Domain 2: Governance & Management of IT Flashcards
What is the difference between Governance and Management?
Governance aims to provide a strategy to obtain business objectives. Managment aims to implement procedures to achieve the business objectives set by the governance body.
What is the primary reason an IS auditor should reviw the organisational chart?
To understand the structure of the organisation.
Who has the final responsibility for IT governance?
Board of directors / CEO
What should IT departments do in order to achieve the organisations objectives?
The IT department should have long and short-term plans that are consistent with the organisation’s buisness objectives.
What is a greatest concern with respect to an organisations governance model?
Senior mangement does not review information security policies
Having approved suppliers for the company’s products is related to what?
Strategic planning
Who is responsible for IT governance?
The board of directors. They are required to ensure that IT activities are moving in the desired direction.
An IT strategic plan should contain?
The IT strategic plan must contain a clear statement regarding the mission and vision of IT.
What is the main objective of IT governance?
Ensuring the optimal use of technology resources
What is the primary purpose of corporate governance?
Corporate governance provides a strategic direction to the organisation as a whole.
What is COBIT?
The Control Objective for Information Technology is an EGIT framework that ensures IT is aligned with business objectives
What is ISO27001?
ISO 27000 is a set of best practices for information security programs.
What is ITIL?
The Information Technology Infrastructure Library is a detailed framework for the operational service management of IT.
What is O-ISM3?
The Open Information Security Management Maturity Model is a process-based ISM maturity model for security.
What is an IT standard?
An IT standard is a mandatory requirement to be followed in order to comply with a given framework or certification.
What is a policy?
A policy is a set of ideas or strategies that are used as a basis for decision making. They are the high-level statements of direction by management.
What is a procedure?
Procedures are detailed steps and action that help support the policy objectives.
What are guidelines?
Guidelines are additional details to help execute procedures.
What should the Information security policy contain?
This should contain the managements commitment for the safeguarding of information assets
When should the information security policy be reviewed?
At least annually or when there is a significant change to the envrionment of the business.
What should be the first step for the auditor after discovering that IT policies are not approved by management?
Report the findings.
How can policy compliance be ensured?
Existing IT systems should be able to enable compliance.
What should the Information security policy include?
This should include something about access control