SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CGEIT: Certified In The Governance Of Enterprise It
Start Test
Study First
Subjects
:
certifications
,
cgeit
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. ISO 27000
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
implementation - information security - assurance - Risk
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
informations inherited
2. application vs. controls. IT general controls
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
To take the residual risk a company is willing risk
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
pain points - improvment opportunities
3. Structure of the 32 COBIT processes mgmt.
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
Saving the cost of damage (eg ALE) minus cost of mitigation
Signature - statement - audit trail
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
4. Value management
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
5. KPI
Observations / findings - risks - recommendation / report
quantitative risk analysis approach - damage cost per year * enter frequency
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
6. IT governance life cycle
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
7. IT Governance and COBIT
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
8. Operational risk is...
9. IT Steering Committee
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
Financial - Operational - Reputation
executive tasks: prioritization - resource alloc - project tracking
10. Procedure for Governance Compliance Review
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
implementation - information security - assurance - Risk
plan-prepare-execute-track-report
11. COBIT enabler guides
pain points - improvment opportunities
only known processes enabling
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
Financial - Operational - Reputation
12. Valit content framework
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
13. IT Strategy Committee
VR level - integration and business strategy it - Chaired by a business executive / board member
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
Saving the cost of damage (eg ALE) minus cost of mitigation
14. Use of balanced scorecards
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
executive tasks: prioritization - resource alloc - project tracking
15. Control risk
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
risk that the controls are inadequate
processes are assets that create value for the customer
To take the residual risk a company is willing risk
16. Risk appetite
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
To take the residual risk a company is willing risk
implementation - information security - assurance - Risk
17. Balanced scorecard - Learning and Growt
18. Three different control categories?
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
VR level - integration and business strategy it - Chaired by a business executive / board member
19. Establishing accountability
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
20. Balanced scorecard (BSC)
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Saving the cost of damage (eg ALE) minus cost of mitigation
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
21. Entity level controls
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
unavoidable risk
COBIT provides the means of risk management - Riskit provides the ends.
22. benefit management (Profit organization realization)
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
23. Risk analysis techniques
Tests - Extensive testing
Encourages the identification of a few relevant high-level financial measures. In Particular - designers were encouraged to choose measures that helped inform the answer to the question 'How do we look to shareholders?'
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
24. The report stage of a review
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
Tests - Extensive testing
To take the residual risk a company is willing risk
Observations / findings - risks - recommendation / report
25. Comprehensive audits
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Tests - Extensive testing
26. Return on security investment ROSI
Saving the cost of damage (eg ALE) minus cost of mitigation
Encourages the identification of measures that answer the question 'How do customers see us?'
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
COBIT provides the means of risk management - Riskit provides the ends.
27. Escrow contracts
plan-prepare-execute-track-report
Trust Service Contracts
risk that the controls are inadequate
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
28. Audit risk consists of...
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
QA
plan-prepare-execute-track-report
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
29. Hierarchy of policies
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
policy - principles - statements
30. Function point analysis
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
Encourages the identification of measures that answer the question 'How do customers see us?'
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
31. COBIT cascading goals
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
processes are assets that create value for the customer
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
32. Balanced scorecard - Financial
33. Good starting points forIT Gov
QA
pain points - improvment opportunities
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
34. ISO 9000
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
operational risk (HR - Law - Nature - IT) - reputational risk
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
35. CSFs
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
inadequate or failed internal processes
critical success factors
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
36. Balanced scorecard - Internal Business Processes
37. Balanced scorecard - Customer
38. The 3 themes of the ICS economic / financial risk
operational risk (HR - Law - Nature - IT) - reputational risk
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
39. risk governance
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
Encourages the identification of measures that answer the question 'How do customers see us?'
risk and risk response evaluation
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
40. Types of assertions
Signature - statement - audit trail
implementation - information security - assurance - Risk
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
executive tasks: prioritization - resource alloc - project tracking
41. COBIT framework
Encourages the identification of a few relevant high-level financial measures. In Particular - designers were encouraged to choose measures that helped inform the answer to the question 'How do we look to shareholders?'
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
Observations / findings - risks - recommendation / report
42. Control self assessment Self-assessment (kd) or a Control Self Assessment (CSA supervised self-assessment
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
operational risk (HR - Law - Nature - IT) - reputational risk
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
43. Inherent risk
Encourages the identification of a few relevant high-level financial measures. In Particular - designers were encouraged to choose measures that helped inform the answer to the question 'How do we look to shareholders?'
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
unavoidable risk
Observations / findings - risks - recommendation / report
44. To address three types of risk in the ICS
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
Trust Service Contracts
Financial - Operational - Reputation
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
45. Raci carts (RACI)
VR level - integration and business strategy it - Chaired by a business executive / board member
Scenarios set in a risk environment
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
46. ISO 9000
risk and risk response evaluation
pain points - improvment opportunities
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
QA
47. Key principle of BPM
processes are assets that create value for the customer
informations inherited
executive tasks: prioritization - resource alloc - project tracking
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
48. The implementation phase of a (Gov. Compliance) Review
enterprise risk management
COBIT provides the means of risk management - Riskit provides the ends.
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
VR level - integration and business strategy it - Chaired by a business executive / board member
49. ISO 31000
VR level - integration and business strategy it - Chaired by a business executive / board member
critical success factors
enterprise risk management
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
50. Derivation Cobit practices / control objectives
VR level - integration and business strategy it - Chaired by a business executive / board member
The identification of measures that answer the question 'What must we excel at?'
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication