SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CGEIT: Certified In The Governance Of Enterprise It
Start Test
Study First
Subjects
:
certifications
,
cgeit
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. application vs. controls. IT general controls
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
Used in business administration figures - references which can be the progress or the level of compliance with regard to important objectives or critical success factors measured within an organization and / or calculated - Important KPIs in the serv
2. CSFs
critical success factors
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
Financial - Operational - Reputation
3. IT Strategy Committee
VR level - integration and business strategy it - Chaired by a business executive / board member
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
unavoidable risk
COBIT provides the means of risk management - Riskit provides the ends.
4. Derivation Cobit practices / control objectives
QA
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
5. Good starting points forIT Gov
Benefits realization - risk optimization - resource optimization
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
unavoidable risk
pain points - improvment opportunities
6. Balanced scorecard (BSC)
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
risk and risk response evaluation
Trust Service Contracts
7. Comprehensive audits
processes are assets that create value for the customer
Tests - Extensive testing
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
QA
8. Types of assertions
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
only known processes enabling
Signature - statement - audit trail
The identification of measures that answer the question 'What must we excel at?'
9. Key principle of BPM
Scenarios set in a risk environment
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
processes are assets that create value for the customer
10. Escrow contracts
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
unavoidable risk
Trust Service Contracts
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
11. Inherent risk
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
operational risk (HR - Law - Nature - IT) - reputational risk
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
unavoidable risk
12. A widely used definition of operational risk is the one contained in the Basel II [1] regulations. This definition states that operational risk is the risk of loss resulting from ____________ - people and systems - or from external events.
inadequate or failed internal processes
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
Scenarios set in a risk environment
implementation - information security - assurance - Risk
13. 3 Governance Objectives
critical success factors
Benefits realization - risk optimization - resource optimization
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
only known processes enabling
14. Methods for continuous process improvement
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
inadequate or failed internal processes
15. Raci carts (RACI)
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
Signature - statement - audit trail
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
16. Function point analysis
Review process for software system - The functional size is determined - where you split the functional requirements of an application into small - meaningful to the user activities that elementary processes. Same elementary processes are evaluated o
executive tasks: prioritization - resource alloc - project tracking
The identification of measures that answer the question 'What must we excel at?'
Saving the cost of damage (eg ALE) minus cost of mitigation
17. ISO 9000
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
QA
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
18. Audit risk consists of...
inherent risk - control risk: insufficient control system - detection risk: insufficient testing
processes are assets that create value for the customer
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
19. Detection risk
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
processes are assets that create value for the customer
risk that something will NOT be revealed - ill-prepared - not tested properly - misinterpreted findings weighted wrong
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
20. benefit management (Profit organization realization)
risk and risk response evaluation
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
Benefits realization management (BRM) (also benefits management or benefits realization) is the explicit planning - delivery and management of whole life benefits from an investment. An investment is only successful if Intended benefits are Realised
21. The 3 themes of the ICS economic / financial risk
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
operational risk (HR - Law - Nature - IT) - reputational risk
22. Refine the innovation process management
quantitative risk analysis approach - damage cost per year * enter frequency
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
create an environment conductive to innovate - Maintain / understand the enterprise environment - monitor / scan the technology environment - assess the potential of emerging tech.- recommend appropriate further initiatives - monitor the implication
executive tasks: prioritization - resource alloc - project tracking
23. COBIT framework
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
informations inherited
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
24. Hierarchy of policies
Tests - Extensive testing
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
policy - principles - statements
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
25. Structure of the 32 COBIT processes mgmt.
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
general: magmt change - security - operations control Application: do everything to do with app. pgm. has zb source management - authentication validation
26. Use of balanced scorecards
performance monitoring - to demostrate the effectivness if IT and communicate about it - Performance - risk and capabilities
policy - principles - statements
(hierarchy) 5 domains (EDM - po ad ds me) - processes 37 - 211 practices
critical success factors
27. Control risk
operational risk (HR - Law - Nature - IT) - reputational risk
risk that the controls are inadequate
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
28. The implementation phase of a (Gov. Compliance) Review
iter (interview - test analysis - detecting / hold / summarize - Discuss with auditee
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
risk and risk response evaluation
Value analysis - was initially applied WA - to identify and eliminate unnecessary costs. WA is equally successful in improving the performance and function of resources other than the costs. In the course of time - extended the WA applications from p
29. ISO 31000
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
enterprise risk management
30. COBIT professional guides
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
implementation - information security - assurance - Risk
pain points - improvment opportunities
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
31. Procedure for Governance Compliance Review
A quality management standard describes the requirements that must be satisfied by the management system of a company in order to meet a certain standard in the implementation of quality management. It can serve both informative for implementation wi
plan-prepare-execute-track-report
The identification of measures that answer the question 'What must we excel at?'
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
32. Establishing accountability
QA
who should do what? - establishing accountability - VR / goals objectives - GL translate strategy into action (automation - cost - risk mgmt)
Benefits realization - risk optimization - resource optimization
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
33. Balanced scorecard - Learning and Growt
34. Riskit vs. COBIT
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
executive tasks: prioritization - resource alloc - project tracking
COBIT provides the means of risk management - Riskit provides the ends.
35. Risk appetite
To take the residual risk a company is willing risk
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
COBIT provides the means of risk management - Riskit provides the ends.
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
36. COBIT cascading goals
what are the drivers - where are we now - where do we want to be - what needs to be done (project plan) - how do we get there (execute) - did we get there - how to keep the momentum going
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
executive tasks: prioritization - resource alloc - project tracking
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
37. Anual loss expectancy ALE
Signature - statement - audit trail
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
quantitative risk analysis approach - damage cost per year * enter frequency
38. risk governance
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
risk and risk response evaluation
only known processes enabling
inadequate or failed internal processes
39. 5 focus area of IT Governance
VR level - integration and business strategy it - Chaired by a business executive / board member
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
An internally controlled collection and analysis of values. In a control self-assessment fill out one or more units surveyed questionnaires - which can then be evaluated independently. This survey can help the units (individuals - groups - department
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
40. Risk analysis methodology
Scenarios set in a risk environment
basic ingredients - basic principles - enterprise enablers - goals cascade - maturity model
Encourages the identification of measures that answer the question? 'How can we continue to improve and create value. '
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
41. IT Governance and COBIT
implementation - information security - assurance - Risk
a risk Arising from execution of a company's business functions. It is a very broad concept Which Focuses on the risks you Arising from the people - systems and processes through Which a company operates. It therefore includes other categories examin
5 gov processes (GL - PR) - std (users realize - risks opt opt ress) and framework - stakeholder transparency create - it gov: provide direction - evaluate performance - it Mgmnt: translate strategy into direction - and report performance mesure - 32
Encourages the identification of a few relevant high-level financial measures. In Particular - designers were encouraged to choose measures that helped inform the answer to the question 'How do we look to shareholders?'
42. Return on security investment ROSI
Saving the cost of damage (eg ALE) minus cost of mitigation
a technique for analysis and presentation of responsibilities - the name is derived from the initial letters of the words Responsible - Accountable - Consulted and Informed.
executive tasks: prioritization - resource alloc - project tracking
TQM - BPM /BPR (... reengineering) - BSC - Six Sigma - CMMI
43. Three different control categories?
plan: align - plan - Organize (PO) - build: build - Aquire - Implement (AI) - run: Deliver - servie - Support (DS) - Monitor: Monitor - Evaluate - control ME
extract optimal value from investments it - value management: processes - monitor - portfolio management: funds - human - investment management: business case - Manging program / projects
Preventive controls - detective controls - corrective controls (troubleshooting instructions)
policy - principles - statements
44. Balanced scorecard - Financial
45. The report stage of a review
executive tasks: prioritization - resource alloc - project tracking
informations inherited
Scenarios set in a risk environment
Observations / findings - risks - recommendation / report
46. COBIT enabler guides
Signature - statement - audit trail
only known processes enabling
risk that the controls are inadequate
Saving the cost of damage (eg ALE) minus cost of mitigation
47. Risk analysis techniques
A strategic performance management tool - a semi-standard structured report - supported by proven design methods and automation tools - that can be used by managers to keep track of the execution of activities by the staff within their control and .
Controls at the corporate level - are internal controls that help Ensure that management directives pertaining to the entire entity are Carried out. They are the second level of a top-down approach to understanding the risks of an organization. Gener
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
Scoping - formal enactment - clear Vogaben at exceptions - verification of compliance
48. Risk treatment process
The identification of measures that answer the question 'What must we excel at?'
Threat analysis - vulnerability assessment - gap analysis - (positive and negative / opportunities and threats)
stratecic establish alignment / framework - value delivery - risk management - resource mgmt - performance mgmt / stakeholer transparency
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
49. IT Steering Committee
Business goals with Gov. goals priorisiern - IT goals with U-prioritize targets (script 82) - prioritize process with IT goals
Trust Service Contracts
executive tasks: prioritization - resource alloc - project tracking
Define risk owners (possibly delegate to process owners) - avoid the formation - reduction - sharing - acceptance - cost benefit measures to keep the residual risk within defined tolerance limits
50. Operational risk is...