Question: Module : Information Systems Audit and Controls Please help on ALL questions below please Question 2 - [Total 25 marks] a) Critical Information resources should

Module : Information Systems Audit and Controls

Please help on ALL questions below please

Module : Information Systems Audit and Controls

Question 2 - [Total 25 marks] a) Critical Information resources should be protected by maintaining security goals. List THREE Security Goals of an information System. [3 marks] b) What are the techniques commonly prescribed by IS auditors in organisations to ensure that the fundamental security goals listed in part (a) are implemented while designing any secured information systems. [7 marks] c) As an Auditor working in a government organization, you have been assigned the task of implementing an Audit process and carrying out an Internal Control. Explain the need for internal control in the organization. [4 marks] d) After auditing an organization which does not use a firewall, the IS auditor has proposed as a priority to include a firewall in the organization. i) Explain the role of a firewall in an organization. [3 marks] ii) Discuss about some characteristic that should be considered before choosing the type of firewall an organization should purchase. [5 marks] e) Electronic Commerce risks can be classified as internal and external. List THREE internal risks. [3 marks] Question 2 - [Total 25 marks] a) Critical Information resources should be protected by maintaining security goals. List THREE Security Goals of an information System. [3 marks] b) What are the techniques commonly prescribed by IS auditors in organisations to ensure that the fundamental security goals listed in part (a) are implemented while designing any secured information systems. [7 marks] c) As an Auditor working in a government organization, you have been assigned the task of implementing an Audit process and carrying out an Internal Control. Explain the need for internal control in the organization. [4 marks] d) After auditing an organization which does not use a firewall, the IS auditor has proposed as a priority to include a firewall in the organization. i) Explain the role of a firewall in an organization. [3 marks] ii) Discuss about some characteristic that should be considered before choosing the type of firewall an organization should purchase. [5 marks] e) Electronic Commerce risks can be classified as internal and external. List THREE internal risks. [3 marks]

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related General Management Questions!