Regarding the risk management three-lines-of-defense model, which of the following dominates the second line of defense?
Blog
Assume that the governance committee states that all project…
Assume that the governance committee states that all projects costing more than $70,000 must be reviewed and approved by the chief information officer (CIO) and the IT senior leadership team (SLT). At this point, the CIO has the responsibility to ensure that management processes observe governance rules. For example, the project team might present the proposed project in an SLT meeting for a vote of approval. What does this scenario illustrate about organizational structure?
True or False? A procedure is a high-level statement, belief…
True or False? A procedure is a high-level statement, belief, goal, or objective.
True or False? A good source for information on continuous i…
True or False? A good source for information on continuous improvement is an employee departing an organization.
Hajar is an IT auditor. She needs to perform a regulatory co…
Hajar is an IT auditor. She needs to perform a regulatory compliance audit of an IT infrastructure. Which of the following is the least useful resource for this situation?
True or False? Motivated employees are more likely to embrac…
True or False? Motivated employees are more likely to embrace the implementation of security policies, but this does not correlate to more risks being identified and mitigated for the organization.
The members of the __________ committee help create prioriti…
The members of the __________ committee help create priorities, remove roadblocks, secure funding, and act as a source of authority. Members of the __________ committee provide important information on the risk appetite of the organization.
True or False? One should focus on measuring risk to the bus…
True or False? One should focus on measuring risk to the business as opposed to implementation of policies and control when tying policy adherence to performance measurement.
Particular roles within the seven domains of a typical IT in…
Particular roles within the seven domains of a typical IT infrastructure are responsible for data handling and data quality. Which of the following individuals is responsible for maintaining the quality of data?
Arturo works for a product-testing company. He spends many h…
Arturo works for a product-testing company. He spends many hours testing the optimal settings for a piece of safety equipment used in factories. One day, the company experiences a power surge that alters the data stored in the testing database. As a result, the company uses incorrect data to recommend equipment settings and jeopardizes the safety of factory workers. Which of the following is most closely related to this scenario?