Governance and Management of IT Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Governance and Management of IT flashcards as text
An organization has a high IT risk appetite but weak internal controls. An IS auditor should PRIMARILY recommend:
Answer: Aligning the control environment with the documented risk appetite
Risk appetite must be supported by a matching control environment; the audit finding is the misalignment between stated appetite and actual controls.
Which of the following BEST describes the difference between IT governance and IT management?
Answer: Governance sets direction and evaluates; management plans and executes
Governance involves evaluating, directing, and monitoring, while management focuses on planning, building, running, and monitoring operations.
A large enterprise uses a federated IT governance model. This means IT governance decisions are:
Answer: Distributed across business units with some central coordination
A federated model distributes IT governance authority to business units while maintaining central coordination for enterprise-wide standards.
When assessing IT governance maturity using COBIT's capability model, a score of Level 2 indicates:
Answer: The process is performed and managed with planned objectives
COBIT's Level 2 (Managed Process) means the process is performed and managed — planned, monitored, and adjusted — with defined outcomes.
Which concept in IT governance ensures that the board of directors remains informed about significant IT risks and opportunities?
Answer: Escalation procedures
Escalation procedures ensure significant IT risks, incidents, and opportunities are reported up to senior management and the board.
An IS auditor reviewing IT governance notes that IT investments are approved project-by-project with no portfolio view. The PRIMARY risk is:
Answer: IT investments may be duplicated or conflict with each other
Without a portfolio view, investments can overlap, conflict, or miss opportunities for synergy, resulting in suboptimal resource use.
Under the CISA framework, which of the following is the MOST important indicator that an organization's IT governance is effective?
Answer: IT goals consistently support and enable business objectives
Effective IT governance is ultimately demonstrated by IT outcomes that consistently support and advance business objectives, not just process compliance.