An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following is the BEST method for determining an enterprise's current appetite for risk?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
Which of the following is the MOST important attribute of an information steward?
An enterprise is evaluating a possible strategic initiative for which IT would be the main driver. There are several risk scenarios associated with the initiative that have been identified. Which of the following should be done FIRST to facilitate a decision?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
Which of the following is the BEST indication of effective IT-business strategic alignment?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
From a governance perspective, which of the following roles is MOST important for an enterprise to keep in-house?
The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department will assume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?
A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by:
A manufacturing company has recently decided to outsource portions of its IT operations. Which of the following would BEST justify this decision?
The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:
The board of a start-up company has directed the CIO to develop a technology resource acquisition and management policy. Which of the following should be the MOST important consideration during the development of this policy?
An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
Which of the following is PRIMARILY achieved through performance measurement?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
Which of the following components of a policy BEST enables the governance of enterprise IT?
A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should be the FIRST governance action?
An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?
The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing new capabilities which must be learned. Which of the following would be the BEST action performed by senior management?
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
Which of the following is the BEST course of action to enable effective resource management?
An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. Which of the following would help ensure that the initiatives meet their goals?
Which of the following BEST reflects mature risk management in an enterprise?
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?
Which of the following is MOST critical for the successful implementation of an IT process?
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
An enterprise is planning a change in business direction. As a result, IT risk will significantly increase. Which of the following should be the GO'S FIRST course of action?
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
When determining the optimal IT service levels to support business, which of the following is MOST important?
The PRIMARY benefit of integrating IT resource planning into enterprise strategic planning is that it enables the enterprise to:
The use of an IT balanced scorecard enables the realization of business value of IT through:
Which of the following should be management's GREATEST consideration when trying to optimize the use of benefits from IT?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
When deciding to develop a system with sensitive data, which of the following is MOST important to include in a business case?
A newly hired CIO has been told the enterprise has an established IT governance process, but finds it is not being followed. To address this problem, the CIO should FIRST
When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?
An airline wants to launch a new program involving the use of artificial intelligence (Al) and machine learning the mam objective of the program is to use customer behavior to determine new routes and markets Which of the following should be done NEXT?
Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
Which of the following provides the BEST evidence of effective IT governance?
An enterprise will be adopting wearable technology to improve business performance Whtch of the following would be the BEST way for the CIO to validate IPs preparedness for this initiative?
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
Which of the following provides the BEST information to assess the effective alignment of IT investments?
A CIO just received a final audit report that indicates there is inconsistent enforcement of the enterprise's mobile device acceptable use policy throughout all business units. Which of the following should be the FIRST step to address this issue?
An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?
Which of the following should IT governance mandate before any transition of data from a legacy system to a new technology platform?
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
Which of the following are the MOST important processes for information asset life cycle management?
A software company's products have had significant quality issues in recent releases. As a result, market reputation and customer satisfaction ratings have been suffering. What should executive leadership do FIRST to address this concern?
Which of the following aspects of IT governance BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country?
A multinational enterprise is planning to migrate to cloud-based systems. Which of the following should be of MOST concern to the risk management committee?
Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?
When developing an IT governance framework, it is MOST important for an enterprise to consider:
When developing a business case for an enterprise resource planning (ERP) implementation, which of the following, if overlooked, causes the GREATEST impact to the enterprise?
Which of the following provides the MOST comprehensive insight into the effectiveness of IT?
To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:
Which of the following should be the FIRST step in planning an IT governance implementation?
The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees’ BEST action to address the board's concern is to:
Which of the following is the BEST way to implement effective IT risk management?
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:
Which of the following is the MOST important consideration when developing a new IT service'?
An enterprise is considering outsourcing non-core IT processes Which of the following should be the FIRST step?
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
The PRIMARY benefit of using an IT service catalog as part of the IT governance program is that it.
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
Which of the following would provide the MOST useful information to understand the associated risks when implementing a new digital transformation strategy?
Which of the following BEST facilitates governance oversight of data protection measures?
An IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor Although the vendor met the SLAs business owner expectations are not met and senior management cancels the contract This situation can be avoided in the future by:
An enterprise has committed to the implementation of a new IT governance model. The BEST way to begin this implementation is to:
Which of the following is the GREATEST benefit of using a quantitative risk assessment method?
The CIO of a large enterprise has taken the necessary steps to align IT objectives with business objectives. What is the BEST way for the CIO to ensure these objectives are delivered effectively by IT staff?
Which of the following is MOST important to review during IT strategy development?
Which of the following BEST enables an enterprise to determine how business expectations should be addressed in a governance program?
Which of the following BEST facilitates the standardization of IT vendor selection?
To meet the growing demands of a newly established business unit, IT senior management has been tasked with changing the current IT organization model to
service-oriented. With significant growth expected of the IT organization, which of the following is the MOST important consideration when planning for long-term IT
service delivery?
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
The MOST effective way to ensure that IT supports the agile needs of an enterprise is to:
The CIO of an international enterprise is considering the use of an offshore cloud service provider to store customer data. Which of the following should be the MOST important consideration when making this decision?
Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?
Which of the following will BEST enable an enterprise to convey IT governance direction and objectives?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
Which of the following BEST enables effective enterprise risk management (ERM)?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
Which of the following is the MOST important consideration regarding IT measures as part of an IT strategic plan?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators.
The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?
Which of the following metrics is MOST useful to ensure IT services meet business requirements?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
The accountability for a business continuity program for business-critical systems is BEST assigned to the:
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?
Which of the following is the BEST indication that an implementation plan for a new governance initiative will be successful?
The MOST appropriate method for evaluating the capability of IT governance is through the use of:
Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
What is the BEST way for IT to achieve compliance with regulatory requirements?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
Which of the following is MOST important to include in the customer dimension of an IT balanced scorecard?
A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Which of the following is the PRIMARY consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method?
An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?
Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?
Which of the following is the MOST efficient way for an IT transformation project manager to communicate the project progress with stakeholders?
A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?
Which of the following is necessary for effective risk management in IT governance?
Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
Which of the following characteristics would BEST indicate that an IT process is a good candidate for outsourcing?
Which of the following roles is directly responsible for information quality?
Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?
A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:
Which of the following is the MOST important reason that IT strategic planning processes need to be adequately documented and communicated?
Which of the following BEST enables an enterprise to achieve the benefits of implementing new Internet of Things (loT) technology?
Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?