Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Management Information Systems - An Overview

An Indian company develops an MIS that stores customers' sensitive personal data. During design, the CS advises building in encryption, access controls and audit logs from the start rather than adding them after go-live. Which approach does this advice best reflect, and why is it preferred?

The advice reflects security by design. Building encryption, access control and audit logs into the MIS architecture from the start is more reliable and cheaper than retrofitting, and it helps the company show reasonable security practices for sensitive personal data. Obscurity or total reliance on a vendor does not discharge that responsibility.

  1. ASecurity by design, because compliance and protection controls are cheaper and more reliable when built into the architectureCorrect
  2. BSecurity by testing, because controls can only be identified after the system is live
  3. CSecurity by obscurity, because hiding the system design removes the need for access controls
  4. DSecurity by delegation, because the vendor alone is responsible for protecting the data

Explanation

Embedding encryption, access control and logging at design stage is security by design, and it supports the reasonable security practices an organisation handling sensitive personal data is expected to maintain. Retrofitting is costly and leaves gaps. Obscurity is not a recognised substitute for controls, and responsibility cannot be shifted wholly to a vendor.

Did you get it right without looking?

One question tells you little. A timed set on Management Information Systems - An Overview shows your real accuracy, how long you take and where you lose marks.

More Management Information Systems - An Overview questions