2. IS Auditing - Overview Flashcards

0
Q

What is the basic point made by snowflake theory?

A

That every information system is unique

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

What theory do Juergens and Maberry apply to information systems?

A

Snowflake Theory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List ten different decisions that will impact on what an information system looks like when in operation.

A
Centrally based or distributed
Managed in-house or externally
Size of the organisation
Choice of operating system
Choice of hardware
Choice of software
Customisation of system
Empowerment of users
Development budget
Degree of innovation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The risks related to information technology and information systems are static/dynamic?

A

Dynamic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A factor of information systems risk is that, while individual risks may be low, when combined…

A

Their sum may be much greater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

List six generic WCGWs for an information system

A
Availability
Security
Integrity
Confidentiality
Effectiveness
Efficiency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The first step when assessing IS risks is to…

A

Identify what could go wrong

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The second step when assessing IS risk is to consider whether the risks…

A

Are specific to one system or process, or pervasive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The third step in a risk assessment of IS is to…

A

Use an appropriate risk assessment technique to help develop the audit plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly