test Flashcards
What is governance?
Set of policies, rules, and processes that organizations implement to ensure their activities align with their business goals
Success involves providing accountability, defining jobs and responsibilities, and evaluating employees based on results.
What are the two focuses of IT management and IT governance?
IT management: present + internal focus; IT governance: future + external focus
What is the ISO/IEC 38500:2015?
Governance is part of Corporate Governance
Define risk management.
Identifying, evaluating, and managing various risks, including legal, financial, and security-related risks.
What does a risk management system consist of?
Personnel + technologies + processes => enforce risk mitigation
What is the success criterion of risk management?
Keeping stakeholders informed, considering legal, contractual, and business requirements.
What framework provides guidelines for managing risks?
ISO 31000
True or False: Risk management should be part of the decision-making process.
True
What does digital trust refer to?
Confidence in the integrity of the relationships, interactions, and transactions among providers and consumers within a digital ecosystem.
What are the key factors of digital trust?
- Quality
- Availability
- Security and privacy
- Ethics and integrity
- Transparency and honesty
- Resiliency
What is the GRC capability model?
Integrates risk, governance, audit, ethics/culture, IT, and compliance.
List the four components of the GRC Capability Model.
- Learn
- Align
- Perform
- Review
Define principled performance.
Reliably achieve objectives, address uncertainty, and act with integrity.
What is the purpose of assurance in governance?
Provides reliability and confidence to management, the governing authority, and other stakeholders.
What are the dimensions to assess ‘total performance’?
- Effectiveness
- Efficiency
- Agility
- Resilience
What is the goal of Open Compliance and Ethics Groups (OCEG)?
To help solve problems using an interdisciplinary approach.
What are the six principles for a governance system?
- Provide Stakeholder Value
- Holistic Approach
- Dynamic Governance System
- Governance Distinct from Management
- Tailored to Enterprise Needs
- End-to-end Governance System
What is the COBIT framework?
Provides guiding principles for directors on the effective, efficient, and acceptable use of IT within their organizations.
What are the two perspectives in governance and management?
- Governance: board level, external, future-oriented
- Management: executive level, internal, present-oriented