4-2. Protection of Information Flashcards
IT policies: what must it be link to?
To entity’s strategy and objectives.
IT policies: what does it need?
- An owner who is responsible for ensuring that the policy is operating and is updated
- A process for evolving with change
IT policies: what should it include?
A title, purpose, scope and context, stmts of responsibilities, time for updating.
IT policies: According to COSO, what are policies?
- Central to internal control
- Reflect management’s intentions re: actions
- Procedures are actions to implement policies
IT policies: purposes?
- Help establish a shared organizational understanding of IT
- Help in managing cyber risks
- Particularly valuable in decentralized or geographically distributed entities
IT policies: what are 4 important policies?
- Values and service culture: expectation of IT function personnel in interactions with clients and others
- Contractors, employees and sourcing: why, when and how entity selects IT human resources from employees vs. outside contractors (i.e. IT sourcing and outsourcing policy)
- Electronic communications use: policy related to employee use of the Internet, intranet, email, blogs, chat rooms and telephones
- Use and connection policy: entity’s position on the use of personal devices and applications in workplace and connection to the entity’s systems
- Procurement: policy on procurement processes for obtaining IT services
- Quality: Stmt of IT performance stds (e.g. we will respond to IT calls within a certain amount of time etc)
- Regulatory compliance: Stmt of regulatory requirements for IT systems (i.e. in banking or investment systems or related data privacy)
- Security: policy related to guarding against physical or electronic threats to IT. May include disaster recovery preparation policies
- Service management and operational service problem solving: policies for ensuring quality of live IT services
IT policies: what are things that included in monitoring?
- May include internal audit staff
- May be continuous or periodic
- Analysis (monitoring) of IT help calls and operational reports provide evidence of policy noncompliance, use, and understanding
What is E-business?
- Business process that relies on electronic dissemination of information or automated transaction processing
- Uses Internet to improve business performance through connectivity.
- Can be within or between organizations
- Most via the Internet using web-based technologies
What is E-commerce?
- Narrower - Transactions between organization and trading partners
- Marketing, buying, and selling of products and services via the Internet
- Relies on intermediaries or brokers to facilitate the sales transaction (e.g. eBay)
What is the relationship between E-business and E-commerce?
E-commerce = subcategory of E-business.
What is B2B?
Business-to-business: A type of e-commerce
e.g. e-processing of business transactions, electronic data interchange (EDI), supply chain management (SCM), and electronic funds transfer (EFT).
What is B2C?
Business-to-consumer e-commerce: selling goods and services to consumers, usually on Internet and web-based technology.
What is B2E?
Business-to-employees e-commerce: sharing information and interacting with employees often using intranet.
What is B2G?
Business-to-government e-commerce: e.g. contract biding, property disposal, audit procurement.
EC: What is a critical requisite?
Trust in trading partners, site or service provider
EC: risks?
- Availability/downtime
- Privacy, security and confidentiality
- Authentication and nonrepudiation (after fact, one can’t claim that transaction never occurred)
- Integrity
EC: risks of failing to implement EC?
- Customer go elsewhere
- Limited growth
- Limited markets
EC: what are business models?
- E-marketplaces and exchanges
- Viral marketing
- Online direct marketing
- E-tendering systems
- Social networking
E-commerce applications: what are common examples?
- Customer Relationship Management (CRM)
- Electronic Data Interchange (EDI)
- Electronic Funds Transfer (EFT)
- Supply Chain Management (SCM)
E-commerce applications: what is CRM?
*Technologies for managing client relationships
E.g. Customer data, profitability, personalized marketing
*Database of customer data