C2 - Governance and Management of IT - Part A: IT Governance, 2.0-2.3 Flashcards

1
Q

A system in which all stakeholders, including the board, senior management, internal customers, and departments, provide input into the IT decision-making process

A

Enterprise Governance of Information and Technology (EGIT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Broad processes of EGIT:

A

IT Resource management, Performance measurement, Compliance Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Makes a clear distinction between governance & management

A

ISACA’s COBIT Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Plans, builds, runs, and monitors activities in alignment with the direction set by the governance body to achieve the enterprise objectives

A

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Ensures that stakeholders needs, conditions, and options are evaluated to determine balanced, agreed-on enterprise objectives

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The basic outcomes of effective information security governance include strategic alignment, risk management, compliance, and value delivery. These outcomes are enabled through the development of:

A

performance measurement, resource management, process integration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Process-based ISM maturity model for security.

A

O-ISM3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Provides guiding principles for members of governing bodies organizations on the effective, efficient, and acceptable use of IT within an org

A

ISO/IEC 38500:2015: Information Technology - Governance of IT for the Organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A specification for service management aligned with ITIL’s service management framework

A

ISO/IEC 2000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Guidelines on and a common approach to risk management for organizations

A

ISO 3100:2018 Risk Management - Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A set of best practices that provides guidance to organizations implementing and maintaining information security programs

A

ISO/IEC 27000 series

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A mandatory requirement, code of practice, or specification approved by a recognized external standards org

A

Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

High-level statements of management intent

A

Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Documented, defined steps for achieving policy objectives

A

Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Should contain information that will be helpful in executing the procedures

A

Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly