Data Systems Risks Suggested Answer
Data Systems Risks Suggested Answer
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
A.2 (a) In the given situation, the following Vs of big data are demonstrated:
▪ Volume: Demonstrated by "massive amounts of data daily" and "millions of
customer reviews."
▪ Velocity: Demonstrated by "thousands of transactions per hour" and the need for
"immediate analysis."
▪ Variety: Demonstrated by the combination of "customer purchase records
(structured)," "customer reviews and social media comments (unstructured)," and
"real-time clickstream data (semi-structured)."
Page 1 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
▪ Data Quality and Data Integration: The inconsistency in customer profiles stems
from integrating diverse data sources with different structures and formats.
Ensuring accuracy and completeness across this varied data landscape is a major
challenge.
▪ Storage and Processing Capacity: Delayed reporting is caused by high data
volume exceeding the capacity of the current infrastructure to process data
efficiently.
Justification: Edge computing brings data processing closer to the source (e.g., at
the customer device or local node), reducing load on central servers and
minimizing latency. By processing high-volume, real-time data (like clickstreams)
at the edge, SwiftCart can improve response times and reporting speed, especially
during peak seasons.
NoSQL databases are highly scalable, particularly with complex data. Examples
include MongoDB and Cassandra.
▪ Typical Applications:
Given their design for unstructured and semi-structured data, NoSQL databases
are often leveraged in Big Data environments.
They are suitable for real-time analytics and machine learning applications. This
makes them ideal for scenarios involving social media data, IoT device data, and
web transactions, where data variety and volume are significant.
Page 3 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
(c) The Network Model organizes data as nodes (entities) connected by links
(relationships), allowing a child node to have more than one parent node. This 'graph-
like structure' provides greater flexibility than the hierarchical model, which is limited
to one-to-many relationships, making the Network Model highly suitable for
managing complex data relationships that involve many-to-many connections. Its
design inherently supports these intricate interconnections, enabling more direct and
efficient navigation of linked data.
Page 4 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
ETL processes automate data consolidation, freeing up staff from manual data
entry and reconciliation, leading to increased efficiency and productivity.
▪ Automated Data Validation and Cleansing Tools:
Implement automated tools that validate and cleanse data as it enters the system.
It reduces manual errors and ensures only high-quality, consistent data enters
reporting systems. This improves trust in analytics, reduces rework, and speeds up
decision-making cycles.
▪ Implement Role-Based Access Control (RBAC) with Unique Login IDs:
Deploy RBAC to ensure employees only access data relevant to their role,
eliminating generic logins. Also, deploy Privileged Access Management (PAM)
for sensitive systems like the SQL database.
It protects sensitive customer and operational data by restricting access to only
authorized users. It minimizes internal risks, increases accountability, and
supports compliance which is critical for customer trust and legal protection.
▪ Enhance IT Security Measures and Monitoring:
Deploy Security Information and Event Management (SIEM) systems for real-
time monitoring of all databases and networks to detect suspicious activity and
prevent unauthorized access.
It enables proactive identification and mitigation of threats through real-time
monitoring and alerts. This reduces downtime, prevents breaches, and protects
company data assets, preserving continuity and customer confidence.
Robust ITGCs and security measures (access controls, monitoring, IRP) minimize
the risk of costly data breaches and operational disruptions, ensuring business
continuity and protecting reputation.
▪ Establish a Data Governance Framework:
Introduce formal policies, procedures, standards, and roles (e.g., data ownership
and stewardship) for data collection, storage, access, and use across the
organization.
It establishes consistent policies and accountability for data handling across
departments. It improves data quality, promotes efficient collaboration, and
ensures that strategic initiatives (like predictive analytics) are based on trustworthy
data.
Page 5 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
A.5 (a) Cloud computing services are delivered through three primary models, each offering
different levels of control, flexibility, and management:
(b) Organizations can adopt different cloud deployment models based on their specific
requirements for security, control, cost, and scalability. Two distinct models are:
▪ Public Cloud:
Key Features:
Public cloud services are delivered over the public internet and are shared among
multiple organizations, often referred to as "tenants". These services are highly
scalable, cost-effective, and easy to implement, with the third-party provider
managing and maintaining the entire infrastructure.
Page 6 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
Typical Use:
Public clouds are an excellent choice for startups or small businesses due to their
low upfront costs and pay-as-you-go pricing. They are also well-suited for
applications with variable workloads, such as e-commerce websites experiencing
fluctuating demand during holiday sales, benefiting from virtually unlimited
scalability.
▪ Private Cloud:
Key Features:
A private cloud is a cloud computing infrastructure dedicated solely to a single
organization, offering enhanced control, security, and customization. It can be
hosted either on the organization's own data centers (on-premises) or by a third-
party cloud provider. Unlike public clouds, resources in a private cloud are not
shared with other organizations.
Typical Use:
Private clouds are ideal for enterprises with strict regulatory, security, or
compliance requirements, such as those in healthcare or finance, that need to meet
stringent data privacy and security standards. They are also preferred by
businesses that require extensive customization of their infrastructure, workflows,
or security settings.
▪ Hybrid Cloud:
Key Features:
A hybrid cloud combines both public and private cloud environments, allowing
organizations to leverage the benefits of both models. Applications and data can
be shared and moved seamlessly between the public and private clouds, providing
a balance between scalability and control.
Typical Use:
Hybrid clouds are suitable for organizations with fluctuating workloads, enabling
them to use the public cloud for peak loads while keeping mission-critical
workloads and sensitive data in the private cloud. They also provide a robust
solution for disaster recovery by using the public cloud as a backup for critical
systems hosted in private clouds.
(c) Organizations can gain several significant benefits from adopting cloud computing:
▪ Cost Efficiency: Cloud computing eliminates the need for large upfront capital
investments in hardware and software, converting them into operational expenses.
This pay-as-you-go model allows businesses to manage and scale expenses
according to their needs.
▪ Scalability: Cloud computing offers unparalleled scalability, allowing
organizations to dynamically adjust their resources (e.g., CPU, memory, or
additional servers) based on current demand. This ensures performance remains
unaffected even during peak usage.
▪ Flexibility: Cloud computing enables unparalleled flexibility by allowing users to
access data and applications from any location with an internet connection. This
supports remote work and multi-location collaboration.
Page 7 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
▪ Disaster Recovery: Cloud providers offer robust disaster recovery solutions with
built-in backup, redundancy, and failover options, ensuring minimal disruption to
operations. Automated backup services ensure critical data is continuously backed
up and can be easily restored.
▪ Innovation: Cloud computing accelerates innovation by providing businesses
with the infrastructure and tools needed to develop, test, and deploy new
applications and services rapidly. Developers can access powerful computing
resources and pre-built models, allowing them to experiment and bring ideas to
market faster.
A.6 (a) Based on the scenario, SecureInvest is facing several cybersecurity and information
security risks:
▪ Malware/Ransomware Attack (Digital Risk): This risk occurs when "One
employee, after clicking a link in such an email, inadvertently downloaded
malicious software that encrypted several local files on their laptop, rendering
them inaccessible". Malware is malicious software designed to infiltrate systems,
steal data, or disrupt operations, and ransomware specifically encrypts data,
demanding payment for decryption.
▪ Cloud Misconfiguration (Cloud Computing Risk / Digital Risk): This risk is
evident when "a critical client data storage bucket in the new public cloud
environment was inadvertently left publicly accessible for several days due to a
misconfiguration during migration". Misconfigurations of cloud settings, such as
publicly exposed storage buckets or improper access controls, are common risks
in cloud environments that can lead to data leaks or unauthorized access.
▪ Third-Party Risk (Operational Risk): This risk is highlighted by the "major
service outage" experienced by "the third-party vendor providing automated
financial reports, leading to significant delays in daily reporting for SecureInvest".
Third-party risks arise from external entities like vendors with access to an
organization’s IT ecosystem, where their outages or failures can disrupt dependent
services.
(b) For each identified risk, here's its impact on the core objectives of information security
(Confidentiality, Integrity, Availability):
▪ Malware/Ransomware Attack:
Confidentiality:
Malware can allow attackers to steal sensitive data before encrypting it. This
exposes confidential information such as personal records, financial data, or
proprietary files to unauthorized parties.
Integrity:
Malware can also alter or corrupt data, affecting its integrity.
Availability:
The encryption of local files by ransomware directly impacts availability, as the
data becomes inaccessible to the legitimate user and the organization.
Example:
The WannaCry Ransomware Attack (2017) is a relevant example, where
ransomware encrypted data on hundreds of thousands of machines, including
critical institutions like the UK’s National Health Service, leading to significant
operational disruption and data inaccessibility.
Page 8 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
▪ Cloud Misconfiguration:
Confidentiality:
A publicly accessible client data storage bucket directly compromises
confidentiality, as sensitive client data could be viewed by unauthorized
individuals.
Integrity:
While not explicitly stated in the scenario, public access also opens the door to
unauthorized modification or deletion, which would impact data integrity.
Availability:
If unauthorized users manage to access the data due to misconfiguration, they can
also impact availability by deleting critical files or overwriting them, making them
inaccessible to legitimate users.
Example:
The Equifax Data Breach (2017), though primarily due to an unpatched
vulnerability, highlights the consequences of insufficient internal detection and
inadequate security configurations leading to the exfiltration of sensitive personal
data. Similarly, the source mentions that "In 2019, a misconfigured cloud database
exposed 540 million Facebook user records," directly illustrating a cloud
misconfiguration risk impacting confidentiality.
(c) Mitigation Strategies (Any three corresponding to the risks explained in part a)
▪ dPeriodically conduct Robust Security Awareness Training Program
▪ Implement Multi-Factor Authentication
▪ Conduct Regular Cloud Configuration Audits
▪ Enforce Cloud Security Best Practices
▪ Strengthen Third-Party Risk Management (TPRM) and Redundancy for Critical
Services
Page 9 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
(b) ▪ General Mitigation Strategies for Physical Infrastructure Risks (e.g., Power
Outages):
Power Resilience Measures:
Deploying Uninterruptible Power Supply (UPS) systems and backup generators
helps maintain operations during power outages. Utilizing redundant power
sources and ensuring environmental controls like temperature regulation in data
centers can also protect IT equipment from damage during power fluctuations.
Page 10 of 11
Data, Systems and Risks
Suggested Answer
Certificate in Accounting and Finance Examination – Model paper
▪ Complexity of IT Environments:
Modern IT environments are highly complex, involving multiple platforms,
diverse applications, and a wide array of devices, including cloud-based systems,
on-premise infrastructure, mobile devices, and IoT networks. Ensuring consistent
controls across this diverse landscape is difficult, especially when integrating
legacy systems that may lack modern security features with newer technologies
that introduce different security requirements.
(THE END)
Page 11 of 11