โ† All ISACA Flashcard Decks

Governance and Management of IT Flashcards

7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Governance and Management of IT flashcards as text
  1. A multinational company wants to adopt a single IT governance framework across all subsidiaries with different regulatory requirements. The BEST approach is to:

    Answer: Select a flexible framework and tailor it to local regulatory contexts

    A flexible framework like COBIT can be tailored to accommodate local regulatory and operational differences while maintaining global consistency.

  2. Which of the following BEST describes the role of Key Risk Indicators (KRIs) in IT governance?

    Answer: They provide early warning signals of increasing risk exposure

    KRIs are forward-looking metrics that signal when risk levels are rising, enabling proactive governance responses before risks materialize.

  3. An IS auditor discovers that IT governance policies were last updated five years ago. What should the auditor PRIMARILY recommend?

    Answer: Establish a periodic policy review cycle aligned with business change

    Governance policies must be reviewed and updated periodically to remain aligned with evolving business strategy, technology, and regulatory requirements.

  4. Which practice BEST demonstrates that an organization's IT governance framework supports ethical use of technology?

    Answer: Establishing and enforcing an acceptable use policy with consequences

    An acceptable use policy with enforced consequences establishes clear ethical boundaries and holds users accountable for technology use.

  5. In the context of IT governance, 'benefit realization' refers to:

    Answer: Ensuring IT investments deliver their intended business value

    Benefit realization is the governance practice of ensuring that promised business benefits from IT investments are actually achieved post-implementation.

  6. An organization's IT steering committee approves a major ERP implementation but the business case shows negative NPV. An IS auditor should FIRST:

    Answer: Verify whether non-financial strategic benefits justify the investment

    A negative NPV does not automatically make an investment wrong; strategic, compliance, or competitive benefits may justify it if properly documented.

  7. Which of the following BEST illustrates the separation between governance and management of IT as defined in COBIT 2019?

    Answer: The board approves IT strategy; the CIO allocates IT resources to execute it

    COBIT 2019 defines governance as setting direction (board approves strategy) and management as executing within that direction (CIO allocates resources).