101. Protecting resources against environmental hazards might include all of the following control plans
except:
A. fire alarms and smoke detectors
102. Searching through rubbish for system information such as passwords is called:
103. ______________________________ is a process that ensures that the enterprise’s IT sustains and extends
the organization’s strategies and objectives.
104. ______________________________ controls provide assurance that all modifications to programs are
authorized and documented, and that the changes are completed, tested, and properly implemented.
105. ______________________________ is a process that employs mathematical algorithms and encryption
keys to encode data (i.e., change un-encoded data, called plaintext, to a coded text form, called ciphertext) so
that it is unintelligible.
106. ______________________________ are particularly important because they operate across all business
processes and affect a company’s capability to meet a multitude of control goals.
107. ______________________________ in an internal control system means assessment by management to
determine whether the control plans in place are continuing to function appropriately over time.
108. The function composed of people, procedures, and equipment and is typically called the information
systems department, IS department, or IT department is the ______________________________.
109. The ______________________________ coordinates the organizational and IT strategic planning
processes and reviews and approves the strategic IT plan.
110. The ______________________________ is charged with safeguarding the IT organization.
111. Management should establish a(n) ______________________________ plan and implement related
activities, including reviews, audits, and inspections, to ensure the attainment of IT customer requirements.
112. The ______________________________ group is responsible for routing all work in to and out of the data
center, correcting errors, and monitoring all error correction.
113. The ______________________________ function provides efficient and effective operation of the
computer equipment by performing tasks such as mounting tapes, disks, and other media and monitoring
equipment operation.
114. The ______________________________ maintains custody of and controls access to programs, files, and
documentation.
115. Combining the functions of authorizing and executing events is a violation of the organizational control
plan known as ______________________________.
116. Segregation of duties consists of separating the four functions of authorizing events,
______________________________ events, ______________________________ events, and safeguarding the
resources resulting from consummating the events.
117. One method for circumventing segregation of duties is ______________________________ between one
or more persons (or departments) to exploit a system and conceal an abuse such as fraud.
118. A small organization that does not have enough personnel to adequately segregate duties must rely on
alternative controls, commonly called ______________________________.
119. The functions of the ______________________________ commonly include assigning passwords and
making sure the IT organization is secure from physical threats.
120. The ______________________________ coordinates the organizational and IT strategic planning
processes and reviews and approves the strategic IT plan.
121. The policy of requiring an employee to alternate jobs periodically is known as
______________________________.
122. ______________________________ is a policy of requiring an employee to take leave from the job and
substituting another employee in his or her place.
123. A(n) ______________________________ indemnifies a company in case it suffers losses from
defalcations committed by its employees.
124. The ______________________________ covers the progression of information systems through the
systems development process, from birth, through implementation, to ongoing use and modification.
125. Computer software that is used to facilitate the execution of a given business process is called
______________________________.
126. The ______________________________ documentation portion of application documentation provides an
overall description of the application, including the system’s purpose; an overview of system procedures; and
sample source documents, outputs, and reports.
127. ______________________________ documentation provides a description of an application computer
program and usually includes the program’s purpose, program flowcharts, and source code listings.
128. The ______________________________ gives detailed instructions to computer operators and to data
control about a particular application.
129. The ______________________________ describes user procedures for an application and assists the user
in preparing inputs and using outputs.
130. ______________________________ are documents that help users learn their jobs and perform
consistently in those jobs.
131. ______________________________ controls restrict access to data, programs and documentation.
132. The terms ______________________________ planning, disaster recovery planning, business interruption
planning, and business continuity planning have all been used to describe the backup and recovery control plans
designed to ensure that an organization can recover from a major calamity.
133. ______________________________ is a service whereby data changes are automatically transmitted over
the Internet on a continuous basis to an off-site server maintained by a third party.
134. With the data replication strategy known as ______________________________ all data changes are data
stamped and saved to secondary systems as the changes are happening.
135. The disaster recovery strategy known as a(n) ______________________________ is a fully equipped data
center that is made available on a standby basis to client companies for a monthly subscriber’s fee.
136. A facility usually comprised of air-conditioned space with a raised floor, telephone connections, and
computer ports, into which a subscriber can move equipment, is called a(n)
______________________________.
137. In a(n) ______________________________ a Web site is overwhelmed by an intentional onslaught of
thousands of simultaneous messages, making it impossible for the attacked site to engage in its normal
activities.
138. ______________________________ identification systems identify authorized personnel through some
unique physical trait such as fingers, hands, voice, eyes, face, and writing dynamics.
139. A(n) ______________________________ is a technique to protect one network from another “untrusted”
network.
140. The most common biometric devices read ______________________________.
141. In an online environment, ______________________________ ensures that only authorized users gain
access to a system through a process of identification (e.g., a unique account number for each user) and
authentication.
142. In an online computer environment, the accumulation of access activity and its review by the security
officer is also called ______________________________.
143. Periodic cleaning, testing, and adjusting of computer equipment is referred to as
______________________________.
144. ______________________________ is the intentional unauthorized access of an organization’s computer
system, accomplished by bypassing the system’s access security controls.
145. Copies of important stored data, programs, and documentation made periodically are called
______________________________.
146. The process whereby lost data is restored and operations are continued is called
______________________________.
147. The site that maintains copies of a primary computing site’s programs and data is a(n)
______________________________ site.
148. A(n) ______________________________ uses many computers, called zombies, that unwittingly
cooperate in a denial-ofservice attack by sending messages to the target Web site.
149. The ______________________________ logs and monitors who is on or is trying to access the network.
150. The ______________________________ actively blocks unauthorized traffic using rules specified by an
organization.
151. Watching a user type in passwords or user IDs or listening as they give account information over the phone
is called ______________________________.
152. ______________________________ is when a hacker calls and requests a password based on some
pretext.
153. ______________________________ helps to solve the problem posed by single key cryptography by
employing a pair of matched keys for each system user, one private (i.e., known only to the party who possesses
it) and one public.
154. ______________________________ is when an e-mail is sent pretending to be a legitimate business
asking for information about your account.
155. Below is a list of ten functional titles for the information systems organization structure shown in Chapter
8. The second list contains descriptions (some partial) of the duties and responsibilities of ten of the functions.
Required:
On the blank line to the left of each numbered description, place the capital letter of the functional title that best
matches the duties and responsibilities described. Do not use a letter more than once.
Function
al Title
A.
F.
Systems programming
B.
G.
Technical services manager
C.
H.
CIO
D.
I.
IT Steering committee
E.
J.
Security officer
ES
1.
Deliver cost-effective, bug-free applications.
2.
Route all work into and out of the data center, correct errors, and monitor all error correction.
3.
Plan IT acquisition and development.
4.
Conduct reviews to determine adherence to IT standards and procedures and achievement of IT objectives.
5.
Issue programs, data, and documentation to authorized users.
6.
Manage functional units such as networks, CAD/CAM and systems programming.
7.
Modify and adapt systems software including operating systems and various utility routines.
8.
Prepare input for computer processing.
9.
Manages physical security and logical security.
10.
Prioritize and select IT projects and resources.
Duties and
Responsibilities
Answer
1
E
3
H
4
A
5
C
6
G
7
F
8
D
9
J
I
156. The four events-processing functions that constitute the segregation of duties control plan are:
A.
Authorizing events
B.
Executing events
C.
Recording events
D.
Safeguarding resources
Required:
Below is a list of ten events-processing activities, five relating to the cycle of activities involved in processing a sales event and seven relating to the
cycle for a purchase event. Classify each of the twelve activities into one of the four functional categories listed above by placing the letter A, B, C,
or D on the answer line to the left of each number. You should use only one letter for each of the answers.
1.
The order entry department instructs the shipping department to ship goods to a customer by sending an approved
document to the shipping department.
2.
The shipping department keeps inventory items in a locked storeroom.
3.
The billing department prepares and mails a bill to the customer.
4.
The invoice in item 3 is added to the customer balance in the accounts receivable master data.
5.
The general ledger bookkeeper enters a sales event in a data file.
(For a purchase event)
6.
The purchasing department order goods.
7.
The inventory control department signs a document requesting that goods be purchased.
8.
The purchasing department manager reviews and signs all purchase order documents in excess of $100.
9.
The receiving department processes goods received from the vendor.
10.
The receiving department completes the receiving report.
11.
After being received goods are placed into the locked inventory storeroom.
12.
A payable is recognized by updating the accounts payable master data.
1
A
2
D
3
B
4
C
5
C
6
B
7
A
event)
157. Listed below are several pervasive control plans discussed in Chapter 8. On the blank line to the left of
each control plan, insert a “P” (preventive), “D” (detective), or “C” (corrective) to best classify that control. If
you think that more than one code could apply to a particular plan, insert all appropriate codes
CODE
CONTROL PLAN
1.
Service level agreements
2.
Program change controls
3.
Fire and water alarms
4.
Adequate fire and water insurance
5.
Install batteries for temporary loss in power
6.
Continuous-data protection (CDP)
7.
Intrusion-detection system (IDS)
8.
IT steering committee
9.
Security officer
10.
Operations run manuals
11.
Rotation of duties and forced vacations
12.
Fidelity bonding
13.
Personnel performance evaluations
14.
Personnel termination procedures
15.
Segregation of duties
16.
Strategic IT plan
17.
Disaster recovery planning
18.
Restrict entry to the computer facility through the use of security guards, locks, badges, and identification cards
19.
Personnel management (supervision)
20.
Library controls
158. The first list below contains 10 control plans discussed in Chapter 8. The second list describes 10 system
failures that have control implications.
Required:
On the answer line to the left of each system failure, insert the capital letter from the first list of the best control
plan to prevent the system failure from occurring. If you can’t find a control that will prevent the failure, then
choose a detective or a corrective plan. A letter should be used only once.
1.
The controller at Infotech, Inc. has just completed an analysis of personnel costs and believes that the cost associated
with training new personnel is too high. She attributes this high cost to the increasing rate at which employees are being
hired to replace defections to Infotech’s competitors.
2.
Paul the programmer has modified the accounts receivable statement program so that the receivables from his cousin
Peter will be eliminated from the accounts receivable master file upon printing of the monthly statements. Paul made
these changes to the program while he was operating the computer on a Saturday morning.
3.
When the hurricane hit the coast, Soggy Records Company lost the use of its flooded computer room. In such cases,
plans called for using an alternate computer center 100 miles inland. However, Soggy was unable to operate in the
alternate facility because the company’s programs and files were lost in the flooded computer facility.
4.
All the files were lost at the Stoughton Company when a visitor sat down at a computer terminal, signed on using one of
the passwords posted on the computer terminals, and erased some of the data files.
5.
Sally is the inventory control/warehouse clerk at Techtron Inc. She has been stealing secret computer components from
the warehouse, selling them to foreign agents, and covering up her thefts by altering the inventory records.
6.
At Maralee Company, there seems to be a lack of progression from lower to middle management. Edward, the director
of personnel, believes that the people being hired have great potential, but they are just not realizing their potential.
7.
Roger, the night-shift computer operator, has had occasion several times in the last month to call his supervisor to
receive assistance¾over the telephone¾to correct a problem that he was having in operating the computer.
8.
Mary had become quite unhappy with her job at Funk, Inc. She knew that she was going to quit soon and decided to
destroy some computer files. Using her own username and password, she found several disk packs on a table outside
the computer room and proceeded to “erase” the data with a powerful magnet. After Mary’s departure, Funk spent
several months reconstructing the data that had been on the lost files.
9.
One of the inventory control programs at Excess Company has been ordering more inventory than is required, causing
an overstock condition on many items. During an investigation of the problem, it was discovered that the inventory
ordering program had recently been changed. The changes were approved, but the new program was never tested.
10.
Sydney, the computer operator, did not want to go to work one day because he wanted to go sailing. He gave his ID
card to his cousin Vinny who went to work for him. Even though he was a computer operator, Vinny did not know how
to operate this computer. He made mistakes and destroyed some data.
Personnel development control plans
Operations run manuals
Disaster recovery plans
Program change controls
Librarian controls
Segregation of systems development and programming from computer operations
Retention control plans
Restriction of physical access to computer resources
Segregation of recording events from safeguarding resources
Biometric identification system
Answers
159. The first list below contains 10 control plans discussed in Chapter 8. The second list describes 10 system
failures that have control implications.
Required:
On the answer line to the left of each system failure, insert the capital letter from the first list of the best control
plan to prevent the system failure from occurring. (If you can’t find a control that will prevent the failure, then
choose a detective or corrective control plan). A letter should be used only once.
1.
Peter the programmer asked for a substantial increase in salary and benefits. When turned down, he submitted his two
week notice. During those two weeks he infected the program he was working on with a damaging computer virus.
2.
Cary enters cash receipts into the computer at Kiting Inc. For the past year she has been pocketing customer payments.
To keep herself from being discovered, she enters credit memos into the computer, which records them as reductions in
the customers’ accounts receivable records¾as if the payment had been made.
3.
Procedures for the approval of orders have been put in place at Overstock Company. Clyde, the new purchasing agent,
was given a briefing on these procedures when he was hired and has been applying those procedures as best as he can
remember them. Consequently, Clyde sometimes orders more inventory than is required.
4.
The new sales reporting system includes a computer printout that was supposed to report daily sales to the V.P. of
marketing. The report was never tested and contains erroneous sales figures and is not presented in the format required
by the V.P.
5.
There was a flood and all of the computers and all their data were destroyed.
6.
Freida was just hired as a computer operator at Vertigo Inc. Just a few days after being hired, she discovered that she
would not be allowed to spend some of her time writing computer programs. This was contrary to what she was told
initially, and she is now quite unhappy with her circumstances.
7.
After careful screening and selection of employees, an organization issues its employees name badges with magnetic
strips that stores the employees’ personal information. Employees in the IT function can scan the badges to gain entry
into various rooms within the IT center. Recently management discovered that employees are sharing their badges to
enable them to gain access to every room in the facility.
8.
A fire at the Mitre Corporation caused the release of a poisonous gas which contaminated the entire building. While the
computer files were not destroyed during the fire, they were contaminated and cannot be removed from the building and
personnel cannot enter the building. It took several months to recreate the computer files.
9.
Sandisfield, Inc. has many IT projects under consideration for development. The CFO has some political connections
with the CIO and so financial applications are given a green light for development while projects for marketing and
logistics are put on hold.
10.
Jet Red Airlines, a new, low-cost start-up airline, has decided to operate its own Web site and reservation system that is
running on servers located at the headquarters. One day, the server room was flooded, the reservation system was not
available for many hours, and many reservations were lost.
1
C
2
D
3
B
4
I
5
H
6
A
7
E
8
F
9
G
10
J
Answers