GRC Governance Frameworks & Best Practices 2 — Questions and Answers
Question 1: Which COBIT 2019 design factor primarily considers the organization's strategy for using IT — ranging from IT avoider to first mover?
- IT strategy (Correct answer)
- Enterprise size
- Risk appetite
- Compliance requirements
Correct answer: IT strategy
COBIT 2019's 'IT strategy' design factor categorizes organizations on a spectrum from IT avoider (minimal IT use) to first mover (IT as competitive differentiator).
Question 2: In ISO/IEC 38500, which principle requires that IT performance be monitored against plans and policies?
- Strategy
- Performance (Correct answer)
- Conformance
- Human behavior
Correct answer: Performance
ISO/IEC 38500's 'Performance' principle requires directors to ensure IT supports the organization and monitor delivery against plans.
Question 3: The ITIL 4 guiding principle 'Focus on Value' most directly aligns with which governance objective?
- Ensuring risk optimization
- Linking all activities to stakeholder benefit (Correct answer)
- Enforcing regulatory compliance
- Standardizing IT processes
Correct answer: Linking all activities to stakeholder benefit
The 'Focus on Value' principle requires that every action and decision be traced back to value creation for stakeholders.
Question 4: Under the NIST Cybersecurity Framework 2.0, which new function was added compared to the original five?
- Respond
- Govern (Correct answer)
- Protect
- Recover
Correct answer: Govern
NIST CSF 2.0 added 'Govern' as a sixth function to emphasize cybersecurity governance at the organizational level.
Question 5: A board committee responsible for overseeing financial reporting accuracy and internal audit functions is called a(n):
- Risk committee
- Audit committee (Correct answer)
- Compliance committee
- IT steering committee
Correct answer: Audit committee
The audit committee oversees financial reporting integrity, internal controls, and the internal/external audit relationship.
Question 6: Which Three Lines Model component is responsible for providing independent assurance to the board?
- First line (operations)
- Second line (risk/compliance functions)
- Third line (internal audit) (Correct answer)
- External auditors
Correct answer: Third line (internal audit)
The third line (internal audit) provides independent, objective assurance and advice to the board on governance, risk, and control.
Question 7: In the context of corporate governance, 'stewardship theory' suggests that managers should be treated as:
- Self-interested agents needing monitoring
- Trustworthy stewards aligned with owner interests (Correct answer)
- External stakeholders with competing goals
- Regulators enforcing compliance
Correct answer: Trustworthy stewards aligned with owner interests
Stewardship theory holds that managers are inherently motivated to act in the best interests of the organization and its owners.
Which COBIT 2019 design factor primarily considers the organization's strategy for using IT — ranging from IT avoider to first mover?