December 1998
SC223: COMPUTER SECURITY

QUESTION 3

Total Marks: 20 Marks

Click here to access other questions

Click to access
SUGGESTED SOLUTIONS
for Question 3

 

(a) (i) Name four activities which are carried out by internal auditors during the auditing process. [4]
(ii) What is the primary function of an external auditor? [1]
(iii) Why is the role of an internal auditor not simply an extension of that of an external auditor?

 

[1]
(b) (i) Why are auditors sometimes actively discouraged from auditing through complex computer systems? [1]
(ii) Why are considerable sums of money typically expended on providing security for systems which are already operational? [1]
(iii) Name two problems in ensuring that the audit function makes a realistic contribution to computer security.

 

[2]
(c) (i) Describe three ways of protecting original products. [6]
(ii) For each of the following, identify which method of protection is most appropriate :
  • Documentation.
  • A customer mailing list.
  • Chips.
  • Software.
[4]