QUESTION TWO
Information systems are organized frameworks that collect, store, manage, and analyze data
to support decision-making within an organization. They integrate technology, people, and
processes to facilitate efficient data flow and enhance communication.
a) Applications of information systems at different levels of management
(13 marks)
Organizations are generally structured into three levels of management, and different types of
information systems support decision-making at each level.
1. Operational level (lower management)
At this level, day-to-day activities and routine transactions are carried out. The main system
used here is the Transaction Processing System (TPS), supported by Office Automation
Systems (OAS). Applications include:
• Recording sales, purchases and payments
• Processing payroll and employee attendance
• Managing inventory levels and stock control
• Handling customer orders and invoicing
These systems ensure daily operations run smoothly and accurately, since supervisors need
immediate, detailed, up-to-date information to control routine tasks.
2. Tactical/middle management level
Middle managers use information to monitor, control and plan over the short-to-medium term.
The systems used here are Management Information Systems (MIS) and Decision Support
Systems (DSS). Applications include:
• Generating periodic (weekly/monthly) performance reports summarizing TPS data
• Budgeting and variance analysis
• Sales trend analysis to guide marketing decisions
• Resource allocation and staff or production scheduling
These systems condense large volumes of operational data into summarized reports, helping
middle managers assess performance against targets and make semi-structured decisions.
3. Strategic/top management level
Top executives (CEOs, directors) are concerned with the long-term direction of the
organization. The system used here is the Executive Support System (ESS), sometimes called
an Executive Information System (EIS). Applications include:
• Long-term forecasting and strategic planning
• Market and competitor analysis
• Identifying new business opportunities and investment decisions
• Monitoring overall organizational performance through dashboards
These systems present highly summarized, graphical information rather than detailed data,
since top managers deal with unstructured, high-level decisions affecting the whole
organization.
Summary: As information moves up the management pyramid, from operational to tactical to
strategic, it becomes less detailed, more summarized, and is used for decisions that are less
routine and more long-term in nature. This shows how information systems work together
across all levels rather than in isolation.
b) Four of the seven key aspects of effective information security
(12 marks)
The seven key aspects generally recognized in information security are: Confidentiality,
Integrity, Availability, Authentication, Authorization, Non-repudiation, and Accountability. Four
of these are explained below.
1. Confidentiality
This ensures that information is accessible only to authorized individuals and is protected from
unauthorized disclosure. It is achieved through measures such as encryption, passwords and
access controls, preventing sensitive data (e.g. customer or financial records) from falling into
the wrong hands.
2. Integrity
This ensures that data remains accurate, complete and unaltered except by authorized action.
It protects information from being modified, corrupted or tampered with, whether accidentally
or maliciously, so that decision-makers can trust the data they are working with.
3. Availability
This ensures that information and systems are accessible to authorized users whenever
needed. Measures such as backups, redundant systems and disaster recovery plans are used
to prevent downtime caused by system failures, attacks (e.g. denial-of-service), or natural
disasters.
4. Authentication
This is the process of verifying the identity of a user, device or system before granting access.
Common methods include passwords, PINs, biometric verification (fingerprints, facial
recognition), and multi-factor authentication, ensuring that only legitimate users can access
the system.