

![]()


This course explores the frameworks, practices, and regulations that guide the effective management and oversight of information technology within organizations. Students will learn how IT governance aligns technology strategies with business goals, manages risks, and ensures compliance with relevant laws, standards, and ethical guidelines. Emphasis is placed on understanding control mechanisms, policy development, audit processes, and compliance requirements such as GDPR, HIPAA, and SOX. By examining real-world cases and industry standards like COBIT and ISO/IEC 38500, students gain practical skills for implementing governance structures that foster transparency, accountability, and value creation in the use of IT resources.
Recommended Textbook
Information Security and IT Risk Management 1st Edition by Manish Agrawal
Available Study Resources on Quizplus
14 Chapters
349 Verified Questions
349 Flashcards
Source URL: https://quizplus.com/study-set/3541 Page 2
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70324
Sample Questions
Q1) Information security professional report spending a lot of time on
A) Researching new technologies
B) Political issues
C) Developing internal security policies, standards and procedures
D) Fixing software bugs
Answer: D
Q2) Confidentiality is
A) Protecting information and information systems from unauthorized use
B) Preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information Choices
C) Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity
D) Ensuring timely and reliable access to and use of information
Answer: B
To view all questions and flashcards with answers, click on the resource link above.

3

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70325
Sample Questions
Q1) Writing the necessary data in the appropriate locations on a computer 's hard drive for running a software program is called
A) Configuration
B) Access control
C) Installation
D) User management
Answer: C
Q2) The types of monitoring include
A) Penetration testing and access control
B) Health checking and log monitoring
C) Nagios and log monitoring
D) Reactive monitoring and pro-active testing
Answer: D
Q3) The domain controller in Active Directory
A) Serves web pages in the domain
B) Bills users in the domain
C) Implements the active directory rules in the domain
D) Installs updated on all computers in the domain
Answer: C
To view all questions and flashcards with answers, click on the resource link above.
Page 4

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70326
Sample Questions
Q1) To view the contents of a file, we can use the command
A) less
B) more
C) cat
D) all of the above
Answer: D
Q2) In the context of system administration, the shell is
A) Software that manages computer hardware and provides common services to user applications
B) Software which controls hardware devices, manages memory, and hides underlying physical hardware from user applications
C) A text based program that allows users to interact with the shell
D) The graphical interface for users to interact with applications
Answer: C
Q3) The command used to copy files in Unix/ Linus is
A) cp
B) copy
C) pwd
D) rm
Answer: A
To view all questions and flashcards with answers, click on the resource link above. Page 5

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70327
Sample Questions
Q1) Threats are
A) Safeguards used to minimize the impact of threats
B) Capabilities, intentions and attack methods of adversaries to cause harm to assets
C) Resource or information that is to be protected
D) Weaknesses in an information system that can lead to a compromise of an asset
Q2) Vulnerabilities in IT systems can be eliminated through secure coding practices
A)True
B)False
Q3) Relative to physical security, information security is challenging because
A) Assets are largely invisible
B) Most assets are easily duplicated
C) Both the above
D) None of the above
Q4) Zero-day exploits are
A) Software used to hide the existence of malicious software on computer systems
B) Exploits that compromise a previously unknown software vulnerability
C) Computers that perform malicious tasks at the direction of a remote controller
D) Manipulating people into performing desired actions
To view all questions and flashcards with answers, click on the resource link above.
6

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70328
Sample Questions
Q1) Essential assets are those whose loss of availability
A) Could be acceptable
B) Could be tolerated for a short period of time
C) Could cause confidentiality breaches
D) Would cause immediate severe repercussions to the organization
Q2) An example of a top-down approach to asset identification is
A) Reading the mission statement of the organization
B) Talking to co-workers
C) Reading on-boarding documentation
D) All of the above
Q3) Restricted assets are
A) Assets whose loss would cause severe repercussions to the organization immediately
B) Importance of an asset to the immediate survival of an organization
C) The damage caused to an organization from a breach of confidentiality or integrity of an asset
D) Assets whose disclosure or alteration would have adverse consequences for the organization
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70329
Sample Questions
Q1) Most attacks on organizations originate from
A) Internal agents
B) External agents
C) Partners
D) Competitors, organized groups and former employees
Q2) The threat model includes
A) Actors, agents and assistants
B) Actions, assets and ambitions
C) Agents, actions and assets
D) Agents, actors and assets
Q3) Phishing is
A) An activity performed by agents to compromise assets
B) Convincing users to do something they would not ordinarily do
C) Using email to try and get a user to divulge confidential information
D) Malicious content entered by an end user on a web-based system
Q4) In the information security context, Black Tuesday refers to
A) The day Google's stock fell by 50% immediately after its IPO
B) The day a company finally turns profitable for the year
C) The day the firm lost a bulk of its email
D) The typical day on which Microsoft releases patches
To view all questions and flashcards with answers, click on the resource link above. Page 8

Available Study Resources on Quizplus for this Chatper
24 Verified Questions
24 Flashcards
Source URL: https://quizplus.com/quiz/70330
Sample Questions
Q1) The first documented instance of encryption was used by
A) Egyptian pharaoh Tutankhamun
B) Italian inventor Leonardo da Vinci
C) Italian artist Michelangelo
D) Roman Emperor Julius Caesar
Q2) Claude Shannon developed the framework for secrecy known as
A) Confusion diffusion
B) 4P model
C) 4C model
D) Inversion of control
Q3) The current standard for secret key encryption is
A) DES Data Encryption Standard
B) AES Advanced Encryption Standard
C) IDEA International Data Encryption Algorithm
D) SHA Secure Hash Algorithm
Q4) The popular encryption method RSA is an example of
A) Secret key encryption
B) Public key encryption
C) Hash functions
D) AES
To view all questions and flashcards with answers, click on the resource link above. Page 9

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70331
Sample Questions
Q1) The stages in identity management are
A) Denial, anger, bargaining, acceptance
B) Plan, do, check, act
C) Plan, acquire, deploy, manage
D) Discovery, reconciliation and enrichment
Q2) OpenID uses an
A) Insecure model of authentication
B) Centralized model for authentication
C) Federated model for authentication
D) Distributed model for authentication
Q3) Identity reconciliation involves
A) Locating all new and updated identities in the organization
B) Comparing each discovered identity to a master record of all individuals in the organization
C) Collecting data about each individual's relationship to the organization
D) Making decisions about granting users access to resources
Q4) Kerberos has been very useful in securing web applications
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 10
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70332
Sample Questions
Q1) Considerations while prioritizing patches include all of the following except the A) Importance of the vulnerability
B) Importance of the system to be patched
C) Licensing costs
D) Dependencies with other patches
Q2) In enterprise networks, power users can facilitate patch management by
A) Administering as much of the patch management themselves as possible
B) Setting automatic updates to as many services and software as possible
C) Using department funds to deploy local patch management systems to as many systems as possible
D) Allowing system administrators to controls as much of the patch management as possible
Q3) A password policy is
A) A set of rules for using passwords
B) Acquiring passwords from storage, network transmission or user knowledge
C) Repeated attempts to authenticate using possible passwords
D) Generating character strings to match existing passwords
To view all questions and flashcards with answers, click on the resource link above.

11
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70333
Sample Questions
Q1) The command to view the contents of a variable at the shell prompt is
A) variablename
B) echo variablename
C) echo $variablename
D) $variablename
Q2) The first line of an executable script needs to be #!/bin/bash, in order to
A) Inform the shell which shell interpreter to use to execute the script
B) Remind the user of the shell interpreter to use when executing the script
C) Remind the user of the shell interpreter used to create the script
D) Serve as a comment for the shell interpreter when executing the script
Q3) Shell scripts are
A) A list of shell commands in a text file
B) Scripts used as a shell, with no content until used
C) A type of compiled programs
D) Lists of drugs prescribed by a physician
Q4) A user needs the following permissions to be able to use a script as a command
A) Read and write
B) Write
C) Read
D) Execute

Page 12
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70334
Sample Questions
Q1) In the context of monitoring, a false positive is
A) An undetected problem
B) A component that is working intermittently
C) A component that is likely to fail soon
D) An alert that upon further investigation turns out to be not a problem
Q2) Performance records of a machine are called
A) Configuration files
B) Sysadmin
C) Logs
D) Debian
Q3) Containment is
A) Saving log files in a server container configured specially for this purpose
B) Preventing the expansion of harm
C) Removing the causes of the adverse event
D) Returning systems to owners for normal operations after the incident
Q4) Eradication is
A) Saving log files in a server container configured specially for this purpose
B) Preventing the expansion of harm
C) Removing the causes of the adverse event
D) Returning systems to owners for normal operations after the incident
To view all questions and flashcards with answers, click on the resource link above. Page 13

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70335
Sample Questions
Q1) Windows logs are also known as
A) Microsoft logs
B) Application logs
C) Operating system logs
D) Event logs
Q2) Developers use logs to
A) Analyze security incidents
B) Ensure that the application is behaving as expected
C) Monitor disk space requirements of applications
D) Ensure optimum performance of the application
Q3) File timestamps are known as MAC timestamps, where MAC stands for
A) Medium access control
B) Modification, access, creation
C) Multiple account creation
D) Media, agent and creativity
Q4) In IT, BYOD stands for
A) Bring your own drink
B) Buy your own drink
C) Buy your own dress'
D) Bring your own device
To view all questions and flashcards with answers, click on the resource link above. Page 14

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70336
Sample Questions
Q1) The need for the policy is specified in the
A) Scope
B) Statement
C) Overview
D) Enforcement
Q2) A policy is
A) Procedures that tell units when it would be nice if things were operated a certain way, but it is not a requirement to do so
B) Guidelines to users and customers on what is appropriate and what is not appropriate to do with information technology resources
C) A document that records a high-level principle or course of action that has been decided on
D) A defined set of rules, accepted and adopted by several organizations
Q3) To minimize ambiguity, it is a good idea to specify the technologies to be used in a policy
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 15

Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70337
Sample Questions
Q1) Risk is quantified by taking the product of
A) Hours and hourly rates
B) GDP and growth rate
C) Likelihood and magnitude
D) Risk frame and risk assessment
Q2) The NIST risk management framework includes
A) Profits, losses
B) Agent, action, asset
C) Assets, threats, vulnerabilities, controls
D) Frame, assess, monitor, respond
Q3) Risk is
A) A quantified measure of the potential damage caused by a specified threat
B) Capabilities, intentions and attack methods of adversaries to cause harm to assets
C) Resource or information that is to be protected
D) Weaknesses in an information system that can lead to a compromise of an asset
Q4) A given threat is usually associated with one risk
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 16