712-50 · Question #129
Which of the following is considered to be an IT governance framework and a supporting toolset that allows for managers to bridge the gap between control requirements, technical issues, and business…
The correct answer is A. Control Objective for Information Technology (COBIT). COBIT (Control Objectives for Information Technology) is specifically designed as an IT governance framework that bridges the gap between business risks, control requirements, and technical issues - making it the only option that fits all three criteria in the question. Why the…
Question
Which of the following is considered to be an IT governance framework and a supporting toolset that allows for managers to bridge the gap between control requirements, technical issues, and business risks?
Options
- AControl Objective for Information Technology (COBIT)
- BCommittee of Sponsoring Organizations (COSO)
- CPayment Card Industry (PCI)
- DInformation Technology Infrastructure Library (ITIL)
How the community answered
(22 responses)- A82% (18)
- B5% (1)
- C5% (1)
- D9% (2)
Explanation
COBIT (Control Objectives for Information Technology) is specifically designed as an IT governance framework that bridges the gap between business risks, control requirements, and technical issues - making it the only option that fits all three criteria in the question.
Why the distractors are wrong:
- COSO is an internal control and enterprise risk management framework, but it's focused on financial reporting and broader organizational controls, not IT-specific governance
- PCI (Payment Card Industry Data Security Standard) is a compliance/security standard for handling cardholder data, not a governance framework
- ITIL is an IT service management framework focused on delivering IT services efficiently - it's a best-practice library, not a governance and control framework
Memory tip: Think of COBIT = Control + Bridge - the word "Control" is right in the name (Control Objectives), and its purpose is to bridge business and IT. If a question mentions bridging business risk with IT controls, COBIT is almost always the answer.
Topics
Community Discussion
No community discussion yet for this question.