Governance and Management of IT Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Governance and Management of IT flashcards as text
Which COBIT 2019 governance objective focuses on ensuring that enterprise risk appetite and tolerance are understood and communicated?
Answer: EDM03 - Ensured Risk Optimization
EDM03 ensures that risk appetite and tolerance are understood, and that residual IT risk is within enterprise limits.
An IS auditor is reviewing IT governance at a company where the IT strategy committee meets quarterly but business unit heads rarely attend. What is the PRIMARY risk?
Answer: IT decisions may not align with business objectives
Without business unit participation, IT decisions risk misalignment with actual business needs and strategy.
Which metric BEST measures the effectiveness of IT governance in delivering business value?
Answer: Percentage of IT investments achieving expected business outcomes
Governance effectiveness is best measured by whether IT investments actually realize the business outcomes they were intended to deliver.
Under ITIL 4, the concept that all IT services should be co-created with customers and stakeholders is called:
Answer: Value co-creation
ITIL 4's service value system is built on the principle of value co-creation between the service provider and its stakeholders.
A company's board has delegated IT governance oversight to a subcommittee. An IS auditor should verify PRIMARILY that the subcommittee:
Answer: Reports its findings and decisions to the full board
Delegating oversight does not transfer accountability; the subcommittee must report to the full board so ultimate accountability remains intact.
Which element of IT governance directly addresses the question: 'Who is entitled to make which IT decisions?'
Answer: IT governance decision rights
Decision rights define who has authority to make specific IT decisions, which is a foundational element of IT governance structure.
When implementing COBIT, an organization starts by defining stakeholder needs and translating them into enterprise goals. This step is part of the:
Answer: Governance and management objectives cascade
COBIT's goals cascade translates stakeholder needs into enterprise goals, then IT-related goals, then governance and management objectives.