Previous Year Question Paper

May 2010 - Final [New] Examination - GROUP II - PAPER – 6 - INFORMATION SYSTEMS CONTROL AND AUDIT

Pages3
FormatPDF
SourceNative text layer

Please verify you're human to unlock the download & viewer links.

Full Text Transcript

v--.. '-"./ rn-!AL(NE'N COURSE) GROOp.n PAPER-6 INFORlviATION SYSTEMS \'.4\ ~~ 'L\) \, i CONTROL AND AUDIT Roll No............................... Total No. of Questions-5] [Total No. of Printed Pages-3 4 Time Allowed-3 Hours Maximum Marks-IOO POK Answers to questions are to be given only in English except in the case of candidates who have opted for Hindi medium. If a candid~te who has not opted for Hindi medium, his answers in Hindi will not be valued. Answer all questions. Marks 1. ASK International proposes to launch a new subsidiary to provide e-consultancy services for organisations throughout the world, to assist them in system development, - - strategic planning and e-governance areas; The fundamental guidelines, programmes modules and draft agreements are all preserved and administered in the e-form only. The company intends to utilize the services of a professional analyst .to conduct a preliminary investigation and present a report on smooth implementation of the ideas of the new subsidiary. Based on the report submitted by the analyst, the company decides to proceed further with three specific objectives (i) reduce operational risk, (ii) increase business efficiency and (iii) ensure that information security is being rationally applied. The company has been advised to adopt BS 7799 for achieving the same. . (a) What are the two primary methods through which the analyst would have 5 collected the data? . (b) To ~chieve their objectives, what are the points BS 7799 has to ensure? 5 .~ (c) Suppose an audit policy is required, how will you lay down the responsibility 5 of audit? (d) To retain their e-documents for a specified period, what are the conditions 5 laid down by Section 7, Chapter III of Information Technology Act, 2000 ? POK P.T.O. ..... '-"" ( 2 ) POK Marks 2. (a) What are common threats to the computerised environment other than natural 5 disasters, fire and power failure? - (b) How would you use Data Dictionary as a tool for file security and audit 5 trails? (c) The management of ABC Ltd. wants to design a detective control mechanism 10 for achieving security policy objective in a computerised environment. As an auditor explain, how audit trails can be used to support security objectives. . . 3. (a) How will you get over the impediments for the successful implementation of 10 ERP ? Mention any five. (b) A company has decided to outsource a third party site for its alternate back-up 5 . and recovery process. What are the issues to be considered by the security administrator while drafting the contract. (c) Explain the role of IS auditor in evaluating logical access controls. 5 4. (a) Describe some of the advantages of continuous audit techniques. 5 (b) Define the following terms related to Information Technology A~t, 2000 : 5 (i) Computer contaminant (m Cyber cafe (iii) Electronic form (iv)' Traffic data (v) Asymmetric crypto system. (c) Give some important advantages of Information System in business. 5 (d) What is COBIT ? Give three vantage points from which the issue of co:q.trol 5 can be addressed by this framework. POK . \.' "" \\.,.; ",' (3 ) POK Marks 5. (a) What are the two primary questions to consider when evaluating the risk 5 inherent in a business function in the context of the risk assessment methodologies? Give the purposes of risk evaluation. .. (b) If you are the CEO of a company, what factors would be considered before 5 undertaking implementation of an ERP system? 5 (c) Briefly describe any three of the characteristics of the types of information used in Executive Decision making. (d) Discuss the benefits and limitations of unit testing. 5 POK