2. IS Auditing - Overview Flashcards
What is the basic point made by snowflake theory?
That every information system is unique
What theory do Juergens and Maberry apply to information systems?
Snowflake Theory
List ten different decisions that will impact on what an information system looks like when in operation.
Centrally based or distributed Managed in-house or externally Size of the organisation Choice of operating system Choice of hardware Choice of software Customisation of system Empowerment of users Development budget Degree of innovation
The risks related to information technology and information systems are static/dynamic?
Dynamic
A factor of information systems risk is that, while individual risks may be low, when combined…
Their sum may be much greater
List six generic WCGWs for an information system
Availability Security Integrity Confidentiality Effectiveness Efficiency
The first step when assessing IS risks is to…
Identify what could go wrong
The second step when assessing IS risk is to consider whether the risks…
Are specific to one system or process, or pervasive
The third step in a risk assessment of IS is to…
Use an appropriate risk assessment technique to help develop the audit plan.