Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Information Systems: formula sheet

Full chapter guide

Key formulas

Data to information
Data + Processing = Information
Information must be meaningful and useful to the person receiving it.
Components of an IS
Hardware + Software + Data + People + Processes (+ Networks)
Use the list in your study material. Explain each component with an example.
System cycle
Input → Processing → Storage → Output → Feedback
Feedback is what makes the system self-correcting. Do not omit it.
Levels and systems
Operational: TPS | Middle: MIS, DSS | Senior: ESS
MIS and DSS both serve middle management, but MIS gives routine reports while DSS supports analysis of specific problems.
Data to information chain
Data → Processing → Information → Decision → Action
Use this to explain how any information system supports decision making.
Levels of management and matching system
Operational → TPS | Middle → MIS, DSS | Top (strategic) → ESS
A common way to classify systems. Match the system to the user and the type of decision.
TPS vs MIS
TPS = records daily transactions | MIS = summarises TPS data into reports
TPS is the data source; MIS is built on it.
ERP vs CRM
ERP = integrates internal functions on one database | CRM = manages customer interactions
ERP is inward-looking across functions; CRM is customer-facing.
Data to information
Data → Processing → Information → Knowledge → Decision
Use this chain to define the terms in one line.
Hierarchical model
One parent → many children (1:N, tree)
A child cannot have two parents.
Network model
Many parents ↔ many children (M:N via links)
More flexible than hierarchical, but complex to design and maintain.
Relational model
Table = rows (records/tuples) × columns (fields/attributes); tables linked by primary key and foreign key
A primary key identifies each row uniquely. A foreign key refers to the primary key of another table.
Data warehouse features
Subject-oriented, integrated, time-variant, non-volatile
Learn these four words. They are the standard definition points.
Warehouse vs mining
Warehouse = storage for analysis; Mining = discovery of patterns
Warehouse is the repository. Mining is the technique applied to data.
CIA triad
Security = Confidentiality + Integrity + Availability
Say which of the three goals a threat or control affects.
Risk relationship
Risk = Threat × Vulnerability × Impact (conceptual)
A conceptual link, not a calculation. No threat or no vulnerability means low risk.
Control by scope
IS controls = General controls + Application controls
General: policies, access, change management, operations, backup, physical security. Application: input, processing, output, storage controls.
Control by purpose
Preventive (before) → Detective (during or after) → Corrective (after detection)
Example: firewall prevents, log review detects, backup restore corrects.
SDLC stage order
Feasibility → Requirements → Design → Development/Acquisition → Testing → Implementation → Review and Maintenance
Stage names vary by source. Keep the order and the output of each stage.
Changeover methods
Direct | Parallel | Phased | Pilot
Parallel runs old and new together and has the lowest risk. Direct has the highest risk.
Information security objectives
Confidentiality + Integrity + Availability
Use these as the test for what an IS audit protects.
IS audit flow
Planning → Fieldwork (evidence and testing) → Reporting → Follow-up
Risk assessment and scoping sit inside planning.
Control types
Preventive | Detective | Corrective
Classify each control by when it acts. A password is preventive, a log review is detective, a backup restore is corrective.
RTO (Recovery Time Objective)
RTO = maximum acceptable time between disruption and restoration of the service
Shorter RTO means a faster, costlier recovery solution such as a hot site.
RPO (Recovery Point Objective)
RPO = maximum acceptable data loss measured in time since the last good backup
An RPO of 4 hours means backups or replication must happen at least every 4 hours.
Relationship of DRP to BCP
BCP ⊃ DRP (DRP is a subset of BCP)
BCP covers the whole business. DRP covers IT recovery only.
Recovery site ladder
Hot site (fastest, costliest) > Warm site > Cold site (slowest, cheapest)
Choose the site by matching RTO and budget. Mirror sites are even faster than hot sites.
Backup types
Full = all data; Incremental = changes since the last backup of any type; Differential = changes since the last full backup
Restore needs: full only; full + all incrementals in order; full + latest differential.
BCP life cycle
Risk assessment → BIA → strategy → plan development → testing → maintenance
Use this sequence as your answer skeleton.

Quick revision

  • An information system combines people, processes, data, hardware and software to support decisions and operations.
  • Data is raw facts; information is data processed to be useful for a decision.
  • Each business function, such as finance, HR, sales and operations, uses systems to record transactions and report results.
  • A database management system stores, organises and controls access to data so it can be shared and kept consistent.
  • Know basic data terms: field, record, file, table, key and the idea of relationships between tables.
  • Security protects confidentiality, integrity and availability of information.
  • Controls can be preventive, detective or corrective; always say which type your example is.
  • Access control limits who can see or change data, for example through authentication and authorisation.
  • The system development life cycle moves through defined stages, and each stage needs review and documentation.
  • IS audit checks whether systems and controls are adequate, working and in line with policy and law.
  • A business continuity plan keeps critical functions running; a disaster recovery plan restores systems and data.
  • Regular backups and tested recovery plans matter more than plans that exist only on paper.

Common mistakes

  • Treating an information system as only computers. Fix: Always name people and processes along with hardware, software and data.
  • Confusing data with information. Fix: Define data as raw facts and information as processed, useful output. Give one example of each.
  • Treating TPS and MIS as the same thing. Fix: Say TPS records transactions; MIS summarises that data into reports for managers.
  • Describing ERP as just accounting software. Fix: Say ERP integrates all functions on one shared database, so data is entered once.
  • Treating data warehouse and data mining as the same thing Fix: Say the warehouse stores integrated historical data and mining discovers patterns in data. One is a repository, the other a process.
  • Saying a child can have many parents in the hierarchical model Fix: Remember the tree: hierarchical is one parent per child. Network allows several parents.
  • Mixing up general and application controls. Fix: Ask: does it protect the whole IT environment (general) or one program's transactions (application)? Password policy is general; a validity check on an input field is application.
  • Treating detective and corrective controls as the same. Fix: Detective finds the problem (audit logs, alerts). Corrective fixes it (restore from backup, patching, rerunning a process).
  • Listing SDLC stages in the wrong order or skipping testing. Fix: Remember the logic: decide, specify, design, build, test, deploy, maintain. Write one output per stage.
  • Confusing implementation with development. Fix: Development creates or buys the system. Implementation puts it into live use through conversion, training and changeover.

Exam tips

  • Begin every answer with a crisp definition. Examiners look for it first.
  • Always tie each type of system to its level of management and give a business example.
  • For distinction questions, use at least four comparison points and write them in pairs.
  • In case questions, quote the facts before naming the system. This shows analysis and earns marks beyond recall.
  • Where space allows, add one line on the risks of the system, such as data security, to link with the later chapters.
  • Answer in the provision, analysis, conclusion pattern: define the system, apply it to the facts, then conclude.
  • Always name the function and the decision in your answer; marks go for application, not definitions alone.
  • For comparison questions, write a point-by-point contrast on user level, data type and purpose.