Which of the following BEST indicates the success of an enterprise's IT governance framework after implementation?
In an enterprise that has worldwide business units and a centralized financial control model, which of the following is a barrier to strategic alignment of business and IT?
To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:
Which of the following is MOST important for an IT strategy committee to ensure before initiating the development of an IT strategic plan?
A software company's products have had significant quality issues in recent releases. As a result, market reputation and customer satisfaction ratings have been suffering. What should executive leadership do FIRST to address this concern?
Which of the following is the MOST significant challenge faced by an enterprise when establishing information stewardship?
Which of the following provides the MOST comprehensive insight into the effectiveness of IT?
Facing financial struggles, a CEO mandated severe budget cuts. A decision was also made to immediately change the enterprise strategic focus to put more reliance on mobile, cloud, and wireless services in an effort to boost revenue. The IT steering committee has asked the CIO to suggest adjustments to the current IT project portfolio to allow support for the new direction despite fewer funds. What should the CIO advise the committee to do FIRST?
Which of the following metrics would provide senior management with the BEST indication of the success of IT investments?
Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?
An enterprise is conducting a SWOT analysis as part of IT strategy development. Which of the following would be MOST helpful to identify opportunities and threats?
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
An enterprise is planning to outsource data processing for personally identifiable information (Pll). When is the MOST appropriate time to define the requirements for security and privacy of information?
An assessment reveals that enterprise risk management (ERM) practices are being applied inconsistently by IT staff. Which of the following would be the MOST effective corrective action?
Which of the following should occur FIRST in the IT investment process?
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?
Which of the following should IT governance mandate before any transition of data from a legacy system to a new technology platform?
A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?
An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?
Which of the following would be the BEST way to facilitate the successful adoption of a new technology across the enterprise?
Which of the following is MOST important to include in IT governance reporting to the board of directors?
The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:
A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?
When evaluating the process for acquiring third-party IT resources, management identified several suppliers with repeated downtime issues impacting the enterprise. Which of the following is the BEST approach to help ensure future service delivery in accordance with business objectives?
An IT department has forwarded a request to the IT strategy committee for funding of a discretionary Investment. The committee's MOST important consideration should be to evaluate:
Which of the following is MOST important for IT governance to have in place to ensure the enterprise can maintain operations during extensive system downtime?
IT maturity models measure:
Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?
Which of the following is the BEST method to confirm whether a pilot project was successful?
An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:
When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:
To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?
An IT steering committee is concerned that enterprise technologies have grown stagnant and are outdated. Which of the following is the BEST strategy to invest in modern technology?
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
Which of the following are the MOST important processes for information asset life cycle management?
An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on:
A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
The BEST time to identity metrics to measure the performance of an IT-enabled investment is during:
Which of the following is the MOST important input for the development of a human resources strategy to address IT skill gaps?
Which of the following is the MOST important input for designing a development program to help IT employees improve their ability to respond to business needs?
An enterprise has performed a business impact analysis (BIA) considering a number of risk scenarios Which of the following should the enterprise do NEXT?
Which of the following should be the PRIMARY basis for establishing categories within an information classification scheme?
The PRIMARY objective of building outcome measures is to:
An airline wants to launch a new program involving the use of artificial intelligence (Al) and machine learning the mam objective of the program is to use customer behavior to determine new routes and markets Which of the following should be done NEXT?
A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?
Which of the following is the BEST way for an organization to minimize the difference between expected and delivered services when acquiring resources?
An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?
In which of the following situations is it MOST appropriate to use a quantitative risk assessment?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
IT senior management has just received a survey report indicating that more than one third of the organization's key IT staff plan to retire within the next 12 months. Which of the following is the MOST important governance action to prepare for this possibility?
From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:
Of the following, who is PRIMARILY responsible for applying frameworks for the governance of IT to balance the need for security controls with business requirements?
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?
Which of the following has the GREATEST impact on the design of an IT governance framework?
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?
Which of the following is the PRIMARY reason to monitor data classification efforts?
The BEST way for a CIO to manage the organizational impact of deploying a new enterprise-wide tool is to implement:
To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
An organization has decided to integrate IT risk with the enterprise risk management (ERM) framework. The FIRST step to enable this integration is to establish:
An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?
To help ensure the IT portfolio provides maximum value to an organization, IT projects are BEST prioritized based on:
An enterprise is exploring a new business opportunity. Which of the following is the BEST way to help ensure related IT projects deliver the business requirements?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
Which of the following is the PRIMARY role of the CEO in IT governance?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
Which of the following is the MOST important consideration regarding IT measures as part of an IT strategic plan?
Which of the following is necessary for effective risk management in IT governance?
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?
ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?
A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
Which of the following is the BEST way to address the risk associated with new IT investments?
An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?
An enterprise has launched a critical new IT initiative that is expected to produce substantial value. Which of the following would BEST facilitate the reporting of benefits realized by the IT investment to the board?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Which of the following is a CIO's BEST approach to ensure IT executes against an approved strategy?
An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
What is the BEST way for IT to achieve compliance with regulatory requirements?
Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
Which of the following will BEST enable an enterprise to convey IT governance direction and objectives?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?
Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
When a shortfall of IT resources is identified, the FIRST course of action is to;
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?
Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?
An enterprise plans to expand into new markets in countries lacking data privacy regulations, increasing risk exposure. Which of the following is the BEST course of action for the CIO?
Which of the following is the MOST important attribute of an information steward?
A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?
The results of an internal audit show that the business and IT acquire resources differently, which causes duplicate purchases. Which of the following is the BEST way to address this issue?
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:
A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
The use of an IT balanced scorecard enables the realization of business value of IT through:
An enterprise's internal audit group has scheduled a control review of a payroll system project but has been told to wait until the system is implemented. Which of the following is the GREATEST risk associated with the delay?
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
Which of the following is the BEST course of action to enable effective resource management?
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention. What is the PRIMARY reason this situation should be escalated to the IT steering committee?
Which of the following roles has PRIMARY accountability for the security related to data assets?
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?
A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?
An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?
An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
Which of the following is MOST important to effectively initiate IT-enabled change?
An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?
Risk management strategies are PRIMARILY adopted to:
Which of the following is the BEST method to monitor IT governance effectiveness?
The MOST successful IT performance metrics are those that:
An enterprise can BEST assess the benefits of a new IT project through its life cycle by:
An enterprise is evaluating a Software as a Service (SaaS) solution to support a core business process. There is no outsourcing governance or vendor management in place. What should be the CEO's FIRST course of action?
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
A CEO determines the enterprise is lagging behind its competitors in consumer mobile offerings, and mandates an aggressive rollout of several new mobile services within the next 12 months. To ensure the IT organization is capable of supporting this business objective, what should the CIO do FIRST?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?
Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?
A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
A manufacturing company has recently decided to outsource portions of its IT operations. Which of the following would BEST justify this decision?
A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
The BEST way to manage an outsourced vendor relationship is by:
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
When developing effective metrics for the measurement of solution delivery, it is MOST important to:
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
Which of the following BEST reflects the ethical values adopted by an IT organization?
The BEST way to ensure an IT steering committee meets enterprise objectives is to:
Which of the following should be the MOST important consideration when defining an information architecture?
An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
An analysis of an organization s security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review: