← All CSI Flashcard Decks

CSI Governance and Compliance Flashcards

6 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CSI Governance and Compliance flashcards as text
  1. How does the concept of 'policy' support CSI governance?

    Answer: Policies set mandatory expectations for how CSI activities must be conducted, ensuring consistency and accountability

    CSI policies establish mandatory behaviors — such as always recording improvements in the register or measuring before and after — that ensure governance rigor.

  2. What does 'audit trail' mean in the context of CSI compliance?

    Answer: A chronological record of all improvement decisions, approvals, and changes that provides evidence for auditors and regulators

    An audit trail documents who approved what, when, and why, providing the evidence needed to demonstrate compliance during external reviews.

  3. How does COBIT relate to ITIL CSI?

    Answer: COBIT provides a governance framework for IT that complements ITIL CSI's improvement practices by adding control objectives and accountability

    COBIT's governance and management objectives provide a control framework that organizations can use alongside ITIL CSI to ensure improvement activities are governed effectively.

  4. What is 'continual compliance monitoring' and why is it important for CSI?

    Answer: Ongoing verification that services and processes continue to meet regulatory and policy requirements, feeding non-compliance into CSI

    Continual compliance monitoring identifies drift from required standards in real time, ensuring that non-compliance triggers CSI improvement actions promptly.

  5. Which governance body typically approves significant CSI investment decisions in a large organization?

    Answer: IT Steering Committee or equivalent senior leadership body

    Major CSI investments require approval at the strategic governance level, typically an IT Steering Committee that balances IT priorities with business objectives.

  6. How does risk management intersect with CSI governance?

    Answer: CSI improvement plans must consider risks associated with making changes, and risk management provides the framework for assessing and mitigating them

    Every improvement carries implementation risk; integrating risk management ensures that CSI changes are assessed and controlled appropriately.

CSI Governance and Compliance Flashcards — CSI Study Cards with Answers