IT governance frameworks and management practice concepts tested on the CISA exam.
36 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of IT governance?
- To align IT strategy with business objectives and ensure effective use of IT resources to support organizational goals.
- What does COBIT stand for?
- Control Objectives for Information and Related Technologies.
- Name the primary process domains in COBIT.
- Governance, Strategy, Planning, Build, Acquire, Implement, Deliver/Service/Support, Monitor/Evaluate.
- What does ITIL focus on?
- Service delivery and support; best practices for managing IT services to meet business needs.
- What is the goal of ISO/IEC 27001?
- To establish a framework for information security management and protect confidentiality, integrity, and availability of information.
- Define risk management.
- The process of identifying, analyzing, and responding to risks that could impact business objectives.
- What are the key steps in a risk assessment?
- Identify risks, analyze likelihood and impact, prioritize, and determine risk tolerance.
- What is risk mitigation?
- Actions taken to reduce the probability or impact of a risk to an acceptable level.
- Name four common risk mitigation strategies.
- Avoid (eliminate the risk), reduce (lower impact or likelihood), transfer (shift to third party), accept (tolerate the risk).
- What is a preventive control?
- A control designed to stop an unwanted event or error from occurring in the first place.
- What is a detective control?
- A control designed to identify and report unwanted events or errors after they have occurred.
- What is a corrective control?
- A control designed to remediate or fix errors and issues that have been detected.
- Define segregation of duties.
- The division of a critical transaction or process among multiple people to prevent fraud and errors.
- What is the principle of least privilege?
- Users and systems should have only the minimum access rights necessary to perform their assigned tasks.
- What is need to know?
- A principle stating that individuals should only have access to information required to perform their specific job function.