Share these flash cards

With group: None
HTML link to set: Tiny link:
Share on Facebook Share on MySpace

All 40 terms

TermDefinition
IT ResourcesApplication, information, infrastructure, people
Applicationsautomated systems and manual procedures that process information
Informationdata, in all forms, that are input, processed, and output by information systems
Infrastructuretechnology and facilities (hardware, operating systems) that enable the processing of the applications
Peoplepersonnel who plan, organize, acquire, implement, deliver, support, monitor and evaluate information systems and services
PeopleThe biggest problem in IT resources
Hypothetical Computer Systemcomputer system consisting of one or more servers, in a computer room within the headquarters, connected to printers, external storage devices and PCs (clients), all connectors are via networks (LAN, WAN), and finally connected via the internet and through firewalls
Client Server"thin", all processing and data are on the server, (slave, dummy, terminal), computers were called "Big Iron"
Distributive Processing"thick", some processing and some data on client or all processing and most data
COBITsupports IT governance by providing a framework to ensure that IT is aligned with the business, enables the business and maximizes benefits, resources are used responsibly, and risks are managed appropriately
IT Control ProcessesPlan & Organize, Acquire & Implement, Deliver & Support, Monitor & Evaluate
Plan and Organize1) Establish strategic vision for IT. (plans and goals, IT strategy for organization, understand physical layout of the system, identify risk, monitor) 2) Develop tactics to plan, communicate, and manage the vision. (project management--determine when/where to spend money, to move from AS-IS to 2-B, establish a code of ethics and conduct, have adequate staffing
As-Isinventory of the current information systems capabilities
2-Bwhere we want to go, implement strategy
Segregation of DutiesCustody, authorization, and record keeping
Segregation of Duties with ITData, programming, operations
Acquire and Implement3) Identify automated solutions (define information requirements, form courses of action, assess risks; solutions should be consistent) 4) Develop and acquire IT solutions. (canned, custom, both) 5) Integrate IT solutions into operational processes. 6) Manage change to IT systems (very high risk area. Must be monitored carefully and controlled. Make sure to update documentation of business processes)
Parallel ConversionRun both old and new IT systems. Both produce output. Compare the output, make sure it is equal.
Cold Turkey Conversion"Flip the switch." Install the new IT system and switch over.
Roll Out ConversionRun either parallel or cold turkey
Delivery and Support7) Deliver required IT services (establish service levels, minimum quantity and quality of services. Allocate cost of IT services) 8) Ensure security & continuous service (disaster recovery planning. Always prepare for the worst case scenario) 9) Provide support services (ex. live chat)
Profit Centercharge for IT services
Cost CenterOverhead allocation
Reasons to Plan for DisastersMinimize threats to IT assets, minimize losses when disaster strikes, minimize liability from internal & external users
Hot Sitefully functioning IT system waiting for data, fully redundant systems (2 systems running parallel; immediate)
Cold Sitebuilding or rental location wired but no hardware/software (1-3 weeks). You must test it, back it up at another corporate location (reciprocal agreements)
Biometricscontrols for restricting acess (ex. fingerprint scan)
Restricting Accessperimeter controls, building controls, computer facility contols
Security Moduleidentification, authentication, access rights, threat monitoring
Strong authentication2 of the following: something you have, something you know, something you are
Monitor and Evaluate Domain10) Monitor and evaluate the processes. Ongoing process to maintain control (security, availability, processing integrity, online privacy, confidentiality)
Personnel Control PlansSelection & hiring, retention, personnel development, personnel management
Selection and hiringqualified, technical background, honest, excellent, if you don't do it right you won't be successful
Retentionkeeping excellent people is just as hard as attracting them. Pay adequately & provide challenging work and advancement opportunities
Personnel Developmentkeep people trained
Personnel Managementterminate systematic process. In an IT environment turn them off before they're fired. Rotation of duties (difficult to do now), forced vacations (reduced opportunity, do at end of month), offer fidelity bonds (insurance)
Once and only onceValid and accurate data should be entered
The Sarbanes-Oxley Act of 2002Federal law that resulted from Enron, et. al.
Ensure security of resourcesIf you label a check "For deposit only", you are doing this type of control
Capacity for RiskExploit opportunities, resilience to market setbacks and disasters.

Set Information

Terms 40
Creator wmhamp2
Created October 29, 2009
Groups None
Subjects None
Access Anyone
Edit Creator Only
Get rid of ads on Quizlet
Pop out

Discuss

No Messages
Last Message: never

You must be logged in to discuss this set.

Top Users

  1. wordtoashley - 147 scores
  2. wmhamp2 - 49 scores

Most Missed Words

  1. Security Module identification, authentication, access rights, threat monitoring - 9 misses
  2. COBIT supports IT governance by providing a framework to ensure that IT is aligned with the business, enables the business and maximizes benefits, resources are used responsibly, and risks are managed appropriately - 8 misses
  3. Distributive Processing "thick", some processing and some data on client or all processing and most data - 4 misses
  4. Personnel Control Plans Selection & hiring, retention, personnel development, personnel management - 4 misses
  5. Restricting Access perimeter controls, building controls, computer facility contols - 4 misses
  6. Acquire and Implement 3) Identify automated solutions (define information requirements, form courses of action, assess risks; solutions should be consistent) 4) Develop and acquire IT solutions. (canned, custom, both) 5) Integrate IT solutions into operational processes. 6) Manage change to IT systems (very high risk area. Must be monitored carefully and controlled. Make sure to update documentation of business processes) - 3 misses
  7. Client Server "thin", all processing and data are on the server, (slave, dummy, terminal), computers were called "Big Iron" - 3 misses