Domain 2: Task 1 Flashcards
- An IS auditor must be able to understand and provide assurance that the organization has:
a. Structure
b. Accountability Mechanisms
c. Monitoring Practices
d. Policies
- For an IS auditor, the knowledge of IT governance forms the foundation for:
a. Evaluating Control Practices
b. Mechanisms for Management Oversight and Review
- A goal of GEIT implementation is to provide a system in which all ____ and ____ provide input into the decision-making process.
a. stakeholders
b. departments
- GEIT seeks to ensure that IT performance meets enterprise objectives by:
a. alignment of objectives
b. realization of benefits
- The GEIT framework provides feedback regarding:
a. How IT delivers value to the enterprise
b. How IT risk is properly managed
- The processes of GEIT implementation must include:
a. IT Resource Management
b. Performance Measurement
c. Compliance Management
Summarize the objective of IT Resource Management.
a. focuses on maintaining updated inventory of IT resources, and
b. addresses risk management process.
Summarize the objective of Performance Measurement.
a. ensures that all IT resources perform to deliver value to the enterprise.
Summarize the areas of compliance requirements that Compliance Management addresses.
a. legal,
b. regulatory, and
c. contractual.
To help business succeed, IT becomes an integral part of ____, not just merely ______
a. an enterprise’s strategy
b. an enabler.
To help business succeed, strategic alignment between ____ and ____ becomes a ____, leading to the achievement of ____.
a. IT
b. enterprise objectives
c. critical success factor
d. business value
The focus areas of Executive Management supporting Value Creation:
a. Benefits Realization,
b. Risk Optimization, and
c. Resource Optimization.
GEIT helps the enterprise through:
a. incorporating and normalizing best practices. (Integrating)
b. enabling full leverage of information (Facilitating)
c. helping to form the relationships and processes used to direct and control the enterprise toward its goals, balanced with risk. (Structuring)
Examples of GEIT frameworks are:
a. COBIT 5
b. ISO/IEC 27001 Series
c. ITIL
d. IT Baseline Protection Catalogs
e. Information Security Management Maturity Model (ISM3)
f. ISO/IEC 38500:2008
g. ISO/IEC 20000
The Audit function helps the enterprise by
a. providing recommendations to senior management.
b. providing independent and balance reviews
c. ensuring compliance.