NEW
Font size
WorksheetsISA 3.0 Module 2
Total questions: 56
Worksheet time: 28mins
An IT steering committee should review information system primarily to assess:
Whether IT processes support business requirements
If proposed system functionality is adequate.
The stability of existing software.
The complexity of install technology.
The most likely effect of lack of senior management commitment to IT strategic planning is:
A lack of investment in technology.
A lack of methodology for system development.
The technology not aligning with the organisations objective.
And absence of control over technology contracts.
which of the following is a function of an IS steering committee?
Monitoring vendor-controlled change control and testing
Ensuring a separation of duties within the information processing environment
Approving and monitoring major projects, the status of IS plans and budgets
Between the highest departments and the end users
An IS Steering committee should:
Include a mix of members from different departments and staff levels.
Ensure that IS security policies and procedures have been executed properly.
Have formal terms of reference and maintain minutes of its meetings.
Be briefed about new trends and products at each meeting by the vendor.
involvement of senior management is most important in the development of:
Strategic plans
IS policies
IS procedures
Standards and guidelines
effective IT governance will ensure that the IT plan is consistent with the organisations:
Business plan
Audit plan
Security plan
Investment plan
establishing the level of acceptable risk is the responsibility of:
Quality assurance management
Senior business management
The chief information officer
The chief security officer
IT Governance is primary, the responsibility of the:
Chief executive officer
Board of directors
IT steering committee
Audit committee
From a control perspective, the key element in job description is that they:
Provide instructions on how to do the job and define authority.
Our current, documented and readily available to the employee.
Communicate management specific job performance expectations.
Established responsibility and accountability for the employees action.
which of the following would best provide assurance of the integrity of new staff?
Background screening
References
Bonding
Qualifications listed on the resume
It is becoming increasingly important for businesses to have a business contingency plan for their information systems. The criticality of the contingency plan will depend mainly upon – – – – – –.
The extent of investment in the organisation on IT
Likely level of impact due to failure or non-availability of IT.
The severity of the incident.
The extent of risk aversion of the organisation.
In terms of ascending order of severity/ intensity, how would the terms incident, crisis, emergency and disaster be ordered?
Incident, crisis, emergency, disaster
Incident, emergency, crisis, disaster
Emergency, incident, crisis, disaster
Emergency, crisis, incident, disaster
An organisation with intensive internet based business has its computer servers located in an area known for power outages at times for several hours a day. How is the organisation exposure to this situation expressed in business continuity management terms?
Risk
Vulnerability
contingency
Emergency
what is minimum business continuity objective?
Organisation objective to continue doing business despite disruptions
Organisation objective to continue minimum level of business even during financial crisis.
Organisation approach to reduce business operations to a minimum level during crisis
Minimum level of services/ products acceptable during a disruption.
what is maximum acceptable outage?
Maximum loss and organisation can afford to observe on account of a disruption
Maximum loss of output and organisation can afford an account of a description
Maximum number of person and organisation can afford to shift out during an emergency
Maximum period of time and organisation can tolerate disruption of a critical business function.
what is contingency plan?
An overall process of repairing for unexpected events
A list of contingency that can strike an organisations operations.
Plan of deployment of a contingent of officials involved with security
Maximum number of person and organisation can afford to shift out during an emergency
preventive measures and corrective measures are two of the three basic strategies that encompass a disaster recovery plan. What is the third basic strategy?
Restoration phase
Planning phase
Stabilisation phase
Multiplication phase
crisis phase, emergency response phase and recovery phase at three of the four phases that are typical of any disaster scenario. What is the fourth phase?
Restoration phase
Planning phase
Multiplication phase
Stabilisation Phase
What are the pre- requisites in developing a business continuity plan, BCP?
Planning for all phases and making it part of business process.
Testing of the BCP.
Waiting for one incident to learn from, before drawing up BCP.
Having the organisation strategic long-term plan ready.
What are the key phases prior to the development of a business continuity plan, BCP?
Maintenance of the BCP.
Business impact analysis and risk assessment.
Testing of the BCP
Training and awareness of employees
Which of the following is the best approach for monitoring the performance of IT resources?
Compare indicators against expected thresholds
Monitor lead indicators with industry best practices.
Define threshold lag indicators based on long-term plan.
Lead indicator on corresponding indicator.
Which of the following is configured as an example of lead indicator?
Number of gaps with respect to industry standard.
Comparative market position of organisation
Percentage of growth achieved over three years
Improvement in customer satisfaction survey
IT resource optimisation plan should primarily focus on
Reducing cost of resources
Ensuring availability
Conducting training program
Information security issues
Which of the following is the primary purpose of optimising the use of IT resources within an enterprise?
To increase likelihood of benefit realisation
To ensure readiness for future change
To reduce cost of IT investments
To address dependency on IT capabilities
An advantage of the use of hot sites as a backup alternative is:
The cost related with hot sites are low.
That hot sites can be used for a long amount of time
That hot sites do not require that equipment and system software be compatible with the primary installation being backed up.
That hot site can be made ready for operation within a short span of time.
An IS auditor reviewing an organisation’s information system disaster recovery plan should verify that it is
Tested every 1 month
Regularly reviewed and updated.
Approved by the chief executive officer
Approved by the top management
Which of the following methods of results analysis, during the testing of the business continuity plan (BCP), provides the best assurance that the plan is workable?
Quantitatively measuring the results of the test
Measurement of accuracy.
Elapsed time for completion of prescribe tasks.
Evaluation of the observed test results
The primary objective of corporate governance is:
Reduce IT cost in line with enterprise objectives and performance.
Optimise implementation of IT controls in line with business needs
Implement security policies and procedures using best practices
Increase shareholder value by enhancing economic performance
How many objectives are there in COBIT - 2019?
5
40
35
114
ISO 27001 consists of how many controls?
10
114
35
40
_____ is an international standard for corporate government for information technology?
ISO 27000
ISO 27001
ISO 38500
ISO 31000
The level to which an enterprise can accept financial loss from a new initiative is:
Risk tolerance
Risk management
Risk appetite
Risk acceptance
which of the following is the most important characteristic of policies?
Must be limited in number
Requires framework to implement
Reviewed periodically
Non-intrusive and logical
Prioritisation of IT initiatives within organisation is primarily based on:
Results of risk assessments
Expected benefit realisation
Recommendations of CIO
Rate of obsolescence of IT
Which of the following is best control for building requisite skills and competencies within an organisation?
Hiring only highly qualified people
Outsourcing the critical operations
Conducting skill enhancement training
Defining skill requirements in job description
What is the most important in developing a performance management system?
Deciding on incentive schemes
Identifying enterprise goals and their linkage to operating environment
Developing clear organisation structure
Benchmarking with industry
A good performance measurement system, assesses performance against goals through key goal indicators. Simultaneously, it monitors performance of process through – – – –.
Work flow indicators.
Moving average indicators.
Key process indicators.
Industry benchmarks.
The approach of using lead indicators for performance measurement is called – – –
Reactive approach
Retroactive approach
Proactive approach
Retrospective approach
The approach of using lag indicators for performance measurement is called – – –
Proactive approach
Reactive approach
Retroactive approach
Retrospective approach
where is the capability maturity framework of performance management system generally used?
Hardware development company
Research and development institution
Software development company
Educational institutions
Mr. Johnson has taken charge as head of an educational institution, which has not had a good track record. He feels that he has his task cut out for him. He needs to focus more on the lead parameters rather than the lag indicators so that he can create sustainable results. Which of the following would be an example of lead indicators?
Number of passes by students in the matriculation examination.
Number of all India rank holders from school in the matriculation examination
Number of failures in the matriculation examination
Number hours of refresher course attended by the teachers
In governance, value creation happens through benefit, realisation, risk optimisation and resource optimisation decisions taking into account – –
All stakeholders needs
All shareholders needs
Organisational goals
Organisational vision, mission
The balance scorecard is an invaluable management tool that helps translate strategy into action and also for – – –
Balancing shareholder needs with employee needs
Bringing non-financial indicators into better focus.
Balancing needs of multiple functions within an organisation
Balancing lead and log indicators
The balance scorecard is designed to ensure that performance metrics and strategic themes are balanced with financial and non-financial, operational and financial, lead and lag indicators. Financial, Customer and internal business process, prospective are three of the four prospective of BSE. The fourth prospective is – –
Learning and growth
Shareholders versus employees
Short-term versus long-term
Lead and lag indicators
The balance scorecard — — — — —
is meant for the use of only the senior level executives
Cannot be linked to the IT goals and objectives
Cannot be the basis for performance incentives
Can be cascaded down to all the levels of the organisation
Strategic position, strategic options and strategy implementation are three of the four basic elements of the CIMA strategic scorecard. What is the fourth element?
Strategic risks
Strategic conformance
Strategic performance
Strategic IT
During 2009, the Satyam computers candle broke out. The companies chairman admitted to falsification of accounts to the tune of US dollar 1.47 billion. The auditors for this company were mainly exposed to what type of risk?
Audit risk
Financial risk
Procedural risk
IT risk
COBIT define six control objectives for application controls. Under which of the following objectives does validating input data classify?
Data collection and entry
Complete and authenticity checks
Processing integrity and validity
Transaction authentication and integrity
Which of the following would an IS auditor consider the most relevant to short-term planning for the IS department?
Allocating resources
Keeping current with Technology advances
Conducting control self assessment
Evaluating hardware needs
Which of the following goals would you expect to find in an organisation strategic plan?
Test a new accounting package
Perform an evaluation of information technology needs
Implement a new project planning system within the next 12 months
Become the supplier of choice for the product offered
which of the following would an IS auditor considered to be the most important when evaluating an organisation IS strategy? That is.:
Has been approved by the line management
Does not vary from the IS departments, preliminary budget
Complies with procurement procedures
Supports the business objectives of the organisation
An IS auditor reviewing and organisation’s IT strategic plan should first REVIEW:
The existing IT environment
The business plan
The present IT budget
Current technology trends
When reviewing IS strategies, the IS auditor can best assess whether IS strategy supports the organisations business objectives by determining if IS
Has all the personal and equipment that needs
Plans are consistent with management strategy
Uses its equipment and personal effectively and efficiently
Has sufficient excess capacity to respond to changing directions
The advantage of a bottom of approach to the development of organisational policies is that the policies:
Are developed for the organisation as a whole
Are more likely to be derived as a result of risk assessment
Will not conflict with overall corporate policy
Ensure consistency across the organisation
which of the following is the greatest risk of an inadequate policy definition for ownership of data and systems?
User management coordination does not exist
Specific user accountability cannot be established
Unauthorised users may have access to originate, modify or delete data
Audit recommendations may not be implemented
The primary objective of an audit of IT security policies is to ensure that:
They are distributed and available to all staff
Security and control policies, support business and IT objectives
There is a published organisational chart with functional descriptions
Duties are appropriately segregated
