SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CGEIT: Certified In The Governance Of Enterprise It
Start Test
Study First
Subjects
:
certifications
,
cgeit
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Key principle of BPM
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
processes are assets that create value for the customer
Encourages the identification of measures that answer the question 'How do customers see us?'
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
2. Valit content framework
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
processes are assets that create value for the customer
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
3. Inherent risk
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
critical success factors
unavoidable risk
4. ISO 9000
Benefits realization - risk optimization - resource optimization
quantitative risk analysis approach - damage cost per year * enter frequency
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
5. Operational risk is...
6. Raci carts (RACI)
inadequate or failed internal processes
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
VR level - integration and business strategy it - Chaired by a business executive / board member
unavoidable risk
7. ISO 31000
enterprise risk management
Benefits realization - risk optimization - resource optimization
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
8. Riskit vs. COBIT
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
COBIT provides the means of risk management - Riskit provides the ends.
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
9. CSFs
only known processes enabling
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
critical success factors
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
10. Balanced scorecard - Customer
11. Establishing accountability
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
processes are assets that create value for the customer
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
12. Three different control categories?
Trust Service Contracts
Observations / findings - risks - recommendation / report
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
COBIT provides the means of risk management - Riskit provides the ends.
13. Value management
To take the residual risk a company is willing risk
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
inadequate or failed internal processes
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
14. Balanced scorecard - Financial
15. ISO 9000
Benefits realization - risk optimization - resource optimization
inadequate or failed internal processes
QA
plan-prepare-execute-track-report
16. Return on security investment ROSI
Saving the cost of damage (eg ALE) minus cost of mitigation
To take the residual risk a company is willing risk
implementation - information security - assurance - Risk
inadequate or failed internal processes
17. The 3 themes of the ICS economic / financial risk
The identification of measures that answer the question 'What must we excel at?'
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
operational risk (HR - Law - Nature - IT) - reputational risk
implementation - information security - assurance - Risk
18. Derivation Cobit practices / control objectives
policy - principles - statements
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
operational risk (HR - Law - Nature - IT) - reputational risk
19. IT Steering Committee
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
operational risk (HR - Law - Nature - IT) - reputational risk
executive tasks: prioritization - resource alloc - project tracking
Financial - Operational - Reputation
20. risk governance
risk and risk response evaluation
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
Saving the cost of damage (eg ALE) minus cost of mitigation
21. Procedure for Governance Compliance Review
plan-prepare-execute-track-report
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
critical success factors
22. Control risk
risk that the controls are inadequate
operational risk (HR - Law - Nature - IT) - reputational risk
Saving the cost of damage (eg ALE) minus cost of mitigation
Trust Service Contracts
23. benefit management (Profit organization realization)
policy - principles - statements
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
critical success factors
24. Detection risk
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
critical success factors
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
25. Comprehensive audits
Encourages the identification of a few relevant high-level financial measures. In Particular - designers were encouraged to choose measures that helped inform the answer to the question 'How do we look to shareholders?'
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
pain points - improvment opportunities
Tests - Extensive testing
26. Control self assessment Self-assessment (kd) or a Control Self Assessment (CSA supervised self-assessment
executive tasks: prioritization - resource alloc - project tracking
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
VR level - integration and business strategy it - Chaired by a business executive / board member
27. COBIT framework
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
28. Function point analysis
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
COBIT provides the means of risk management - Riskit provides the ends.
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
unavoidable risk
29. Use of balanced scorecards
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
VR level - integration and business strategy it - Chaired by a business executive / board member
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
30. Methods for continuous process improvement
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
31. Types of assertions
Observations / findings - risks - recommendation / report
risk and risk response evaluation
Signature - statement - audit trail
informations inherited
32. The implementation phase of a (Gov. Compliance) Review
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
VR level - integration and business strategy it - Chaired by a business executive / board member
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
33. Hierarchy of policies
implementation - information security - assurance - Risk
QA
policy - principles - statements
enterprise risk management
34. COBIT cascading goals
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
operational risk (HR - Law - Nature - IT) - reputational risk
informations inherited
35. Risk analysis methodology
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Scenarios set in a risk environment
informations inherited
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
36. 5 focus area of IT Governance
COBIT provides the means of risk management - Riskit provides the ends.
Saving the cost of damage (eg ALE) minus cost of mitigation
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
37. KPI
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
risk and risk response evaluation
only known processes enabling
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
38. Audit risk consists of...
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
Benefits realization - risk optimization - resource optimization
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
Encourages the identification of measures that answer the question 'How do customers see us?'
39. A widely used definition of operational risk is the one contained in the Basel II [1] regulations. This definition states that operational risk is the risk of loss resulting from ____________ - people and systems - or from external events.
inadequate or failed internal processes
operational risk (HR - Law - Nature - IT) - reputational risk
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
40. IT governance life cycle
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
operational risk (HR - Law - Nature - IT) - reputational risk
To take the residual risk a company is willing risk
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
41. Entity level controls
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
risk that the controls are inadequate
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
42. application vs. controls. IT general controls
Signature - statement - audit trail
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
43. Best practices in dealing with policies Policies (not principles)
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
44. COBIT professional guides
Signature - statement - audit trail
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
implementation - information security - assurance - Risk
45. Structure of the 32 COBIT processes mgmt.
risk and risk response evaluation
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
46. Balanced scorecard - Learning and Growt
47. IT Governance and COBIT
executive tasks: prioritization - resource alloc - project tracking
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
48. Balanced scorecard - Internal Business Processes
49. Good starting points forIT Gov
Trust Service Contracts
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
pain points - improvment opportunities
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
50. Risk treatment process
plan-prepare-execute-track-report
VR level - integration and business strategy it - Chaired by a business executive / board member
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
inherent risk - control risk: insufficient control system - detection risk: insufficient testing