SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CGEIT: Certified In The Governance Of Enterprise It
Start Test
Study First
Subjects
:
certifications
,
cgeit
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Balanced scorecard (BSC)
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
quantitative risk analysis approach - damage cost per year * enter frequency
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
2. Riskit vs. COBIT
COBIT provides the means of risk management - Riskit provides the ends.
VR level - integration and business strategy it - Chaired by a business executive / board member
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
3. A widely used definition of operational risk is the one contained in the Basel II [1] regulations. This definition states that operational risk is the risk of loss resulting from ____________ - people and systems - or from external events.
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
inadequate or failed internal processes
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
4. Procedure for Governance Compliance Review
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
plan-prepare-execute-track-report
Benefits realization - risk optimization - resource optimization
5. Detection risk
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
6. IT Steering Committee
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
plan-prepare-execute-track-report
executive tasks: prioritization - resource alloc - project tracking
Encourages the identification of measures that answer the question 'How do customers see us?'
7. The report stage of a review
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
Observations / findings - risks - recommendation / report
Signature - statement - audit trail
8. IT governance life cycle
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
9. Derivation Cobit practices / control objectives
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
QA
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
The identification of measures that answer the question 'What must we excel at?'
10. Risk analysis techniques
plan-prepare-execute-track-report
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
Saving the cost of damage (eg ALE) minus cost of mitigation
QA
11. Control risk
Encourages the identification of measures that answer the question 'How do customers see us?'
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
To take the residual risk a company is willing risk
risk that the controls are inadequate
12. risk governance
plan-prepare-execute-track-report
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
risk and risk response evaluation
13. Use of balanced scorecards
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
implementation - information security - assurance - Risk
14. Anual loss expectancy ALE
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
Saving the cost of damage (eg ALE) minus cost of mitigation
quantitative risk analysis approach - damage cost per year * enter frequency
15. Inherent risk
Encourages the identification of measures that answer the question 'How do customers see us?'
risk that the controls are inadequate
unavoidable risk
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
16. Function point analysis
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
Financial - Operational - Reputation
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
risk and risk response evaluation
17. Balanced scorecard - Customer
18. COBIT framework
only known processes enabling
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
Tests - Extensive testing
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
19. COBIT enabler guides
risk and risk response evaluation
only known processes enabling
Benefits realization - risk optimization - resource optimization
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
20. Escrow contracts
implementation - information security - assurance - Risk
Trust Service Contracts
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
only known processes enabling
21. Risk appetite
To take the residual risk a company is willing risk
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
operational risk (HR - Law - Nature - IT) - reputational risk
22. Risk treatment process
To take the residual risk a company is willing risk
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
23. Value management
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
Financial - Operational - Reputation
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
24. Return on security investment ROSI
plan-prepare-execute-track-report
policy - principles - statements
quantitative risk analysis approach - damage cost per year * enter frequency
Saving the cost of damage (eg ALE) minus cost of mitigation
25. Best practices in dealing with policies Policies (not principles)
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
26. Good starting points forIT Gov
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
pain points - improvment opportunities
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
27. CSFs
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
informations inherited
critical success factors
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
28. Raci carts (RACI)
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
implementation - information security - assurance - Risk
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
29. application vs. controls. IT general controls
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
30. ISO 27000
executive tasks: prioritization - resource alloc - project tracking
informations inherited
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
inadequate or failed internal processes
31. benefit management (Profit organization realization)
critical success factors
quantitative risk analysis approach - damage cost per year * enter frequency
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
32. To address three types of risk in the ICS
enterprise risk management
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
QA
Financial - Operational - Reputation
33. 5 focus area of IT Governance
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
QA
Saving the cost of damage (eg ALE) minus cost of mitigation
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
34. ISO 31000
executive tasks: prioritization - resource alloc - project tracking
enterprise risk management
risk and risk response evaluation
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
35. Entity level controls
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
Benefits realization - risk optimization - resource optimization
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
36. Control self assessment Self-assessment (kd) or a Control Self Assessment (CSA supervised self-assessment
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
implementation - information security - assurance - Risk
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
37. Hierarchy of policies
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
policy - principles - statements
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
38. Risk analysis methodology
inadequate or failed internal processes
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
Scenarios set in a risk environment
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
39. The 3 themes of the ICS economic / financial risk
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
operational risk (HR - Law - Nature - IT) - reputational risk
unavoidable risk
40. Types of assertions
pain points - improvment opportunities
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
inadequate or failed internal processes
Signature - statement - audit trail
41. KPI
Scenarios set in a risk environment
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
Financial - Operational - Reputation
VR level - integration and business strategy it - Chaired by a business executive / board member
42. Valit content framework
risk and risk response evaluation
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
processes are assets that create value for the customer
Financial - Operational - Reputation
43. The implementation phase of a (Gov. Compliance) Review
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
44. COBIT professional guides
only known processes enabling
implementation - information security - assurance - Risk
pain points - improvment opportunities
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
45. Operational risk is...
46. Balanced scorecard - Internal Business Processes
47. ISO 9000
Encourages the identification of measures that answer the question 'How do customers see us?'
VR level - integration and business strategy it - Chaired by a business executive / board member
risk and risk response evaluation
QA
48. Methods for continuous process improvement
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
49. ISO 9000
policy - principles - statements
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
50. IT Governance and COBIT
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
VR level - integration and business strategy it - Chaired by a business executive / board member
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
critical success factors