IT Security, Risks and Controls Flashcards
Control plans
are policies and procedures that assist in accomplishing control goals.
Note - No control plan is 100% effective
A combination of plans must be used to maximize effectiveness. What are those Three level of plans?
1) control environment (top level),
2) pervasive control Plans (mid-level)
3) application control (detail level) Plans
Preventive vs Detective vs Corrective control plans
Preventive control plans stop problems from occurring.
Detective control plans discover problems that have already occurred.
Corrective control plans correct problems that have already occurred.
What functions at a minimum should be separated
programming
operations
library
Examples of confidential data
Transaction details engineering details of products business plans banking information legal documents inventory or other account information customer lists confidential details of operations
It is more difficult to control access outside of a controlled MIS environment because
controls are less visible and more dependent on individual users
Information System risks examples
Financial Risk
Information Risk
Strategy Risk
Stragetic Risk
Poor Information Systems Decisions
Information Risk
Risk of Data Loss