CTO IT Governance & Risk Management 5 — Questions and Answers
Question 1: What is the primary objective of IT general controls (ITGCs) in the context of SOX compliance?
- To ensure application-level business logic is correct
- To provide a foundation of reliability for application controls by governing the IT environment (Correct answer)
- To document all manual business processes
- To replace financial audit procedures
Correct answer: To provide a foundation of reliability for application controls by governing the IT environment
ITGCs (covering change management, access controls, and operations) establish the control environment that application controls depend upon, making them foundational to SOX IT audit.
Question 2: A healthcare IT organization experiences a ransomware attack. Under HIPAA, what is the FIRST governance action the CTO should initiate?
- Pay the ransom to restore access
- Activate the incident response plan and conduct a breach risk assessment to determine notification obligations (Correct answer)
- Immediately notify all patients of a breach
- Shut down all IT systems to contain the attack
Correct answer: Activate the incident response plan and conduct a breach risk assessment to determine notification obligations
HIPAA requires a risk assessment to determine if PHI was compromised and whether the incident qualifies as a reportable breach before notification obligations are triggered.
Question 3: Which approach to IT risk assessment involves assigning numerical values to threat likelihood and impact to calculate risk scores?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Scenario-based risk assessment
- Delphi method assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical probabilities and financial values to risks, enabling calculation of metrics like ALE and ROI on security controls.
Question 4: A CTO is implementing a governance structure for a multinational organization where IT decisions need local flexibility but global consistency. Which model BEST supports this?
- Centralized IT governance
- Decentralized IT governance
- Federated IT governance (Correct answer)
- Shadow IT governance
Correct answer: Federated IT governance
Federated IT governance balances central standards and policies with local autonomy, allowing regional units to adapt within globally set boundaries.
Question 5: In the context of IT control frameworks, what is the difference between preventive and detective controls?
- Preventive controls respond to incidents; detective controls prevent them
- Preventive controls stop unwanted events from occurring; detective controls identify events that have already occurred (Correct answer)
- Detective controls are more effective than preventive controls
- Preventive controls apply only to physical security; detective controls apply to logical security
Correct answer: Preventive controls stop unwanted events from occurring; detective controls identify events that have already occurred
Preventive controls (e.g., access restrictions) block incidents before they occur, while detective controls (e.g., audit logs, IDS) identify incidents after they have taken place.
Question 6: Which COSO component addresses how an organization identifies and responds to business risks, including IT risks, in achieving its objectives?
- Control activities
- Risk assessment (Correct answer)
- Information and communication
- Monitoring activities
Correct answer: Risk assessment
The COSO Risk Assessment component requires organizations to identify risks to achieving objectives and analyze them to determine how they should be managed.
Question 7: A CTO is asked to demonstrate IT governance value to the board. Which metric BEST illustrates the effectiveness of IT risk management over time?
- Number of IT projects completed on time
- Trend in residual risk scores across the IT risk register quarter-over-quarter (Correct answer)
- Total IT budget spent on security tools
- Number of security certifications held by IT staff
Correct answer: Trend in residual risk scores across the IT risk register quarter-over-quarter
Tracking residual risk trends over time demonstrates whether risk management activities are actually reducing exposure, which directly shows governance effectiveness to the board.
What is the primary objective of IT general controls (ITGCs) in the context of SOX compliance?