ANSWERS GRADED A+
✔✔keyloggers - ✔✔software that records keystrokes
✔✔trojan horse - ✔✔Malicious computer instructions in an authorized and properly
functioning program
✔✔bluesnarfing - ✔✔stealing contact lists, images, and other data using bluetooth
✔✔primary objective of an AIS - ✔✔to control the organization so the organization can
achieve its objectives
✔✔Internal controls - ✔✔implemented to provide assurance that the following objectives
are achieved
-safeguard assets
-maintain enough records
-provide accurate and reliable information
-prepare financial reports
-promote and improve operational efficiency
-encourage adherence with management policies
-comply with laws and regulations
✔✔preventive controls - ✔✔deter problems before they arise
✔✔detective controls - ✔✔discover problems that are not prevented
✔✔corrective controls - ✔✔identify and correct problems as well as correct and recover
from the resulting errors
✔✔general controls - ✔✔make sure an organization's control environment is stable and
well managed
✔✔application control - ✔✔prevent, detect, and correct transaction errors and fraud
✔✔input controls - ✔✔observation, recording, and transcription
✔✔processing controls - ✔✔data access controls, data manipulation controls
✔✔output controls - ✔✔validate processing results, regulate distribution of results
✔✔COBIT - ✔✔Framework for IT control
✔✔COSO - ✔✔framework for enterprise internal controls
, ✔✔COSO-ERM - ✔✔Expands COSO framework taking a risk-based approach
✔✔governance - ✔✔ensures that enterprise objectives are achieved by evaluating
stakeholders needs, conditions and option
✔✔management - ✔✔plans, builds, runs, and monitors activities in alignment with the
direction set by the governance body to achieve the enterprise objective
✔✔strategic objective - ✔✔high level goals
✔✔operations objectives - ✔✔effectiveness and efficiency of operations
✔✔reporting objectives - ✔✔Improve decision making and monitor performance
✔✔compliance objective - ✔✔compliance with applicable laws and regulations
✔✔likelihood - ✔✔probability that an event will occur
✔✔inherent - ✔✔risk that exists before plans are made to control it
✔✔residual - ✔✔risk that is left over after you control it
✔✔reduce risk response - ✔✔implement effective internal control
✔✔accept risk response - ✔✔do noting, accept likelihood and impact of risk
✔✔share risk response - ✔✔buy insurance, outsource or hedge
✔✔avoid risk response - ✔✔Do not engage in the activity
✔✔expected loss - ✔✔impact x likelihood
✔✔symmetric encryption - ✔✔uses 1 key to encrypt and decrypt
✔✔asymmetric encryption - ✔✔uses two keys (public and private) created as a
matched pair.
✔✔hashing - ✔✔transforming plaintext of any length into a short code called a hash
✔✔hash - ✔✔plaintext that has been transformed into short code
✔✔How to create digital signatures - ✔✔created by asymmetric encryption and hashing