How unit 5 is examined
This unit covers evaluating and maintaining an MIS, security and control, threats and safeguards, control technologies, disaster recovery and emerging trends; security challenges carry the most marks, then maintenance and disaster recovery.
Evaluation and Maintenance of MIS
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>MIS evaluation checks whether the system meets its objectives, and maintenance is the modification of a live system after delivery to correct errors, adapt it to change and improve it.</mark>
Key points.
- Maintenance is needed because requirements, business rules, laws and technology keep changing after the system goes live.
- Corrective maintenance fixes errors and bugs found in use; adaptive maintenance modifies the system for a new environment such as new hardware, software or regulations.
- Perfective maintenance adds features and improves performance; preventive maintenance restructures the system to avoid future faults.
- Effective maintenance needs a change-request process (log, analyse, approve, implement, test, release), up-to-date documentation, version control, trained support staff and regular user feedback and audits.
Asked: [7 marks] (Nov 2023) What is need of maintenance in MIS? How do you ensure the effective maintenance of your MIS?
Protecting the Information Systems: Security challenges in E-enterprises
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. Security is protection of the information system and its data from unauthorised access, damage or loss; control means the policies, procedures and mechanisms that ensure the system is accurate, reliable and secure.
Key points.
- Unauthorised access: hackers or insiders gain entry to confidential data through weak passwords or open networks.
- Malware: viruses, worms and ransomware corrupt or lock data and spread quickly across networks.
- Fraud and theft: falsified transactions, credit-card theft and identity theft cause direct financial loss.
- Privacy: customer data collected online can be leaked or misused, and the enterprise must protect it legally.
- Network and transaction risks: sniffing, denial-of-service attacks and fake websites threaten online payments, and availability of the site must be maintained 24x7.
- Control measures are physical (locks, guards, backups), logical (passwords, encryption, firewalls, antivirus) and administrative (policies, training, audits, separation of duties).
- Difference from traditional security: traditional security protects paper records and premises within a boundary, while E-enterprises are open to anyone on the internet, transactions are remote and electronic, and attacks are anonymous, global and fast.
| Aspect | Traditional | E-enterprise |
|---|---|---|
| Assets | Paper, premises | Data, networks, websites |
| Attacker | Local, visible | Remote, anonymous |
| Boundary | Physical walls | Open internet |
| Control | Locks, guards | Encryption, firewalls, authentication |
Answer frame. Open with the definition of security and control; list threats (points 1-5); give the three control types (point 6); draw the comparison table for the E-enterprise question; close with the importance of protecting data, trust and business continuity.
Asked: [7 marks] (Nov 2022, Nov 2023) What are the security and control issues in MIS? What are the specific security challenges faced by E-enterprises and how do they differ from traditional security concerns?
Security threats, vulnerability, and safeguards
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A threat is a potential danger to the system, a vulnerability is a weakness that a threat can exploit, and a safeguard is a measure that reduces the risk.
Key points.
- Threats include hackers, viruses, natural disasters, employee errors and insider misuse.
- Vulnerabilities include weak passwords, unpatched software, poor physical access and untrained staff.
- Safeguards include firewalls, antivirus, backups, access control and security policies.
Controlling security threat and vulnerability
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Controlling threats means identifying risks, reducing vulnerabilities and monitoring the system so that damage is prevented, detected and corrected.
Key points.
- Preventive controls stop incidents, such as passwords and firewalls.
- Detective controls find incidents, such as audit logs and intrusion detection.
- Corrective controls restore normal working, such as backups and patches.
- Risk analysis, regular security audits and employee training keep the controls effective.
Technologies for Information System Control
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. These are technical tools that restrict access to data and protect it in storage and transit.
Key points.
- Access control uses user IDs, passwords, biometrics and role-based permissions to allow only authorised users.
- A firewall filters incoming and outgoing network traffic according to security rules.
- Encryption converts data into unreadable cipher text, and digital signatures prove the sender and integrity.
- Antivirus software, intrusion detection, audit trails and regular backups complete the control set.
Disaster Recovery Plans
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>A disaster recovery plan (DRP) is a documented set of procedures to restore IT systems, data and operations quickly after a disaster such as fire, flood, cyber attack or hardware failure.</mark>
Key points.
- Purpose: minimise downtime and data loss and protect business continuity.
- Phases: (i) risk assessment and business impact analysis, (ii) setting recovery objectives and strategy, (iii) preventive measures such as offsite backups and standby sites (hot, warm, cold), (iv) plan development with roles and procedures, (v) training and awareness, (vi) testing, (vii) recovery and execution, and (viii) review and maintenance of the plan.
- Testing through drills and simulations, and updating the plan after every change, keep it workable.
Asked: [7 marks] (Nov 2022) Define DRP and describe all phases in a disaster recovery plan in detail.
Emerging trends and technologies with regard to Management Information Systems
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Emerging trends are new technologies that are reshaping how MIS collects, processes and uses information.
Key points.
- Cloud computing provides scalable, pay-per-use storage and applications.
- Big data and analytics extract insights from very large data sets, and AI and machine learning automate decisions.
- Internet of Things, mobile computing and blockchain add real-time data, anywhere access and secure records.
Last-minute revision
- Maintenance types: corrective, adaptive, perfective, preventive.
- Security protects data from unauthorised access, damage and loss.
- Control types: physical, logical, administrative.
- Threat exploits a vulnerability; a safeguard reduces the risk.
- Controls are preventive, detective and corrective.
- Technologies: access control, firewall, encryption, antivirus.
- DRP restores systems after a disaster; test and update it regularly.
- Standby sites: hot, warm, cold.
- Emerging trends: cloud, big data, AI, IoT, blockchain.
Memory hooks
- Maintenance: "CAPP" = Corrective, Adaptive, Perfective, Preventive.
- Control: "PLA" = Physical, Logical, Administrative.
- Safeguard order: Prevent, Detect, Correct.
- Standby sites: Hot is ready now, Cold is an empty room.
Coverage checklist
- Evaluation and Maintenance of MIS: Nov 2023 maintenance question.
- Protecting the Information Systems- Security challenges in E-enterprises: Nov 2022, Nov 2023 security questions.
- Security threats, vulnerability, and safeguards: no past questions.
- Controlling security threat and vulnerability: no past questions.
- Technologies for Information System Control: no past questions.
- Disaster Recovery Plans: Nov 2022 DRP question.
- Emerging trends and technologies with regard to Management Information Systems: no past questions.