Checked 29 September 2026. From the revised syllabus of 12.07.2024 and the CAG Standing Order of 06.08.2020. The syllabus names the 2013 editions of the Microsoft Office books; if Exam Wing revises the list, this page changes. Nothing had been notified by 29 September 2026.
Section III of the Finance & Government Accounts paper is 20 marks of IT Theory. It is the section where the syllabus reads most like a textbook contents page: computers, Office software, networks, the IT Act, information security and databases. It also names one CAG document, the Standing Order on Auditing in an IT Environment of 06.08.2020, which gives exact definitions an MCQ can quote. This guide lists every topic, the books named against it, the Standing Order's definitions, and where the section overlaps the Regulations on Audit and Accounts in Section II. ProSyllabus is an independent study site, not part of the Comptroller and Auditor General of India, the Indian Audit and Accounts Department or the Controller General of Accounts. Every rule here is quoted or summarised from Exam Wing and field-office circulars and from the documents the syllabus names; the competent authority in your office decides every individual case.
Where other pages get this wrong
The one CAG document named in Section III is the Standing Order of 06.08.2020. It replaced Chapter 22 of MSO (Audit) 2002 and the 2006 IT Audit Manual, so notes built on those are out of date.
Commonly published instead: Older IT audit notes built on MSO (Audit) Chapter 22 or the 2006 Manual of Information Technology Audit.
The syllabus itself says the Standing Order "replaces existing Chapter 22 of MSO (Audit) 2002 and also the Manual of Information Technology Audit issued in 2006", and the Standing Order says the same on its first page.
Revised syllabus (12.07.2024); Standing Order of 06.08.2020 para 2.2 (official).
The syllabus, block by block
| Block | Topics named | Reference named |
|---|---|---|
| 1. Fundamentals of computers and IT | Introduction to computers and their components; MS Word, MS Excel, MS PowerPoint; operating system and its functions; LAN, WAN, Internet, server-client infrastructure, end-point devices | Peter Norton, Introduction to Computers; Microsoft Word 2013 Step by Step (Lambert & Cox); Excel 2013 Step by Step (Frye); PowerPoint 2013 Step by Step (Lambert & Cox) |
| 2. IT Act, 2000 | The Information Technology Act, 2000 and subsequent amendments | The Information Technology Act, 2000 |
| 3. Protection of information assets | Confidentiality, integrity, non-repudiability and availability; privacy principles and principles of personally identifiable information; physical access and environment control | Standing Order on Auditing in an IT environment, 06.08.2020 |
| 4. Database management systems | DBMS and RDBMS basics, designing a database, normalization; integrity constraints (primary and foreign keys), types of relationships; action queries, joins, views, data manipulation | None named separately |
Two things follow from that list. First, the Office books are the 2013 editions; the menus have moved since, but the concepts an MCQ can test (what a formula, a mail merge, a slide master or a pivot table does) have not. Second, the only document from the CAG in this section is the Standing Order, and it is where the section's security vocabulary comes from. Learn its definitions as written.
The Standing Order's eight information criteria
Para 2.2 of the Standing Order says that "to satisfy business objectives, information needs to conform to certain control criteria or attributes" and defines eight. The syllabus names four of them directly (confidentiality, integrity, non-repudiability, availability), and para 4.3 of the Standing Order defines information security as the ability to protect information and system resources with regard to exactly those four. The other four complete the list regulation 17 of the Regulations on Audit and Accounts also uses.
| Criterion | Standing Order para 2.2 says it | Named in the syllabus? |
|---|---|---|
| Confidentiality | concerns the protection of sensitive information from unauthorised disclosure | Yes (block 3) |
| Integrity | relates to the accuracy and completeness of information as well as to its validity in accordance with business values and expectations | Yes (block 3) |
| Non-repudiability | is the assurance that a party cannot later deny originating data and is based on provision of proof of the integrity and origin of the data that can be verified by a third party | Yes (block 3) |
| Availability | relates to information being available when required by the business process now and in the future. It also concerns the safeguarding of necessary resources and associated capabilities | Yes (block 3) |
| Effectiveness | deals with information being relevant and pertinent to the business process as well as being delivered in a timely, correct, consistent and usable manner | No, but in the Standing Order and RAA reg 17 |
| Efficiency | concerns the provision of information through the optimal (most productive and economical) use of resources | No, but in the Standing Order and RAA reg 17 |
| Compliance | deals with complying with the laws, regulations and contractual arrangements to which the business process is subject, i.e. externally imposed business criteria as well as internal policies | No, but in the Standing Order and RAA reg 17 |
| Reliability | relates to the provision of appropriate information for management to operate the entity and exercise its fiduciary and governance responsibilities | No, but in the Standing Order and RAA reg 17 |
Which criterion is at stake?
Information criterion matcher
Pick a situation. The matcher names the criterion most directly at stake and quotes the Standing Order's definition. The situations are our examples; the definitions are the Standing Order's.
Definitions from the Standing Order of 06.08.2020 para 2.2 (official). Real cases often touch more than one criterion; an exam question will usually point at one.
What else in the Standing Order is testable
| Para | Topic | The point |
|---|---|---|
| 1.2 | Audit of IT systems vs IT-assisted audits | An IT audit examines the system itself; an IT-assisted audit is a financial, compliance or performance audit that uses IT tools |
| 2 | Frameworks | Built largely on COBIT 4.1 and COBIT 5 (ISACA) and ISO/IEC 38500:2015, with ISO/IEC 27000 for security, in the absence of a Government of India framework |
| 2.3 | IT resources | Applications, information, infrastructure and people |
| 2.4.1 | General and application controls | General controls cover the environment in which all applications run (IT strategy, security policy, segregation of duties, disaster recovery, environment and physical access); application controls are specific to each application |
| 2.5 | ISMS control areas (ISO/IEC 27001) | Includes physical and environmental security, access control, cryptographic controls, operations and communications security, supplier relationships, incident and continuity management |
| 2.6 | IT domains | Plan and Organize; Acquire and Implement; Deliver and Support; Monitor and Evaluate |
| 4.1 | Application controls | Four kinds: input controls (the most important source of error or fraud is input), processing controls, output controls, and application security controls (para 4.1.4: traceability of transactions, user and account permissions, IT and development team access to production databases, master file and standing data protection, segregation of duties) |
| 4.3 | IT security | Security is protection with regard to confidentiality, integrity, non-repudiability and availability |
Physical access and environment control, named in block 3 of the syllabus, recur in several places in the Standing Order: as a general control (physical access controls over the data centre, environment controls), under "managing the physical environment" in delivery and support, and as one of the ISO/IEC 27001 control areas, "physical and environmental security". Privacy and the protection of personally identifiable information are mentioned in the Standing Order (as external requirements an IT process must comply with) but not defined there, and the syllabus names no other reference for them; your textbook is the place for the principles.
Database management: the terms to know
Block 4 is standard database theory, and the syllabus names no book for it. The meanings below are the usual textbook ones, in our words, not from any CAG document.
| Term | Usual textbook meaning |
|---|---|
| DBMS / RDBMS | Software to store and retrieve data; a relational DBMS keeps data in tables of rows and columns related by keys |
| Primary key | A column (or set of columns) whose value identifies each row uniquely and is never empty |
| Foreign key | One or more columns that refer to the primary key (or another unique key) of a table, usually another table; referential integrity means every non-null foreign key value must match a row that exists |
| Relationships | One-to-one, one-to-many and many-to-many links between tables |
| Normalization | Splitting tables to remove repeated data and update anomalies, in stages called normal forms |
| Action query | A query that changes data (insert, update, delete, make-table) rather than only selecting it |
| Join | Combining rows of two tables on a matching column; inner joins keep only matches, left and right outer joins also keep unmatched rows from one side, a full outer join from both sides |
| View | A saved query that behaves like a table but stores no data of its own |
The Standing Order links to databases in several places: "referential integrity checks" among processing controls in para 4.1.2, IT and development team access to production databases and master file protection in para 4.1.4, and querying of RDBMS data among audit techniques. A question that links a foreign key to referential integrity is therefore on both the textbook side and the CAG side of this section.
The IT Act 2000
The syllabus names "IT Act, 2000 and subsequent amendments" and the Act itself as the reference. It gives no section list. We have not summarised the Act's sections here, because a paraphrase from memory is exactly how wrong section numbers get into study notes. Read the current consolidated text on India Code, which carries the amendments in place, and, as our study suggestion rather than a syllabus boundary (the syllabus names the whole Act), start with the parts a government accounts office meets: electronic records and digital or electronic signatures, their legal recognition, and unauthorised access and data damage, where the Act keeps two things apart: liability to pay compensation for the act itself, and a separate criminal offence when the same act is done dishonestly or fraudulently.
Where Section III overlaps Section II
| Topic | Section II (RAA 2020, Ch 3) | Section III (Standing Order) |
|---|---|---|
| IT audit vs IT-assisted audit | Regulations 16-18 | Para 1.2 |
| Information criteria | Regulation 17(2)(ii) | Para 2.2 |
| General and application controls | Regulation 17 | Paras 2.4.1 and 4.1 |
| Off-site audit where systems are end-to-end automated | Regulation 16(4) | Para 4.2 (substantive testing and CAATs) |
Reading the Standing Order therefore pays twice: it is the named reference for Section III, and it expands Chapter 3 of the Regulations in Section II. Because it overlaps Sections II and III, close study of its 29 pages covers material for both.
Tick off Section III
Section III tracker
Our study checklist built from the syllabus topics, with the named reference in brackets; the count is ours, not an official topic count.
0 of 16 done
Ticks are saved only in this browser on this device.
What is in the IT Theory section of the Sr. Accountant incentive exam?
Computer fundamentals, MS Word, Excel and PowerPoint, operating systems and networks; the IT Act 2000 and amendments; confidentiality, integrity, non-repudiability, availability, privacy and PII, physical access and environment control; and database management (DBMS, RDBMS, normalization, keys, relationships, action queries, joins and views). 20 marks.
Which books are named for IT Theory?
Peter Norton's Introduction to Computers; Microsoft Word 2013, Excel 2013 and PowerPoint 2013 Step by Step; the IT Act 2000; and the CAG Standing Order on Auditing in an IT environment of 06.08.2020.
What does non-repudiability mean in the CAG Standing Order?
The assurance that a party cannot later deny originating data, based on proof of the integrity and origin of the data that a third party can verify (para 2.2).
Does the Standing Order replace the old IT audit manual?
Yes. It replaces Chapter 22 of MSO (Audit) 2002 and the Manual of Information Technology Audit issued in 2006.
Is there a practical computer test?
Not for this exam. The paper is 100 MCQ in 2 hours; IT practicals belong to other departmental exams.
Do I need the 2013 editions of the Office books?
They are the editions the syllabus names. Concepts matter more than menus for MCQs, and for any version-specific detail use those editions unless the Exam Wing issues a revised reference list.
Sources
- official — Revised Syllabus of "Incentive Examination for Senior Accountants", Paper: Finance & Government Accounts (standalone copy on the CAG Syllabus and Books page, PDF of 15.07.2024)
- official — Exam Wing Circular No. 02 of 2024, No. 237/03-Exam/Syllabus Revision/2024 (12.07.2024): revised syllabus of the DE for Accountants and the IE for Sr. Accountants of A&E offices, applicable from the date of issue
- official — CAG Standing Order "Auditing in an Information Technology (IT) Environment", No. 94/17-PPG/2019 (06.08.2020): replaces Chapter 22 of MSO (Audit) 2002 and the IT Audit Manual of 2006
- official — Regulations on Audit and Accounts (Amendments) 2020, the CAG book (15 chapters, 173 regulations)
- official — India Code (Legislative Department): official text of the Information Technology Act, 2000 as amended
- official — Exam Wing Circular No. 01 of 2024, No. 15/15-Exam/Exam Conducting Centrally/2023 (17.01.2024): central conduct from 01.07.2024; IE "once in a year i.e. April"; 2 hours, 100 MCQ, pass 50% in the IE, 0.25 negative, round-up rule, chances counted afresh
official = a document published by the conducting body. reported = a news or coaching site we could not check against an original. Where sources disagree this page says so rather than picking one.








