CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Information Systems: formula sheet
Key formulas
- Data to information
- Data + Processing = Information
- Information must be meaningful and useful to the person receiving it.
- Components of an IS
- Hardware + Software + Data + People + Processes (+ Networks)
- Use the list in your study material. Explain each component with an example.
- System cycle
- Input → Processing → Storage → Output → Feedback
- Feedback is what makes the system self-correcting. Do not omit it.
- Levels and systems
- Operational: TPS | Middle: MIS, DSS | Senior: ESS
- MIS and DSS both serve middle management, but MIS gives routine reports while DSS supports analysis of specific problems.
- Data to information chain
- Data → Processing → Information → Decision → Action
- Use this to explain how any information system supports decision making.
- Levels of management and matching system
- Operational → TPS | Middle → MIS, DSS | Top (strategic) → ESS
- A common way to classify systems. Match the system to the user and the type of decision.
- TPS vs MIS
- TPS = records daily transactions | MIS = summarises TPS data into reports
- TPS is the data source; MIS is built on it.
- ERP vs CRM
- ERP = integrates internal functions on one database | CRM = manages customer interactions
- ERP is inward-looking across functions; CRM is customer-facing.
- Data to information
- Data → Processing → Information → Knowledge → Decision
- Use this chain to define the terms in one line.
- Hierarchical model
- One parent → many children (1:N, tree)
- A child cannot have two parents.
- Network model
- Many parents ↔ many children (M:N via links)
- More flexible than hierarchical, but complex to design and maintain.
- Relational model
- Table = rows (records/tuples) × columns (fields/attributes); tables linked by primary key and foreign key
- A primary key identifies each row uniquely. A foreign key refers to the primary key of another table.
- Data warehouse features
- Subject-oriented, integrated, time-variant, non-volatile
- Learn these four words. They are the standard definition points.
- Warehouse vs mining
- Warehouse = storage for analysis; Mining = discovery of patterns
- Warehouse is the repository. Mining is the technique applied to data.
- CIA triad
- Security = Confidentiality + Integrity + Availability
- Say which of the three goals a threat or control affects.
- Risk relationship
- Risk = Threat × Vulnerability × Impact (conceptual)
- A conceptual link, not a calculation. No threat or no vulnerability means low risk.
- Control by scope
- IS controls = General controls + Application controls
- General: policies, access, change management, operations, backup, physical security. Application: input, processing, output, storage controls.
- Control by purpose
- Preventive (before) → Detective (during or after) → Corrective (after detection)
- Example: firewall prevents, log review detects, backup restore corrects.
- SDLC stage order
- Feasibility → Requirements → Design → Development/Acquisition → Testing → Implementation → Review and Maintenance
- Stage names vary by source. Keep the order and the output of each stage.
- Changeover methods
- Direct | Parallel | Phased | Pilot
- Parallel runs old and new together and has the lowest risk. Direct has the highest risk.
- Information security objectives
- Confidentiality + Integrity + Availability
- Use these as the test for what an IS audit protects.
- IS audit flow
- Planning → Fieldwork (evidence and testing) → Reporting → Follow-up
- Risk assessment and scoping sit inside planning.
- Control types
- Preventive | Detective | Corrective
- Classify each control by when it acts. A password is preventive, a log review is detective, a backup restore is corrective.
- RTO (Recovery Time Objective)
- RTO = maximum acceptable time between disruption and restoration of the service
- Shorter RTO means a faster, costlier recovery solution such as a hot site.
- RPO (Recovery Point Objective)
- RPO = maximum acceptable data loss measured in time since the last good backup
- An RPO of 4 hours means backups or replication must happen at least every 4 hours.
- Relationship of DRP to BCP
- BCP ⊃ DRP (DRP is a subset of BCP)
- BCP covers the whole business. DRP covers IT recovery only.
- Recovery site ladder
- Hot site (fastest, costliest) > Warm site > Cold site (slowest, cheapest)
- Choose the site by matching RTO and budget. Mirror sites are even faster than hot sites.
- Backup types
- Full = all data; Incremental = changes since the last backup of any type; Differential = changes since the last full backup
- Restore needs: full only; full + all incrementals in order; full + latest differential.
- BCP life cycle
- Risk assessment → BIA → strategy → plan development → testing → maintenance
- Use this sequence as your answer skeleton.
Quick revision
- An information system combines people, processes, data, hardware and software to support decisions and operations.
- Data is raw facts; information is data processed to be useful for a decision.
- Each business function, such as finance, HR, sales and operations, uses systems to record transactions and report results.
- A database management system stores, organises and controls access to data so it can be shared and kept consistent.
- Know basic data terms: field, record, file, table, key and the idea of relationships between tables.
- Security protects confidentiality, integrity and availability of information.
- Controls can be preventive, detective or corrective; always say which type your example is.
- Access control limits who can see or change data, for example through authentication and authorisation.
- The system development life cycle moves through defined stages, and each stage needs review and documentation.
- IS audit checks whether systems and controls are adequate, working and in line with policy and law.
- A business continuity plan keeps critical functions running; a disaster recovery plan restores systems and data.
- Regular backups and tested recovery plans matter more than plans that exist only on paper.
Common mistakes
- Treating an information system as only computers. Fix: Always name people and processes along with hardware, software and data.
- Confusing data with information. Fix: Define data as raw facts and information as processed, useful output. Give one example of each.
- Treating TPS and MIS as the same thing. Fix: Say TPS records transactions; MIS summarises that data into reports for managers.
- Describing ERP as just accounting software. Fix: Say ERP integrates all functions on one shared database, so data is entered once.
- Treating data warehouse and data mining as the same thing Fix: Say the warehouse stores integrated historical data and mining discovers patterns in data. One is a repository, the other a process.
- Saying a child can have many parents in the hierarchical model Fix: Remember the tree: hierarchical is one parent per child. Network allows several parents.
- Mixing up general and application controls. Fix: Ask: does it protect the whole IT environment (general) or one program's transactions (application)? Password policy is general; a validity check on an input field is application.
- Treating detective and corrective controls as the same. Fix: Detective finds the problem (audit logs, alerts). Corrective fixes it (restore from backup, patching, rerunning a process).
- Listing SDLC stages in the wrong order or skipping testing. Fix: Remember the logic: decide, specify, design, build, test, deploy, maintain. Write one output per stage.
- Confusing implementation with development. Fix: Development creates or buys the system. Implementation puts it into live use through conversion, training and changeover.
Exam tips
- Begin every answer with a crisp definition. Examiners look for it first.
- Always tie each type of system to its level of management and give a business example.
- For distinction questions, use at least four comparison points and write them in pairs.
- In case questions, quote the facts before naming the system. This shows analysis and earns marks beyond recall.
- Where space allows, add one line on the risks of the system, such as data security, to link with the later chapters.
- Answer in the provision, analysis, conclusion pattern: define the system, apply it to the facts, then conclude.
- Always name the function and the decision in your answer; marks go for application, not definitions alone.
- For comparison questions, write a point-by-point contrast on user level, data type and purpose.