CTO IT Governance & Risk Management 2 — Questions and Answers
Question 1: Which COBIT 5 principle states that governance and management of enterprise IT should cover the enterprise end-to-end, addressing all functions and processes?
- Separating governance from management
- Covering the enterprise end-to-end (Correct answer)
- Applying a single integrated framework
- Meeting stakeholder needs
Correct answer: Covering the enterprise end-to-end
The 'Covering the Enterprise End-to-End' principle ensures IT governance addresses all technology and information processing wherever it occurs across the enterprise.
Question 2: A CTO discovers that a critical vendor handles sensitive customer PII but has not undergone a SOC 2 Type II audit. What is the MOST appropriate immediate action?
- Terminate the vendor contract immediately
- Conduct a third-party risk assessment and require the vendor to obtain SOC 2 Type II certification within a defined timeline (Correct answer)
- Accept the risk since the vendor is critical
- Migrate all data to an internal system
Correct answer: Conduct a third-party risk assessment and require the vendor to obtain SOC 2 Type II certification within a defined timeline
Conducting a risk assessment establishes the current risk posture while requiring SOC 2 Type II sets a contractual path to compliance without disrupting critical services.
Question 3: In the context of IT risk management, what does 'residual risk' refer to?
- Risk identified during an initial assessment but not yet analyzed
- The risk that remains after controls have been applied (Correct answer)
- Risk transferred to a third-party vendor
- Risk that has been formally accepted by the board
Correct answer: The risk that remains after controls have been applied
Residual risk is the level of risk remaining after mitigating controls have been implemented, which must be compared against the organization's risk appetite.
Question 4: Which IT governance framework is specifically designed around aligning IT strategy with business strategy using a Balanced Scorecard approach?
- COBIT
- ITIL
- Val IT (Correct answer)
- ISO/IEC 38500
Correct answer: Val IT
Val IT focuses on IT-enabled business change and value creation, using investment portfolio management and Balanced Scorecard perspectives to align IT with business strategy.
Question 5: An organization's risk appetite statement says 'We will not accept risks with a residual likelihood above Medium and impact above High.' A new SaaS deployment presents a Medium likelihood and High impact risk. What should the CTO do?
- Proceed since the risk is at the boundary
- Implement additional controls to reduce likelihood or impact before proceeding (Correct answer)
- Escalate to the CEO for a waiver
- Cancel the SaaS deployment entirely
Correct answer: Implement additional controls to reduce likelihood or impact before proceeding
The risk exactly meets the boundary of the unacceptable zone, so additional controls should be applied to bring residual risk within appetite before proceeding.
Question 6: What is the primary purpose of an IT governance committee at the board level?
- To manage day-to-day IT operations
- To provide oversight of IT investments, risk, and alignment with corporate strategy (Correct answer)
- To approve all software procurement decisions
- To replace the CISO function in smaller organizations
Correct answer: To provide oversight of IT investments, risk, and alignment with corporate strategy
Board-level IT governance committees provide strategic oversight, ensuring IT investments are aligned with business objectives and that major IT risks are visible and managed.
Question 7: Which risk treatment option involves purchasing cyber liability insurance to offset the financial impact of a data breach?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, without eliminating the underlying risk itself.
Which COBIT 5 principle states that governance and management of enterprise IT should cover the enterprise end-to-end, addressing all functions and processes?