FlashKeepers

CISM/CISA · CISA

CISA Governance and Management of IT

IT governance frameworks and management practice concepts tested on the CISA exam.

36 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Look inside first Get FlashKeepers for iPhone
What is the primary purpose of IT governance?
To align IT strategy with business objectives and ensure effective use of IT resources to support organizational goals.
What does COBIT stand for?
Control Objectives for Information and Related Technologies.
Name the primary process domains in COBIT.
Governance, Strategy, Planning, Build, Acquire, Implement, Deliver/Service/Support, Monitor/Evaluate.
What does ITIL focus on?
Service delivery and support; best practices for managing IT services to meet business needs.
What is the goal of ISO/IEC 27001?
To establish a framework for information security management and protect confidentiality, integrity, and availability of information.
Define risk management.
The process of identifying, analyzing, and responding to risks that could impact business objectives.
What are the key steps in a risk assessment?
Identify risks, analyze likelihood and impact, prioritize, and determine risk tolerance.
What is risk mitigation?
Actions taken to reduce the probability or impact of a risk to an acceptable level.
Name four common risk mitigation strategies.
Avoid (eliminate the risk), reduce (lower impact or likelihood), transfer (shift to third party), accept (tolerate the risk).
What is a preventive control?
A control designed to stop an unwanted event or error from occurring in the first place.
What is a detective control?
A control designed to identify and report unwanted events or errors after they have occurred.
What is a corrective control?
A control designed to remediate or fix errors and issues that have been detected.
Define segregation of duties.
The division of a critical transaction or process among multiple people to prevent fraud and errors.
What is the principle of least privilege?
Users and systems should have only the minimum access rights necessary to perform their assigned tasks.
What is need to know?
A principle stating that individuals should only have access to information required to perform their specific job function.

21 more cards in the app