Governance and Management of IT Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Governance and Management of IT flashcards as text
Which ISO standard provides the code of practice for information security controls and is frequently referenced alongside ISO/IEC 27001?
Answer: ISO/IEC 27002
ISO/IEC 27002 is the code of practice providing guidance on implementing information security controls referenced in ISO/IEC 27001.
An organization uses a Responsibility Assignment Matrix (RACI) for IT governance decisions. The 'A' in RACI stands for:
Answer: Accountable
In a RACI matrix, 'A' stands for Accountable — the one person ultimately answerable for the correct completion of a task.
An IS auditor finds that IT management reports to the CFO rather than directly to the CEO or board. What governance concern should be raised?
Answer: IT strategy may be overly focused on financial efficiency over innovation
Reporting to the CFO can bias IT decisions toward cost reduction rather than strategic business enablement.
Under Val IT, the concept of 'investment portfolio management' means:
Answer: Selecting and balancing IT investments across risk and return profiles
Val IT's investment portfolio management ensures an organization selects, balances, and monitors IT investments to maximize business value.
Which COBIT 2019 design factor relates to the organization's current level of capability in its IT processes?
Answer: Current IT capability level
Current IT capability level is one of COBIT 2019's design factors that shapes how governance and management objectives are prioritized.
A CISA candidate reviewing an IT governance framework notices that corrective actions from audits are tracked but never followed up. Which governance process is MOST deficient?
Answer: Monitoring and evaluation
Monitoring and evaluation includes following up on audit findings to ensure corrective actions are implemented and effective.
ISO/IEC 38500 defines IT governance principles for corporate governance of IT. Which of the following is NOT one of its six principles?
Answer: Optimization
ISO/IEC 38500's six principles are Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour — Optimization is not among them.