AG: 1-Overview Flashcards

0
Q

What is the role of assessor judgement and experience?

A

Although COBIT 5 assessment is a standard-based approach, but the assessor judgement and experience will impact the depth of the evaluation result

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

What is the value of making COBIT 5 assessment a standard-based approach?

A

To minimize to extend the subjectivity of assessment activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How self-assessment guid is compared to the assessor guide?

A

It is used to perform a less rigorous assessment of the capability of organization processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the key elements/basis for COBIT 5 PAM?

A
  • COBIT 5 PRM: The specifications of the processes

- ISO/IEC 15504: The capability of each process & measurement scale

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the critical success factors of COBIT 5 assessment? (As well as the process Improvement plan?)

A
  • Sponsorship
  • Clear purpose, scope and constraints definition
  • Appropriate assessment class selection
  • Class project leadership
  • Engagement by required participants
  • Consistent application of the assessment methodology
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the major differences between the three available classes of COBIT 5 assessment?

A

The level of rigour (and thus the cost of assessment) increases from class three to class one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the major purpose(s) of class 3 assessment?

A
  • Testing and understanding the IT process
  • Testing and understanding the potential benefits from IT improvement
  • Monitoring the ongoing progress of an improvement programm
  • Identify key issues for a later class one or class two assessment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the major purpose(s) of class 2 assessment?

A
  • reliable assessment for internal reporting

- a basis for an initial assessment at the commencement of an improvement programme

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the major purpose(s) of class 1 assessment?

A

Comparison with other organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the impact of a competent assessor on the COBIT assessment?

A

The (effectiveness) of the assessment is dependent on the skills and judgement of the assessors and, in particular, the lead assessor, who must have knowledge of both the assessment process and COBIT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How the sponsor of COBIT 5 assessment can ensure the effectiveness of the conducted assessment?

A

By ensuring that the assessment is led by a competent assessor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the major characteristics of COBIT 5 competent assessor?

A
  • Trained on COBIT 5 PRM & PAM
  • Attended the assessor training
  • Certified Assessor
  • Has IT & Process oriented knowledge
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How to ensure an adequate level of engagement from the key participants in COBIT 5 assessment?

A
  • Ensure that the sponsor motivate them to participate

- Make a comprehensive list from process owners, manager and practitioners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the typical target audience of the COBIT 5 PAM?

A
  • Certified assessor
  • Internal auditors
  • Assessment team members
  • Organization management & stakeholders (such as the sponsor)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the typical sequence of the assessments classes?

A

Class 2
Class 3
Class 1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is exactly the output report of the COBIT 5 assessment? What are the 3 main elements that it links?

A

It is a report that contains the capability of the selected processes (defined in the COBIT PRM) against the capability scale (defined in ISO/IEC 15504-2) as documented in the COBIT PAM

16
Q

What the assessment report is NOT?

A

The report is not an attestation or assurance report on the effectiveness of the process or its internal controls

17
Q

Why COBIT 5 assessment results should be combined with other information and indicative results?

A

Because process capability is only one aspect of enterprise performance and goal achievement.