NivaarExam PrepOfficial exam papers ↗

23-Ind-B4 Design of Information Systems · December 2013

Question 6 of 13: Internal and External Threats to Information Systems

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams — December 2013 — 98-Ind-B4, Design of Information Systems. 3 hours; closed book, no calculator permitted. The exam comprises four parts: Part A (select 20 of 40 terms and explain each in a sentence or two, 2 marks each = 40 marks), Parts B and C (select 2 of 5 questions in each part, 11 marks each = 22 marks per part), and Part D (select 1 of 2 questions, 16 marks). Complete answers to every term and every question in all four parts follow below, not only the minimum selection a candidate would submit on exam day.

Reference texts: Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 15th ed.; Schwalbe, Information Technology Project Management, 9th ed.

Question 6 (Part B.5): Internal and External Threats to Information Systems (11 marks)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

External Threats

Internal Threats

The Common Thread

Effective defence against both categories rests on the same core disciplines applied consistently: layered technical controls (defence in depth, so no single control's failure is catastrophic), least-privilege access control, continuous monitoring, and, critically, an organizational security culture and governance structure — because the internal category above shows that technology alone cannot address threats that arise from how people, not systems, behave.