IT Governance Flashcards

1
Q

How leadership accomplishes the delivery of mission-critical business capabilities using IT strategies, goals, and objectives:

A

IT Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

7 elements of IT Governance:

A

Availability, architecture, metadata, policy, quality, regulatory compliance and privacy, and security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What three organizations issue guidance and best privatizes for establishing effective IT governance?

A

COSO’s internal control integrated framework
ISACA’s controls objectives for information and related technology (COBIT) framework
Axelo’s information technology infrastructure library (ITIL) framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

COSO internal control integrated framework has to categories that pertain specifically to internal control over IT, they are:

A

Control activities

Information and communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISACA’s COBIT framework distinguishes between governance and management objectives. Governance objectives are all in a single domain that is centered on evaluating, directing, and monitoring. Managements are grouped how?

A

Into 4 domains tat focus on supporting activities, integrating IT solutions into business processes, delivering IT services securely, and monitoring IT task performances with internal targets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The ITIL framework focuses on delivering IT services across what four domains?

A

Organizations & people
Information & technology
Partners & suppliers
Value streams & processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IT governance should support what? And vice versa

A

Organizational objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Aligning the corporate strategy objectives with this will optimize and organizations efforts in achieving those objectives.

A

IT strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What IT factors might impact the company’s corporate strategy?

A

Available IT personnel
Network design - (decentralized or centralized network)
Cybersecurity
Network design - (physical or virtual network)
Disaster recovery & business continuity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who are the decision makers and drivers of the way IT governance is structured?

A

The people within an organization

BOD, Executive Management, Middle Management, Accountants, IT staff, External Stakeholders, End users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Performs oversight that IT is supporting the business strategy and operational needs

A

Board of Directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Make key strategic decisions and responsible for ensuring IT governance structure is in place and effective. Also set a clear tone at the top.

A

Executive Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Responsible for carrying out governance policies and make sure subordinates are doing the same. Ensures IT projects have appropriate resources and support

A

Middle Management

Below Exec management, but above end users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Responsible for daily planning of IT governance policies and/or carrying out these policies; design no maintain a company’s network; firs response when end users have IT problems; and ensure safe and secure use of IT assets.

A

IT support staff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Much of the data they handle is confidential. They act as stewards of accounting information systems, members of project development teams, and test a lot of IT systems

A

Accountants

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Everybody else that uses the IT systems. Responsible for following processes that have been established within the IT governance structure.

A

End users

17
Q

The two process groups within IT governance execution is:

A

Project development team

Steering committee

18
Q

Management, IT system personnel, accountants, and system users form a team responsible for project monitoring, managing human elements, communicate, and manage risk and escalate issues that cannot be resolved within the team for new IT projects:

A

Project development teams

19
Q

Consists of high level management and executives, experts, IT development heads, and other people in authoritative positions that develop and communicate strategize goals, review budgets budgets and allocate costs, provide ongoing guidance, ensure management participation, and monitor project development progress:

A

Steering committees

20
Q

Identifies how quickly essential business units or processes can return to full operation following a disaster. Also identifies the resources required to resume business operations.

A

Business impact analysis

21
Q

What are the steps in assessing risk in IT:

A

Identify IT resources and assets that exist
Evaluate the impact and likelihood of risk
Evaluate outcomes
Implement a response

22
Q

Determines the criteria for categorizing the list of information resources as high, moderate or low related to the effect on day to day operations. Criteria include characteristics such as how critical the asset is to business operations, costs of a failure, publicity, an any legal or ethical issues.

A

Impact

23
Q

Under this impact:
The company cannot operate without it, high recover costs, the company may fail to meet objectives or maintain its reputation

A

High impact

24
Q

Under this impact:
The company could partially function temporarily, some costs of recovery, the company may fail to meet objectives or maintain its reputation.

A

Moderate impact

25
Q

Under this impact:
The company could operate for an extended period of time, or may notice an effect on achieving the organizations objectives or an effect on its reputation

A

Low impact

26
Q

Under this likelihood:

The risk is highly probably, has occurred recently, can occur frequently, or controls o prevent it are ineffective

A

High likelihood

27
Q

Under this likelihood:

The risk could occur, but controls are in place that may impede its vulnerability

A

Medium likelihood

28
Q

Under this likelihood:

The risk is improbable, or controls are in place to prevent or significantly impede vulnerability

A

Low likelihood