CISA Preparation - Know the benefits of Encryption
CISA Quick Tips 18
following are the benefits of encryption:
1. Confidentiality
Only legitimate destination (to whom data has been sent) can access the data.
2. Integrity
Data has not been modified in the transmission process
****3. Non-repudiation****
Sender later can not deny his sending of data.
Where use of encryption is beneficial ?
For Financial transactions and Payment processing industries
Where use of encryption is harmful?
Use by criminals with malicious intent
-----------------------------------------------------------------------------------------------------------
CISA Type Question 18
What an IS auditor should see while evaluating/auditing encryption policy of an organization?
1. Where encryption has been used ?
2. How encryption has been used?
3. Existing Government & Regulatory Policies on encryption
4. All of the above
------------------------------------------------------------------------------------------------------------
Answer to CISA Type Question 17
Today also i received few emails and comments, most of them saying answer should be Simple Random sampling. But this time i do not agree with their views.Although I believe that representation of sample is dependent on type of population,nature of population, nature of audit and many other factors. So, this is not always appropriate to ask which of the four will best/least represent the population.
But for such questions you need to understand the basics. As I mentioned Simple Random sampling , Stratified Random Sampling & Multistage Cluster Sampling are mathematical way of choosing sample where as Purposive sampling is actually a judgmental sampling (Non mathematical way). So, all other factor remaining same,chances are always that Mathematical way will better represent the population as compared to non mathematical way.
So, the answer should be 4. Purposive sampling.
---------------------------------------------------------------------------------------------------------------
**** Very Important
1 comments:
correct i also agree that purposive sampling should be the answer.
explanation is very good.
Post a Comment