IT Security, Risks and Controls Flashcards

1
Q

Control plans

A

are policies and procedures that assist in accomplishing control goals.

Note - No control plan is 100% effective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A combination of plans must be used to maximize effectiveness. What are those Three level of plans?

A

1) control environment (top level),
2) pervasive control Plans (mid-level)
3) application control (detail level) Plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Preventive vs Detective vs Corrective control plans

A

Preventive control plans stop problems from occurring.

Detective control plans discover problems that have already occurred.

Corrective control plans correct problems that have already occurred.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What functions at a minimum should be separated

A

programming

operations

library

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Examples of confidential data

A
Transaction details 
engineering details of products 
business plans 
banking information 
legal documents 
inventory or other account information 
customer lists 
confidential details of operations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

It is more difficult to control access outside of a controlled MIS environment because

A

controls are less visible and more dependent on individual users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Information System risks examples

A

Financial Risk
Information Risk
Strategy Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Stragetic Risk

A

Poor Information Systems Decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Information Risk

A

Risk of Data Loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly