Domain 2: Governance and Management of IT Part 2B Flashcards
Before implementing an IT balanced scorecard, an organization must:
define key performance indicators.
A decision support system is used to help high-level management:
make decisions based on data analysis and interactive models.
During a feasibility study regarding outsourcing IT processing, the relevance for the IS auditor of reviewing the vendor’s business continuity plan is to:
evaluate the adequacy of the service levels that the vendor can provide ina contingency.
During an audit, which of the following situations are MOST concerning for an organization that significantly outsources IS processing to a private network?
The contract does not contain a right-to-audit clause for the third party.
An employee who has access to highly confidential information resigned. Upon departure, which of the following should be done FIRST?
Revoke the employee’s access to all systems.
An enterprise hosts its data center onsite and has outsourced the management of its key financial applications to a service provider. Which of the following controls BEST ensures that the service provider’s employees adhere to the security policies?
An indemnity clause is included in the contract with the service provider.
An enterprise is looking to obtain cloud hosting services from a cloud vendor with a high level of maturity. Which of the following is MOST important for the auditor to ensure continued alignment with the enterprise’s security requirements?
The vendor agrees to provide annual external audit reports in the contract.
An enterprise selected a vendor to develop and implement a new software system. To ensure that the enterprise’s investment in software is protected, which of the following security clauses is MOST important to include in the master services agreement?
Software escrow
In a review of the human resources policies and procedures within an organization, an IS auditor is MOST concerned with the absence of a:
termination checklist.
In reviewing the IT short-range (tactical) plan, an IS auditor should determine whether:
there is an integration of IT and business personnel within projects.
An IS auditor is assigned to review IT structures and activities recently outsourced to various providers. Which of the following should the IS auditor determine FIRST?
The contractual warranties of the providers support the business needs of the organization.
An IS auditor is reviewing a contract management process to determine the financial viability of a software vendor for a critical business application. An IS auditor should determine whether the vendor being considered:
can support the organization in the long term.
An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise’s investment in software is protected, which of the following should be recommended by the IS auditor?
There should be a source code escrow agreement in place.
An IS auditor reviewing an organization that uses cross-training practices should assess the risk of:
one person knowing all parts of a system.
An IS auditor reviewing an outsourcing contract of IT facilities expects it to define the:
ownership of intellectual property.
An IS auditor was asked to review a contract for a vendor being considered to provide data center services. Which is the BEST way to determine whether the terms of the contract are adhered to after the contract is signed?
Conduct periodic audit reviews of the vendor.
Many organizations require an employee to take a mandatory vacation (holiday) of a week or more to:
reduce the opportunity for an employee to commit an improper or illegal act.
An organization has contracted with a vendor for a turnkey solution for their electronic toll collection system (ETCS). The vendor has provided its proprietary application software as part of the solution. The contract should require that:
source code of the ETCS application is placed in escrow.