test Flashcards

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is governance?

A

Set of policies, rules, and processes that organizations implement to ensure their activities align with their business goals

Success involves providing accountability, defining jobs and responsibilities, and evaluating employees based on results.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two focuses of IT management and IT governance?

A

IT management: present + internal focus; IT governance: future + external focus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the ISO/IEC 38500:2015?

A

Governance is part of Corporate Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Define risk management.

A

Identifying, evaluating, and managing various risks, including legal, financial, and security-related risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does a risk management system consist of?

A

Personnel + technologies + processes => enforce risk mitigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the success criterion of risk management?

A

Keeping stakeholders informed, considering legal, contractual, and business requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What framework provides guidelines for managing risks?

A

ISO 31000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False: Risk management should be part of the decision-making process.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does digital trust refer to?

A

Confidence in the integrity of the relationships, interactions, and transactions among providers and consumers within a digital ecosystem.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the key factors of digital trust?

A
  • Quality
  • Availability
  • Security and privacy
  • Ethics and integrity
  • Transparency and honesty
  • Resiliency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the GRC capability model?

A

Integrates risk, governance, audit, ethics/culture, IT, and compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

List the four components of the GRC Capability Model.

A
  • Learn
  • Align
  • Perform
  • Review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define principled performance.

A

Reliably achieve objectives, address uncertainty, and act with integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of assurance in governance?

A

Provides reliability and confidence to management, the governing authority, and other stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the dimensions to assess ‘total performance’?

A
  • Effectiveness
  • Efficiency
  • Agility
  • Resilience
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the goal of Open Compliance and Ethics Groups (OCEG)?

A

To help solve problems using an interdisciplinary approach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the six principles for a governance system?

A
  • Provide Stakeholder Value
  • Holistic Approach
  • Dynamic Governance System
  • Governance Distinct from Management
  • Tailored to Enterprise Needs
  • End-to-end Governance System
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the COBIT framework?

A

Provides guiding principles for directors on the effective, efficient, and acceptable use of IT within their organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the two perspectives in governance and management?

A
  • Governance: board level, external, future-oriented
  • Management: executive level, internal, present-oriented
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the overall goal of the COBIT framework?

A

Enterprise goals have been consolidated, reduced, updated, and clarified.

22
Q

Fill in the blank: The purpose of process EDM01 is to __________.

A

Evaluate, direct, and monitor the governance system to ensure effectiveness, transparency, and alignment with business strategy.

23
Q

What are the key activities in the process EDM01?

A
  • Evaluate stakeholder needs
  • Direct governance principles to leadership
  • Monitor governance performance
24
Q

What are the risks associated with AI?

A
  • Misbehavior of AI
  • Bias
  • Abuse of AI systems
  • Black box algorithms
25
Q

What is Explainable AI (XAI)?

A

Makes AI systems more transparent by providing clear explanations of their decisions.

26
Q

What does the EU AI Act classify AI systems into?

A
  • Unacceptable risk
  • High risk
  • Limited risk
  • Low risk
27
Q

What is the significance of digital trust in today’s business environment?

A

Essential for digital-first businesses and impacts stakeholder perceptions, brand reputation, and operational resilience.

28
Q

What are the four risk categories defined by the EU AI Act?

A
  1. Minimal risk
  2. Limited risk
  3. High risk
  4. Unacceptable risk

The EU AI Act classifies AI systems into these four categories based on their potential impact.

29
Q

What is the main goal of Explainable AI (XAI)?

A

To make AI black box algorithms understandable for human users

XAI aims to increase transparency in AI systems.

30
Q

What does the EU Digital Strategy focus on?

A

Technology in the interest of humanity, a democratic and sustainable society, and a fair and competitive economy

This strategy emphasizes the ethical use of technology.

31
Q

How is trust defined in the context of psychology?

A

As a bridge between a trustor and a trustee, aimed at reducing complexity and includes a willingness to take risks

This definition highlights the relational aspect of trust.

32
Q

What is the purpose of the Digital Trust Radar (DTR)?

A

To filter and access specific guidelines on responsible and trustworthy AI

The DTR serves as a tool for evaluating AI trustworthiness.

33
Q

What is data privacy designed to protect?

A

Our personality and fundamental rights

Data privacy is essential for maintaining democratic principles.

34
Q

What constitutes personal data under data protection laws?

A

Data relating to an identified or identifiable natural person

This includes any information that can directly or indirectly identify an individual.

35
Q

What must consent for data processing be?

A

Voluntary and explicit

Consent is a key requirement for lawful data processing.

36
Q

What is a Data Protection Impact Assessment (DPIA)?

A

A tool for self-evaluation on data processing risks

DPIA helps organizations identify and mitigate risks associated with data processing.

37
Q

What does the GDPR regulate?

A

The processing and using of Personal Data of European citizens

GDPR is a comprehensive data protection regulation in the EU.

38
Q

What is the core principle of GDPR?

A

Data protection by design and by default

This principle ensures privacy is integrated into data processing systems.

39
Q

What is an internal audit?

A

An audit performed by employees of the organization

Internal audits help organizations review their processes and compliance.

40
Q

What type of audits focuses on operational efficiency?

A

Operational audits

These audits assess how well an organization is achieving its operational goals.

41
Q

What is the purpose of compliance audits?

A

To ensure regulatory conformity

Compliance audits verify that organizations adhere to laws and regulations.

42
Q

What are the three types of controls in auditing?

A
  1. Preventive control
  2. Detective control
  3. Corrective control

Each type serves a different function in managing risks.

43
Q

What must companies processing personal data systematically nominate?

A

A Data Protection Officer (DPO)

The DPO is responsible for overseeing data protection strategy and compliance.

44
Q

What are the 5Cs used for in auditing findings?

A
  1. Criteria
  2. Condition
  3. Cause
  4. Consequence
  5. Corrective Action Plans

The 5Cs framework helps auditors structure their findings.

45
Q

What is the primary role of an auditor?

A

To provide assurance regarding organizational goals and regulatory compliance

Auditors assess whether operations meet established standards.

46
Q

Fill in the blank: Data protection is about data relating to an _______.

A

[identified or identifiable natural person]

47
Q

True or False: Data processing activities must be documented according to GDPR.

A

True

Documentation is essential for transparency and compliance.

48
Q

What is the significance of a risk-based approach in auditing?

A

To prioritize what can go wrong and address those risks

This approach enhances the effectiveness of the audit.

49
Q

What is the role of communication in the auditing process?

A

To ensure stakeholders are informed and understand audit results

Effective communication facilitates transparency and follow-up actions.

50
Q
A