Understanding and Defining IT Governance

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/71

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

72 Terms

1
New cards

IT governance framework

Outlines how leadership accomplishes delivery of mission-critical business capabilities using IT strategies, goals, and objectives

2
New cards

Data governance policies

Focus on effective management of data, ensuring availability, integrity, usability, and security

3
New cards

Availability

Data should be available to the right employees at the right time

4
New cards

Integrity

Data must have proper integrity, with no missing, duplicate, or mismatched values

5
New cards

Usable format

Data must be in a usable format for easy interpretation and analysis

6
New cards

Security

Data must be secure, especially personally identifiable and regulatorily constrained information

7
New cards

Architecture

Job roles and IT applications designed to fulfill governance objectives

8
New cards

Metadata

Data describing other data, robust in terms of breadth and specificity

9
New cards

Policy

Translates management and governance objectives into practice

10
New cards

Quality

Ensures data has no anomalies, such as missing, duplicate, or mismatched values

11
New cards

Regulatory compliance and privacy

Secures personally identifiable and regulatorily constrained data

12
New cards

Security

Preserves, stores, and transmits data securely

13
New cards

COSO Internal Control--Integrated Framework

Governance framework with general controls over technology to achieve organizational objectives

14
New cards

Control activities

General controls over technology to achieve organizational objectives

15
New cards

Information and communication

Acquiring, creating, and using quality information to support internal controls

16
New cards

ISACA's Control Objectives for Information and Related Technology (COBIT) framework

Distinguishes between governance and management, recognizing them as two unique disciplines

17
New cards

Organizational governance

Responsibility of board of directors, focusing on organizational structure

18
New cards

Management

Responsible for daily planning and administration of operations

19
New cards

Aligning IT Governance with Organizational Objectives

Designing IT governance to facilitate the achievement of the company's vision and corporate strategy

20
New cards

Vision

Company's aspiration and goals, IT governance should support the achievement of that vision

21
New cards

Corporate strategy

The way in which an organization achieves its goals and objectives

22
New cards

IT strategy

Aligning IT strategy with corporate strategy objectives to optimize achievement of those objectives

23
New cards

Documentation

Strategy and architecture provide a strong understanding of the organization's capabilities

24
New cards

Virtual/physical network design

Companies choose between physical or virtual network design based on power needs and demand spikes

25
New cards

Centralized/decentralized network design

Companies choose between centralized or decentralized network design based on range of locations and control needs

26
New cards

Cybersecurity

More of a concern for companies with large regulatory burden or compliance

27
New cards

Disaster recovery and business continuity

Speed can vary greatly based on industry, ensuring business continuity and recovery plans

28
New cards

Available IT personnel

Staffing for IT needs can be insourced, outsourced, or a combination

29
New cards

Support functions

HR, marketing, legal, internal audit, determine IT strategy and expertise needed

30
New cards

Structuring and Executing IT Governance

Involves decision makers at all levels and various IT support staff

31
New cards

Board of directors

Evaluates IT governance policies and ensures they meet strategic and operational needs

32
New cards

Executive management

Makes key strategic decisions and ensures effective execution of IT governance

33
New cards

Middle management

Carries out governance policies and ensures subordinates follow them

34
New cards

IT support staff

Responsible for daily planning and execution of governance policies

35
New cards

Network engineers

Design and maintain a company's network infrastructure

36
New cards

Help desk and lower-level IT support

Provide troubleshooting and support for end users

37
New cards

Cybersecurity staff

Ensure safe and secure usage of company data and IT assets

38
New cards

Function-specific staff

Accountants, project development teams, testers, end users

39
New cards

External stakeholders

Customers, vendors, auditors, regulators influence IT governance structure

40
New cards

Processes for governance execution

Project development teams and steering committees oversee IT governance

41
New cards

Project development teams

Formed for new IT projects, responsible for planning, design, and monitoring

42
New cards

Steering committees

Oversee information systems function, set governing policies, provide guidance

43
New cards

Assessing IT Governance Risks

Performed through business impact analysis (BIA) to identify essential processes and resources

44
New cards

Business impact analysis (BIA)

Identifies essential business units, processes, resources, and required IT resources

45
New cards

Impact

High, moderate, or low impact of a risk on department or organization

46
New cards

Likelihood

High, medium, or low likelihood of a risk occurring

47
New cards

Evaluate outcomes

Take appropriate corrective action based on the impact and likelihood of risks

48
New cards

Implement the response

Identify and evaluate mitigation recommendations, choose, plan, and implement

49
New cards

System and Organization Controls (SOC)

Reports provide assurance on controls and information systems

50
New cards

SOC 1

Reports on controls for financial statements and operational needs

51
New cards

SOC 2

Reports on controls related to security, processing integrity, availability, and privacy

52
New cards

SOC 3

Similar to SOC 2, provides attestation on controls related to security, processing integrity, availability, and privacy

53
New cards

Data and Information Management

Storing, managing, and analyzing data for decision-making purposes

54
New cards

Relational databases

Efficient method to store and manage data with tables, attributes, records, and fields

55
New cards

Data queries and reports

Extracting data using SQL commands and generating reports

56
New cards

Extract, Transform, and Load (ETL)

Process of extracting, transforming, and loading data for analysis

57
New cards

Data storage

Operational data store, data warehouse, data mart, and data lake

58
New cards

Entity integrity

Each table must have a unique primary key as a record identifier

59
New cards

Referential integrity

Changes to primary keys must also cause changes to related foreign keys

60
New cards

Data analytics

Process of transforming raw data into insights for decision-making

61
New cards

Descriptive analytics

Summarizes and observes data to indicate what happened

62
New cards

Diagnostic analytics

Uncover correlations and patterns to explain why an event happened

63
New cards

Predictive analytics

Forecast future data points based on historical data

64
New cards

Prescriptive analytics

Recommends optimal actions to achieve desired outcomes

65
New cards

Data visualizations

Representing data in visual formats for easier understanding

66
New cards

Line chart

Shows quantitative trends over time

67
New cards

Column chart

Effective for comparisons

68
New cards

Scatter plot

Demonstrates relationships between variables

69
New cards

Pie chart

Shows proportions of a whole value

70
New cards

Flowchart

Maps out a process with steps and decision points

71
New cards

Waterfall chart

Shows cumulative effect of a series of data points

72
New cards

Data visualization considerations

Scale, legends, bias, time periods, colors, titles, labels