F.2. Data Governance and Management Flashcards

Explore principles of data governance, IT control frameworks, and records/data lifecycle management. (14 cards)

1
Q

What is data governance?

A

It encompasses the practices, procedures, processes, methods, technologies, and activities that deal with the overall management of the data assets and data flows within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the objective of data governance?

A

To enable reliable and consistent data so that management can properly assess the organization’s performance, make decisions, and manage the associated risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Data management is part of data governance.

What does data management include?

A
  • Creating data
  • Collecting data
  • Storing data
  • Maintaining data
  • Securing data
  • Archiving data
  • Destroying data
  • Using data to add value to a business
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data governance and data management involve management of:

A
  • Data availability
  • Data usability
  • Data integrity
  • Data security
  • Data privacy
  • Data integration
  • System availability
  • System maintenance
  • Compliance with regulations
  • Determination of roles and responsibilities of managers and employees
  • Data flows, both internal and external
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does management of data integrity in the context of data governance involve?

A

It involves managing the completeness, consistency, reliability, and accuracy of data, including specifications for data entry, fields, timing, entry by whom, sources, and control structures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does management of data privacy in the context of data governance involve?

A

It involves determining who is authorized to access data and which items of data each authorized person can access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of IT governance and control frameworks?

A

To provide models or sets of standardized guidelines for managing IT resources and processes, identifying roles and responsibilities, assessing risks and controls, and achieving regulatory compliance. They break down overall objectives and activities into components in order to provide specific guidance for each component.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the five interrelated components of COSO’s Internal Control – Integrated Framework?

A
  • Control environment
  • Risk assessment
  • Control activities
  • Information and communication
  • Monitoring activities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the data life cycle?

A

It encompasses the period from creation of data and its initial storage through the time the data becomes out of date or no longer needed and is purged.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the stages of the data life cycle?

A
  • Data capture
  • Data qualifying
  • Data maintenance
  • Data transformation, synthesis, and simplification
  • Data usage
  • Data analytics
  • Data publication or reporting
  • Data archival
  • Data purging
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the main governance challenge in the data capture stage?

A

Governance involves identifying the methods of capture and defining the data to be captured.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is data purging?

A

The removal of every copy of a data item from all locations within the organization, typically done only for data that has been previously archived.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What should a records management policy establish?

A

How records are to be maintained, identified, retrieved, preserved, and when and how they are to be destroyed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the benefits of a documented and well-executed records management policy?

A
  • Easier and more efficient document location
  • Demonstrates legitimate purpose for document destruction in the event of an examination
  • Increases compliance with regulations
  • Records are adequately protected and accessibility maintained
  • Timely destruction of records no longer needed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly