Domain 2 Task Statements Flashcards
Domain 2— Governance and Management of IT (16%)
Provide assurance that the necessary leadership and organizational structures and processes are in place to achieve objectives and to support the organization’s strategy.
T2.1
Evaluate the IT strategy, including the IT direction, and the processes for the strategy’s development, approval, implementation and maintenance for alignment with the organization’s strategies and objectives.
T2.2
Evaluate the effectiveness of the IT governance structure to determine whether IT decisions, directions and performance support the organization’s strategies and objectives.
T2.3
Evaluate IT organizational structure and human resources (personnel) management to determine whether they support the organization’s strategies and objectives.
T2.4
Evaluate the organization’s IT policies, standards, and procedures, and the processes for their development, approval, release/publishing, implementation, and maintenance to determine whether they support the IT strategy and comply with regulatory and legal requirements.
T2.5
Evaluate IT resource management, including investment, prioritization, allocation and use for alignment with the organization’s strategies and objectives.
T2.6
Evaluate IT portfolio management, including investment, prioritization and allocation, for alignment with the organization’s strategies and objectives.
T2.7
Evaluate risk management practices to determine whether the organization’s IT‐related risks are identified, assessed, monitored, reported and managed.
T2.8
Evaluate IT management and monitoring of controls (e.g., continuous monitoring, quality assurance [QA]) for compliance with the organization’s policies, standards and procedures.
T2.9
Evaluate monitoring and reporting of IT key performance indicators (KPIs) to determine whether management receives sufficient and timely information.
T2.10
Evaluate the organization’s business continuity plan (BCP), including alignment of the IT disaster recovery plan (DRP) with the BCP, to determine the organization’s ability to continue essential business operations during the period of an IT disruption.