CSI CSI Governance and Compliance 2 — Questions and Answers
Question 1: How does the concept of 'policy' support CSI governance?
- Policies set mandatory expectations for how CSI activities must be conducted, ensuring consistency and accountability (Correct answer)
- Policies are optional guidelines that teams may follow if convenient
- Policies replace the need for CSI processes
- Policies are only relevant for information security, not service improvement
Correct answer: Policies set mandatory expectations for how CSI activities must be conducted, ensuring consistency and accountability
CSI policies establish mandatory behaviors — such as always recording improvements in the register or measuring before and after — that ensure governance rigor.
Question 2: What does 'audit trail' mean in the context of CSI compliance?
- A chronological record of all improvement decisions, approvals, and changes that provides evidence for auditors and regulators (Correct answer)
- A physical inspection of IT infrastructure
- A record of all customer complaints
- A log of all employee login events
Correct answer: A chronological record of all improvement decisions, approvals, and changes that provides evidence for auditors and regulators
An audit trail documents who approved what, when, and why, providing the evidence needed to demonstrate compliance during external reviews.
Question 3: How does COBIT relate to ITIL CSI?
- COBIT provides a governance framework for IT that complements ITIL CSI's improvement practices by adding control objectives and accountability (Correct answer)
- COBIT replaces ITIL CSI entirely
- COBIT and ITIL are incompatible frameworks
- COBIT only applies to financial services organizations
Correct answer: COBIT provides a governance framework for IT that complements ITIL CSI's improvement practices by adding control objectives and accountability
COBIT's governance and management objectives provide a control framework that organizations can use alongside ITIL CSI to ensure improvement activities are governed effectively.
Question 4: What is 'continual compliance monitoring' and why is it important for CSI?
- Ongoing verification that services and processes continue to meet regulatory and policy requirements, feeding non-compliance into CSI (Correct answer)
- A one-time audit conducted annually
- A financial reporting obligation
- Monitoring of employee behavior only
Correct answer: Ongoing verification that services and processes continue to meet regulatory and policy requirements, feeding non-compliance into CSI
Continual compliance monitoring identifies drift from required standards in real time, ensuring that non-compliance triggers CSI improvement actions promptly.
Question 5: Which governance body typically approves significant CSI investment decisions in a large organization?
- IT Steering Committee or equivalent senior leadership body (Correct answer)
- Service Desk Team Lead
- Change Advisory Board
- Configuration Manager
Correct answer: IT Steering Committee or equivalent senior leadership body
Major CSI investments require approval at the strategic governance level, typically an IT Steering Committee that balances IT priorities with business objectives.
Question 6: How does risk management intersect with CSI governance?
- CSI improvement plans must consider risks associated with making changes, and risk management provides the framework for assessing and mitigating them (Correct answer)
- Risk management and CSI operate in completely separate domains
- CSI eliminates all risks by improving services
- Risk management only applies to project initiation, not ongoing improvement
Correct answer: CSI improvement plans must consider risks associated with making changes, and risk management provides the framework for assessing and mitigating them
Every improvement carries implementation risk; integrating risk management ensures that CSI changes are assessed and controlled appropriately.
How does the concept of 'policy' support CSI governance?