Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

Which of the following best describes the 'integrity' objective in the confidentiality-integrity-availability model used in information security audits?

Integrity means information is accurate and complete and cannot be altered without authorisation. Access whenever needed is availability, restricting disclosure to authorised persons is confidentiality, and preventing users from denying their transactions is non-repudiation.

  1. AEnsuring that information is accessible to authorised users whenever required
  2. BEnsuring that information is accurate and complete and is not altered without authorisationCorrect
  3. CEnsuring that information is disclosed only to authorised persons
  4. DEnsuring that users cannot deny having performed a transaction

Explanation

Integrity means information stays accurate, complete and protected from unauthorised modification. Accessibility on demand is availability, restricting disclosure is confidentiality, and preventing denial of actions is non-repudiation, a separate concept.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions