What is governance?
Set of policies, rules, and processes that organizations implement to ensure their activities align with their business goals
Success involves providing accountability, defining jobs and responsibilities, and evaluating employees based on results.
What are the two focuses of IT management and IT governance?
IT management: present + internal focus; IT governance: future + external focus
What is the ISO/IEC 38500:2015?
Governance is part of Corporate Governance
Define risk management.
Identifying, evaluating, and managing various risks, including legal, financial, and security-related risks.
What does a risk management system consist of?
Personnel + technologies + processes => enforce risk mitigation
What is the success criterion of risk management?
Keeping stakeholders informed, considering legal, contractual, and business requirements.
What framework provides guidelines for managing risks?
ISO 31000
True or False: Risk management should be part of the decision-making process.
True
What does digital trust refer to?
Confidence in the integrity of the relationships, interactions, and transactions among providers and consumers within a digital ecosystem.
What are the key factors of digital trust?
What is the GRC capability model?
Integrates risk, governance, audit, ethics/culture, IT, and compliance.
List the four components of the GRC Capability Model.
Define principled performance.
Reliably achieve objectives, address uncertainty, and act with integrity.
What is the purpose of assurance in governance?
Provides reliability and confidence to management, the governing authority, and other stakeholders.
What are the dimensions to assess ‘total performance’?
What is the goal of Open Compliance and Ethics Groups (OCEG)?
To help solve problems using an interdisciplinary approach.
What are the six principles for a governance system?
What is the COBIT framework?
Provides guiding principles for directors on the effective, efficient, and acceptable use of IT within their organizations.
What are the two perspectives in governance and management?
What is the overall goal of the COBIT framework?
Enterprise goals have been consolidated, reduced, updated, and clarified.
Fill in the blank: The purpose of process EDM01 is to __________.
Evaluate, direct, and monitor the governance system to ensure effectiveness, transparency, and alignment with business strategy.
What are the key activities in the process EDM01?
What are the risks associated with AI?