01. Governance vs Management Flashcards
1
Q
Governance vs Management
Governance
A
C-Level Executives
Stakeholder needs, conditions and options
* Enterprise objectives
* Setting direction
* Monitoring performance and compliance
* Risk appetite
2
Q
Governance vs Management
Management
A
- Plans
- Builds
- Monitorings activities
- Aligns to the direction the governance body has set
- How do we get to the destination set by C-Level Executives
- Risk tolerance - practically working wiht risk appetite in work environment
3
Q
Governance vs Management
Risk Appetite
A
- Aggressive
- Neutral
- Adverse
- Risk appetite set by C-Level
- Whichever strategy chosen has unique opportunities and unique threats
- i.e. High risk, high rewards
4
Q
Governance vs Management
Bottom Up Organisation
A
IT Security = Nuisance
- not seen as a helper
- Does not have senior managment approval or buy in which trickles down to the organisation
5
Q
Governance vs Management
Top-Down Organisation
A
IT Leadership represented at board level
- they lead and support the direction that they have
- Exam is seen from this perspective
7
Q
Governance vs Management
CIO
A
Chief Information Officer
- CIO or CTO usually sit above CISO or IT Security Manager
8
Q
Governance vs Management
CTO
A
Chief Technology Officer
- CIO or CTO usually sit above CISO or IT Security Manager