Chapter 8Controlling Information Systems: Introduction to
Pervasive Controls Key
1. IT governance is a process that ensures that the organization’s IT sustains and extends the organization’s
strategies and objectives.
2. According to COBIT, IT resources include applications, information, infrastructure, and people.
3. According to COBIT, IT resources must be managed by IT control processes to ensure that an organization
has the information it needs to achieve its objectives.
4. The system of controls used in this text consists of the control environment, pervasive control plans, IT
general controls, and business process and application control plans.
5. The information systems function is synonymous with the accounting function.
6. The function composed of people, procedures, and equipment and is typically called the information systems
department, IS department, or the IT department is the information systems organization.
7. The IS function with the responsibility of guiding the IT organization in establishing and meeting user
information requirements is the IT steering committee.
8. The IS function with the principal responsibilities of ensuring the security of all IT resources is data control.
9. The IS function of quality assurance conducts reviews to ensure the attainment of IT objectives.
10. The chief information officer (CIO) prioritizes and selects IT projects and resources.
11. Within the data center, the data control group is responsible for routing all work into and out of the data
center, correcting errors, and monitoring error correction.
12. The systems development function provides efficient and effective operation of the computer equipment.
13. Within the data center, the data librarian function grants access to programs, data, and documentation.
14. Combining the functions of authorizing and executing events is a violation of the organizational control plan
known as segregation of duties.
15. Segregation of duties consists of separating the four functions of authorizing events, executing events,
recording events, and safeguarding the resources resulting from consummating the events.
16. Embezzlement is a fraud committed by two or more individuals or departments.
17. A small organization that does not have enough personnel to adequately segregate duties must rely on
alternative controls, commonly called resource controls.
18. The functions of the security officer commonly include assigning passwords and working with human
resources to ensure proper interview practices are conducted during the hiring process.
19. Individual departments coordinate the organizational and IT strategic planning processes and reviews and
approves the strategic IT plan.
20. The policy of requiring an employee to alternate jobs periodically is known as forced vacations.
21. Forced vacations is a policy of requiring an employee to take leave from the job and substitute another
employee in his or her place.
22. A fidelity bond indemnifies a company in case it suffers losses from defalcations committed by its
employees.
23. The WebTrust family of services offers best practices and e-business solutions related exclusively to B2B
electronic commerce.
24. Data encryption is a process that codes data to make it readable to human eye.
25. Systems documentation provides an overall description of the application, including the system’s purpose;
an overview of system procedures; and sample source documents, outputs, and reports.
26. Program documentation provides a description of an application program and usually includes the program’s
purpose, program flowcharts, and source code listings.
27. The user manual gives detailed instructions to computer operators and to data control about a particular
application.
28. The operations run manual describes user procedures for an application and assists the user in preparing
inputs and using outputs.
29. Training materials help users learn their jobs and perform consistently in those jobs.
30. Program change controls provide assurance that all modifications to programs are authorized and
documented, and that the changes are completed, tested, and properly implemented.
31. Business continuity planning is the process that identifies events that may threaten an organization and
provide a framework whereby the organization will continue to operate when the threatened event occurs or
resume operations with a minimum of disruption.
32. Business continuity is the process of using backup measures to restore lost data and resume operations.
33. With continuous data protection (CDP) all data changes are data stamped and saved to secondary systems as
the changes are happening.
34. The disaster backup and recovery technique known as electronic vaulting is a service whereby data changes
are automatically transmitted over the Internet on a continuous basis to an off-site server maintained by a third
party.
35. The disaster recovery strategy known as a cold site is a fully equipped data center that is made available to
client companies for a monthly subscriber fee.
36. A facility usually comprised of air-conditioned space with a raised floor, telephone connections, and
computer ports, into which a subscriber can move equipment, is called a hot site.
37. In a logic bomb attack, a Web site is overwhelmed by an intentional onslaught of thousands of simultaneous
messages, making it impossible for the attacked site to engage in its normal activities.
38. Biometric identification systems identify authorized personnel through some unique physical trait such as
fingers, hands, voice, eyes, face, or writing dynamics.
39. Antivirus is a technique to protect one network from another “untrusted” network.
40. The most common biometric devices perform retinal eye scans.
42. Threat monitoring is a technique to protect one network from another “untrusted” network.
43. Application controls restrict access to data, programs, and documentation.
44. An intrusion-detection systems (IDS) logs and monitors who is on or trying to access the network.
45. Intrusion-prevention systems (IPS) actively block unauthorized traffic using rules specified by the
organization.
46. Periodic cleaning, testing, and adjusting of computer equipment is referred to as preventative maintenance.
47. Computer hacking and cracking is the intentional, unauthorized access to an organization’s computer
system, accomplished by bypassing the system’s access security controls.
48. The use of IT resources for enterprise systems and e-business:
49. Top 10 management concerns about IT’s capability to support an organization’s vision and strategy include
all except the following:
50. Top security concerns reported by IT security professionals include all the following except:
51. Pervasive control plans:
52. COBIT was developed to:
53. The department or function that develops and operates an organization’s information systems is often called
the:
54. In an information systems organization structure, the three functions that might logically report directly to
the CIO would be:
55. COBIT was developed by:
D. AICPA
56. Quality assurance function:
57. This IT function’s key control concern is that organization and IT strategic objectives are misaligned:
58. ____ can consist of many computers and related equipment connected together via a network.
59. In an information systems organization, which of the following reporting relationships makes the least
sense?
60. In an information systems organization, all of the following functions might logically report to the data
center manager except:
A. data control
61. Managing functional units such as networks, CAD/CAM and systems programming typically is a major
duty of:
62. From the standpoint of achieving the operations system control goal of security of resources, which of the
following segregation of duties possibilities is least important?
63. A key control concern is that certain people within an organization have easy access to applications
programs and data files. The people are:
64. Which of the following has the major duties of prioritizing and selecting IT projects and resources?
65. Which of the following has the responsibility to ensure the security of all IT resources?
66. Which of the following has the responsibility of efficient and effective operation of IT?
67. In an information systems organizational structure, the function of ____ is the central point from which to
control data and is a central point of vulnerability.
A. data control
68. The control concern that there will be a high risk of data conversion errors relates primarily to which of the
following information systems functions?
69. The controlled access to data, programs, and documentation is a principal responsibility of which of the
following functions?
70. Which of the following is not one of COBIT’s four broad IT control process domains?
71. Which of the following is not a strategic planning process?
A. IT-related requirements to comply with industry, regulatory, legal, and contractual obligations, including
privacy, transborder data flows, e-business, and insurance contracts.
72. Which one of the following personnel is not involved in safeguarding resources resulting from
consummating events?
A. security officer
73. The segregation of duties control plan consists of separating all of the following event-processing functions
except:
74. A warehouse clerk manually completing an order document and forwarding it to purchasing for approval is
an example of:
A. authorizing events
75. Specifications for availability, reliability, performance, capacity for growth, levels of user support, disaster
recovery, security, minimal system functionality, and service charges are included in:
76. Approving a customer credit purchase would be an example of which basic events processing function?
77. An employee of a warehouse is responsible for taking a computer-generated shipping list, pulling the items
from the warehouse shelves and placing them on a cart which is transferred to shipping when the list is
completely filled. This is an example of:
78. An outside auditing firm annually supervises a physical count of the items in a retail store‘s shelf inventory.
This is an example of:
A. authorizing events
79. A warehouse supervisor prepares a sales order listing items to be shipped to a customer and then signs it
approving the removal of the items from the warehouse. The supervisor is performing which functions?
A. authorizing events and safeguarding of resources
80. A clerk receives checks and customer receipts in the mail. He endorses the checks, fills out the deposit slip,
and posts the checks to the cash receipts events data. The clerk is exercising which functions?
C. recording and authorizing events
D. safeguarding of resources and authorizing events
81. When segregation of duties cannot be effectively implemented because the organization is too small, we
may rely on a more intensive implementation of other control plans such as personnel control plans. This is
called:
82. A method of separating systems development and operations is to prevent programmers from:
A. performing technical services
83. Which of the following control plans is not a retention control plan?
84. Personnel development control plans consist of each of the following except:
85. The primary reasons for performing regular employee performance reviews include all of the following
except:
A. determine whether an employee is satisfying the requirements indicated by a job description
86. A policy that requires employees to alternate jobs periodically is called:
87. A control plan that is designed to detect a fraud by having one employee periodically do the job of another
employee is called:
88. A mechanism by which a company is reimbursed for any loss that occurs when an employee commits fraud
is called a:
89. Which of the following personnel security control plans is corrective in nature as opposed to being a
preventive or detective control plan?
90. Personnel termination control plans might include all of the following except:
91. Instructions for computer setup, required data, restart procedures, and error messages are typically contained
in a(n):
92. Application documentation that describes the application and contains instructions for preparing inputs and
using outputs is a(n):
93. Alternative names for contingency planning include all of the following except:
94. A data replication strategy where all data changes are data stamped and saved to secondary systems as the
changes are happening is called:
95. All of the following are components of a backup and recovery strategy except:
96. Which of the following statements related to denial of service attacks is false?
A. Insurance is available to offset the losses suffered by denial of service attacks.
97. In an on-line computer system, restricting user access to programs and data files includes all of the
following except:
A. user identification
98. Sending out an e-mail pretending to be a legitimate business asking for information about a person’s account
is called:
99. Which of the following controls restrict access to programs, data, and documentation?
100. This logs and monitors who is on or trying to access an organization’s network.