Tuesday, January 25, 2011

CA Final - New Syllabus - Group II - Paper 6: ISCA: Scan of Past Exam Questions with reference to Study Material








CHAPTER
8

INFORMATION
SYSTEMS AUDITING STANDARDS, GUIDELINES, BEST PRACTICES

Scan
of Past Exam Questions:


Year

Marks

Questions

Answers in ICAI-ISCA Study Material Page
No:

N 08

10

4(a) What do you understand by Software
Process Maturity? Discuss five levels of Software Process Maturity of
Capability Maturity Model (CMM)?

8.13, 8.14

J 09

10

5(a) When
an organization is audited for the effective implementation of ISO
27001-(BS 7799: Part II)-Information Security Management System, what
are to be verified under. (i) Establishing Management Framework (ii)
Implementation (iii) Documentation.

8.5

5

5(c) Briefly explain Asset
Classification and Control under Information Security Management Systems

8.7

5

7(b) Control OBjectives for Information
related Technology (COBIT)

8.17

N 09


Worldwide,
a global telecom company is serving to more than 10 million customers
in the area of communications through fixed land lines, mobiles,
internet services, digital TV and satellite system etc.
The
financial analysts of the company are located in different functional
groups in six geographical regions. These analysts are missing the
access to the same data, as well as timely access to the information.
Dated budget and actual numbers for each business unit reside in seven
different systems, separating critical components of the Profit and
Loss account and inhibiting analyst’s ability to assess
results. The problem gets further complicated as the field analysts are
not able to go to one universal place to retrieve the data themselves
and they have to rely upon the home office for the same.
The
objective of the company is to set some critical financial goals so
that the company could remain competitive and increase market share.
Read
the above carefully and answer the following with justifications:


10

1(a) To overcome the problems which the
financial analysts are facing, what kind of software the company should
select?


5

1(b) The company is advised that the
adoption of BS 7799 International Standard will help in overcoming the
problems and achieving its goals. Discuss


5

1(c) How should the human resources be
enriched for effective utilization of the proposed new systems and
standards?

Old MICS

M 10

5

4(c) What is COBIT? Give three vantage
points from which the issue of control can be addressed by this
framework.

8.17

N 10

5

7(e) Write short notes on: SysTrust and
WebTrust Services

8.26









For comments / suggestions / queries:
SMS: 98400 63269
email: gkr@icai.org

No comments: