IT Management Flashcards
WHAT is the primary objective of an IT performance measurement process?
To Optimize performance
Note: this can also be used to measure and manage products/services, assure accountability and make budget decisions
WHAT should the IS auditor do when they realize the auditees IT structures and activities were recently outsourced to various providers?
Determine the contractual warranties of the providers support and business needs of the organization
What should an IS auditor assess when reviewing an organization that uses cross-training practices?
The risk of one person knowing all parts of a system
What should an IS auditor determine when reviewing the IT short-range (tactical) plan?
Whether there is an integration of IT and business personnel within projects
i.e. The integration of IT and business personnel in projects is an operational issue and should be considered while reviewing the short-range plan
Why should the IS Auditor review the vendor’s business continuity plan (during a feasibility study involving outsourcing of IT processing)?
To evaluate the adequacy of the service levels that the vendor can provide in a contingency.
i.e. the capability of the vendor to face a contingency and continue to support the organization’s processing requirements.
WHAT should you expect to find (as an IS Auditor) in an organization’s strategic plan?
Approved suppliers for products offered by the company
i.e. Approved suppliers of choice for the product is a strategic business objective that is intended to focus the overall direction of the business
What should an IS Auditor expect to find in an outsourcing contract of IT facilities while reviewing it?
THE ownership of intellectual property
What is the best indicator an IS Auditor can use to determine a vendor’s ability to meet service level agreement (SLA) requirements for a critical IT security service?
Agreed-on key performance metrics
What is the IS Auditor primarily focused on when reviewing the auditee Quality Management System?
Evidence that continuous improvement targets are being monitored.
What would be considered an important factor for an IS auditor when reviewing a service level agreement of an external IT service provider?
Uptime guarantee
i.e. A measurable term of performance