Full Text Transcript
v--.. '-"./
rn-!AL(NE'N COURSE)
GROOp.n PAPER-6
INFORlviATION SYSTEMS
\'.4\ ~~ 'L\) \, i CONTROL AND AUDIT
Roll No...............................
Total No. of Questions-5] [Total No. of Printed Pages-3
4
Time Allowed-3 Hours Maximum Marks-IOO
POK
Answers to questions are to be given only in English except in the case of candidates
who have opted for Hindi medium. If a candid~te who has not opted for Hindi
medium, his answers in Hindi will not be valued.
Answer all questions.
Marks
1. ASK International proposes to launch a new subsidiary to provide e-consultancy
services for organisations throughout the world, to assist them in system development,
- -
strategic planning and e-governance areas; The fundamental guidelines, programmes
modules and draft agreements are all preserved and administered in the e-form
only.
The company intends to utilize the services of a professional analyst .to conduct
a preliminary investigation and present a report on smooth implementation of the
ideas of the new subsidiary. Based on the report submitted by the analyst, the
company decides to proceed further with three specific objectives (i) reduce operational
risk, (ii) increase business efficiency and (iii) ensure that information security is
being rationally applied. The company has been advised to adopt BS 7799 for
achieving the same. .
(a) What are the two primary methods through which the analyst would have 5
collected the data?
.
(b) To ~chieve their objectives, what are the points BS 7799 has to ensure? 5
.~
(c) Suppose an audit policy is required, how will you lay down the responsibility 5
of audit?
(d) To retain their e-documents for a specified period, what are the conditions 5
laid down by Section 7, Chapter III of Information Technology Act, 2000 ?
POK P.T.O.
.....
'-""
( 2 )
POK Marks
2. (a) What are common threats to the computerised environment other than natural 5
disasters, fire and power failure? -
(b) How would you use Data Dictionary as a tool for file security and audit 5
trails?
(c) The management of ABC Ltd. wants to design a detective control mechanism 10
for achieving security policy objective in a computerised environment. As an
auditor explain, how audit trails can be used to support security objectives.
. .
3. (a) How will you get over the impediments for the successful implementation of 10
ERP ? Mention any five.
(b) A company has decided to outsource a third party site for its alternate back-up 5
. and recovery process. What are the issues to be considered by the security
administrator while drafting the contract.
(c) Explain the role of IS auditor in evaluating logical access controls. 5
4. (a) Describe some of the advantages of continuous audit techniques. 5
(b) Define the following terms related to Information Technology A~t, 2000 : 5
(i) Computer contaminant
(m Cyber cafe
(iii) Electronic form
(iv)' Traffic data
(v) Asymmetric crypto system.
(c) Give some important advantages of Information System in business. 5
(d) What is COBIT ? Give three vantage points from which the issue of co:q.trol 5
can be addressed by this framework.
POK
.
\.'
""
\\.,.;
",'
(3 )
POK Marks
5. (a) What are the two primary questions to consider when evaluating the risk 5
inherent in a business function in the context of the risk assessment
methodologies? Give the purposes of risk evaluation. ..
(b) If you are the CEO of a company, what factors would be considered before 5
undertaking implementation of an ERP system?
5
(c) Briefly describe any three of the characteristics of the types of information
used in Executive Decision making.
(d) Discuss the benefits and limitations of unit testing. 5
POK