23-Ind-B4 Design of Information Systems · December 2017
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
National Exams — December 2017 — 98-Ind-B4, Design of Information Systems. 3 hours; closed book, no calculator permitted. The exam comprises four parts: Part A (select 20 terms from the list given and explain each in a sentence or two, no more than 50 words, 2 marks each = 40 marks), Parts B and C (select 2 of 5 questions in each part, 11 marks each = 22 marks per part), and Part D (select 1 of 2 questions, 16 marks). Complete answers to every term and every question in all four parts follow below, not only the minimum selection a candidate would submit on exam day.
Reference texts: Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 15th ed.; Schwalbe, Information Technology Project Management, 9th ed.
Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.
Controls are the specific methods, policies, and organizational procedures that safeguard assets, ensure accuracy and reliability of records, and enforce management standards — split into general controls (governing the overall IT environment: access control, Question 1's identity management, physical security, disaster recovery) and application controls (specific to individual applications: input, processing, and output validation). Risk assessment (Question 1, term 22) identifies assets, the threats and vulnerabilities each faces, and the probability and business impact of each threat materializing, so security spending is prioritized toward the highest-value exposures rather than spread evenly. Security policy is the organization's ranked statement of what information assets matter most and what an acceptable level of risk is for each, from which an acceptable-use policy and identity-management policy are then derived to govern day-to-day behaviour.
Encryption transforms readable data (plaintext) into an unreadable form (ciphertext) using a mathematical algorithm and a key, so that only a party holding the correct key can reverse the transformation and recover the original data. Symmetric-key encryption uses the same key to encrypt and decrypt, which is fast but requires the key to be shared securely in advance. Asymmetric (public-key) encryption uses a mathematically linked key pair — a public key, freely shared, and a private key, kept secret — where data encrypted with the public key can only be decrypted with the matching private key, eliminating the need to pre-share a secret key at all.
PKI is the complete supporting ecosystem — hardware, software, policies, and a trusted third-party Certificate Authority — needed to create, distribute, manage, and revoke digital certificates (Question 1, term 21) that bind a public key to a verified identity. Because a public key by itself proves nothing about who owns it, PKI is what lets two parties with no prior direct relationship establish that a given public key genuinely belongs to who it claims to belong to, before trusting anything encrypted or signed with it.
1. Confidentiality. Encryption ensures that data, whether in transit (e.g., HTTPS traffic) or at rest (e.g., a stored database), is unreadable to anyone who intercepts or accesses it without the correct key, directly enforcing the controls component above. 2. Authentication. A digital certificate, verified via PKI, lets one party prove its identity to another — a web server's certificate proves to a browser that it is really communicating with the claimed domain, and a digital signature (data signed with a private key, verifiable with the matching public key) proves a message genuinely came from the claimed sender. 3. Integrity and non-repudiation. A digital signature also proves the signed data has not been altered since signing (any change invalidates the signature) and, because only the signer holds the private key, the signer cannot credibly deny having sent it — a property essential to contracts, financial transactions, and audit trails.