign keys), types of relationships; action queries, joins, views, data manipulationNone named separately

Two things follow from that list. First, the Office books are the 2013 editions; the menus have moved since, but the concepts an MCQ can test (what a formula, a mail merge, a slide master or a pivot table does) have not. Second, the only document from the CAG in this section is the Standing Order, and it is where the section's security vocabulary comes from. Learn its definitions as written.

The Standing Order's eight information criteria

Para 2.2 of the Standing Order says that "to satisfy business objectives, information needs to conform to certain control criteria or attributes" and defines eight. The syllabus names four of them directly (confidentiality, integrity, non-repudiability, availability), and para 4.3 of the Standing Order defines information security as the ability to protect information and system resources with regard to exactly those four. The other four complete the list regulation 17 of the Regulations on Audit and Accounts also uses.

CriterionStanding Order para 2.2 says itNamed in the syllabus?
Confidentialityconcerns the protection of sensitive information from unauthorised disclosureYes (block 3)
Integrityrelates to the accuracy and completeness of information as well as to its validity in accordance with business values and expectationsYes (block 3)
Non-repudiabilityis the assurance that a party cannot later deny originating data and is based on provision of proof of the integrity and origin of the data that can be verified by a third partyYes (block 3)
Availabilityrelates to information being available when required by the business process now and in the future. It also concerns the safeguarding of necessary resources and associated capabilitiesYes (block 3)
Effectivenessdeals with information being relevant and pertinent to the business process as well as being delivered in a timely, correct, consistent and usable mannerNo, but in the Standing Order and RAA reg 17
Efficiencyconcerns the provision of information through the optimal (most productive and economical) use of resourcesNo, but in the Standing Order and RAA reg 17
Compliancedeals with complying with the laws, regulations and contractual arrangements to which the business process is subject, i.e. externally imposed business criteria as well as internal policiesNo, but in the Standing Order and RAA reg 17
Reliabilityrelates to the provision of appropriate information for management to operate the entity and exercise its fiduciary and governance responsibilitiesNo, but in the Standing Order and RAA reg 17

Which criterion is at stake?

Information criterion matcher

Pick a situation. The matcher names the criterion most directly at stake and quotes the Standing Order's definition. The situations are our examples; the definitions are the Standing Order's.

Definitions from the Standing Order of 06.08.2020 para 2.2 (official). Real cases often touch more than one criterion; an exam question will usually point at one.

What else in the Standing Order is testable

ParaTopicThe point
1.2Audit of IT systems vs IT-assisted auditsAn IT audit examines the system itself; an IT-assisted audit is a financial, compliance or performance audit that uses IT tools
2FrameworksBuilt largely on COBIT 4.1 and COBIT 5 (ISACA) and ISO/IEC 38500:2015, with ISO/IEC 27000 for security, in the absence of a Government of India framework
2.3IT resourcesApplications, information, infrastructure and people
2.4.1General and application controlsGeneral controls cover the environment in which all applications run (IT strategy, security policy, segregation of duties, disaster recovery, environment and physical access); application controls are specific to each application
2.5ISMS control areas (ISO/IEC 27001)Includes physical and environmental security, access control, cryptographic controls, operations and communications security, supplier relationships, incident and continuity management
2.6IT domainsPlan and Organize; Acquire and Implement; Deliver and Support; Monitor and Evaluate
4.1Application controlsFour kinds: input controls (the most important source of error or fraud is input), processing controls, output controls, and application security controls (para 4.1.4: traceability of transactions, user and account permissions, IT and development team access to production databases, master file and standing data protection, segregation of duties)
4.3IT securitySecurity is protection with regard to confidentiality, integrity, non-repudiability and availability

Physical access and environment control, named in block 3 of the syllabus, recur in several places in the Standing Order: as a general control (physical access controls over the data centre, environment controls), under "managing the physical environment" in delivery and support, and as one of the ISO/IEC 27001 control areas, "physical and environmental security". Privacy and the protection of personally identifiable information are mentioned in the Standing Order (as external requirements an IT process must comply with) but not defined there, and the syllabus names no other reference for them; your textbook is the place for the principles.

Database management: the terms to know

Block 4 is standard database theory, and the syllabus names no book for it. The meanings below are the usual textbook ones, in our words, not from any CAG document.

TermUsual textbook meaning
DBMS / RDBMSSoftware to store and retrieve data; a relational DBMS keeps data in tables of rows and columns related by keys
Primary keyA column (or set of columns) whose value identifies each row uniquely and is never empty
Foreign keyOne or more columns that refer to the primary key (or another unique key) of a table, usually another table; referential integrity means every non-null foreign key value must match a row that exists
RelationshipsOne-to-one, one-to-many and many-to-many links between tables
NormalizationSplitting tables to remove repeated data and update anomalies, in stages called normal forms
Action queryA query that changes data (insert, update, delete, make-table) rather than only selecting it
JoinCombining rows of two tables on a matching column; inner joins keep only matches, left and right outer joins also keep unmatched rows from one side, a full outer join from both sides
ViewA saved query that behaves like a table but stores no data of its own

The Standing Order links to databases in several places: "referential integrity checks" among processing controls in para 4.1.2, IT and development team access to production databases and master file protection in para 4.1.4, and querying of RDBMS data among audit techniques. A question that links a foreign key to referential integrity is therefore on both the textbook side and the CAG side of this section.

The IT Act 2000

The syllabus names "IT Act, 2000 and subsequent amendments" and the Act itself as the reference. It gives no section list. We have not summarised the Act's sections here, because a paraphrase from memory is exactly how wrong section numbers get into study notes. Read the current consolidated text on India Code, which carries the amendments in place, and, as our study suggestion rather than a syllabus boundary (the syllabus names the whole Act), start with the parts a government accounts office meets: electronic records and digital or electronic signatures, their legal recognition, and unauthorised access and data damage, where the Act keeps two things apart: liability to pay compensation for the act itself, and a separate criminal offence when the same act is done dishonestly or fraudulently.

Where Section III overlaps Section II

TopicSection II (RAA 2020, Ch 3)Section III (Standing Order)
IT audit vs IT-assisted auditRegulations 16-18Para 1.2
Information criteriaRegulation 17(2)(ii)Para 2.2
General and application controlsRegulation 17Paras 2.4.1 and 4.1
Off-site audit where systems are end-to-end automatedRegulation 16(4)Para 4.2 (substantive testing and CAATs)

Reading the Standing Order therefore pays twice: it is the named reference for Section III, and it expands Chapter 3 of the Regulations in Section II. Because it overlaps Sections II and III, close study of its 29 pages covers material for both.

Tick off Section III

Section III tracker

Our study checklist built from the syllabus topics, with the named reference in brackets; the count is ours, not an official topic count.

0 of 16 done

1. Fundamentals (0/6)
2 and 3. Law and security (0/5)
4. Databases (0/5)

Ticks are saved only in this browser on this device.

What is in the IT Theory section of the Sr. Accountant incentive exam?

Computer fundamentals, MS Word, Excel and PowerPoint, operating systems and networks; the IT Act 2000 and amendments; confidentiality, integrity, non-repudiability, availability, privacy and PII, physical access and environment control; and database management (DBMS, RDBMS, normalization, keys, relationships, action queries, joins and views). 20 marks.

Which books are named for IT Theory?

Peter Norton's Introduction to Computers; Microsoft Word 2013, Excel 2013 and PowerPoint 2013 Step by Step; the IT Act 2000; and the CAG Standing Order on Auditing in an IT environment of 06.08.2020.

What does non-repudiability mean in the CAG Standing Order?

The assurance that a party cannot later deny originating data, based on proof of the integrity and origin of the data that a third party can verify (para 2.2).

Does the Standing Order replace the old IT audit manual?

Yes. It replaces Chapter 22 of MSO (Audit) 2002 and the Manual of Information Technology Audit issued in 2006.

Is there a practical computer test?

Not for this exam. The paper is 100 MCQ in 2 hours; IT practicals belong to other departmental exams.

Do I need the 2013 editions of the Office books?

They are the editions the syllabus names. Concepts matter more than menus for MCQs, and for any version-specific detail use those editions unless the Exam Wing issues a revised reference list.

This chapter is part of the CAG Incentive Examination for Senior Accountants Board ExaminationExplore every chapter — summary, notes, extra questions & MCQ quizzes

More on CAG Incentive Examination for Senior Accountants4 guides

Group Discussions

No forum posts available.

Share this article