NivaarExam PrepOfficial exam papers ↗

23-Ind-B4 Design of Information Systems · December 2013

Question 1 of 13: Information Systems Terminology — Select-20-of-40 Glossary

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams — December 2013 — 98-Ind-B4, Design of Information Systems. 3 hours; closed book, no calculator permitted. The exam comprises four parts: Part A (select 20 of 40 terms and explain each in a sentence or two, 2 marks each = 40 marks), Parts B and C (select 2 of 5 questions in each part, 11 marks each = 22 marks per part), and Part D (select 1 of 2 questions, 16 marks). Complete answers to every term and every question in all four parts follow below, not only the minimum selection a candidate would submit on exam day.

Reference texts: Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 15th ed.; Schwalbe, Information Technology Project Management, 9th ed.

Question 1 (Part A): Information Systems Terminology — Select-20-of-40 Glossary (40 marks: 20 × 2)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

All 40 listed terms are defined below, not only the 20 a candidate would select on exam day; each entry targets the depth a 2-mark, 50-word answer supports.

Access Control

The security function that determines which authenticated users, systems, or processes may read, write, execute, or delete a specific information resource, and under what conditions — implemented through role-based permissions, access-control lists, and least-privilege policy. It is the authorization half of "authenticate, then authorize": authentication only proves identity, access control decides what that identity may do.

Agile Development

An iterative, incremental systems-development approach that delivers working software in short cycles (sprints) with continuous customer feedback, rather than specifying the complete system upfront. It contrasts with the sequential, document-heavy waterfall SDLC, trading some upfront predictability of scope for a much faster response to changing requirements.

Analytics

The systematic use of data, statistical methods, and modelling to describe past performance, explain why something happened, forecast future outcomes, or recommend actions in support of business decisions. Business-intelligence and big-data platforms are the technology; analytics is the analytical discipline applied on top of them.

Authentication

The process of verifying that a user, device, or system is who or what it claims to be, typically via something the user knows (password), has (token, smart card), or is (biometric). It is a prerequisite to access control — identity must be authenticated before what that identity may do can be authorized.

Behaviour Monitoring

The continuous observation and logging of user or system activity — keystrokes, application usage, network traffic, physical movement — to detect policy violations, insider threats, or anomalous activity. It raises the privacy and information-rights tensions developed in Question 10, which must be balanced against legitimate security need.

Big Data

Datasets whose volume, velocity, and variety exceed the capacity of traditional database tools to capture, store, and analyze economically. Its business value comes from the analytics applied to it — combining structured transactional data with unstructured sources (social media, sensor streams, clickstreams) to reveal patterns no single source shows alone.

Bottom-up Estimating

A project cost/effort estimation technique that decomposes a project into its smallest work packages (via a work breakdown structure), estimates each individually, and sums them into a total. It is more time-consuming but generally more accurate than top-down/analogous estimating, since it is grounded in specific tasks rather than a rough analogy to a past project.

Business Driver

A factor — competitive pressure, customer or supplier demand, a regulatory requirement, cost pressure, or a strategic opportunity — that creates the actual business need or justification for an information-system investment. Every IS project should be traceable to one or more explicit business drivers, distinguishing systems the business genuinely needs from ones built for technology's own sake.

BYOD (Bring Your Own Device)

A policy allowing employees to use their own personal smartphones, tablets, or laptops to access organizational systems and data, rather than being issued company-owned hardware. It lowers hardware cost and raises user satisfaction, but complicates security (device management, data leakage, lost-device exposure) and needs a mobile-device-management and acceptable-use policy to control the added risk.

Capital Budgeting

The formal process by which an organization evaluates, ranks, and selects among competing long-term investment proposals — including major IT projects — using methods such as payback period, net present value, and internal rate of return to compare expected costs and benefits over the asset's life. Total cost of ownership (Question 11) is the cost side of this evaluation.

Change Control

The formal process for proposing, evaluating, approving, and documenting any modification to an information system's scope, requirements, design, or code once it is under development or in production. It prevents uncontrolled scope creep and ensures every change is assessed for cost, schedule, and risk impact before being implemented.

Cloud Computing

A model for delivering computing resources — servers, storage, databases, software — as an on-demand, elastically scalable, metered service over the internet, rather than as owned on-premises infrastructure. Delivered through IaaS/PaaS/SaaS service models and public/private/hybrid deployment models, developed fully in Question 2.

Conversion

The final phase of systems implementation in which an organization switches from its old (legacy) system to the new one, via parallel (both run simultaneously), direct/plunge (old is shut off immediately), pilot (new system trialled on one unit first), or phased (rolled out module by module) strategy. The chosen strategy trades risk against cost and disruption.

Cookie

A small text file a web server places on a user's browser to store state information — session identifiers, preferences, shopping-cart contents — between otherwise stateless HTTP requests. First-party cookies support a site's own function; third-party cookies (set by an embedded ad network) are the primary mechanism behind cross-site behavioural tracking, raising the privacy-policy concerns of Question 11's twin, Question 1's term 34.

CRM (Customer Relationship Management)

Enterprise software that consolidates all customer-facing data and interactions — sales, marketing, service, support — across every channel into a single view, so the organization can coordinate customer-facing processes, improve retention, and identify cross-sell opportunities. A core enterprise-system category alongside ERP and supply-chain management.

Cyber Security

The organizational policies, procedures, and technologies used to protect information systems, networks, and data from unauthorized access, disruption, or theft — spanning technical controls (firewalls, encryption, intrusion detection), administrative controls (policy, training), and physical controls, all aimed at preserving confidentiality, integrity, and availability.

Data Warehousing

The practice of extracting data from multiple operational systems, cleansing and transforming it for consistency, and loading it into a separate, subject-oriented, non-volatile, time-variant repository optimized for query and analysis rather than transaction processing. It supports business intelligence and analytics (term 3) without burdening production systems.

Database Conceptual Schema

The logical, implementation-independent description of a database's entire structure — its entities, their attributes, and the relationships among them — usually expressed as an entity-relationship diagram, independent of any specific DBMS or physical storage detail. It sits above the physical schema and below any user-specific view in the classic three-schema architecture.

DoS Attack (Denial-of-Service)

An attack that floods a target system or network with an overwhelming volume of illegitimate traffic, exhausting its processing, memory, or bandwidth capacity so legitimate users cannot access the service. A Distributed DoS launches the flood simultaneously from many compromised hosts (a botnet), making it far harder to block than a single-source attack.

Entity

In data modelling, a distinct person, place, object, event, or concept about which an organization wants to store data — e.g., Customer, Order, Product — represented in a database as a table, with each instance a row and each descriptive attribute a column. The fundamental building block of a conceptual schema (term 18).

ERM (Enterprise Risk Management)

A structured, organization-wide framework for identifying, assessing, prioritizing, and responding to financial, operational, strategic, and IT risk in a coordinated way across the whole enterprise, rather than each department or project managing risk in isolation. It aligns risk appetite with strategic objectives and gives senior management one consolidated risk picture.

Hashing

A one-way function that transforms an input of any size into a fixed-length output (a digest), such that the same input always produces the same output but the output cannot practically be reversed. Used to store passwords securely (only the hash is stored) and to verify data integrity, since a changed file produces a different hash.

Information Rights

The moral and legal entitlements individuals and organizations hold regarding personal or proprietary information collected about or created by them — including the right to know what is collected, to access and correct it, and to control its further disclosure. One of the five moral dimensions of information systems developed in Question 10.

IT Governance

The framework of decision rights, accountability structures, and processes (e.g., COBIT, ITIL) an organization uses to ensure IT investment and operations align with and deliver value toward overall business strategy, while managing IT-related risk appropriately. It answers who decides what about IT, and how they are held accountable, at the senior-management level.

Java Stripping

A network- or proxy-level content-filtering technique that removes Java applets, and similarly other active/executable web content, from inbound pages before they reach a user's browser, to prevent mobile-code-borne malware from executing on the internal network. An older perimeter-security control, largely superseded by modern web-application firewalls and sandboxing (term 37).

Key

In relational database design, an attribute or set of attributes that uniquely identifies a row within a table (a primary key) or that references another table's primary key to establish a relationship (a foreign key). Keys are the mechanism that enforces entity and referential integrity in a relational schema.

Knowledge Management

The business processes and technologies — document repositories, expertise-location systems, communities of practice, collaboration platforms — an organization uses to create, capture, organize, and share both explicit and tacit knowledge, so organizational learning does not leave with any one employee.

Malware

Malicious software — viruses, worms, trojans, ransomware, spyware — deliberately designed to damage, disrupt, gain unauthorized access to, or exfiltrate data from a system without the owner's consent. Distinguished from a DoS attack by intent: malware is software built specifically to cause harm, not a traffic-volume technique.

Mashups

Web applications that combine data or functionality from two or more existing sources, often via public APIs, into a single new integrated service or view — e.g., overlaying a company's store-location data on a mapping service. A lightweight, composition-based alternative to building integrated functionality from scratch, developed further in Question 3.

MIS (Management Information Systems)

Both the academic discipline and the class of systems concerned with combining information technology, business process, and people to support the planning, control, and decision-making of managers at every organizational level — turning raw transactional data into the structured, summarized reports managers actually need to run the business.

Network Resilience

The ability of a network, and the systems it connects, to keep delivering an acceptable level of service despite component failure, attack, or unexpected load — achieved through redundancy, fault-tolerant design, load balancing, and disaster-recovery planning, so no single point of failure takes the whole network down.

Normalization

The systematic process of organizing a relational database's tables and columns to minimize redundancy and avoid update, insert, and delete anomalies, by progressively decomposing tables through a series of normal forms (1NF, 2NF, 3NF, …), each removing a specific dependency that would otherwise let the same fact be stored, and go inconsistent, in more than one place.

Portfolio Analysis

A technique for managing an organization's proposed and in-progress information-system projects as a single portfolio, evaluating each on expected benefit versus risk and cost — often plotted on a risk/benefit grid — so investment is balanced across the whole portfolio rather than each project being approved or rejected purely on its own merits (developed further in Question 13).

Privacy Policy

A published statement in which an organization discloses what personal information it collects, how it will be used, with whom it may be shared, how long it is retained, and what choices the individual has over that data. The primary instrument through which an organization operationalizes the information rights of term 23.

PKI (Public Key Infrastructure)

The hardware, software, policies, and trusted third-party Certificate Authority needed to create, distribute, manage, and revoke digital certificates that bind a public key to a verified identity, enabling asymmetric-key encryption, digital signatures, and authentication between parties with no prior direct trust relationship.

RFQ (Request for Quotation)

A formal procurement document sent to prospective vendors specifying a well-defined product or service and asking for a firm price, so competing quotes can be compared on price for an already-known specification — distinct from a Request for Proposal, used when the buyer needs vendors to propose the solution approach itself, not just price a known one.

Sandbox

An isolated execution environment, separated from the production system and its data, in which untrusted code, files, or updates can be run and observed safely, so that if the code proves malicious or defective, any damage is contained within the sandbox and never reaches production systems or data.

Search Costs

The time, effort, and money a buyer or seller must expend to find a trading partner and compare product, price, and quality information before completing a transaction. Internet-based information systems dramatically reduce search costs, which is a core driver of the market-efficiency and disintermediation effects e-commerce produces.

Sociotechnical Design

A systems-development philosophy holding that an information system's success depends on jointly optimizing both its technical components (hardware, software, data) and its social components (people, structure, process, culture) — because a technically excellent system that ignores how people will actually use it fails in practice regardless of its technical merit (revisited in Question 13).

Spoofing

An attack in which the attacker disguises the origin of a communication — forging a sender's email address, IP address, website, or caller ID — to impersonate a trusted source and trick the recipient into an action they would not take if the true origin were known. The foundation technique behind phishing and many DoS and man-in-the-middle attacks.

← Paper overview