Lecture 9: Security & Employers and Employees Flashcards

1
Q

What is Creesseys hypothesis?

A

People in trusted positions can also become trust violators.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are some Motives for Committing crime?

A
  1. Monetary gain - hacking financial institutions, identity theft, trade secrets
  2. strong emotions - love or despair (cyber stalking), hatred, dissatisfaction (customers), disgrunted employees, feuds
  3. Political or religious beliefs - crimes against minorities governments and society
  4. Sexual impulses - pornography, grooming, paedophillia
  5. Boredom or the desire for a “little fun”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some characteristics of cyber criminals?

A
  1. Some measure of technical knowledge
  2. Disregard the law or rationalisations about why particular laws are invalids or should not apply to them
  3. High tolerance for risk or need for “thrill factor”
  4. “Control freak” nature, enjoyment in manipulating or “outsmarting” others
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is IS audit?

A

IS auditing is about ensuring controls are present and assets are safeguarded, maintaned and operating effectively to achieve organisations objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Control?

A

Defined as:

  1. policies
  2. procedures
  3. practices &
  4. organisational structures

designed to provide reasonable assurance that business objectives will be achieved and that undesired events will be prevented, detected or corrected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is controls 3 classifications?

A
  1. Preventive - deter problems before they arise
  2. Detective - detect and report the occurrence of an error, omission or malicious act
  3. Corrective - minimise the impact of a threat, remedy problems discovered by corrective controls and identify the cause of the problem.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is organisational control?

A

The process of establishing and maintaining authority over and throughout an enterprise.

Are there written job descriptions for all jobs within the IT department?

Need a strategic plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are code maintaince and development?

A
  • Are there written standards for program maintainance?
  • Are changes to programs initiated by written request from user department and approved?
  • Are their tests before system acceptance?
  • are all program changes properly documented?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are software purchases?

A
  • Are there procedures addressing controls over selection, testing and acceptance of packaged software?
  • is adequate documentation maintained for all software purchased?
  • Are vendor warranties still in force?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are access controls?

A
  • Are there procedures or rules and regulations in place to ensure removal/termination of employees passwords and other authorisations?
  • is application level security violations logged?
  • Do termintals automatically log off after a set period of time?
  • are keys, locks, cards or other physical devices used to restrict access to only authorised users?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

List other controls?

A
  • Visitor control
  • Physical access
  • Backup
  • Disaster Recovery
  • Personnel policies - training, ID cards
  • Power suppy protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the difference between wages and salary?

A

Wages:

  • paid hourly.
  • over time, weekends are a higher rate
  • work roster is irregular

Salary

  • Paid weekly, forthnightly, monthly
  • Work is considered regular
  • may contain non-cash components
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are other distinctions of employees?

A
  • full time, part time
  • ongoing/permanent, fixed-time contract
  • part-time, casual
  • salary, commision
  • salary, bonuses (cash, shares)
  • award, award-free
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Employee or Contractor?

What is best for you?

Though career, financial, personal point of view?

A

Control Over Work

  • E: can direct and control work
  • C:has discretion over how to do work, unless specified in contract

Independence

  • E: employees work is integral to the firm
  • C: contractors work is complementary

Payment:

  • E: based on the period of time worked, “piece rates” or commision
  • C: depends on the performance of the contracted service

Commercial Risk:

  • E: generally bears no legal risks in respect of work
  • C: bears legal risk in respect to work, have potential to make profit or loss, must fix any faulty work at their own expense

Ability to delegate:

  • E: performs the work personally and generally cannot subcontract the work to someone else
  • C: unless otherwise specified in the contract. they can subcontract or delegate work

Tools and Equipments:

  • E: usually provided with tools (ipones) etc…unless specified not to
  • C:provides their own tools

Total Earnings package:

  • E: will receive superannouation, annual leave, sick leave and long service leave in accordance with the award under which their employment is regulated
  • C: will recieve a higher rate of pay to compensate for these additional payments to employees (superannuation)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the 8 steps of motivating employees?

A
  1. Focus
  2. Personalities
  3. Communication
  4. Leadership
  5. Expectations
  6. Cost
  7. Environment
  8. Emotions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly