S1M5 Flashcards
Role of management
daily planning and admin of organization
Selected by BOD
Consists of COO, CFO, CEO
What is a stakeholder
Anyone with a “steak” in the company weather internal or external
What 5 components make up COBIT 2019
COBIT 5
6 principles for governance system
3 principles for governance framework
Other standards
Community Contribution
3 principles for governance framework
Based on a conceptual model
Open and flexible
Align to major standards
CFA
6 Principles of a governance system
Provide stakeholder value
Holistic approach
Dynamic governance system
Governance distinct from management
Tailored to enterprise needs
End to End governance system
Very healthy dieters do try everything
What is the governance objective
Evaluate, direct, monitor (EDM)
What are the management objectives
Assign, plan, organize (APO)
Build, acquire, implement (BAI)
Deliver, service, support (DSS)
Monitor, evaluate, assess
What is EDM and examples
Those charged with governance evaluate strategic objectives, direct management, and monitor if objectives are being met
EX: framework setting, risk and resource optimization, stakeholder engagement
What is APO
Focuses on organization technology’s overall strategy, organization, and supporting activities
EX: innovation, budgeting, HR, provide guidance on IT infrastructure
What is BAI
Addresses implementation of IT solutions in organization’s business processes
EX: identifying solutions, dealing with organizations and IT change, administering assets
What is DSS
Addresses security, delivery, and support of IT services
EX: Service requests, managed problems, business process controls
What is MEA
Addresses IT conformance to performance targets and control objectives
EX: managed performance, managed system of internal control, compliance
7 components of a governance system
Processes
Organizational structures
Principles, policies, frameworks
Information
Culture, ethics, behavior
people, skills, competencies
Services, infrastructure, appliances
11 Design factors
Enterprise strategy
Enterprise goals
risk profile
IT issues
role of IT
IT implementation
threat landscape
compliance requirements
Sourcing model for IT
tech adoption
enterprise size