Domain 5 Notes Flashcards
Process ownership assignment does not have a feature to
track the completion percentage of deliverables.
Whether the design cost of test cases will be optimized is not determined from
the assignment of process ownership. It may help to some extent; however, there are many other factors involved in the design of test cases.
For gap minimization, a specific requirements analysis framework should be in place and then applied; however, a gap may be found between the design and the as-built system that could lead to
system functionality not meeting requirements. This will be identified during user acceptance testing (UAT). Process ownership alone does not have the capability to minimize requirement gaps.
The involvement of process owners will ensure
that the system will be designed according to the needs of the business processes that depend on system functionality.
A sign-off on the design by the process owners is crucial before
development begins.
To ensure proper segregation of duties, developers should
be restricted to the development environment only
If code needs to be modified after user acceptance testing (UAT),
the process must be restarted in development.
While security controls should be a requirement for any application, the primary focus of the enterprise architecture (EA) is
to ensure that new applications are consistent with enterprise standards.
When selecting an application, the business requirements as well as the suitability of the application for the IT environment
must be considered.
If the business units selected their application without IT involvement, they would be more likely to choose a solution that
fit their business process the best with less emphasis on how compatible and supportable the solution would be in the enterprise, and this would not be a concern.
The primary focus of the EA is to ensure that technology investments are
consistent with the platform, data and development standards of the IT organization.
The EA defines both a current and future state in areas such as
the use of standard platforms, databases or programming languages.
If a business unit selected an application using a database or operating system (OS) that is not part of the EA for the business, this would
increase the cost and complexity of the solution and ultimately deliver less value to the business.
While any new software implementation may create support issues, the primary benefit of the EA is
ensuring that the IT solutions deliver value to the business.
Decreased support costs may be a benefit of the EA, but the lack of IT involvement
would not affect the support requirements.
Directive controls, such as IT policies and procedures, would not apply in a case
of automated control.
Corrective controls are designed to
correct errors, omissions and unauthorized uses and intrusions, when they are detected
Corrective controls provide
a mechanism to detect when malicious events have happened and correct the situation.
A compensating control is used
where other controls are not sufficient to protect the system.
A corrective control in place, like ab antivirus system which automatically determines if the latest signatures files are up to date, will
will effectively protect the system from access via an unpatched device.
Detective controls exist to
detect and report when errors, omissions and unauthorized uses or entries occur
Although missing a component of a release is indicative of a process deficiency, it is of more concern that the missed change
was promoted into the production environment without management approval.
Management approval of changes mitigates
the risk of unauthorized changes being introduced to the production environment.
Unauthorized changes might result in
disruption of systems or fraud.
It is imperative to ensure that
each change has appropriate management approval.
Most release/change control errors are discovered
during postimplementation review.
It is of greater concern that the change was promoted
without management approval after it was discovered.
Using the same change order number is not a relevant
concern.