Free CGEIT Exam Braindumps (page: 43)

Page 42 of 119

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

  1. risk management reporting tool to ensure compliance.
  2. balanced scorecard that includes IT risks.
  3. risk management committee to identify IT-related risks.
  4. risk management framework.

Answer(s): C



An independent consultant has been hired to conduct an ad hoc audit of an enterprise's information security office with results reported to the IT governance committee and the board. Which of the following is MOST important to provide to the consultant before the audit begins?

  1. The scope and stakeholders of the audit
  2. The organizational structure of the security office
  3. The polices and framework used by the security office
  4. Acceptance of the audit risks and opportunities

Answer(s): A



The PRIMARY reason for using quantitative criteria in developing business cases for IT projects is to:

  1. benchmark project success with similar enterprises.
  2. learn lessons from errors made in past projects.
  3. improve the process of evaluating returns after implementation.
  4. apply other corporate standards to the development project.

Answer(s): C



A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?

  1. CIO
  2. CEO
  3. IT strategy committee
  4. Human resource director

Answer(s): C






Post your Comments and Discuss ISACA CGEIT exam with other Community members:

CGEIT Discussions & Posts