The COBIT Model of IT Governance and Management Flashcards

1
Q

What is the COBIT Model? What is the purpose the framework?

A

The purpose is to align IT with business goals/strategies

Link business risks, control needs, and IT

Common language for users, auditors, management, and business process owners in identifying risks and structuring controls

Purpose:
- How much should we invest?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the basic COBIT framework?

A
  • To provide information that the organization needs to achieve its objectives, IT resources need to be managed by a set of naturally grouped processes.

The framework is an ongoing process that repeats starting with:

1) Business requirements
2) IT Resources
3) IT Processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do COSO and COBIT have in common?

A

Monitoring and evaluation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the seven desired attributes of COBIT?

A

Information (seven desired attributes)

1) Effective
2) Efficient
3) Confidential
4) Integrity
5) Available
6) Complaint
7) Reliable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

According to COBIT there are five IT Resources…?

A

1) Data
2) Application systems
3) Technology
4) Facilities
5) People

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

COSO is bigger focused than COBIT, what is the COSO focus?

A

organizational controls and processes.

COBIT (BIT SMALLER): IT controls and processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the monitor and evaluate processes ob COBIT? What are the topics?

A

includes:
- Regularly assess IT Processes for quality and compliance
- Includes management oversight of controls and independent assurance

Topcis:

  • Assessment over time, delivering assurance
  • Management oversight of the control system
  • Performance measurement

Questions to think about?

  • Can IT performance be measured and corrected?
  • Need independent assurance in critical areas?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the four processes of monitor and evaluation?

A

Monitor the processes

Access internal control adequacy

Obtain independent assurance

Provide for independent audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly