IT'S ALL IN A PHASE WORK


WHOSE JOB IS IT


DOUMENTS, TECHNIQUES & CONTROLS


FAMOUS ATTRIBUTES


RISKS & CONTROLS


100

The SDLC phase that involves all concerned management and user groups

What is Requirements Definition

100

This individual's primary role on a project team is that of a Control Expert

Who is the IT Auditor


100

This document provides the justification for a project

What is a Business Case

100

Application controls help to ensure this attribute for completeness and accuracy

What is integrity

100

This is the risk specifically associated with agile development

What is a lack of documentation

200

The SDLC phase that takes place after the new system has stabilized in the production environment

What is the Post-Implementation Phase


200

This person or group assumes ownership of the project and the resulting system

Who is User Management

200

An estimating methodology used to determine time/ task duration used in the planning phase--It has zero slack time

What is the critical path

200

Encryption helps to preserve this attribute for sensitive or proprietary data

What is Confidentiality

200

A business continuity plan is an example of this type of control

What is a Corrective Control

300

Estimating tools are typically used in this PROJECT phase

What is planning phase

300

This person is responsible for planning & executing IS projects and provides leadership

Who is the Project Manager

300

These high-level documents represent corp. philosophy of an org. and the strategic thinking of senior mgmt.

What are policies

300

A virtual private network (VPN) provides this attribute using tunneling or encapsulating traffic

What is confidentiality

300

The foremost risk is transaction authorization for this technology

What is EDI

400

This phase represents the optimum point for base lining to occur

What is the Design Phase

400

This person or group provides funding for the project

Who is the Project Sponsor or Owner

400

This technique uses small windows of time with predetermined resources mostly used with agile development

What is timebox Management

400

A piece of information provides sender authenticity, message integrity and non-repudiation--usually generated using the sender's private key, or applying a one-way hash

What is a Digital Signature

400

Key controls may be removed out of a business process is a major risk for this process

What is BPR risk

500

This is a process--not a true phase, if the decision was made to acquire rather than develop

What is Selection


500

This team/person is ultimately responsible for project deliverables

What is a Project Steering Committee

500

This document states the objective of the project, stakeholders, project manager and sponsor

What is a project charter

500

This attribute set bears on the capability of software to maintain its level of performance under stated conditions

What is reliability

500

This type of risk relates to the likelihood that the new system may not meet the user's business needs, requirements, and expectations

What is Business Risk or Benefit Risk

M
e
n
u