CORRECT Answers
ISACA (Information Systems Audit and Control Association) - CORRECT ANSWERS -
Through its comprehensive guidance and services, ISACA defines the roles of information
systems governance, security, audit and assurance professionals worldwide.
-Responsible for the COBIT framework and the CISA, CISM, CGEIT and CRISC certifications.
COBIT (Control Objectives for Information and related Technology) - CORRECT ANSWERS -
A framework for the governance and management of information and technology, aimed at the
whole enterprise.
-From its foundation in the IT audit community, COBIT has developed into a broader and more
comprehensive I&T governance and management framework and continues to establish itself as
a generally accepted framework for I&T governance.
-Creating an enterprise governance of information and technology that is custom tailored to the
business' objectives, focus areas, and metrics
What COBIT 2019 is - CORRECT ANSWERS -A framework for the governance and
management of enterprise information and technology
-COBIT defines the components to build and sustain a governance system
-COBIT defines the design factors that should be considered by the enterprise to build a best fit
governance system
-COBIT is flexible and allows guidance on new topics to be added
,- COBIT defines all the components that describe which decisions should be taken, and how and
by whom they should be taken
What COBIT 2019 is not - CORRECT ANSWERS -A full description of the whole IT
environment of an enterprise
-A framework to organize business processes
-An (IT) technical framework to manage all technology
-COBIT does not make or prescribe any IT-related decisions
-It will not decide what the best IT strategy is, what the best architecture is, or how much IT can
or should cost.
COBIT Internal Stakeholders - CORRECT ANSWERS 1) Boards- Provides insights on how to
get value from the use of I&T and explains relevant board responsibilities
2)Executive Management- Provides guidance on how to organize and monitor performance of
I&T across the enterprise.
3) Business Managers- Helps to understand how to obtain the I&T solutions enterprises require
and how the best way to exploit new technology for new strategic opportunities
4) IT Managers- Provides guidance on how best to build and structure the IT department,
manage performance of IT, run an efficient and effective IT operation, control IT costs, align IT
strategy to business priorities
, 5) Assurance Providers- Help manage dependency on external service providers, get assurance
over IT, and ensure the existence of an effective efficient system of intern controls
6) Risk Management-Helps to ensure the identification and management of all IT-related risk
COBIT External Stakeholders - CORRECT ANSWERS 1) Regulators- Helps ensure the
enterprise is compliant with applicable rules and regulations and has the right governance
system in place to manage and sustain compliance
2) Business Partners- Helps ensure that a business partner's operations are secure, reliable, and
compliant with applicable rules and regulations
3) IT Vendors- Helps to ensure that the IT vendor's operations are secure, reliable and complaint
with applicable rules and regulations
Enterprise Governance of Information and Technology (EGIT) - CORRECT ANSWERS -A
crucial part of corporate governance that It is exercised by the board that oversees the
definition and implementation of processes, structures and relational mechanisms in the
organization
-This enables both business and IT people to execute their responsibilities in support of
business/IT alignment and the creation of business value from I&T-enabled business
investments.
Three Outcomes- Benefits realization,Risk optimization, and Resource optimization
Benefits Realization - CORRECT ANSWERS -Consists of creating value for the enterprise
through I&T, maintaining and increasing value derived from existing I&T investments, and
eliminating IT initiatives and assets that are not creating sufficient value.