test Flashcards

1
Q

What are the different kind of losses

A
  1. Monetary losses
  2. Loss in reputation
  3. Loss of compliance to regulation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the types of decisions made that are affected by poor data

A
  1. Strategic planning
  2. Operational planning
  3. Management control
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of computer abuse

A
  1. Hacking -
  2. Malware -
  3. Illegal physical access -
  4. Abuse of privileges -
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Consequences of computer abuse

A
  1. Destruction of assets - hardware, software, data can be destroyed
  2. Theft of assets - ^ can be stolen
  3. Modification of assets - data can be modified
  4. Privacy violation - privacy of personal data compromised
  5. Disruption of operations - day to day operations can cease to operate immediately
  6. Unauthorized use of data - unauthorized users
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Cost of computer abuse

A
  1. monetary costs - business market share, government
  2. costs - human life, environment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Definition of auditing

A

the process
of collecting and evaluating evidence to
determine whether a computer system
safeguards assets, maintains data integrity,
allows organizational goals to be achieved
effectively, and uses resources efficiently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

4 foundations of IS auditing

A
  1. Infosystems management - technical know how of how to do
  2. Traditional auditing - forms base knowledge content about auditing using knowledge from traditional auditing
  3. Computer science - technical know how on how tor rectify errors
  4. Behavioral science - non-compliance generated from human so what are the conditions that cause humans to be non compliant
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

4 objectives of IS auditing

A
  1. Asset safeguarding
  2. Data integrity
  3. System efficiency
  4. System effectiveness
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What can standards help with

A
  1. Provide a set of best practices to follow
  2. Framework for organizations to rate themselves and certify themselves
  3. Framework for collaboration with other companies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Definition of standards

A

Mandatory activities, actions, rules or regulations that are used to provide support to policies to make it meaningful and effective.

Provide common standard for security evaluation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are policies and procedures

A

Set of documents that describe the org policies for operation and procedures necessary to fulfil the policies.

Policies are usually based on management’s goals or adoption of best practices from standards

Procedures are usually just steps in order to fulfil a task which is in line with the policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly